Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Problems With Popup, Need Some Help


  • Please log in to reply
29 replies to this topic

#1 bassbone

bassbone

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 17 August 2008 - 01:24 AM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:23:31, on 17.08.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Programfiler\Fellesfiler\PCSuite\Services\ServiceLayer.exe
C:\Programfiler\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Programfiler\ATI Technologies\ATI.ACE\CLI.EXE
C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe
C:\Programfiler\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\taskswitch.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Windows Live\Messenger\msnmsgr.exe
C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programfiler\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\FELLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\Internet Explorer\IEXPLORE.EXE
C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programfiler\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Programfiler\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Eivind\Skrivebord\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programfiler\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ATICCC] "C:\Programfiler\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programfiler\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [AnyDVD] C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Hege')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe (User 'Hege')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [A00F10AB45.exe] C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00F10AB45.exe (User 'Hege')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [A00F3C774F.exe] C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00F3C774F.exe (User 'Hege')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.buypass.no (HKLM)
O15 - Trusted Zone: http://*.headit.no (HKLM)
O15 - Trusted Zone: http://*.norsk-tipping.no (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.eurofoto.no/uploader/ImageUploader4.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D1EA8D3D-F511-4388-B754-4A0CC14A4778} (Aurigma Image Uploader 3.0 Control) - http://www.eurofoto.no/activex/ImageUploader3.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.eurofoto.no/uploader/ImageUploader4.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: __c0016C6C - C:\WINDOWS\system32\__c0016C6C.dat
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Programfiler\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Programfiler\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\Fellesfiler\PCSuite\Services\ServiceLayer.exe

--
End of file - 10939 bytes

BC AdBot (Login to Remove)

 


m

#2 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:12:56 PM

Posted 17 August 2008 - 02:55 PM

Hello bassbone

Welcome to BleepingComputer :thumbsup:
========================
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\__c0016C6C.dat
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
=================
Please visit this web page for instructions for downloading and running Combofix >ComboFix Instructions
We now suggest that you install the Windows Recovery Console.
The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you in the case that your computer has a problem after an attempted removal of malware.

Post the log from ComboFix when you've accomplished all of that, along with a new HijackThis log.

(Note:If the Recovery Console fails to install then do not proceed rather alert me and post back here we will continue)
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#3 bassbone

bassbone
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 17 August 2008 - 04:16 PM

Hi! Thanks :thumbsup:
Here are the requested logfiles:

OTMoveit2

File move failed. C:\WINDOWS\system32\__c0016C6C.dat scheduled to be moved on reboot.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08172008_225140

Files moved on Reboot...
File C:\WINDOWS\system32\__c0016C6C.dat not found!


Combofix

ComboFix 08-08-17.01 - Eivind 2008-08-17 23:01:40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1044.18.972 [GMT 2:00]
Running from: C:\Documents and Settings\Eivind\Skrivebord\ComboFix.exe
* Created a new restore point
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Eivind\Cookies\eivind@ad.yieldmanager[2].txt
C:\Documents and Settings\Eivind\Cookies\eivind@adtrgt[2].txt
C:\Documents and Settings\Eivind\Cookies\eivind@network.adsmarket[1].txt
C:\Documents and Settings\Eivind\UserData
C:\Documents and Settings\Eivind\UserData\2LQ98F2V\oWindowsUpdate[1].xml
C:\Documents and Settings\Eivind\UserData\index.dat
C:\Documents and Settings\Hege\Cookies\hege@adtrgt[2].txt
C:\Documents and Settings\Hege\Cookies\hege@facebook[2].txt
C:\Documents and Settings\Hege\Cookies\hege@network.adsmarket[1].txt
C:\Documents and Settings\Hege\Cookies\hege@network.adsmarket[3].txt
C:\Documents and Settings\Hege\UserData
C:\Documents and Settings\Hege\UserData\1I376ZXZ\confirmauthoringLeftaspx_annkv_Collapsible[1].xml
C:\Documents and Settings\Hege\UserData\B7KDQFSJ\confirmauthoringQuestionnaireaspx_annkv_m1sl[1].xml
C:\Documents and Settings\Hege\UserData\index.dat
C:\Documents and Settings\Hege\UserData\KUHVVVE6\confirmauthoringQuestionnaireaspx_annkv_Collapsible[1].xml
C:\Documents and Settings\Hege\UserData\NOYWVNI8\Tdy58[1].xml
C:\WINDOWS\system32\__c004B5D9.dat
C:\WINDOWS\system32\~.exe
C:\xcrashdump.dat

.
((((((((((((((((((((((((( Files Created from 2008-07-17 to 2008-08-17 )))))))))))))))))))))))))))))))
.

2008-08-17 22:51 . 2008-08-17 22:51 <DIR> d-------- C:\_OTMoveIt
2008-08-15 23:10 . 2008-08-15 23:10 <DIR> d-------- C:\Programfiler\MSECache
2008-08-15 15:16 . 2008-08-17 22:58 <DIR> dr-h----- C:\Documents and Settings\Eivind\Siste
2008-08-14 23:45 . 2008-05-01 16:38 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-14 23:44 . 2008-04-11 21:06 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-12 23:52 . 2008-08-12 23:52 <DIR> dr-h----- C:\Documents and Settings\Hege\Siste
2008-08-09 22:07 . 2008-08-09 22:07 <DIR> d-------- C:\Documents and Settings\Hege\Programdata\Nokia Multimedia Player
2008-08-06 22:27 . 2008-08-06 22:27 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-08-01 15:27 . 2008-08-01 15:27 99,648 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-07-21 14:11 . 2008-07-21 14:11 24,392 --a------ C:\WINDOWS\system32\drivers\ElbyCDIO.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-16 22:10 --------- d-----w C:\Documents and Settings\Eivind\Programdata\Azureus
2008-08-12 21:51 --------- d-----w C:\Programfiler\Macrogaming
2008-08-06 06:53 --------- d-----w C:\Programfiler\Azureus
2008-08-02 17:27 --------- d-----w C:\Programfiler\Java
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-26 11:06 93,128 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll
2008-06-24 16:46 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 13:14 --------- d-----w C:\Programfiler\Windows Live Safety Center
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:49 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-05-28 21:27 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-05-01 21:53 1,212 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot_2008-08-13_23.03.37.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-07 20:26:07 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:50 17,784 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:50 232,824 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:50 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:47 760,696 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:48 385,912 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-07-11 12:51:51 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:19:51 17,784 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:19:51 232,824 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:19:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 12:39:50 760,696 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 12:39:50 385,912 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-06-24 16:54:35 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 12:39:50 17,784 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 12:39:50 232,824 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 12:39:50 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 12:39:50 760,696 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 12:39:50 385,912 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-04-23 04:22:22 124,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
+ 2008-04-23 04:22:22 347,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2008-04-23 04:22:22 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
+ 2008-04-23 04:22:22 133,120 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
+ 2008-04-23 04:22:22 63,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll
+ 2008-04-22 07:43:26 70,656 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2008-04-23 04:22:22 153,088 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
+ 2008-04-23 04:22:22 230,400 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
+ 2008-04-20 05:07:51 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
+ 2008-04-23 04:22:22 383,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll
+ 2008-04-23 04:22:22 384,512 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2008-04-23 04:22:23 6,066,176 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll
+ 2008-04-23 04:22:23 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
+ 2008-04-23 04:22:23 267,776 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll
+ 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
+ 2008-04-22 07:43:46 625,664 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
+ 2008-04-23 04:22:23 27,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
+ 2008-04-23 04:22:23 459,264 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll
+ 2008-04-23 04:22:23 52,224 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll
+ 2008-04-23 20:22:24 3,591,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
+ 2008-04-23 04:22:23 478,208 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
+ 2008-04-23 04:22:23 193,024 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
+ 2008-04-23 04:22:23 671,232 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
+ 2008-04-23 04:22:23 102,912 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
+ 2008-04-23 04:22:23 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-03-06 02:01:51 214,752 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe
+ 2007-03-06 02:03:01 374,496 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll
+ 2008-04-23 04:22:23 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll
+ 2008-04-23 04:22:23 1,159,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
+ 2008-04-23 04:22:23 233,472 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
+ 2008-04-23 04:22:23 826,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
+ 2007-05-10 08:11:42 1,767,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\PPCNV.DLL
+ 2007-03-21 17:00:06 72,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\PXBCOM.EXE
+ 2007-03-21 16:58:40 4,145,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\WRD12CNV.DLL
+ 2007-03-21 16:58:46 24,416 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\WRD12EXE.EXE
+ 2007-05-10 08:25:40 14,677,368 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\XL12CNV.EXE
+ 2007-05-31 11:35:22 6,420,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
- 2008-07-09 21:42:09 593,920 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-08-15 01:06:23 593,920 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-07-09 21:42:09 12,288 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-08-15 01:06:24 12,288 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-07-09 21:42:09 86,016 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-08-15 01:06:24 86,016 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-07-09 21:42:09 135,168 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-08-15 01:06:23 135,168 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-07-09 21:42:09 11,264 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-08-15 01:06:24 11,264 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-07-09 21:42:09 27,136 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-08-15 01:06:24 27,136 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-07-09 21:42:09 4,096 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-08-15 01:06:24 4,096 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-07-09 21:42:09 794,624 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-08-15 01:06:24 794,624 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-07-09 21:42:09 249,856 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-08-15 01:06:23 249,856 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-07-09 21:42:09 61,440 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-08-15 01:06:23 61,440 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-07-09 21:42:09 23,040 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-08-15 01:06:24 23,040 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-07-09 21:42:09 286,720 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-08-15 01:06:23 286,720 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-07-09 21:42:09 409,600 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-08-15 01:06:23 409,600 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-08-17 01:01:24 38,240 ----a-r C:\WINDOWS\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2008-04-23 04:22:22 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-06-23 16:57:25 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
- 2008-04-23 04:22:22 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-06-23 16:57:25 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll
- 2008-04-23 04:22:22 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-06-23 16:57:25 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-04-23 04:22:22 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-06-23 16:57:25 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-07-07 20:29:49 253,952 -c----w C:\WINDOWS\system32\dllcache\es.dll
- 2008-04-23 04:22:22 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-06-23 16:57:26 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-04-23 04:22:22 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-06-23 16:57:26 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
- 2008-04-22 07:43:26 70,656 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-06-23 09:22:59 70,656 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2008-04-23 04:22:22 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-06-23 16:57:27 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2008-04-23 04:22:22 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-06-23 16:57:27 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2008-04-20 05:07:51 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-06-21 05:23:54 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2008-04-23 04:22:22 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-06-23 16:57:27 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2008-04-23 04:22:22 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-06-23 16:57:27 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2008-04-23 04:22:23 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-06-23 16:57:31 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2008-04-23 04:22:23 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-06-23 16:57:31 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2008-04-23 04:22:23 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-06-23 16:57:31 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
- 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2008-04-22 07:43:46 625,664 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-06-23 09:23:15 625,664 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2008-04-23 04:22:23 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-06-23 16:57:33 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-06-24 16:46:40 74,240 -c----w C:\WINDOWS\system32\dllcache\mscms.dll
- 2008-04-23 04:22:23 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-06-23 16:57:33 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
- 2008-04-23 04:22:23 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-06-23 16:57:33 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2008-04-23 20:22:24 3,591,680 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-06-24 08:57:38 3,592,192 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-04-23 04:22:23 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-06-23 16:57:37 477,696 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-04-23 04:22:23 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-06-23 16:57:38 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2008-04-23 04:22:23 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-06-23 16:57:38 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2008-04-23 04:22:23 102,912 -c----w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-06-23 16:57:39 102,912 -c----w C:\WINDOWS\system32\dllcache\occache.dll
- 2008-04-23 04:22:23 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-06-23 16:57:39 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2008-04-23 04:22:23 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-06-23 16:57:39 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll
- 2008-04-23 04:22:23 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-06-23 16:57:39 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-04-23 04:22:23 233,472 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-06-23 16:57:40 233,472 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2008-04-23 04:22:23 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-06-23 16:57:40 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2008-04-23 04:22:22 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-06-23 16:57:25 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-04-23 04:22:22 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-06-23 16:57:25 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-04-23 04:22:22 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-06-23 16:57:26 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2008-06-15 01:06:33 236,760 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-08-17 20:53:42 255,864 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-04-23 04:22:22 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-06-23 16:57:26 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2008-04-22 07:43:26 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-06-23 09:22:59 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2008-04-23 04:22:22 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
+ 2008-06-23 16:57:27 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
- 2008-04-23 04:22:22 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
+ 2008-06-23 16:57:27 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
- 2008-04-20 05:07:51 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2008-06-21 05:23:54 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
- 2008-04-23 04:22:22 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-06-23 16:57:27 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2008-04-23 04:22:22 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-06-23 16:57:27 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
- 2008-04-23 04:22:23 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-06-23 16:57:31 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2008-04-23 04:22:23 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2008-06-23 16:57:31 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
- 2008-04-23 04:22:23 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-06-23 16:57:31 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2008-04-22 07:39:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2008-04-14 16:22:03 691,712 ----a-w C:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 19:06:47 691,712 ----a-w C:\WINDOWS\system32\inetcomm.dll
- 2008-04-23 04:22:23 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-06-23 16:57:33 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2008-06-25 16:15:46 17,972,344 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-08-05 18:11:01 15,888,504 ----a-w C:\WINDOWS\system32\MRT.exe
- 2008-04-23 04:22:23 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-06-23 16:57:33 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2008-04-23 04:22:23 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-06-23 16:57:33 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2008-04-23 20:22:24 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-06-24 08:57:38 3,592,192 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2008-04-23 04:22:23 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-06-23 16:57:37 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2008-04-23 04:22:23 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-06-23 16:57:38 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
- 2008-04-23 04:22:23 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-06-23 16:57:38 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
- 2008-04-23 04:22:23 102,912 ----a-w C:\WINDOWS\system32\occache.dll
+ 2008-06-23 16:57:39 102,912 ----a-w C:\WINDOWS\system32\occache.dll
- 2008-08-12 17:41:11 79,710 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-17 20:58:17 79,710 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-12 17:41:11 88,500 ----a-w C:\WINDOWS\system32\perfc014.dat
+ 2008-08-17 20:58:17 88,500 ----a-w C:\WINDOWS\system32\perfc014.dat
- 2008-08-12 17:41:11 461,918 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-17 20:58:17 461,918 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-08-12 17:41:11 464,504 ----a-w C:\WINDOWS\system32\perfh014.dat
+ 2008-08-17 20:58:17 464,504 ----a-w C:\WINDOWS\system32\perfh014.dat
- 2008-04-23 04:22:23 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-06-23 16:57:39 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2007-11-30 12:39:50 17,784 ------w C:\WINDOWS\system32\spmsg.dll
- 2008-04-14 16:23:14 60,416 ------w C:\WINDOWS\system32\tzchange.exe
+ 2008-07-11 12:42:28 62,976 ------w C:\WINDOWS\system32\tzchange.exe
- 2008-04-23 04:22:23 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-06-23 16:57:39 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2008-04-23 04:22:23 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-06-23 16:57:39 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2008-04-23 04:22:23 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-06-23 16:57:40 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-08-17 20:54:12 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1b4.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 18:22 15360]
"msnmsgr"="C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"PcSync"="C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984]
"AnyDVD"="C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-08-01 15:32 2161600]
"swg"="C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-06 06:31 68856]
"WMPNSCFG"="C:\Programfiler\Windows Media Player\WMPNSCFG.exe" [2006-11-15 11:46 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-01-19 22:40 339968]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-11 00:26 406016]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 12:36 229376]
"ATICCC"="C:\Programfiler\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"UnlockerAssistant"="C:\Programfiler\Unlocker\UnlockerAssistant.exe" [2006-09-07 19:19 15872]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30 45632]
"Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-28 23:27 1177368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 18:22 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-02-23 16:45 278528 C:\Programfiler\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"navapsvc"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"iPodService"=3 (0x3)
"Automatisk LiveUpdate-planlegging"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programfiler\\Azureus\\Azureus.exe"=
"C:\\Programfiler\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"C:\\Programfiler\\AVG\\AVG8\\avgupd.exe"=
"C:\\Programfiler\\Fellesfiler\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Programfiler\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-28 23:27]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-28 23:27]
R3 cxbu0wdm;CardMan 3x21;C:\WINDOWS\system32\DRIVERS\cxbu0wdm.sys [2006-07-11 12:03]
S3 MosIrUsb;MosIrUsb.sys;C:\WINDOWS\system32\DRIVERS\MosIrUsb.sys [2004-04-14 15:52]
S3 msloop;Driver for Microsoft tilbakekoblingskort;C:\WINDOWS\system32\DRIVERS\loop.sys [2001-08-17 22:53]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 16:49]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2008-08-17 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Programfiler\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]

2008-08-17 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Programfiler\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

Notify-__c0016C6C - C:\WINDOWS\system32\__c0016C6C.dat


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Eivind\Programdata\Mozilla\Firefox\Profiles\w3oedprl.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.startsiden.no/


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-17 23:04:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-17 23:05:10
ComboFix-quarantined-files.txt 2008-08-17 21:05:08
ComboFix2.txt 2008-08-13 21:04:12
ComboFix3.txt 2008-03-12 18:26:34

Pre-Run: 13,569,368,064 byte ledig
Post-Run: 13,741,432,832 byte ledig

374 --- E O F --- 2008-08-17 01:01:25







HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:09:38, on 17.08.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe
C:\Programfiler\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Windows Live\Messenger\msnmsgr.exe
C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programfiler\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\FELLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programfiler\Fellesfiler\PCSuite\Services\ServiceLayer.exe
C:\Programfiler\Windows Live\Messenger\usnsvc.exe
C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Documents and Settings\Eivind\Skrivebord\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programfiler\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ATICCC] "C:\Programfiler\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programfiler\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [AnyDVD] C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.buypass.no (HKLM)
O15 - Trusted Zone: http://*.headit.no (HKLM)
O15 - Trusted Zone: http://*.norsk-tipping.no (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.eurofoto.no/uploader/ImageUploader4.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D1EA8D3D-F511-4388-B754-4A0CC14A4778} (Aurigma Image Uploader 3.0 Control) - http://www.eurofoto.no/activex/ImageUploader3.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.eurofoto.no/uploader/ImageUploader4.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Programfiler\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Programfiler\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\Fellesfiler\PCSuite\Services\ServiceLayer.exe

--
End of file - 10201 bytes

#4 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:12:56 PM

Posted 17 August 2008 - 04:42 PM

Looks good everything back to normal?
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#5 bassbone

bassbone
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 18 August 2008 - 04:03 PM

No, the popups is still here :thumbsup:
Are there anything else I can do?

#6 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:12:56 PM

Posted 18 August 2008 - 06:12 PM

What kind of popups are you getting?
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#7 bassbone

bassbone
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 18 August 2008 - 11:39 PM

Most of the popups are from wixawin.com

#8 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:12:56 PM

Posted 19 August 2008 - 04:00 AM

Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#9 bassbone

bassbone
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 19 August 2008 - 09:44 AM

Thanks, here is the logfile.
It is in norwegian, but it found 3 infections :thumbsup:

Malwarebytes' Anti-Malware 1.25
Database versjon: 1070
Windows 5.1.2600 Service Pack 3

16:40:19 19.08.2008
mbam-log-08-19-2008 (16-40-19).txt

Skanntype: Rask Skann
Objekter skannet: 50500
Tid tilbakelagt: 4 minute(s), 23 second(s)

Minneprosesser infisert: 0
Minnemoduler infisert: 1
Registernøkler infisert: 1
Registerverdier infisert: 0
Registerfiler infisert: 0
Mapper infisert: 0
Filer infisert: 1

Minneprosesser infisert:
(Ingen mistenkelige filer funnet)

Minnemoduler infisert:
C:\WINDOWS\system32\__c00C690F.dat (Trojan.Zlob) -> Delete on reboot.

Registernøkler infisert:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00c690f (Trojan.Agent) -> Quarantined and deleted successfully.

Registerverdier infisert:
(Ingen mistenkelige filer funnet)

Registerfiler infisert:
(Ingen mistenkelige filer funnet)

Mapper infisert:
(Ingen mistenkelige filer funnet)

Filer infisert:
C:\WINDOWS\system32\__c00C690F.dat (Trojan.Agent) -> Delete on reboot.

#10 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:12:56 PM

Posted 19 August 2008 - 09:46 AM

Ok please post a new Hijackthis log please.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#11 bassbone

bassbone
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 20 August 2008 - 09:59 AM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:59:18, on 20.08.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe
C:\Programfiler\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Programfiler\ATI Technologies\ATI.ACE\CLI.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Windows Live\Messenger\msnmsgr.exe
C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programfiler\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\FELLES~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programfiler\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Programfiler\Fellesfiler\PCSuite\Services\ServiceLayer.exe
C:\Programfiler\Windows Live\Messenger\usnsvc.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\Internet Explorer\IEXPLORE.EXE
C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Documents and Settings\Eivind\Skrivebord\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programfiler\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programfiler\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programfiler\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ATICCC] "C:\Programfiler\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programfiler\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [AnyDVD] C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETTVERKSTJENESTE')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Hege')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe (User 'Hege')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [A00F10AB45.exe] C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00F10AB45.exe (User 'Hege')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [A00F3C774F.exe] C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00F3C774F.exe (User 'Hege')
O4 - HKUS\S-1-5-21-583907252-1659004503-725345543-1005\..\Run: [A00FB3E83B8.exe] C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00FB3E83B8.exe (User 'Hege')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Programfiler\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.buypass.no (HKLM)
O15 - Trusted Zone: http://*.headit.no (HKLM)
O15 - Trusted Zone: http://*.norsk-tipping.no (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.eurofoto.no/uploader/ImageUploader4.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D1EA8D3D-F511-4388-B754-4A0CC14A4778} (Aurigma Image Uploader 3.0 Control) - http://www.eurofoto.no/activex/ImageUploader3.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.eurofoto.no/uploader/ImageUploader4.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Programfiler\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Programfiler\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\Fellesfiler\PCSuite\Services\ServiceLayer.exe

--
End of file - 10973 bytes

#12 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:12:56 PM

Posted 20 August 2008 - 10:04 AM

ANymore Popups?
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#13 bassbone

bassbone
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 21 August 2008 - 11:09 AM

There has ben one wixawin popup since that scanning.

#14 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:12:56 PM

Posted 21 August 2008 - 11:14 AM

download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    • Reg - BotCheck
      File - Additional Folder Scans
      Rootkit Search -Yes
      Drivers -Non Microsoft
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. Make sure that the first line is code with brackets around it [] and that the last line is /code with brackets around it [].

If, after posting, the last line is not <End of Report> then the log is too big to fit into a single post and you will need to split it into multiple posts or attach it as a file.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#15 bassbone

bassbone
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:06:56 PM

Posted 21 August 2008 - 04:33 PM

OTScanIt logfile created on: 21.08.2008 23:18:42

OTScanIt by OldTimer - Version 1.0.16.2	 Folder = C:\Documents and Settings\Eivind\Skrivebord\OTScanIt

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.11)

Locale: 00000414 | Country: Norge | Language: NOR | Date Format: dd.MM.yyyy

 

1,50 Gb Total Physical Memory | 0,75 Gb Available Physical Memory | 50,11% Memory free

3,61 Gb Paging File | 2,83 Gb Available in Paging File | 78,43% Paging File free

Paging file location(s): C:\pagefile.sys 2304 2304;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programfiler

Drive C: | 40,00 Gb Total Space | 12,28 Gb Free Space | 30,69% Space Free | Partition Type: NTFS

Drive D: | 232,88 Gb Total Space | 10,51 Gb Free Space | 4,51% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

Drive G: | 37,25 Gb Total Space | 0,38 Gb Free Space | 1,03% Space Free | Partition Type: NTFS

Drive H: | 74,56 Gb Total Space | 29,98 Gb Free Space | 40,21% Space Free | Partition Type: NTFS

Drive I: | 109,05 Gb Total Space | 70,02 Gb Free Space | 64,21% Space Free | Partition Type: NTFS

Drive J: | 37,27 Gb Total Space | 17,23 Gb Free Space | 46,25% Space Free | Partition Type: NTFS



Computer Name: MASKIN1

Current User Name: Eivind

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users



[Processes - Non-Microsoft Only]

ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4149 | Size = 430080 bytes | Modified Date = 12.10.2006 03:37:23 | Attr =	]

ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4149 | Size = 430080 bytes | Modified Date = 12.10.2006 03:37:23 | Attr =	]

aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware\aawservice.exe -> Lavasoft [Ver = 7,1,0,12 | Size = 611664 bytes | Modified Date = 01.08.2008 10:34:49 | Attr =	]

launch~1.exe -> %ProgramFiles%\Nokia\Nokia PC Suite 6\LaunchApplication.exe -> Nokia [Ver = 6, 81, 61, 4 | Size = 229376 bytes | Modified Date = 15.06.2006 12:36:18 | Attr =	]

jusched.exe -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 144784 bytes | Modified Date = 10.06.2008 04:27:04 | Attr =	]

unlockerassistant.exe -> %ProgramFiles%\Unlocker\UnlockerAssistant.exe ->  [Ver =  | Size = 15872 bytes | Modified Date = 07.09.2006 19:19:27 | Attr =	]

taskswitch.exe -> %SystemRoot%\system32\TaskSwitch.exe ->  [Ver =  | Size = 45632 bytes | Modified Date = 19.03.2002 17:30:00 | Attr =	]

cli.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.11.0.0 | Size = 45056 bytes | Modified Date = 02.01.2006 17:41:22 | Attr =	]

avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.94 | Size = 1177368 bytes | Modified Date = 28.05.2008 23:27:29 | Attr =	]

pcsync2.exe -> %ProgramFiles%\Nokia\Nokia PC Suite 6\PcSync2.exe -> Time Information Services Ltd. [Ver = 2.00 (506) | Size = 1449984 bytes | Modified Date = 27.06.2006 16:21:14 | Attr =	]

anydvdtray.exe -> %ProgramFiles%\SlySoft\AnyDVD\AnyDVDtray.exe -> SlySoft, Inc. [Ver = 6.4.5.9 | Size = 2161600 bytes | Modified Date = 01.08.2008 15:32:10 | Attr =	]

googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 06.06.2007 06:31:38 | Attr =	]

avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.100 | Size = 282904 bytes | Modified Date = 28.05.2008 23:27:26 | Attr =	]

mpapi3s.exe -> %CommonProgramFiles%\Nokia\MPAPI\MPAPI3s.exe -> Nokia Corporation [Ver = 6.81.161.1 | Size = 471552 bytes | Modified Date = 09.06.2006 10:37:18 | Attr =	]

pmshost.exe -> %ProgramFiles%\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe -> Pinnacle Systems [Ver = 1.1.232.0 | Size = 49152 bytes | Modified Date = 19.01.2006 09:22:20 | Attr =	]

avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.84 | Size = 311576 bytes | Modified Date = 28.05.2008 23:27:31 | Attr =	]

servicelayer.exe -> %CommonProgramFiles%\PCSuite\Services\ServiceLayer.exe -> Nokia. [Ver = 6, 81, 60, 0 | Size = 174080 bytes | Modified Date = 05.06.2006 13:59:18 | Attr =	]

cli.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.11.0.0 | Size = 45056 bytes | Modified Date = 02.01.2006 17:41:22 | Attr =	]

cli.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.11.0.0 | Size = 45056 bytes | Modified Date = 02.01.2006 17:41:22 | Attr =	]

ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4149 | Size = 430080 bytes | Modified Date = 12.10.2006 03:37:23 | Attr =	]

launch~1.exe -> %ProgramFiles%\Nokia\Nokia PC Suite 6\LaunchApplication.exe -> Nokia [Ver = 6, 81, 61, 4 | Size = 229376 bytes | Modified Date = 15.06.2006 12:36:18 | Attr =	]

jusched.exe -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 144784 bytes | Modified Date = 10.06.2008 04:27:04 | Attr =	]

unlockerassistant.exe -> %ProgramFiles%\Unlocker\UnlockerAssistant.exe ->  [Ver =  | Size = 15872 bytes | Modified Date = 07.09.2006 19:19:27 | Attr =	]

taskswitch.exe -> %SystemRoot%\system32\TaskSwitch.exe ->  [Ver =  | Size = 45632 bytes | Modified Date = 19.03.2002 17:30:00 | Attr =	]

avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.94 | Size = 1177368 bytes | Modified Date = 28.05.2008 23:27:29 | Attr =	]

googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 06.06.2007 06:31:38 | Attr =	]

cli.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.11.0.0 | Size = 45056 bytes | Modified Date = 02.01.2006 17:41:22 | Attr =	]

cli.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.11.0.0 | Size = 45056 bytes | Modified Date = 02.01.2006 17:41:22 | Attr =	]

cli.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.11.0.0 | Size = 45056 bytes | Modified Date = 02.01.2006 17:41:22 | Attr =	]

otscanit.exe -> %UserProfile%\Skrivebord\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.16.2 | Size = 397312 bytes | Modified Date = 12.07.2008 09:29:54 | Attr =	]



[Win32 Services - Non-Microsoft Only]

(aawservice) Lavasoft Ad-Aware Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware\aawservice.exe -> Lavasoft [Ver = 7,1,0,12 | Size = 611664 bytes | Modified Date = 01.08.2008 10:34:49 | Attr =	]

(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4149 | Size = 430080 bytes | Modified Date = 12.10.2006 03:37:23 | Attr =	]

(ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe ->  [Ver = 5.13.0025 | Size = 520192 bytes | Modified Date = 11.10.2006 22:05:00 | Attr =	]

(Automatisk LiveUpdate-planlegging) Automatisk LiveUpdate-planlegging [Win32_Own | Disabled | Stopped] ->  -> File not found

(avg8wd) AVG8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.100 | Size = 282904 bytes | Modified Date = 28.05.2008 23:27:26 | Attr =	]

(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 01.02.2007 05:03:29 | Attr =	]

(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 04.04.2005 00:41:10 | Attr =	]

(iPodService) iPodService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 6.0.4.2 | Size = 323584 bytes | Modified Date = 23.02.2006 16:45:06 | Attr =	]

(NetSvc) Intel NCS NetService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Intel\NCS\Sync\NetSvc.exe -> Intel® Corporation [Ver = 1.2.26.0 | Size = 143360 bytes | Modified Date = 03.03.2003 14:33:40 | Attr =	]

(PinnacleSys.MediaServer) Pinnacle Systems Media Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe -> Pinnacle Systems [Ver = 1.1.232.0 | Size = 49152 bytes | Modified Date = 19.01.2006 09:22:20 | Attr =	]

(ServiceLayer) ServiceLayer [Win32_Own | On_Demand | Running] -> %CommonProgramFiles%\PCSuite\Services\ServiceLayer.exe -> Nokia. [Ver = 6, 81, 60, 0 | Size = 174080 bytes | Modified Date = 05.06.2006 13:59:18 | Attr =	]



[Driver Services - Non-Microsoft Only]

(aeaudio) aeaudio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\aeaudio.sys -> Andrea Electronics Corporation [Ver = 1.0.0.2 (STUB) | Size = 4816 bytes | Modified Date = 01.04.2002 15:15:00 | Attr =	]

(AnyDVD) AnyDVD [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\AnyDVD.sys -> SlySoft, Inc. [Ver = 6.4.5.9 | Size = 99648 bytes | Modified Date = 01.08.2008 15:27:35 | Attr =	]

(ASAPIW2K) ASAPIW2K [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\asapiW2k.sys -> VOB Computersysteme GmbH [Ver = 6, 0, 0, 1 | Size = 11264 bytes | Modified Date = 23.02.2005 17:40:26 | Attr =	]

(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> ATI Technologies Inc. [Ver = 6.14.10.6648 | Size = 1777152 bytes | Modified Date = 12.10.2006 03:43:54 | Attr =	]

(AvgLdx86) AVG AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avgldx86.sys -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.58 | Size = 96520 bytes | Modified Date = 28.05.2008 23:27:55 | Attr =	]

(AvgMfx86) AVG On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\system32\drivers\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 8.0.0.46 | Size = 26184 bytes | Modified Date = 28.05.2008 23:27:55 | Attr =	]

(catchme) catchme [Kernel | On_Demand | Stopped] -> %SystemDrive%\ComboFix\catchme.sys -> File not found

(cxbu0wdm) CardMan 3x21 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\cxbu0wdm.sys -> OMNIKEY [Ver = 1.1.1.3 | Size = 84608 bytes | Modified Date = 11.07.2006 12:03:30 | Attr =	]

(dmload) dmload [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 09.10.2001 14:00:00 | Attr =	]

(E100B) Intel® PRO Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\e100b325.sys -> Intel Corporation [Ver = 7.0.26.0 built by: WinDDK | Size = 145408 bytes | Modified Date = 04.03.2003 13:56:26 | Attr =	]

(ElbyCDIO) ElbyCDIO Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\ElbyCDIO.sys -> Elaborate Bytes AG [Ver = 6, 0, 1, 2 | Size = 24392 bytes | Modified Date = 21.07.2008 14:11:58 | Attr =	]

(ElbyDelay) ElbyDelay [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ElbyDelay.sys -> Elaborate Bytes AG [Ver = 5, 1, 0, 1 | Size = 11984 bytes | Modified Date = 16.02.2007 02:56:49 | Attr =	]

(GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\GEARAspiWDM.sys -> File not found

(MarvinBus) Pinnacle Marvin Bus [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\MarvinBus.sys -> Pinnacle Systems GmbH [Ver = 2.1.23.0 | Size = 171008 bytes | Modified Date = 02.06.2005 19:28:38 | Attr =	]

(MosIrUsb) MosIrUsb.sys [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\MosIrUsb.sys ->  [Ver = 1, 0, 0, 8 | Size = 20736 bytes | Modified Date = 14.04.2004 15:52:54 | Attr =	]

(Nokia USB Generic) Nokia USB Generic [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcdc.sys -> Nokia [Ver = 6.80.5.0 | Size = 8704 bytes | Modified Date = 29.05.2006 08:26:36 | Attr =	]

(Nokia USB Modem) Nokia USB Modem [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcdcm.sys -> Nokia [Ver = 6.80.5.0 | Size = 13312 bytes | Modified Date = 29.05.2006 08:26:36 | Attr =	]

(Nokia USB Phone Parent) Nokia USB Phone Parent [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcd.sys -> Nokia [Ver = 6.80.5.0 | Size = 127488 bytes | Modified Date = 29.05.2006 08:26:38 | Attr =	]

(Nokia USB Port) Nokia USB Port [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcdcj.sys -> Nokia [Ver = 6.80.5.0 | Size = 13312 bytes | Modified Date = 29.05.2006 08:26:36 | Attr =	]

(OMCI) OMCI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\omci.sys -> Dell Computer Corporation [Ver = 6, 1, 0, 242 | Size = 13632 bytes | Modified Date = 22.08.2001 09:42:58 | Attr =	]

(PCLEPCI) PCLEPCI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\Pclepci.sys -> Pinnacle Systems GmbH [Ver = 1.06 | Size = 14165 bytes | Modified Date = 09.02.2005 11:59:00 | Attr =	]

(Ptilink) Direkte parallell koblingsdriver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 09.10.2001 14:00:00 | Attr =	]

(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> Sonic Solutions [Ver = 2.03.28a | Size = 20640 bytes | Modified Date = 05.12.2005 07:12:26 | Attr =	]

(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 13.11.2007 12:25:55 | Attr =	]

(smwdm) smwdm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\smwdm.sys -> Analog Devices, Inc. [Ver = 5.12.01.3600 | Size = 580992 bytes | Modified Date = 06.05.2003 10:14:34 | Attr =	]

(symlcbrd) symlcbrd [Kernel | Auto | Stopped] -> %SystemRoot%\system32\drivers\symlcbrd.sys -> File not found

(viamraid) viamraid [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\viamraid.sys -> VIA Technologies inc,.ltd [Ver = 5.1.6000.562 | Size = 114944 bytes | Modified Date = 17.07.2007 14:35:00 | Attr =	]

(w300bus) Sony Ericsson W300 Driver driver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\w300bus.sys -> MCCI [Ver = V4.34 | Size = 60800 bytes | Modified Date = 13.03.2006 16:49:54 | Attr = R  ]



[Registry - Non-Microsoft Only]

< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 

Adobe Reader Speed Launcher -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe ["C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> Adobe Systems Incorporated [Ver = 8.0.0.0 | Size = 39792 bytes | Modified Date = 11.01.2008 23:16:38 | Attr =	]

ATICCC -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLIStart.exe ["C:\Programfiler\ATI Technologies\ATI.ACE\CLIStart.exe"] ->  [Ver =  | Size = 90112 bytes | Modified Date = 10.05.2006 11:12:06 | Attr =	]

ATIPTA -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe [C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe] -> ATI Technologies, Inc. [Ver = 6.14.10.5140 | Size = 339968 bytes | Modified Date = 19.01.2005 22:40:00 | Attr =	]

AVG8_TRAY -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.94 | Size = 1177368 bytes | Modified Date = 28.05.2008 23:27:29 | Attr =	]

CoolSwitch -> %SystemRoot%\system32\TaskSwitch.exe [C:\WINDOWS\system32\taskswitch.exe] ->  [Ver =  | Size = 45632 bytes | Modified Date = 19.03.2002 17:30:00 | Attr =	]

NeroFilterCheck -> %SystemRoot%\system32\NeroCheck.exe [C:\WINDOWS\system32\NeroCheck.exe] -> Ahead Software Gmbh [Ver = 1, 0, 0, 2 | Size = 155648 bytes | Modified Date = 09.07.2001 12:50:42 | Attr =	]

PCSuiteTrayApplication -> %ProgramFiles%\Nokia\Nokia PC Suite 6\LaunchApplication.exe [C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup] -> Nokia [Ver = 6, 81, 61, 4 | Size = 229376 bytes | Modified Date = 15.06.2006 12:36:18 | Attr =	]

PinnacleDriverCheck -> %SystemRoot%\system32\PSDrvCheck.exe [C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg] ->  [Ver = 1.0.0.63 | Size = 406016 bytes | Modified Date = 11.03.2004 00:26:10 | Attr =	]

SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe ["C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe"] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 144784 bytes | Modified Date = 10.06.2008 04:27:04 | Attr =	]

UnlockerAssistant -> %ProgramFiles%\Unlocker\UnlockerAssistant.exe ["C:\Programfiler\Unlocker\UnlockerAssistant.exe"] ->  [Ver =  | Size = 15872 bytes | Modified Date = 07.09.2006 19:19:27 | Attr =	]

< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> 

IMAIL-> Installed = 1 -> 

MAPI-> Installed = 1 -> 

MSFS-> Installed = 1 -> 

< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 

AnyDVD -> %ProgramFiles%\SlySoft\AnyDVD\AnyDVDtray.exe [C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe] -> SlySoft, Inc. [Ver = 6.4.5.9 | Size = 2161600 bytes | Modified Date = 01.08.2008 15:32:10 | Attr =	]

PcSync -> %ProgramFiles%\Nokia\Nokia PC Suite 6\PcSync2.exe [C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog] -> Time Information Services Ltd. [Ver = 2.00 (506) | Size = 1449984 bytes | Modified Date = 27.06.2006 16:21:14 | Attr =	]

swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 06.06.2007 06:31:38 | Attr =	]

< Run [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 

AnyDVD -> %ProgramFiles%\SlySoft\AnyDVD\AnyDVDtray.exe [C:\Programfiler\SlySoft\AnyDVD\AnyDVDtray.exe] -> SlySoft, Inc. [Ver = 6.4.5.9 | Size = 2161600 bytes | Modified Date = 01.08.2008 15:32:10 | Attr =	]

PcSync -> %ProgramFiles%\Nokia\Nokia PC Suite 6\PcSync2.exe [C:\Programfiler\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog] -> Time Information Services Ltd. [Ver = 2.00 (506) | Size = 1449984 bytes | Modified Date = 27.06.2006 16:21:14 | Attr =	]

swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 06.06.2007 06:31:38 | Attr =	]

< Run [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 

A00F10AB45.exe -> %SystemDrive%\DOCUME~1\Hege\LOKALE~1\Temp\_A00F10AB45.exe [C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00F10AB45.exe] -> File not found

A00F3C774F.exe -> %SystemDrive%\DOCUME~1\Hege\LOKALE~1\Temp\_A00F3C774F.exe [C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00F3C774F.exe] -> File not found

A00F9A61BD6.exe -> %SystemDrive%\Documents and Settings\Hege\Lokale innstillinger\temp\_A00F9A61BD6.exe [C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00F9A61BD6.exe] ->  [Ver =  | Size = 37376 bytes | Modified Date = 21.08.2008 13:49:25 | Attr =	]

A00FB3E83B8.exe -> %SystemDrive%\DOCUME~1\Hege\LOKALE~1\Temp\_A00FB3E83B8.exe [C:\DOCUME~1\Hege\LOKALE~1\Temp\_A00FB3E83B8.exe] -> File not found

swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 06.06.2007 06:31:38 | Attr =	]

< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart -> 

< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start-meny\Programmer\Oppstart -> 

< Eivind Startup Folder > -> C:\Documents and Settings\Eivind\Start-meny\Programmer\Oppstart -> 

< Hege Startup Folder > -> C:\Documents and Settings\Hege\Start-meny\Programmer\Oppstart -> 

< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> 

*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> 

avgrsstx.dll -> %SystemRoot%\system32\avgrsstx.dll -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.80 | Size = 10520 bytes | Modified Date = 28.05.2008 23:27:56 | Attr =	]

*MultiFile Done* -> -> 

< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 

*SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 

msapsspc.dll schannel.dll digest.dll msnsspc.dll ->  -> File not found

*MultiFile Done* -> -> 

< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 

Explorer.exe -> %SystemRoot%\explorer.exe -> Microsoft Corporation [Ver = 6.00.2900.5512 (xpsp.080413-2105) | Size = 1033728 bytes | Modified Date = 14.04.2008 18:22:49 | Attr =	]

*MultiFile Done* -> -> 

*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit -> 

C:\WINDOWS\system32\userinit.exe -> %SystemRoot%\system32\userinit.exe -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 26112 bytes | Modified Date = 14.04.2008 18:23:14 | Attr =	]

*MultiFile Done* -> -> 

*UIHost* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost -> 

logonui.exe -> %SystemRoot%\system32\logonui.exe -> Microsoft Corporation [Ver = 6.00.2900.5512 (xpsp.080413-2105) | Size = 514560 bytes | Modified Date = 14.04.2008 18:22:55 | Attr =	]

*MultiFile Done* -> -> 

*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet -> 

rundll32 shell32 -> %SystemRoot%\system32\shell32.dll -> Microsoft Corporation [Ver = 6.00.2900.5512 (xpsp.080413-2105) | Size = 8466944 bytes | Modified Date = 14.04.2008 18:22:21 | Attr =	]

Control_RunDLL "sysdm.cpl" -> %SystemRoot%\system32\sysdm.cpl -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2105) | Size = 301056 bytes | Modified Date = 14.04.2008 18:23:19 | Attr =	]

*MultiFile Done* -> -> 

< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon settings [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon settings [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 

__c00381B7 -> %SystemRoot%\system32\__c00381B7.dat ->  [Ver =  | Size = 30208 bytes | Modified Date = 21.08.2008 13:49:29 | Attr =	]

AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> ATI Technologies Inc. [Ver = 6.14.10.4149 | Size = 90112 bytes | Modified Date = 12.10.2006 03:38:26 | Attr =	]

< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Attachments\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Attachments\\ScanWithAntiVirus -> 2 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\\{17492023-C23A-453E-A040-C7C580BBF700} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> 

< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 0 -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> 

< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> 

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> 

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 0 -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> 

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

< CDROM Autorun Settings > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> ->

*DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup -> 

SCSI miniport ->  -> File not found

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM-driver -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> %SystemRoot%\system32\drivers\cdrom.sys [System32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2108) | Size = 62976 bytes | Modified Date = 13.04.2008 20:40:46 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 -> 

*AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable -> 

NEC	 MBR-7	->  -> File not found

NEC	 MBR-7.4  ->  -> File not found

PIONEER CHANGR DRM-1804X ->  -> File not found

PIONEER CD-ROM DRM-6324X ->  -> File not found

PIONEER CD-ROM DRM-624X  ->  -> File not found

TORiSAN CD-ROM CDR_C36 ->  -> File not found

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\0 -> IDE\CdRom_NEC_DVD+-RW_ND-3530A___________________102B____\5&33fcab6&0&0.0.0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\Count -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\NextInstance -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\1 -> IDE\CdRomMSI_CD-RW_CR52__________________________3.30____\5&33fcab6&0&0.1.0 -> 

< Drives - Autoruns > ->  -> 

AUTOEXEC.BAT [SET PATH=C:\Programfiler\Pinnacle\Shared Files;C:\Programfiler\Pinnacle\Shared Files\Filter | ] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] ->  [Ver =  | Size = 93 bytes | Modified Date = 29.07.2006 23:40:32 | Attr =	]

< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 

< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 

HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> [url=http://go.microsoft.com/fwlink/?LinkId=69157]http://go.microsoft.com/fwlink/?LinkId=69157[/url] -> 

HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> [url=http://go.microsoft.com/fwlink/?LinkId=54896]http://go.microsoft.com/fwlink/?LinkId=54896[/url] -> 

HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 

HKEY_LOCAL_MACHINE\: Main\\Search Page -> [url=http://go.microsoft.com/fwlink/?LinkId=54896]http://go.microsoft.com/fwlink/?LinkId=54896[/url] -> 

HKEY_LOCAL_MACHINE\: Main\\Start Page -> [url=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home]http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home[/url] -> 

HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> [url=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm]http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm[/url] -> 

HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> [url=http://www.google.com/ie]http://www.google.com/ie[/url] -> 

HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> [url=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm]http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm[/url] -> 

< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 

HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 

HKEY_CURRENT_USER\: Main\\Search Page -> [url=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch]http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch[/url] -> 

HKEY_CURRENT_USER\: Main\\Start Page -> [url=http://www.startsiden.no/]http://www.startsiden.no/[/url] -> 

HKEY_CURRENT_USER\: SearchURL\\ -> [url=http://www.google.com/search?q=%s]http://www.google.com/search?q=%s[/url][Reg Error: Value provider does not exist or could not be read.] -> 

HKEY_CURRENT_USER\: URLSearchHooks\\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 

< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 

HKEY_USERS\.DEFAULT\: Main\\Search Page -> [url=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch]http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch[/url] -> 

HKEY_USERS\.DEFAULT\: Main\\Start Page -> [url=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome]http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome[/url] -> 

HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 -> 

< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 

HKEY_USERS\S-1-5-18\: Main\\Search Page -> [url=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch]http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch[/url] -> 

HKEY_USERS\S-1-5-18\: Main\\Start Page -> [url=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome]http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome[/url] -> 

HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 -> 

< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 

HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 -> 

< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 

HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 -> 

< Internet Explorer Settings [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\: Main\\Search Page -> [url=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch]http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch[/url] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\: Main\\Start Page -> [url=http://www.startsiden.no/]http://www.startsiden.no/[/url] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\: SearchURL\\ -> [url=http://www.google.com/search?q=%s]http://www.google.com/search?q=%s[/url][Reg Error: Value provider does not exist or could not be read.] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\: URLSearchHooks\\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\: ProxyEnable -> 0 -> 

< Internet Explorer Settings [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: Main\\Search Bar -> [url=http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR]http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR[/url] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: Main\\Search Page -> [url=http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR]http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR[/url] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: Main\\Start Page -> [url=http://www.vg.no/]http://www.vg.no/[/url] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: Search\\CustomizeSearch -> [url=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm]http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm[/url] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: Search\\SearchAssistant -> [url=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm]http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm[/url] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: SearchURL\\ -> [url=http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR]http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR[/url][Reg Error: Value provider does not exist or could not be read.] -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\: ProxyEnable -> 0 -> 

< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4 domain(s) found. -> 

buypass.no .[http] -> Trusted sites -> 

buypass.no .[https] -> Trusted sites -> 

headit.no .[http] -> Trusted sites -> 

headit.no .[https] -> Trusted sites -> 

norsk-tipping.no .[http] -> Trusted sites -> 

norsk-tipping.no .[https] -> Trusted sites -> 

4 domain(s) and sub-domain(s) not assigned to a zone.

< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 

< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 

< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 

< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 

< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 

< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 

< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 

< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Koblingshjelpeprogram for Adobe PDF Reader] -> Adobe Systems Incorporated [Ver = 8.0.0.2006102200 | Size = 62080 bytes | Modified Date = 23.10.2006 00:08:42 | Attr =	]

{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.90 | Size = 419096 bytes | Modified Date = 28.05.2008 23:27:33 | Attr =	]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_07\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 509328 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [Google Toolbar Notifier BHO] -> Google Inc. [Ver = 2, 0, 301, 7164 | Size = 325048 bytes | Modified Date = 06.06.2007 06:31:38 | Attr =	]

{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2419776 bytes | Modified Date = 20.01.2007 00:56:38 | Attr = R  ]

< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Bars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Bars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Bars [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Bars [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Bars [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Bars [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 

{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2419776 bytes | Modified Date = 20.01.2007 00:56:38 | Attr = R  ]

< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 

ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2419776 bytes | Modified Date = 20.01.2007 00:56:38 | Attr = R  ]

WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found

< Internet Explorer ToolBars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\ -> 

WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2419776 bytes | Modified Date = 20.01.2007 00:56:38 | Attr = R  ]

WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer ToolBars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\ -> 

WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2419776 bytes | Modified Date = 20.01.2007 00:56:38 | Attr = R  ]

WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ -> 

ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2419776 bytes | Modified Date = 20.01.2007 00:56:38 | Attr = R  ]

WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found

< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\Software\Microsoft\Internet Explorer\Toolbar\ -> 

WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2419776 bytes | Modified Date = 20.01.2007 00:56:38 | Attr = R  ]

WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 132496 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_07\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 509328 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

{85d1f590-48f4-11d9-9669-0800200c9a66}:Exec -> %SystemRoot%\bdoscandel.exe [Uninstall BitDefender Online Scanner v8] ->  [Ver =  | Size = 53248 bytes | Modified Date = 25.05.2006 01:22:06 | Attr =	]

< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 132496 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 

Add to Windows &Live Favorites ->  -> File not found

< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> 

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 132496 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> 

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 132496 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\Software\Microsoft\Internet Explorer\Extensions\ -> 

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 132496 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> 

Add to Windows &Live Favorites ->  -> File not found

< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\Software\Microsoft\Internet Explorer\Extensions\ -> 

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 132496 bytes | Modified Date = 10.06.2008 04:27:02 | Attr =	]

< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\] > -> HKEY_USERS\S-1-5-21-583907252-1659004503-725345543-1005\Software\Microsoft\Internet Explorer\MenuExt\ -> 

Add to Windows &Live Favorites ->  -> File not found

< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 

PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 

PluginsPage -> [url=http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s]http://activex.microsoft.com/controls/find...=%s&mime=%s[/url] -> 

< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 

{16DCC64C-A372-4FCF-8FBF-94C64CCA6E05} ->	(Microsoft tilbakekoblingskort) -> 

{2E438800-2104-4C5A-9561-B6CF8CFDE10B} ->	(1394-nettverkskort) -> 

{41C2FBD8-4749-4DB8-BFE3-8ADBAA3123AF} ->	() -> 

{84C73AD1-053B-4581-AA05-CA2F008CBD9C} ->	(Intel® PRO/100 VE Network Connection) -> 

< Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 

shell -> shell protocol not assigned -> 

< Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 

shell -> shell protocol not assigned -> 

< Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 

shell -> shell protocol not assigned -> 

< Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 

shell -> shell protocol not assigned -> 

< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 

ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value

linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AVG\AVG8\avgpp.dll[XPLPPFilter Class] -> AVG Technologies CZ, s.r.o. [Ver =  | Size = 79128 bytes | Modified Date = 28.05.2008 23:27:41 | Attr =	]

msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 

{0CCA191D-13A6-4E29-B746-314DEE697D83}[HKEY_LOCAL_MACHINE] -> [url=http://upload.facebook.com/controls/FacebookPhotoUploader5.cab]http://upload.facebook.com/controls/Facebo...toUploader5.cab[/url][Facebook Photo Uploader 5] -> 

{17492023-C23A-453E-A040-C7C580BBF700}[HKEY_LOCAL_MACHINE] -> [url=http://go.microsoft.com/fwlink/?linkid=39204]http://go.microsoft.com/fwlink/?linkid=39204[/url][Windows Genuine Advantage Validation Tool] -> 

{215B8138-A3CF-44C5-803F-8226143CFC0A}[HKEY_LOCAL_MACHINE] -> [url=http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab]http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab[/url][Trend Micro ActiveX Scan Agent 6.6] -> 

{5C6698D9-7BE4-4122-8EC5-291D84DBD4A0}[HKEY_LOCAL_MACHINE] -> [url=http://upload.facebook.com/controls/FacebookPhotoUploader3.cab]http://upload.facebook.com/controls/Facebo...toUploader3.cab[/url][Facebook Photo Uploader 4 Control] -> 

{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}[HKEY_LOCAL_MACHINE] -> [url=http://download.bitdefender.com/resources/scan8/oscan8.cab]http://download.bitdefender.com/resources/scan8/oscan8.cab[/url][BDSCANONLINE Control] -> 

{5F8469B4-B055-49DD-83F7-62B522420ECC}[HKEY_LOCAL_MACHINE] -> [url=http://upload.facebook.com/controls/FacebookPhotoUploader.cab]http://upload.facebook.com/controls/Facebo...otoUploader.cab[/url][Facebook Photo Uploader Control] -> 

{6E5E167B-1566-4316-B27F-0DDAB3484CF7}[HKEY_LOCAL_MACHINE] -> [url=http://www.eurofoto.no/uploader/ImageUploader4.cab]http://www.eurofoto.no/uploader/ImageUploader4.cab[/url][Image Uploader Control] -> 

{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.6.0_07] -> 

{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}[HKEY_LOCAL_MACHINE] -> [url=http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab]http://messenger.msn.com/download/MsnMesse...pDownloader.cab[/url][MsnMessengerSetupDownloadControl Class] -> 

{C3F79A2B-B9B4-4A66-B012-3EE46475B072}[HKEY_LOCAL_MACHINE] -> [url=http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab]http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab[/url][MessengerStatsClient Class] -> 

{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab]http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.5.0_10] -> 

{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab]http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.5.0_11] -> 

{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.6.0_01] -> 

{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.6.0_02] -> 

{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.6.0_03] -> 

{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.6.0_05] -> 

{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.6.0_07] -> 

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> [url=http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab]http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[/url][Java Plug-in 1.6.0_07] -> 

{D1EA8D3D-F511-4388-B754-4A0CC14A4778}[HKEY_LOCAL_MACHINE] -> [url=http://www.eurofoto.no/activex/ImageUploader3.cab]http://www.eurofoto.no/activex/ImageUploader3.cab[/url][Aurigma Image Uploader 3.0 Control] -> 

{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> [url=http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]http://download.macromedia.com/pub/shockwa...ash/swflash.cab[/url][Shockwave Flash Object] -> 

{EDFCB7CB-942C-4822-AF14-F0B687409848}[HKEY_LOCAL_MACHINE] -> [url=http://www.eurofoto.no/uploader/ImageUploader4.cab]http://www.eurofoto.no/uploader/ImageUploader4.cab[/url][Image Uploader Control] -> 

{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}[HKEY_LOCAL_MACHINE] -> [url=http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab]http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab[/url][Minesweeper Flags Class] -> 

< Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/bdoscandel.exe\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/bdoscandel.exe\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/bdoscandel.exe\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/bdoscandellang.ini\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/bdoscandellang.ini\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/bdoscandellang.ini\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bdcore.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bdcore.dll\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bdcore.dll\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bdupd.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bdupd.dll\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bdupd.dll\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/FacebookPhotoUploader.ocx\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/FacebookPhotoUploader.ocx\\.Owner -> {5F8469B4-B055-49DD-83F7-62B522420ECC} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/FacebookPhotoUploader.ocx\\{5F8469B4-B055-49DD-83F7-62B522420ECC} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Housecall_ActiveX.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Housecall_ActiveX.dll\\.Owner -> {215B8138-A3CF-44C5-803F-8226143CFC0A} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Housecall_ActiveX.dll\\{215B8138-A3CF-44C5-803F-8226143CFC0A} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\\.Owner -> {D1EA8D3D-F511-4388-B754-4A0CC14A4778} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\\{D1EA8D3D-F511-4388-B754-4A0CC14A4778} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.1.ocx\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.1.ocx\\.Owner -> {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.1.ocx\\{5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.ocx\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.ocx\\.Owner -> {6E5E167B-1566-4316-B27F-0DDAB3484CF7} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.ocx\\{6E5E167B-1566-4316-B27F-0DDAB3484CF7} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.ocx\\{5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader4.ocx\\{EDFCB7CB-942C-4822-AF14-F0B687409848} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader5.ocx\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader5.ocx\\.Owner -> {0CCA191D-13A6-4E29-B746-314DEE697D83} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader5.ocx\\{0CCA191D-13A6-4E29-B746-314DEE697D83} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ipsupd.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ipsupd.dll\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ipsupd.dll\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/lang.ini\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/lang.ini\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/lang.ini\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/libfn.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/libfn.dll\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/libfn.dll\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/live.ini\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/live.ini\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/live.ini\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\\.Owner -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\\{C3F79A2B-B9B4-4A66-B012-3EE46475B072} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MineSweeper.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MineSweeper.dll\\.Owner -> {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MineSweeper.dll\\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MsnMessengerSetupDownloader.ocx\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MsnMessengerSetupDownloader.ocx\\.Owner -> {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MsnMessengerSetupDownloader.ocx\\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/oscan8.ocx\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/oscan8.ocx\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/oscan8.ocx\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/oscan81.ocx_x\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/oscan81.ocx_x\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/oscan81.ocx_x\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/scanoptions.tsi\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/scanoptions.tsi\\.Owner -> {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/scanoptions.tsi\\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/LegitCheckControl.DLL\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/LegitCheckControl.DLL\\.Owner -> Unknown Owner -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/LegitCheckControl.DLL\\{17492023-C23A-453E-A040-C7C580BBF700} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/mfc42.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/mfc42.dll\\.Owner -> Unknown Owner -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/mfc42.dll\\{215B8138-A3CF-44C5-803F-8226143CFC0A} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcp60.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcp60.dll\\.Owner -> Unknown Owner -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcp60.dll\\{215B8138-A3CF-44C5-803F-8226143CFC0A} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcrt.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcrt.dll\\.Owner -> Unknown Owner -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcrt.dll\\{215B8138-A3CF-44C5-803F-8226143CFC0A} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/olepro32.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/olepro32.dll\\.Owner -> Unknown Owner -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/olepro32.dll\\{215B8138-A3CF-44C5-803F-8226143CFC0A} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\.Owner -> Unknown Owner -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{5F8469B4-B055-49DD-83F7-62B522420ECC} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{6E5E167B-1566-4316-B27F-0DDAB3484CF7} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{EDFCB7CB-942C-4822-AF14-F0B687409848} ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{0CCA191D-13A6-4E29-B746-314DEE697D83} ->  -> 





[Registry - Additional Scans - Non-Microsoft Only]

< BotCheck > -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> [Binary data over 100 bytes] -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> [Binary data over 100 bytes] -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> [Binary data over 100 bytes] -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\DisableMonitoring -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\\DisableMonitoring -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> ->

*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 

msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 132608 bytes | Modified Date = 14.04.2008 18:22:13 | Attr =	]

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> 0  [binary data] -> 

*Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 

kerberos -> %SystemRoot%\system32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 299520 bytes | Modified Date = 14.04.2008 18:22:05 | Attr =	]

msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 132608 bytes | Modified Date = 14.04.2008 18:22:13 | Attr =	]

schannel -> %SystemRoot%\system32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 144384 bytes | Modified Date = 14.04.2008 18:22:19 | Attr =	]

wdigest -> %SystemRoot%\system32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 49152 bytes | Modified Date = 14.04.2008 18:22:32 | Attr =	]

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 824 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing ->  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> 

*Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> 

scecli -> %SystemRoot%\system32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 183808 bytes | Modified Date = 14.04.2008 18:22:19 | Attr =	]

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\enabledcom -> y -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> 

*ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> 

Windows NT Access Provider ->  -> File not found

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> %SystemRoot%\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2113) | Size = 118784 bytes | Modified Date = 14.04.2008 18:22:15 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> 87 C7 D4 70 2D D4 CF A2 9A 5F 07 67 6E F1 0D 52 62 66 65 63 34 33 65 62 00 68 07 00 01 00 00 00 DC 00 00 00 E0 00 00 00 48 FA 06 00 97 55 57 74 04 00 00 00 A0 FD 06 00 B8 FD 06 00 27 6B 4A F9  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> 4D 1A EA 1E 8C 63 76 32 09  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> CC EB C2 A3 3F 8C  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\Auth132 -> %SystemRoot%\system32\iissuba.dll [IISSUBA] -> Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 9216 bytes | Modified Date = 09.10.2001 14:00:00 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminclientsec -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminserversec -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> 09 4C 7B 66 78 44 62 97 79 5F F6 EB 6B 53 48 C3  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> [url=http://www.passport.com]http://www.passport.com[/url] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> 14 87 29 22 0B 02 C9 01  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> 80 80 B1 A8 4B 9E C8 01  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> 00 25 71 B0 4B 9E C8 01  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> 80 BB 09 B1 4B 9E C8 01  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2111) | Size = 14336 bytes | Modified Date = 14.04.2008 18:23:12 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall / Internet Connection Sharing (ICS) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup ->  -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Tilbyr nettverksadresseløsing (NAT), adressering, navneløsingstjenester og/eller tjenester til forhindring av inntrenging for hjemmenettverk eller små kontornettverk. -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 11514 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-0852) | Size = 330240 bytes | Modified Date = 14.04.2008 18:22:04 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2111) | Size = 140800 bytes | Modified Date = 14.04.2008 18:23:10 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> %SystemRoot%\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-0852) | Size = 558080 bytes | Modified Date = 13.04.2008 20:53:32 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Programfiler\Windows Live\Messenger\msnmsgr.exe -> %ProgramFiles%\Windows Live\Messenger\msnmsgr.exe [C:\Programfiler\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> Microsoft Corporation [Ver = 8.5.1302.1018 | Size = 5724184 bytes | Modified Date = 18.10.2007 12:34:28 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Programfiler\Windows Live\Messenger\livecall.exe -> %ProgramFiles%\Windows Live\Messenger\livecall.exe [C:\Programfiler\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> Microsoft Corporation [Ver = 1.5.204.0 | Size = 304488 bytes | Modified Date = 02.10.2007 18:18:24 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:*:Enabled:@xpsp2res.dll,-22004 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:*:Enabled:@xpsp2res.dll,-22005 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:*:Enabled:@xpsp2res.dll,-22001 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:*:Enabled:@xpsp2res.dll,-22002 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DisableNotifications -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2111) | Size = 140800 bytes | Modified Date = 14.04.2008 18:23:10 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programfiler\Azureus\Azureus.exe -> %ProgramFiles%\Azureus\Azureus.exe [C:\Programfiler\Azureus\Azureus.exe:*:Enabled:Azureus] -> Azureus Inc [Ver = 3.0.0.0 | Size = 254976 bytes | Modified Date = 08.03.2008 22:48:17 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programfiler\Pinnacle\Studio 10\programs\Studio.exe -> %ProgramFiles%\Pinnacle\Studio 10\programs\Studio.exe [C:\Programfiler\Pinnacle\Studio 10\programs\Studio.exe:*:Disabled:Studio program file] -> Pinnacle Systems [Ver = 10.5.1.2809 | Size = 4358144 bytes | Modified Date = 22.02.2006 14:19:38 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programfiler\AVG\AVG8\avgupd.exe -> %ProgramFiles%\AVG\AVG8\avgupd.exe [C:\Programfiler\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.80 | Size = 796440 bytes | Modified Date = 28.05.2008 23:27:28 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programfiler\Fellesfiler\Nokia\Service Layer\A\nsl_host_process.exe -> %CommonProgramFiles%\Nokia\Service Layer\A\nsl_host_process.exe [C:\Programfiler\Fellesfiler\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process ] -> Nokia Corporation [Ver = 2008.7.6.33132 | Size = 383416 bytes | Modified Date = 29.04.2008 15:55:34 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programfiler\Nokia\Nokia Software Updater\nsu_ui_client.exe -> %ProgramFiles%\Nokia\Nokia Software Updater\nsu_ui_client.exe [C:\Programfiler\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater] -> Nokia Corporation [Ver = 1.3.10.33107 | Size = 1636792 bytes | Modified Date = 02.05.2008 00:49:52 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> %SystemRoot%\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-0852) | Size = 558080 bytes | Modified Date = 13.04.2008 20:53:32 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programfiler\Windows Live\Messenger\msnmsgr.exe -> %ProgramFiles%\Windows Live\Messenger\msnmsgr.exe [C:\Programfiler\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> Microsoft Corporation [Ver = 8.5.1302.1018 | Size = 5724184 bytes | Modified Date = 18.10.2007 12:34:28 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Programfiler\Windows Live\Messenger\livecall.exe -> %ProgramFiles%\Windows Live\Messenger\livecall.exe [C:\Programfiler\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> Microsoft Corporation [Ver = 1.5.204.0 | Size = 304488 bytes | Modified Date = 02.10.2007 18:18:24 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> [Binary data over 100 bytes] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %SystemRoot%\system32\svchost.exe [%systemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2111) | Size = 14336 bytes | Modified Date = 14.04.2008 18:23:12 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Aktiverer nedlasting og installasjon av Windows-oppdateringer. Hvis tjenesten er deaktivert, kan ikke datamaskinen bruke funksjonen Automatiske oppdateringer eller Web-området Windows Update. -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> %SystemRoot%\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.5512 (xpsp.080413-0852) | Size = 6656 bytes | Modified Date = 14.04.2008 18:22:35 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Description -> Eksterne brukere kan redigere registerinnstillinger på datamaskinen. Hvis tjenesten stoppes, kan registret bare redigeres av brukere på denne datamaskinen. Hvis tjenesten deaktiveres, kan ikke tjenester som er avhengig av denne, startes. -> 

*DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DependOnService -> 

RPCSS -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2108) | Size = 399360 bytes | Modified Date = 14.04.2008 18:22:19 | Attr =	]

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DisplayName -> Remote Registry -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ErrorControl -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k LocalService] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2111) | Size = 14336 bytes | Modified Date = 14.04.2008 18:23:12 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ObjectName -> NT AUTHORITY\LocalService -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Group ->  -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Start -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Type -> 32 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\FailureActions -> 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 E0 AD 08 00 01 00 00 00 E8 03 00 00  [binary data] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\\ServiceDll -> %SystemRoot%\system32\regsvc.dll [%SystemRoot%\system32\regsvc.dll] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2111) | Size = 59904 bytes | Modified Date = 14.04.2008 18:22:19 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\\Security -> [Binary data over 100 bytes] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\0 -> Root\LEGACY_REMOTEREGISTRY\0000 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\Count -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\NextInstance -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Type -> 16 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Start -> 3 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ErrorControl -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ImagePath -> %SystemRoot%\system32\tlntsvr.exe [C:\WINDOWS\System32\tlntsvr.exe] -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-0852) | Size = 73216 bytes | Modified Date = 14.04.2008 18:23:13 | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DisplayName -> Telnet -> 

*DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnService -> 

RPCSS -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.5512 (xpsp.080413-2108) | Size = 399360 bytes | Modified Date = 14.04.2008 18:22:19 | Attr =	]

TCPIP ->  -> File not found

NTLMSSP ->  -> File not found

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnGroup ->  -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ObjectName -> LocalSystem -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Description -> Gjør at en ekstern bruker kan logge på denne datamaskinen og kjøre programmer, og støtter forskjellige TCP/IP Telnet-klienter, inkludert UNIX-baserte og Windows-baserte datamaskiner. Hvis denne tjenesten stoppes, kan ekstern brukertilgang til programmer bli utilgjengelig. Hvis denne tjenesten deaktiveres, kommer ikke tjenester som er direkte avhengig av den, til å starte. -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\\Security -> [Binary data over 100 bytes] -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> 





[Files/Folders - Created Within 30 days]

Boot.bak -> %SystemDrive%\Boot.bak ->  [Ver =  | Size = 214 bytes | Created Date = 13.08.2008 22:55:19 | Attr =	]

cmdcons -> %SystemDrive%\cmdcons ->  [Folder | Created Date = 13.08.2008 22:55:09 | Attr =	]

cmldr -> %SystemDrive%\cmldr ->  [Ver =  | Size = 237216 bytes | Created Date = 13.08.2008 22:55:16 | Attr =	]

RECYCLER -> %SystemDrive%\RECYCLER ->  [Folder | Created Date = 17.08.2008 23:39:27 | Attr =  HS]

_OTMoveIt -> %SystemDrive%\_OTMoveIt ->  [Folder | Created Date = 17.08.2008 22:51:40 | Attr =	]

AnyDVD.sys -> %SystemRoot%\System32\drivers\AnyDVD.sys -> SlySoft, Inc. [Ver = 6.4.5.9 | Size = 99648 bytes | Created Date = 01.08.2008 15:27:35 | Attr =	]

mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> Malwarebytes Corporation [Ver = 1, 0, 0, 1 | Size = 17144 bytes | Created Date = 19.08.2008 16:31:13 | Attr =	]

mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> Malwarebytes Corporation [Ver = 1.00 | Size = 38472 bytes | Created Date = 19.08.2008 16:31:12 | Attr =	]

java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 135168 bytes | Created Date = 02.08.2008 19:27:14 | Attr =	]

javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 135168 bytes | Created Date = 02.08.2008 19:27:14 | Attr =	]

javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 139264 bytes | Created Date = 02.08.2008 19:27:14 | Attr =	]

__c00381B7.dat -> %SystemRoot%\System32\__c00381B7.dat ->  [Ver =  | Size = 30208 bytes | Created Date = 21.08.2008 13:49:27 | Attr =	]

~.exe -> %SystemRoot%\System32\~.exe ->  [Ver =  | Size = 37376 bytes | Created Date = 21.08.2008 13:49:25 | Attr =	]

fdsv.exe -> %SystemRoot%\fdsv.exe -> Smallfrogs Studio [Ver = 1, 2, 0, 22 | Size = 89504 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

grep.exe -> %SystemRoot%\grep.exe ->  [Ver =  | Size = 80412 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

LastGood -> %SystemRoot%\LastGood ->  [Folder | Created Date = 21.08.2008 18:11:07 | Attr =	]

5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 

Nircmd.exe -> %SystemRoot%\Nircmd.exe -> NirSoft [Ver = 2.10 | Size = 28672 bytes | Created Date = 13.08.2008 22:53:55 | Attr =	]

sed.exe -> %SystemRoot%\sed.exe ->  [Ver =  | Size = 98816 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

swreg.exe -> %SystemRoot%\swreg.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

swsc.exe -> %SystemRoot%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

swxcacls.exe -> %SystemRoot%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

Thumbs.db -> %SystemRoot%\Thumbs.db ->  [Ver =  | Size = 7680 bytes | Created Date = 06.08.2008 22:27:33 | Attr =  HS]

@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable

VFind.exe -> %SystemRoot%\VFind.exe ->  [Ver =  | Size = 49152 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

zip.exe -> %SystemRoot%\zip.exe ->  [Ver =  | Size = 68096 bytes | Created Date = 13.08.2008 22:53:54 | Attr =	]

[Files Created - Additional Folder Scans - Non-Microsoft Only]

Malwarebytes -> %AllUsersProfile%\Programdata\Malwarebytes ->  [Folder | Created Date = 19.08.2008 16:31:11 | Attr =	]

Malwarebytes -> %AppData%\Malwarebytes ->  [Folder | Created Date = 19.08.2008 16:31:16 | Attr =	]

DVD Cover -> D:\DVD Cover ->  [Folder | Created Date = 16.08.2008 22:38:11 | Attr =	]

Varg.Veum.Falne.Engler.NORWEGIAN.PAL.DVDR-SVENNE -> D:\Varg.Veum.Falne.Engler.NORWEGIAN.PAL.DVDR-SVENNE ->  [Folder | Created Date = 17.08.2008 00:09:03 | Attr =	]

Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Skrivebord\Malwarebytes' Anti-Malware.lnk ->  [Ver =  | Size = 702 bytes | Created Date = 19.08.2008 16:31:13 | Attr =	]

ComboFix.exe -> %UserProfile%\Skrivebord\ComboFix.exe ->  [Ver =  | Size = 2718447 bytes | Created Date = 13.08.2008 22:52:23 | Attr = R  ]

HiJackThis.exe -> %UserProfile%\Skrivebord\HiJackThis.exe -> Trend Micro Inc. [Ver = 2.00.0002 | Size = 401720 bytes | Created Date = 17.08.2008 08:22:21 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\HiJackThis.exe:Zone.Identifier

mbam-setup.exe -> %UserProfile%\Skrivebord\mbam-setup.exe -> Malwarebytes Corporation									 [Ver = 1.25				 | Size = 2085280 bytes | Created Date = 19.08.2008 16:30:17 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\mbam-setup.exe:Zone.Identifier

OBD2 på Audi -> %UserProfile%\Skrivebord\OBD2 på Audi ->  [Folder | Created Date = 17.08.2008 20:32:11 | Attr =	]

OTMoveIt2.exe -> %UserProfile%\Skrivebord\OTMoveIt2.exe -> OldTimer Tools [Ver = 1.0.4.3 | Size = 291840 bytes | Created Date = 17.08.2008 22:50:13 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\OTMoveIt2.exe:Zone.Identifier

OTScanIt -> %UserProfile%\Skrivebord\OTScanIt ->  [Folder | Created Date = 21.08.2008 23:11:49 | Attr =	]

OTScanIt.exe -> %UserProfile%\Skrivebord\OTScanIt.exe ->  [Ver =  | Size = 568477 bytes | Created Date = 21.08.2008 23:10:51 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\OTScanIt.exe:Zone.Identifier

Prosjekt hus klagesak ytter tak -> %UserProfile%\Skrivebord\Prosjekt hus klagesak ytter tak ->  [Folder | Created Date = 09.08.2008 10:57:51 | Attr =	]

Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware ->  [Folder | Created Date = 19.08.2008 16:31:11 | Attr =	]





MSECache -> %ProgramFiles%\MSECache ->  [Folder | Created Date = 15.08.2008 23:10:38 | Attr =	]



[Files/Folders - Modified Within 30 days]

$AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ ->  [Folder | Modified Date = 20.08.2008 12:38:12 | Attr =  H ]

boot.ini -> %SystemDrive%\boot.ini ->  [Ver =  | Size = 286 bytes | Modified Date = 13.08.2008 22:55:19 | Attr = RHS]

cmdcons -> %SystemDrive%\cmdcons ->  [Folder | Modified Date = 13.08.2008 22:55:19 | Attr =	]

Programfiler -> %ProgramFiles% ->  [Folder | Modified Date = 19.08.2008 16:31:11 | Attr =	]

QooBox -> %SystemDrive%\QooBox ->  [Folder | Modified Date = 17.08.2008 23:05:11 | Attr =	]

RECYCLER -> %SystemDrive%\RECYCLER ->  [Folder | Modified Date = 17.08.2008 23:39:27 | Attr =  HS]

WINDOWS -> %SystemRoot% ->  [Folder | Modified Date = 21.08.2008 18:11:42 | Attr =	]

_OTMoveIt -> %SystemDrive%\_OTMoveIt ->  [Folder | Modified Date = 17.08.2008 22:51:40 | Attr =	]

AnyDVD.sys -> %SystemRoot%\System32\drivers\AnyDVD.sys -> SlySoft, Inc. [Ver = 6.4.5.9 | Size = 99648 bytes | Modified Date = 01.08.2008 15:27:35 | Attr =	]

Avg -> %SystemRoot%\System32\drivers\Avg ->  [Folder | Modified Date = 20.08.2008 23:11:19 | Attr =	]

incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm ->  [Ver =  | Size = 26485328 bytes | Modified Date = 20.08.2008 23:11:18 | Attr =	]

microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg ->  [Ver =  | Size = 50972 bytes | Modified Date = 20.08.2008 23:11:18 | Attr =	]

miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg ->  [Ver =  | Size = 211986 bytes | Modified Date = 08.08.2008 22:24:04 | Attr =	]

etc -> %SystemRoot%\System32\drivers\etc ->  [Folder | Modified Date = 13.08.2008 22:59:28 | Attr =	]

hosts -> %SystemRoot%\System32\drivers\etc\hosts ->  [Ver =  | Size = 27 bytes | Modified Date = 13.08.2008 22:59:28 | Attr =	]

mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> Malwarebytes Corporation [Ver = 1, 0, 0, 1 | Size = 17144 bytes | Modified Date = 17.08.2008 15:01:14 | Attr =	]

mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> Malwarebytes Corporation [Ver = 1.00 | Size = 38472 bytes | Modified Date = 17.08.2008 15:01:18 | Attr =	]

appmgmt -> %SystemRoot%\System32\appmgmt ->  [Folder | Modified Date = 12.08.2008 23:51:07 | Attr =	]

4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 

CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Modified Date = 21.08.2008 18:11:05 | Attr =	]

dllcache -> %SystemRoot%\System32\dllcache ->  [Folder | Modified Date = 21.08.2008 18:11:33 | Attr =	]

drivers -> %SystemRoot%\System32\drivers ->  [Folder | Modified Date = 19.08.2008 16:51:37 | Attr =	]

FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT ->  [Ver =  | Size = 255864 bytes | Modified Date = 17.08.2008 22:53:42 | Attr =	]

perfc009.dat -> %SystemRoot%\System32\perfc009.dat ->  [Ver =  | Size = 79710 bytes | Modified Date = 19.08.2008 16:56:30 | Attr =	]

perfc014.dat -> %SystemRoot%\System32\perfc014.dat ->  [Ver =  | Size = 88500 bytes | Modified Date = 19.08.2008 16:56:30 | Attr =	]

perfh009.dat -> %SystemRoot%\System32\perfh009.dat ->  [Ver =  | Size = 461918 bytes | Modified Date = 19.08.2008 16:56:30 | Attr =	]

perfh014.dat -> %SystemRoot%\System32\perfh014.dat ->  [Ver =  | Size = 464504 bytes | Modified Date = 19.08.2008 16:56:30 | Attr =	]

PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI ->  [Ver =  | Size = 1111108 bytes | Modified Date = 19.08.2008 16:56:30 | Attr =	]

wbem -> %SystemRoot%\System32\wbem ->  [Folder | Modified Date = 15.08.2008 09:41:00 | Attr =	]

wpa.dbl -> %SystemRoot%\System32\wpa.dbl ->  [Ver =  | Size = 2206 bytes | Modified Date = 19.08.2008 21:19:39 | Attr =	]

__c00381B7.dat -> %SystemRoot%\System32\__c00381B7.dat ->  [Ver =  | Size = 30208 bytes | Modified Date = 21.08.2008 13:49:29 | Attr =	]

~.exe -> %SystemRoot%\System32\~.exe ->  [Ver =  | Size = 37376 bytes | Modified Date = 21.08.2008 13:49:25 | Attr =	]

$hf_mig$ -> %SystemRoot%\$hf_mig$ ->  [Folder | Modified Date = 15.08.2008 03:06:41 | Attr =  H ]

5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 

AppPatch -> %SystemRoot%\AppPatch ->  [Folder | Modified Date = 17.08.2008 23:03:09 | Attr =	]

bootstat.dat -> %SystemRoot%\bootstat.dat ->  [Ver =  | Size = 2048 bytes | Modified Date = 19.08.2008 16:51:59 | Attr =   S]

Debug -> %SystemRoot%\Debug ->  [Folder | Modified Date = 15.08.2008 15:16:28 | Attr =	]

Fonts -> %SystemRoot%\Fonts ->  [Folder | Modified Date = 21.08.2008 18:11:15 | Attr = R S]

Help -> %SystemRoot%\Help ->  [Folder | Modified Date = 21.08.2008 18:11:27 | Attr =	]

inf -> %SystemRoot%\inf ->  [Folder | Modified Date = 15.08.2008 03:06:52 | Attr =  H ]

Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 20.08.2008 03:01:11 | Attr =  HS]

LastGood -> %SystemRoot%\LastGood ->  [Folder | Modified Date = 21.08.2008 18:11:27 | Attr =	]

NeroDigital.ini -> %SystemRoot%\NeroDigital.ini ->  [Ver =  | Size = 116 bytes | Modified Date = 11.08.2008 19:23:34 | Attr =	]

Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 21.08.2008 23:12:57 | Attr =	]

system.ini -> %SystemRoot%\system.ini ->  [Ver =  | Size = 227 bytes | Modified Date = 17.08.2008 23:04:04 | Attr =	]

system32 -> %SystemRoot%\system32 ->  [Folder | Modified Date = 21.08.2008 18:11:27 | Attr =	]

Tasks -> %SystemRoot%\Tasks ->  [Folder | Modified Date = 19.08.2008 16:55:20 | Attr =   S]

Temp -> %SystemRoot%\Temp ->  [Folder | Modified Date = 21.08.2008 23:19:03 | Attr =	]

Thumbs.db -> %SystemRoot%\Thumbs.db ->  [Ver =  | Size = 7680 bytes | Modified Date = 06.08.2008 22:27:33 | Attr =  HS]

@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable

win.ini -> %SystemRoot%\win.ini ->  [Ver =  | Size = 650 bytes | Modified Date = 15.08.2008 03:02:09 | Attr =	]

Check Updates for Windows Live Toolbar.job -> %SystemRoot%\tasks\Check Updates for Windows Live Toolbar.job ->  [Ver =  | Size = 254 bytes | Modified Date = 21.08.2008 23:14:00 | Attr =	]

MP Scheduled Scan.job -> %SystemRoot%\tasks\MP Scheduled Scan.job ->  [Ver =  | Size = 328 bytes | Modified Date = 21.08.2008 02:12:04 | Attr =  H ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Modified Date = 19.08.2008 16:52:14 | Attr =  H ]

C:\Documents and Settings\All Users\Programdata\Microsoft\HTML Help\ -> C:\Documents and Settings\All Users\Programdata\Microsoft\HTML Help ->  [Folder | Modified Date = 22.06.2006 16:01:41 | Attr =	]

hhcolreg.dat -> C:\Documents and Settings\All Users\Programdata\Microsoft\HTML Help\hhcolreg.dat ->  [Ver =  | Size = 9163 bytes | Modified Date = 29.03.2007 23:06:56 | Attr =	]

C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader ->  [Folder | Modified Date = 18.11.2005 17:15:24 | Attr =	]

qmgr0.dat -> C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 5485 bytes | Modified Date = 20.08.2008 06:03:37 | Attr =	]

qmgr1.dat -> C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 4232 bytes | Modified Date = 20.08.2008 06:03:37 | Attr =	]

C:\Documents and Settings\All Users\Programdata\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Programdata\Microsoft\OFFICE\DATA ->  [Folder | Modified Date = 18.11.2005 17:58:09 | Attr =	]

opa11.dat -> C:\Documents and Settings\All Users\Programdata\Microsoft\OFFICE\DATA\opa11.dat ->  [Ver =  | Size = 8206 bytes | Modified Date = 18.11.2005 17:58:09 | Attr =	]

C:\Documents and Settings\Eivind\Lokale innstillinger\Temp\ -> C:\Documents and Settings\Eivind\Lokale innstillinger\Temp ->  [Folder | Modified Date = 21.08.2008 23:18:28 | Attr =	]

Perflib_Perfdata_128.dat -> C:\Documents and Settings\Eivind\Lokale innstillinger\Temp\Perflib_Perfdata_128.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 19.08.2008 16:52:28 | Attr =	]

Perflib_Perfdata_82c.dat -> C:\Documents and Settings\Eivind\Lokale innstillinger\Temp\Perflib_Perfdata_82c.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 19.08.2008 16:53:21 | Attr =	]

Perflib_Perfdata_838.dat -> C:\Documents and Settings\Eivind\Lokale innstillinger\Temp\Perflib_Perfdata_838.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 19.08.2008 16:53:20 | Attr =	]

4 C:\Documents and Settings\Eivind\Lokale innstillinger\Temp\*.tmp files -> C:\Documents and Settings\Eivind\Lokale innstillinger\Temp\*.tmp -> 

C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp ->  [Folder | Modified Date = 21.08.2008 23:19:04 | Attr =	]

CompiledAdapter.dll -> C:\WINDOWS\Temp\CompiledAdapter.dll ->   [Ver = 0.0.0.0 | Size = 49152 bytes | Modified Date = 19.08.2008 16:52:37 | Attr =	]

C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp ->  [Folder | Modified Date = 21.08.2008 23:19:04 | Attr =	]

Perflib_Perfdata_aa0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_aa0.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 19.08.2008 16:52:25 | Attr =	]

[Files Modified - Additional Folder Scans - Non-Microsoft Only]

.zreglib -> %AllUsersProfile%\Programdata\.zreglib ->  [Ver =  | Size = 43 bytes | Modified Date = 17.08.2008 20:04:19 | Attr =  HS]

Malwarebytes -> %AllUsersProfile%\Programdata\Malwarebytes ->  [Folder | Modified Date = 19.08.2008 16:31:11 | Attr =	]

Azureus -> %AppData%\Azureus ->  [Folder | Modified Date = 17.08.2008 00:10:23 | Attr =	]

Malwarebytes -> %AppData%\Malwarebytes ->  [Folder | Modified Date = 19.08.2008 16:31:16 | Attr =	]

DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Lokale innstillinger\Programdata\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ->  [Ver =  | Size = 125952 bytes | Modified Date = 06.08.2008 16:59:37 | Attr =	]

GDIPFONTCACHEV1.DAT -> %UserProfile%\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT ->  [Ver =  | Size = 66032 bytes | Modified Date = 16.08.2008 14:19:23 | Attr =	]

Microsoft -> %UserProfile%\Lokale innstillinger\Programdata\Microsoft ->  [Folder | Modified Date = 16.08.2008 21:01:04 | Attr =	]

Adobe Photoshop 10 CS3+KeyGen ViCiOuS -> D:\Adobe Photoshop 10 CS3+KeyGen ViCiOuS ->  [Folder | Modified Date = 16.08.2008 22:11:33 | Attr =	]

Adya Classic -> D:\Adya Classic ->  [Folder | Modified Date = 20.08.2008 17:05:39 | Attr =	]

Brandi Carlile - The Story -> D:\Brandi Carlile - The Story ->  [Folder | Modified Date = 16.08.2008 22:11:33 | Attr =	]

Diverse Skrivebord -> D:\Diverse Skrivebord ->  [Folder | Modified Date = 13.08.2008 23:21:35 | Attr =	]

DVD Cover -> D:\DVD Cover ->  [Folder | Modified Date = 17.08.2008 00:42:25 | Attr =	]

Eivind -> D:\Eivind ->  [Folder | Modified Date = 07.08.2008 10:50:51 | Attr =	]

Mine delte mapper.lnk -> D:\Mine delte mapper.lnk ->  [Ver =  | Size = 400 bytes | Modified Date = 19.08.2008 16:53:12 | Attr =	]

Mine SERIER -> D:\Mine SERIER ->  [Folder | Modified Date = 06.08.2008 16:59:25 | Attr = R  ]

torrent -> D:\torrent ->  [Folder | Modified Date = 17.08.2008 00:10:16 | Attr =	]

Varg.Veum.Falne.Engler.NORWEGIAN.PAL.DVDR-SVENNE -> D:\Varg.Veum.Falne.Engler.NORWEGIAN.PAL.DVDR-SVENNE ->  [Folder | Modified Date = 17.08.2008 00:09:03 | Attr =	]

AnyDVD.lnk -> %AllUsersProfile%\Skrivebord\AnyDVD.lnk ->  [Ver =  | Size = 758 bytes | Modified Date = 02.08.2008 19:26:12 | Attr =	]

CloneDVD2.lnk -> %AllUsersProfile%\Skrivebord\CloneDVD2.lnk ->  [Ver =  | Size = 856 bytes | Modified Date = 25.07.2008 16:00:07 | Attr =	]

Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Skrivebord\Malwarebytes' Anti-Malware.lnk ->  [Ver =  | Size = 702 bytes | Modified Date = 19.08.2008 16:31:13 | Attr =	]

CCleaner.lnk -> %UserProfile%\Skrivebord\CCleaner.lnk ->  [Ver =  | Size = 1550 bytes | Modified Date = 07.08.2008 00:10:55 | Attr =	]

ComboFix.exe -> %UserProfile%\Skrivebord\ComboFix.exe ->  [Ver =  | Size = 2718447 bytes | Modified Date = 17.08.2008 23:00:41 | Attr = R  ]

HiJackThis.exe -> %UserProfile%\Skrivebord\HiJackThis.exe -> Trend Micro Inc. [Ver = 2.00.0002 | Size = 401720 bytes | Modified Date = 17.08.2008 08:22:30 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\HiJackThis.exe:Zone.Identifier

mbam-setup.exe -> %UserProfile%\Skrivebord\mbam-setup.exe -> Malwarebytes Corporation									 [Ver = 1.25				 | Size = 2085280 bytes | Modified Date = 19.08.2008 16:30:26 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\mbam-setup.exe:Zone.Identifier

OBD2 på Audi -> %UserProfile%\Skrivebord\OBD2 på Audi ->  [Folder | Modified Date = 17.08.2008 20:32:33 | Attr =	]

OTMoveIt2.exe -> %UserProfile%\Skrivebord\OTMoveIt2.exe -> OldTimer Tools [Ver = 1.0.4.3 | Size = 291840 bytes | Modified Date = 17.08.2008 22:50:15 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\OTMoveIt2.exe:Zone.Identifier

OTScanIt -> %UserProfile%\Skrivebord\OTScanIt ->  [Folder | Modified Date = 21.08.2008 23:11:49 | Attr =	]

OTScanIt.exe -> %UserProfile%\Skrivebord\OTScanIt.exe ->  [Ver =  | Size = 568477 bytes | Modified Date = 21.08.2008 23:10:57 | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserProfile%\Skrivebord\OTScanIt.exe:Zone.Identifier

Prosjekt hus klagesak ytter tak -> %UserProfile%\Skrivebord\Prosjekt hus klagesak ytter tak ->  [Folder | Modified Date = 14.08.2008 22:21:34 | Attr =	]

Signaturer.dot -> %UserProfile%\Skrivebord\Signaturer.dot ->  [Ver =  | Size = 27136 bytes | Modified Date = 05.08.2008 13:38:07 | Attr =	]

SpeedTouch - Home.url -> %UserProfile%\Skrivebord\SpeedTouch - Home.url ->  [Ver =  | Size = 228 bytes | Modified Date = 09.08.2008 22:27:09 | Attr =	]

@Alternate Data Stream - 1406 bytes -> %UserProfile%\Skrivebord\SpeedTouch - Home.url:favicon

Microsoft Shared -> %CommonProgramFiles%\Microsoft Shared ->  [Folder | Modified Date = 15.08.2008 23:10:52 | Attr =	]



[CatchMe Rootkit Scan by GMER]

< Windows folder & sub-folders >

scanning hidden processes ...

IPC error: 2 Systemet finner ikke angitt fil.

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

C:\WINDOWS\system32\drivers\Avg\incavi.avm.prepare

C:\WINDOWS\Thumbs.db:encryptable 0 bytes

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 2

< Document and Settings folder & sub folders >

scanning hidden files ...

IPC error: 2 Systemet finner ikke angitt fil.

C:\Documents and Settings\All Users\Dokumenter\Min musikk\Eksempelmusikk\Thumbs.db:encryptable 0 bytes

C:\Documents and Settings\All Users\Dokumenter\Mine bilder\Eksempelbilder\Thumbs.db:encryptable 0 bytes

C:\Documents and Settings\All Users\Programdata\Pinnacle Studio\Data\Render\MY MOVIE B7FB025F\tmp.m2v:PinnacleIndex 0 bytes

C:\Documents and Settings\Eivind\Favoritter\Koblinger\DnB NOR.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\Koblinger\Eurofoto.url:favicon 4286 bytes

C:\Documents and Settings\Eivind\Favoritter\Koblinger\Facebook.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\Koblinger\Gule Sider®.url:favicon 25214 bytes

C:\Documents and Settings\Eivind\Favoritter\Koblinger\VG.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Koblinger\yr.no.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\AltaVista - Babel Fish Oversett.url:favicon 318 bytes

C:\Documents and Settings\Eivind\Favoritter\AudioVideo\AVforum.no - Home.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\AudioVideo\ELTEK AS.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\AudioVideo\Siv. ing. Benum AS.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\AudioVideo\€€ Velkommen til Installbay.no €€.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\AVISER\VG Nett - Hovedsiden.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Audi\Die Audi 100-A6 C4 Homepage.url:favicon 3134 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Audi\ross-tech VAG-COM Downloads Current Release and Manual.url:favicon 318 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Bilinform.no - Spør vår bilmekaniker - Forsiden.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\FinalGear.com  News.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Hej Bilist.url:favicon 1718 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Mercedes\Gørløse Autoimport » Reservedele.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Mercedes\Mercedes Benz Parts, Mercedes Parts, Accessories.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Mercedes\Mercedes-Benz Club Russia  Mercedes-Benz - Code.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Mercedes\Mercedes-Benz Club Russia  Mercedes-Benz - VIN.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Mercedes\

C:\Documents and Settings\Eivind\Favoritter\Bil\Mercedes\MBEntusiastklubb.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\Mercedes\MBenzNL - Home.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\Bil\RATS.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\Data&Elektronikk\Boot INI Options Reference.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\Data&Elektronikk\Chieftec - Arena Electronic GmbH.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\Data&Elektronikk\EnhanceIE.com - Your source for Internet Explorer Enhancements.url:favicon 318 bytes

C:\Documents and Settings\Eivind\Favoritter\Data&Elektronikk\LEDteknikk Webshop  led  lysdioder  leds  spot  powerchip  nova  luxeon.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\Data&Elektronikk\Ukjente filer siden!.url:favicon 318 bytes

C:\Documents and Settings\Eivind\Favoritter\Data&Elektronikk\Win-XP.no.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\Data&Elektronikk\www.kompotek.no - nettbutikken med det meste.url:favicon 1618 bytes

C:\Documents and Settings\Eivind\Favoritter\DIVERSE\Norsk Huskattforening.url:favicon 10134 bytes

C:\Documents and Settings\Eivind\Favoritter\DIVERSE\online.no.url:favicon 766 bytes

C:\Documents and Settings\Eivind\Favoritter\DIVERSE\HijackThis Logfileauswertung.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\DnB NOR.no.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\Kontakt\Blink - Norges største nettsamfunn.url:favicon 2494 bytes

C:\Documents and Settings\Eivind\Favoritter\Kontakt\Facebook  Welcome to Facebook!.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\Map24 - Ruteplanlegger og kart for Norge, Europa og USA.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\Black Dyke Band - Home Page.url:favicon 1718 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\Grimethorpe Colliery Band Home Page.url:favicon 318 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\Kopervik Musikkorps.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\Oslofjord Brass - Hjem.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\Provinciale Brassband Groningen - Home.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\Velkommen til Frelsesarmeens Territoriale Hornorkester.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\Windcorp Brassband.url:favicon 2238 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass Band's\YBS Band Welcome to the band's website.url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Brass-Forum.co.uk - The Online Home for Brass Musicians.url:favicon 3262 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Contrabass Mania.url:favicon 4710 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\Musikk forretning - verksted\Woodwind and Brasswind - Largest provider of Band Instruments (woodwind, brass, string and percussion) at guaranteed low prices.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\The Brass Band Portal.url:favicon 534 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\World of Brass - The Home of Brass Sound  5 Years  2002 - 2007.url:favicon 3128 bytes

C:\Documents and Settings\Eivind\Favoritter\Musikk-Instrument\World of Brass - The Home of Brass Sound.url:favicon 3128 bytes

C:\Documents and Settings\Eivind\Favoritter\Forum\Bilforumet.net - powered by vBulletin.url:favicon 10134 bytes

C:\Documents and Settings\Eivind\Favoritter\Forum\BleepingComputer.com - Computer Help Forums.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Forum\Brass-Forum.co.uk.url:favicon 3262 bytes

C:\Documents and Settings\Eivind\Favoritter\Forum\merceforumet.url:favicon 1758 bytes

C:\Documents and Settings\Eivind\Favoritter\Forum\Offroad.no (Powered by Invision Power Board).url:favicon 3638 bytes

C:\Documents and Settings\Eivind\Favoritter\Forum\The Trombone Forum - Index.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Heinzelnisse - Ordbok Norsk Tysk.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\http--www.kompotek.no-calc-motstand.htm.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\Isabella A-mål søk.url:favicon 568 bytes

C:\Documents and Settings\Eivind\Favoritter\JetCarrier - magnum NO AS, Norway, Sweden, USA.url:favicon 318 bytes

C:\Documents and Settings\Eivind\Favoritter\PiercingKlærMoteSmykkeraccessoriesKlokker - Superkul.no.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\Scan Messenger  Finn ut hvem som slettet deg fra MSN uten at du merket det.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\SpeedTouch - Home.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\Torrent\The Pirate Bay - Verdens største BitTorrent tracker.url:favicon 824 bytes

C:\Documents and Settings\Eivind\Favoritter\Torrent\Convivea - Home of Bit Che - Torrent Search.url:favicon 18942 bytes

C:\Documents and Settings\Eivind\Favoritter\Torrent\EZTV - TV Torrents Online.url:favicon 894 bytes

C:\Documents and Settings\Eivind\Favoritter\Torrent\Torrent Portal - Free BitTorrent File Download Index and Torrent Search.url:favicon 766 bytes

C:\Documents and Settings\Eivind\Favoritter\Torrent\TorrentSpy.com  The Most Advanced Torrent Search Engine.url:favicon 1150 bytes

C:\Documents and Settings\Eivind\Favoritter\TriTrans interaktiv ordbok - Engelsk - Spansk - Norsk..url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Favoritter\TV\NRK.no - Forsida.url:favicon 15086 bytes

C:\Documents and Settings\Eivind\Favoritter\TV\TVNORGE.url:favicon 4464 bytes

C:\Documents and Settings\Eivind\Favoritter\yr.no - Været for Norge og verden fra Meteorologisk institutt og NRK.url:favicon 11758 bytes

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\Sharing Folders\morc@spray.no\Thumbs.db:encryptable 0 bytes

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\01\13-{A35D3A3A-25CE-9C50-8101-8C504ABA0011}-v1-{857E01E8-84EE-4383-8643-F7D12233E211}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\33\52-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v33-{B7CE174A-7650-497A-9F0A-8CE370183395}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1092 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\33\52-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v33-{B7CE174A-7650-497A-9F0A-8CE370183395}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\34\53-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v34-{B7CE174A-7650-497A-9F0A-8CE370183395}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1308 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\34\53-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v34-{B7CE174A-7650-497A-9F0A-8CE370183395}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 144 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\35\54-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v35-{B7CE174A-7650-497A-9F0A-8CE370183395}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2010 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\35\54-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v35-{B7CE174A-7650-497A-9F0A-8CE370183395}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 216 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\36\72-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v36-{B7CE174A-7650-497A-9F0A-8CE370183395}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1272 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\36\72-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v36-{B7CE174A-7650-497A-9F0A-8CE370183395}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 152 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\37\56-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v37-{B7CE174A-7650-497A-9F0A-8CE370183395}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1398 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\37\56-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v37-{B7CE174A-7650-497A-9F0A-8CE370183395}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 168 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\38\57-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v38-{B7CE174A-7650-497A-9F0A-8CE370183395}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1416 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\38\57-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v38-{B7CE174A-7650-497A-9F0A-8CE370183395}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 152 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\39\58-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v39-{B7CE174A-7650-497A-9F0A-8CE370183395}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1398 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\39\58-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v39-{B7CE174A-7650-497A-9F0A-8CE370183395}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 152 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\40\59-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v40-{B7CE174A-7650-497A-9F0A-8CE370183395}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1344 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\40\59-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v40-{B7CE174A-7650-497A-9F0A-8CE370183395}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 152 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\41\60-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v41-{B7CE174A-7650-497A-9F0A-8CE370183395}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1344 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\41\60-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v41-{B7CE174A-7650-497A-9F0A-8CE370183395}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 160 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\42\61-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v42-{B7CE174A-7650-497A-9F0A-8CE370183395}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1704 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\42\61-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v42-{B7CE174A-7650-497A-9F0A-8CE370183395}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 208 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\43\62-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v43-{B7CE174A-7650-497A-9F0A-8CE370183395}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 624 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\43\62-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v43-{B7CE174A-7650-497A-9F0A-8CE370183395}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 72 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\44\63-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v44-{B7CE174A-7650-497A-9F0A-8CE370183395}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1794 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\44\63-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v44-{B7CE174A-7650-497A-9F0A-8CE370183395}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 192 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\45\64-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v45-{B7CE174A-7650-497A-9F0A-8CE370183395}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1650 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\45\64-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v45-{B7CE174A-7650-497A-9F0A-8CE370183395}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 184 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\47\66-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v47-{B7CE174A-7650-497A-9F0A-8CE370183395}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2694 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\47\66-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v47-{B7CE174A-7650-497A-9F0A-8CE370183395}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 296 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\48\67-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v48-{B7CE174A-7650-497A-9F0A-8CE370183395}-v67-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2586 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\48\67-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v48-{B7CE174A-7650-497A-9F0A-8CE370183395}-v67-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 288 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\49\68-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v49-{B7CE174A-7650-497A-9F0A-8CE370183395}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2676 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\49\68-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v49-{B7CE174A-7650-497A-9F0A-8CE370183395}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 296 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\50\69-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v50-{B7CE174A-7650-497A-9F0A-8CE370183395}-v69-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3234 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\50\69-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v50-{B7CE174A-7650-497A-9F0A-8CE370183395}-v69-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 336 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\51\70-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v51-{B7CE174A-7650-497A-9F0A-8CE370183395}-v70-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2928 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\51\70-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v51-{B7CE174A-7650-497A-9F0A-8CE370183395}-v70-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 320 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\52\71-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v52-{B7CE174A-7650-497A-9F0A-8CE370183395}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2532 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Programdata\Microsoft\Messenger\bassbone@hotmail.com\SharingMetadata\morc@spray.no\DFSR\Staging\CS{A35D3A3A-25CE-9C50-8101-8C504ABA0011}\52\71-{4479913C-5767-4C49-97BD-CBFB6DB51957}-v52-{B7CE174A-7650-497A-9F0A-8CE370183395}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 288 bytes hidden from API

C:\Documents and Settings\Eivind\Lokale innstillinger\Temp\cgbdlpmx.dll

C:\Documents and Settings\Eivind\Skrivebord\OBD2 på Audi\Thumbs.db:encryptable 0 bytes

C:\Documents and Settings\Eivind\Skrivebord\SpeedTouch - Home.url:favicon 1406 bytes

C:\Documents and Settings\Eivind\Skrivebord\Thumbs.db:encryptable 0 bytes

C:\Documents and Settings\Hege\Favoritter\Arguineguín - Don Paco - Vings Verden.url:favicon 894 bytes

C:\Documents and Settings\Hege\Favoritter\Arguineguín - Dorado Beach - Vings Verden.url:favicon 894 bytes

C:\Documents and Settings\Hege\Favoritter\Buzzador - Mine egne sider.url:favicon 2862 bytes

C:\Documents and Settings\Hege\Favoritter\DinSide.no - Få gratis advokathjelp.url:favicon 1150 bytes

C:\Documents and Settings\Hege\Favoritter\Familjetorget - Till Pappa Keps-Skärp.url:favicon 1078 bytes

C:\Documents and Settings\Hege\Favoritter\http--www.messengerdeletechecker7.tk-.url:favicon 894 bytes

C:\Documents and Settings\Hege\Favoritter\KAKEMONSEN.NO - Størst på Kakeoppskrifter.url:favicon 3262 bytes

C:\Documents and Settings\Hege\Favoritter\Tine.no - Oppskrifter - Sans dessert.url:favicon 1150 bytes

C:\Documents and Settings\Hege\Favoritter\VG Nett - Hovedsiden.url:favicon 1406 bytes

C:\Documents and Settings\Hege\Favoritter\yesstyle.com Shopping Bag.url:favicon 3638 bytes

C:\Documents and Settings\Hege\Favoritter\YEYE - Slik lager du iskrem selv.url:favicon 1406 bytes

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\Sharing Folders\moop86@hotmail.com\Thumbs.db:encryptable 0 bytes

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\22\1322-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1322-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1322-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 736 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\22\2722-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2722-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2722-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\54\1254-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1254-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1254-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\54\1254-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1254-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1254-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\54\1354-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1354-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1354-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1144 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\54\2654-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2654-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2654-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1416 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\00\1300-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1300-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4926 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\00\1300-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1300-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 584 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\00\1400-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1400-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1400-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\00\2700-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2700-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2700-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1552 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\01\1301-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1301-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1301-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4962 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\01\1301-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1301-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1301-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 560 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\01\14-{8F730115-15C2-7A17-B3DB-AEF4F7967476}-v1-{58BEA296-2C5F-4F6A-8062-F89C86B1AD9E}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\01\2701-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2701-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2701-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1776 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\02\1302-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1302-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1302-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7050 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\02\1302-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1302-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1302-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\02\2702-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2702-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2702-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1840 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\03\1303-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1303-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1303-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6006 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\03\1303-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1303-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1303-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\03\2703-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2703-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2703-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\04\1304-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1304-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1304-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 728 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\04\2704-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2704-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2704-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1616 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\05\1305-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1305-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1305-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\05\2705-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2705-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2705-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1736 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\06\1306-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1306-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1306-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\06\2706-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2706-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2706-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\07\1307-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1307-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1307-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\07\2707-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2707-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2707-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\08\1308-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1308-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1308-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 856 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\08\2708-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2708-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2708-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\09\1309-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1309-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1309-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 864 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\09\2709-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2709-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2709-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1736 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\10\1310-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1310-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1310-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 632 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\10\2710-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2710-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2710-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1832 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\11\1311-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1311-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1311-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\11\2711-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2711-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2711-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1632 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\12\1312-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1312-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1312-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\12\2712-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2712-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2712-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1504 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\13\1313-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1313-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1313-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\13\2713-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2713-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2713-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\14\1314-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1314-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1314-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\14\2714-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2714-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2714-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1128 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\15\1315-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1315-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1315-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 992 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\15\2715-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2715-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2715-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1608 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\16\1316-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1316-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1316-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\16\2716-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2716-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2716-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\17\1317-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1317-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1317-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\17\2717-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2717-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2717-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1744 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\18\1318-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1318-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1318-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1024 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\18\2718-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2718-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2718-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1496 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\19\1319-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1319-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1319-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\19\2719-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2719-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2719-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1448 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\20\1320-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1320-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1320-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\20\2720-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2720-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2720-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1344 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\21\1321-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1321-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1321-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\21\2721-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2721-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2721-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\55\1255-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1255-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1255-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6618 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\55\1255-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1255-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1255-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\55\1355-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1355-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1355-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\55\2655-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2655-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2655-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\56\1256-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1256-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1256-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6204 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\56\1256-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1256-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1256-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 704 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\56\1356-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1356-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1356-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\56\2656-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2656-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2656-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1232 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\57\1257-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1257-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1257-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6780 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\57\1257-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1257-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1257-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\57\1357-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1357-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1357-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\57\2657-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2657-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2657-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1456 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\58\1258-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1258-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5610 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\58\1258-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1258-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 624 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\58\1358-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1358-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1358-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1112 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\58\2658-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2658-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2658-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1576 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\59\1259-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1259-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1259-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5466 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\59\1259-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1259-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1259-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 608 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\59\1359-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1359-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1359-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\59\2659-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2659-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2659-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1576 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\60\1260-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1260-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1260-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5448 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\60\1260-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1260-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1260-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 616 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\60\1360-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1360-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1360-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\60\2660-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2660-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2660-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1608 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\61\1261-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1261-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1261-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5736 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\61\1261-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1261-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1261-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\61\1361-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1361-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1361-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1048 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\61\2661-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2661-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2661-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1528 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\62\1262-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1262-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1262-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6132 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\62\1262-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1262-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1262-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\62\1362-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1362-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1362-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1008 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\62\2662-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2662-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2662-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1112 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\63\1263-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1263-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1263-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6834 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\63\1263-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1263-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1263-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\63\1363-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1363-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1363-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\63\2663-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2663-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2663-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1344 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\64\1264-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1264-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1264-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\64\1264-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1264-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1264-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 736 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\64\1364-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1364-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1364-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1136 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\64\2664-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2664-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2664-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\65\1265-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1265-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1265-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\65\1265-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1265-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1265-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\65\1365-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1365-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1365-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1136 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\65\2665-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2665-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2665-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\66\1266-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1266-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1266-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7482 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\66\1266-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1266-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1266-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\66\1366-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1366-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1366-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\66\2666-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2666-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2666-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1416 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\67\1267-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1267-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1267-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6420 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\67\1267-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1267-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1267-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 696 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\67\1367-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1367-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1367-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1080 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\67\2667-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2667-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2667-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1512 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\68\1268-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1268-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1268-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6582 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\68\1268-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1268-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1268-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\68\1368-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1368-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1368-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\68\2668-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2668-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2668-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1152 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\69\1269-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1269-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1269-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6294 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\69\1269-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1269-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1269-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\69\1369-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1369-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1369-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1256 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\69\2669-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2669-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2669-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\70\1270-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1270-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1270-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6384 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\70\1270-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1270-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1270-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\70\1370-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1370-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1370-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\70\2670-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2670-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2670-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1528 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\71\1271-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1271-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1271-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5952 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\71\1271-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1271-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1271-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\71\1371-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1371-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1371-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1008 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\71\2671-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2671-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2671-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1808 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\72\1272-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1272-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4980 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\72\1272-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1272-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 568 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\72\1372-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1372-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1372-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1000 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\72\2672-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2672-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2672-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1608 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\73\1273-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1273-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1273-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5520 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\73\1273-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1273-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1273-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 576 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\73\1373-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1373-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1373-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\73\2673-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2673-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2673-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1496 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\74\1274-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1274-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1274-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5970 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\74\1274-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1274-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1274-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 656 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\74\1374-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1374-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1374-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\74\2674-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2674-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2674-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\75\1275-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1275-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1275-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6906 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\75\1275-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1275-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1275-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\75\1375-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1375-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1375-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1048 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\75\2675-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2675-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2675-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1152 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\76\1276-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1276-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1276-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6636 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\76\1276-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1276-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1276-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\76\1376-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1376-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1376-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1032 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\76\2676-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2676-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2676-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\77\1277-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1277-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1277-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5700 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\77\1277-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1277-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1277-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 632 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\77\1377-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1377-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1377-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1040 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\77\2677-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2677-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2677-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\78\1278-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1278-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1278-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8364 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\78\1278-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1278-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1278-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 912 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\78\1378-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1378-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1378-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\78\2678-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2678-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2678-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1536 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\79\1279-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1279-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8058 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\79\1279-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1279-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 912 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\79\1379-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1379-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1379-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1032 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\79\2679-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2679-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2679-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1400 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\80\1280-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1280-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7428 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\80\1280-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1280-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\80\1380-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1380-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1380-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\80\2680-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2680-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2680-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1464 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\81\1281-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1281-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7572 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\81\1281-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1281-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\81\1381-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1381-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1381-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 688 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\81\2681-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2681-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2681-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1392 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\82\1282-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1282-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7122 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\82\1282-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1282-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\82\1382-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1382-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1382-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 688 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\82\2682-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2682-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2682-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1464 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\83\1283-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1283-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5664 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\83\1283-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1283-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 632 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\83\1383-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1383-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1383-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\83\2683-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2683-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2683-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1608 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\84\1284-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1284-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\84\1284-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1284-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 728 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\84\1384-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1384-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1384-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 856 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\84\2684-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2684-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2684-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1664 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\85\1285-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1285-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6420 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\85\1285-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1285-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\85\1385-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1385-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1385-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\85\2685-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2685-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2685-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\86\1286-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1286-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6204 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\86\1286-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1286-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\86\1386-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1386-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1386-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 888 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\86\2686-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2686-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2686-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1232 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\87\1287-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1287-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5862 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\87\1287-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1287-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\87\1387-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1387-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1387-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 960 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\87\2687-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2687-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2687-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1296 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\87\887-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v887-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v887-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1728 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\88\1288-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1288-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6168 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\88\1288-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1288-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\88\1388-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1388-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1388-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 600 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\88\2688-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2688-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2688-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 984 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\88\888-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v888-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v888-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1752 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\89\1289-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1289-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7878 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\89\1289-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1289-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\89\1389-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1389-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1389-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\89\2689-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2689-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2689-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1424 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\89\889-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v889-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v889-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1576 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\90\1290-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1290-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8166 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\90\1290-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1290-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\90\1390-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1390-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1390-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\90\2690-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2690-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2690-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1528 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\90\890-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v890-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v890-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\91\1291-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1291-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7266 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\91\1291-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1291-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\91\1391-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1391-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1391-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 712 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\91\2691-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2691-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2691-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1344 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\91\891-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v891-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v891-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\92\1292-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1292-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1292-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9030 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\92\1292-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1292-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1292-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 984 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\92\1392-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1392-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1392-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\92\2692-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2692-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2692-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\93\1293-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1293-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7194 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\93\1293-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1293-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 784 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\93\1393-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1393-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1393-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\93\2693-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2693-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2693-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\94\1294-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1294-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8886 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\94\1294-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1294-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 976 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\94\1394-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1394-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1394-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\94\2694-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2694-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2694-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\95\1295-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1295-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6294 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\95\1295-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1295-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 712 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\95\1395-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1395-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1395-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\95\2695-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2695-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2695-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1624 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\96\1296-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1296-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7968 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\96\1296-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1296-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\96\1396-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1396-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1396-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\96\2696-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2696-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2696-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1648 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\97\1297-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1297-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8436 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\97\1297-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1297-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\97\1397-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1397-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1397-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 584 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\97\2697-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2697-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2697-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1688 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\98\1298-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1298-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7932 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\98\1298-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1298-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\98\1398-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1398-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1398-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 632 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\98\2698-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2698-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2698-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1520 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\99\1299-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1299-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8346 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\99\1299-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1299-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 944 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\99\1399-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1399-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1399-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 736 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\99\2699-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2699-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2699-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1176 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\23\1323-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1323-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1323-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\23\2723-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2723-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2723-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1376 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\24\1324-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1324-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1324-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 784 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\24\2724-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2724-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2724-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1200 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\25\1325-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1325-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1325-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 728 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\25\2725-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2725-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2725-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1408 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\26\1326-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1326-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1326-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\26\2726-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2726-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2726-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1416 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\27\1327-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1327-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1327-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\27\2727-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2727-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2727-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1480 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\28\1328-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1328-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1328-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\28\2628-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2628-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2628-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\28\2728-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2728-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2728-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1600 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\29\1329-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1329-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1329-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1072 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\29\2629-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2629-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2629-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1488 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\29\2729-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2729-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2729-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1384 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\30\1330-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1330-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1330-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\30\2630-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2630-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2630-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1544 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\30\2730-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2730-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2730-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\31\1331-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1331-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1331-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\31\2631-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2631-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2631-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1592 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\31\2731-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2731-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2731-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1648 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\32\1332-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1332-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1332-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 784 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\32\2632-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2632-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2632-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1384 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\32\2732-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2732-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2732-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\33\1233-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1233-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1233-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\33\1233-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1233-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1233-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\33\1333-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1333-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1333-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 712 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\33\2633-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2633-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2633-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1408 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\33\2733-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2733-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2733-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1664 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\34\1234-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1234-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7104 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\34\1234-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1234-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\34\1334-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1334-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1334-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\34\2634-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2634-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2634-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1760 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\34\2734-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2734-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2734-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\35\1235-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1235-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8724 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\35\1235-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1235-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 992 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\35\1335-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1335-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1335-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 888 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\35\2635-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2635-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2635-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1792 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\35\2735-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2735-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2735-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1656 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\36\1236-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1236-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9984 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\36\1236-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1236-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\36\1336-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1336-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1336-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\36\2636-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2636-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2636-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\36\2736-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2736-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2736-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1472 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\37\1237-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1237-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1237-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5880 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\37\1237-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1237-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1237-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\37\1337-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1337-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1337-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 736 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\37\2637-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2637-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2637-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1400 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\37\2737-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2737-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2737-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1696 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\38\1238-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1238-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1238-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7032 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\38\1238-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1238-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1238-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\38\1338-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1338-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1338-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\38\2638-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2638-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2638-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1424 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\38\2738-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2738-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2738-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1568 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\39\1239-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1239-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6528 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\39\1239-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1239-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 712 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\39\1339-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1339-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1339-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\39\2639-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2639-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2639-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1472 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\39\2739-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2739-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2739-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1696 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\40\1240-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1240-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1240-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6042 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\40\1240-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1240-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1240-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\40\1340-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1340-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1340-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\40\2640-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2640-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2640-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1304 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\40\2740-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2740-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2740-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1808 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\41\1241-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1241-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1241-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4962 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\41\1241-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1241-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1241-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 552 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\41\1341-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1341-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1341-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\41\2641-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2641-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2641-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1256 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\41\2741-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2741-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2741-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2392 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\42\1242-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1242-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1242-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5520 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\42\1242-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1242-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1242-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\42\1342-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1342-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1342-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 744 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\42\2642-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2642-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2642-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1296 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\42\2742-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2742-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2742-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1456 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\43\1243-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1243-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1243-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7086 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\43\1243-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1243-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1243-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\43\1343-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1343-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1343-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\43\2643-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2643-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2643-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1400 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\44\1244-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1244-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1244-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6474 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\44\1244-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1244-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1244-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 712 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\44\1344-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1344-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1344-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 728 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\44\2644-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2644-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2644-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1320 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\45\1245-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1245-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1245-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5880 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\45\1245-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1245-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1245-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\45\1345-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1345-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1345-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\45\2645-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2645-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2645-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1184 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\46\1246-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1246-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1246-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5988 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\46\1246-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1246-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1246-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\46\1346-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1346-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1346-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\46\2646-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2646-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2646-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\47\1247-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1247-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1247-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5952 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\47\1247-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1247-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1247-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 672 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\47\1347-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1347-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1347-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\47\2647-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2647-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2647-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1600 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\48\1248-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1248-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1248-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5520 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\48\1248-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1248-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1248-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 616 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\48\1348-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1348-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1348-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\48\2648-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2648-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2648-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1720 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\49\1249-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1249-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1249-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5574 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\49\1249-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1249-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1249-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 600 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\49\1349-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1349-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1349-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\49\2649-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2649-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2649-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1144 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\50\1250-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1250-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1250-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5916 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\50\1250-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1250-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1250-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\50\1350-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1350-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1350-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1184 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\50\2650-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2650-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2650-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1144 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\51\1251-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1251-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1251-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5592 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\51\1251-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1251-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1251-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 616 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\51\1351-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1351-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1351-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1112 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\51\2651-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2651-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2651-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1496 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\52\1252-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1252-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1252-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8166 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\52\1252-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1252-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1252-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\52\1352-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1352-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1352-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\52\2652-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2652-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2652-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1280 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\53\1253-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1253-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1253-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7950 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\53\1253-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1253-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1253-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\53\1353-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1353-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v1353-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1048 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\moop86@hotmail.com\DFSR\Staging\CS{8F730115-15C2-7A17-B3DB-AEF4F7967476}\53\2653-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2653-{46D96083-E6A9-4F5D-8F02-F1D64D1673F0}-v2653-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1232 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\ran-1964@hotmail.com\DFSR\Staging\CS{AFA0B755-C363-BB9A-D514-6A928B0FB0EF}\01\13-{AFA0B755-C363-BB9A-D514-6A928B0FB0EF}-v1-{58BEA296-2C5F-4F6A-8062-F89C86B1AD9E}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API

C:\Documents and Settings\Hege\Lokale innstillinger\Programdata\Microsoft\Messenger\tigerpusen1111@hotmail.com\SharingMetadata\Working\database_2C74_985B_7498_2A1A\fsr0444A.log 131072 bytes

scan completed successfully

hidden files: 503



< End of report >





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users