Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rundll and ntload.dll errors possible virus, malware, spyware


  • This topic is locked This topic is locked
13 replies to this topic

#1 socain

socain

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:48 PM

Posted 22 January 2010 - 03:27 PM

Fist of all I would like to give thanks in advance to any and all that are willing to help. Second I would like to apologize for my dull sense of ability when it comes to things like this, but for the ones that are actually here to help people like me again thankyou. Third, please excuse my literacy.

So I have followed the Preparation Guide for use before posting about your potential Malware problem, and hopefully all is well. The basic problem is that I get a very specific error when I boot up. It is a Rundll Error. C:\users\"myname"~1\ntload.dll. And it happens every time. Recently I noticed my computer being very sluggish and laggy, start up takes a really long time. I have Avast version 4.8 Home Edition. And I have Spybot Search&Destroy. So I ran both as boot time scans and found several problems. Some were fixed and some were not able to be moved or fixed. And as a result My computer remains in the same state. I do have windows firewall active. My network is secured. My internet activities vary from surfing, to email, downloading, and some peer to peer stuff. There have been times while on the internet that avast warns me of a detection of a virus or what not and says "not to panic that it stopped it from entering my computer" and to either move it to chest or delet it, so I did, thinking nothing of it as my mind was put to ease that the program had done its job. I dont know what else to add, please if you need any other info that i have not added just ask.

My system info is as follows.

Vista Home Premium Ver. 6.0.6002 Service Pack 2
Inspirion 530
Intel Core 2 Quad CPU @ 2.4Ghz, 2400 Mhz 4
Installed 3.00 GB
Total Physical Mem. 2.99 GB
Available 1.46 GB
Total Virtual Mem. 6.21 GB
Available Virtual Mem. 4.64 GB
Page File Space 3.28 GB

The rest is the information gathered for the Prep. Guide. I do have a "HijackThis" log as well. I will attatch it as well. If it may help.


DDS (Ver_09-12-01.01) - NTFSx86
Run by Josh Graves at 11:04:47.64 on Fri 01/22/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3060.1661 [GMT -8:00]

SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\System32\alg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\DWA-160\AirNCFG.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Windows\System32\explorer32\winsysmngr32.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Users\Josh Graves\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2DTQMEUZ\HijackThis[1].exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Josh Graves\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080313
mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080313
uInternet Settings,ProxyOverride = *.local
BHO: MRI_DISABLED - No File
BHO: Browser Address Error Redirector - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [notepad] rundll32.exe c:\users\joshgr~1\ntload.dll,_IWMPEvents@0
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [D-Link D-Link Xtreme N Dual Band DWA-160 ] c:\program files\d-link\dwa-160\AirNCFG.exe
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [WinLoad] c:\windows\system32\Winload.exe
mRun: [Winload32] c:\windows\system32\explorer32\winload32.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
StartupFolder: c:\users\joshgr~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\digita~1.lnk - c:\program files\digital line detect\DLG.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-10 114768]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-10 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2008-12-10 53328]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-12-10 138680]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-1-1 1153368]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-12-10 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-12-10 352920]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-4-16 11520]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 libusb0;LibUsb-Win32 - Kernel Driver 08/27/2006, 0.1.12.0;c:\windows\system32\drivers\libusb0.sys [2008-2-18 33792]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2009-3-15 599040]

=============== Created Last 30 ================

2010-01-22 16:38:48 486 ----a-w- c:\windows\wininit.ini
2010-01-22 09:57:34 834048 ----a-w- c:\windows\system32\wininet.dll
2010-01-22 09:57:30 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-15 15:47:36 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-15 15:47:36 156672 ----a-w- c:\windows\system32\t2embed.dll

==================== Find3M ====================

2010-01-14 19:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-06 22:22:33 635 ----a-w- c:\program files\common files\tempeml.html
2009-12-03 21:18:19 18816 ----a-w- c:\windows\system32\drivers\dvd43llh.sys
2009-11-30 02:17:39 51200 ----a-w- c:\windows\inf\infpub.dat
2009-11-30 02:17:39 143360 ----a-w- c:\windows\inf\infstrng.dat
2009-11-30 02:17:39 143360 ----a-w- c:\windows\inf\infstor.dat
2009-11-24 23:49:48 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-17 11:19:06 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-16 16:09:16 940 ----a-w- c:\users\joshgr~1\appdata\roaming\wklnhst.dat
2009-11-09 12:31:42 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30:03 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-10-29 09:17:42 2048 ----a-w- c:\windows\system32\tzres.dll
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2006-05-31 16:14:50 108056 ----a-w- c:\program files\common files\secman.dll

============= FINISH: 11:05:10.96 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:08:48 AM

Posted 23 January 2010 - 01:54 AM

Hi socain,

Welcome to Virus/Trojan/Spyware/Malware Removal (VTSMR) forum. I am going to assist you with your problem.

Please refrain from making any changes to your system (scanning or running other tools, updating Windows, installing applications, removing files, etc.) from now on as it might interfere with our fixes. Please let me know in your next reply if you agree with this.

Your log(s) show that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world the cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."


Removal Instructions
  1. Please tell me if you have yourself installed PC Tattletale software on the computer. This is a keylogger and the question is if it is installed by you, other wise we have to remove it.

  2. Download the GMER Rootkit Scanner exe file from here and save it to your desktop.
    • Temporarily disable any real-time active protection so your security program drivers will not conflict with gmer's driver.
    • Click on this link to see a list of programs that should be disabled.
    • Disconnect from the Internet and close all running programs.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
    • In the right panel, you will see several boxes that have been checked. Make sure the following are unchecked:
      • Sections
      • IAT/EAT
      • Drives/Partition other than C:\ drive (C:\ drive should remain checked)
      • Show All (this one also should be unchecked)
    • Then click the Scan button & wait for it to begin. (Please be patient as it can take some time to complete).
    • When the scan is finished, you will see the scan button appears again. Click Save to save the scan results to your Desktop.
    • Save the file as gmer.log and copy/paste the contents in your next reply.


#3 socain

socain
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:48 PM

Posted 23 January 2010 - 02:20 PM

Thanks farbar


So first things first, yes I have a key logger. I have two children that well lets say use the internet for more than educational purposes. This has been a great tool to keep them from abusing the internet, they know that it is there so they don’t even try. I would like to keep this if possible. And second is the peer 2 peer. Yes there are 2 that I know of. Lime Wire, pro, which I bought for my oldest. I bought it because she told me that the free version does not protect against viruses. And Vuze I believe is the other one. Which I didn’t have to pay for, because my younger said that what he downloads is just bits of info from people that he knows and they are all friends. Those are the only ones that I know of. And third. I have pasted the log you requested but I thought that I should let you know that instead of it saying "scan complete" or something similar it just said "scan was stopped". I don’t know if that means anything or not. And I am going to keep all the security settings disabled until I get a reply from you, I will just unplug the modem until then, I will get a notice on my blackberry when you reply. Thanks allot, I really appreciate all this.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-23 11:03:35
Windows 6.0.6002 Service Pack 2
Running: 3wsv57yf.exe; Driver: C:\Users\JOSHGR~1\AppData\Local\Temp\pflcrfoc.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-1 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdePort0 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdePort1 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdePort2 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdePort3 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 dvd43llh.sys (dvd43llh.sys/RIF)

AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Modules - GMER 1.0.15 ----

Module \SystemRoot\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) 8200C000-823C5000 (3903488 bytes)
Module \SystemRoot\system32\hal.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 823C5000-823F8000 (208896 bytes)
Module \SystemRoot\system32\kdcom.dll (Kernel Debugger HW Extension DLL/Microsoft Corporation) 8040C000-80413000 (28672 bytes)
Module \SystemRoot\system32\mcupdate_GenuineIntel.dll (Intel Microcode Update Library/Microsoft Corporation) 80413000-80483000 (458752 bytes)
Module \SystemRoot\system32\PSHED.dll (Platform Specific Hardware Error Driver/Microsoft Corporation) 80483000-80494000 (69632 bytes)
Module \SystemRoot\system32\BOOTVID.dll (VGA Boot Driver/Microsoft Corporation) 80494000-8049C000 (32768 bytes)
Module \SystemRoot\system32\CLFS.SYS (Common Log File System Driver/Microsoft Corporation) 8049C000-804DD000 (266240 bytes)
Module \SystemRoot\system32\CI.dll (Code Integrity Module/Microsoft Corporation) 804DD000-805BD000 (917504 bytes)
Module \SystemRoot\system32\drivers\Wdf01000.sys (WDF Dynamic/Microsoft Corporation) 80606000-80682000 (507904 bytes)
Module \SystemRoot\system32\drivers\WDFLDR.SYS (WDFLDR/Microsoft Corporation) 80682000-8068F000 (53248 bytes)
Module \SystemRoot\system32\drivers\acpi.sys (ACPI Driver for NT/Microsoft Corporation) 8068F000-806D5000 (286720 bytes)
Module \SystemRoot\system32\drivers\WMILIB.SYS (WMILIB WMI support library Dll/Microsoft Corporation) 806D5000-806DE000 (36864 bytes)
Module \SystemRoot\system32\drivers\msisadrv.sys (ISA Driver/Microsoft Corporation) 806DE000-806E6000 (32768 bytes)
Module \SystemRoot\system32\drivers\pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation) 806E6000-8070D000 (159744 bytes)
Module \SystemRoot\System32\drivers\partmgr.sys (Partition Management Driver/Microsoft Corporation) 8070D000-8071C000 (61440 bytes)
Module \SystemRoot\system32\drivers\volmgr.sys (Volume Manager Driver/Microsoft Corporation) 8071C000-8072B000 (61440 bytes)
Module \SystemRoot\System32\drivers\volmgrx.sys (Volume Manager Extension Driver/Microsoft Corporation) 8072B000-80775000 (303104 bytes)
Module \SystemRoot\system32\DRIVERS\intelide.sys (Intel PCI IDE Driver/Microsoft Corporation) 80775000-8077C000 (28672 bytes)
Module \SystemRoot\system32\DRIVERS\PCIIDEX.SYS (PCI IDE Bus Driver Extension/Microsoft Corporation) 8077C000-8078A000 (57344 bytes)
Module \SystemRoot\system32\drivers\pciide.sys (Generic PCI IDE Bus Driver/Microsoft Corporation) 8078A000-80791000 (28672 bytes)
Module \SystemRoot\System32\drivers\mountmgr.sys (Mount Point Manager/Microsoft Corporation) 80791000-807A1000 (65536 bytes)
Module \SystemRoot\system32\drivers\atapi.sys (ATAPI IDE Miniport Driver/Microsoft Corporation) 807A1000-807A9000 (32768 bytes)
Module \SystemRoot\system32\drivers\ataport.SYS (ATAPI Driver Extension/Microsoft Corporation) 807A9000-807C7000 (122880 bytes)
Module \SystemRoot\system32\drivers\fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) 807C7000-807F9000 (204800 bytes)
Module \SystemRoot\system32\drivers\fileinfo.sys (FileInfo Filter Driver/Microsoft Corporation) 805BD000-805CD000 (65536 bytes)
Module \SystemRoot\System32\Drivers\PxHelp20.sys (Px Engine Device Driver for Windows 2000/XP/Sonic Solutions) 805CD000-805D6000 (36864 bytes)
Module \SystemRoot\System32\Drivers\ksecdd.sys (Kernel Security Support Provider Interface/Microsoft Corporation) 82605000-82676000 (462848 bytes)
Module \SystemRoot\system32\drivers\ndis.sys (NDIS 6.0 wrapper driver/Microsoft Corporation) 82676000-82781000 (1093632 bytes)
Module \SystemRoot\system32\drivers\msrpc.sys (Kernel Remote Procedure Call Provider/Microsoft Corporation) 82781000-827AC000 (176128 bytes)
Module \SystemRoot\system32\drivers\NETIO.SYS (Network I/O Subsystem/Microsoft Corporation) 827AC000-827E7000 (241664 bytes)
Module \SystemRoot\System32\drivers\tcpip.sys (TCP/IP Driver/Microsoft Corporation) 8A206000-8A2F0000 (958464 bytes)
Module \SystemRoot\System32\drivers\fwpkclnt.sys (FWP/IPsec Kernel-Mode API/Microsoft Corporation) 8A2F0000-8A30B000 (110592 bytes)
Module \SystemRoot\System32\Drivers\Ntfs.sys (NT File System Driver/Microsoft Corporation) 8A408000-8A518000 (1114112 bytes)
Module \SystemRoot\system32\drivers\volsnap.sys (Volume Shadow Copy Driver/Microsoft Corporation) 8A518000-8A551000 (233472 bytes)
Module \SystemRoot\System32\Drivers\spldr.sys (loader for security processor/Microsoft Corporation) 8A551000-8A559000 (32768 bytes)
Module \SystemRoot\system32\DRIVERS\sbp2port.sys (SBP-2 Protocol Driver/Microsoft Corporation) 8A559000-8A56F000 (90112 bytes)
Module \SystemRoot\System32\Drivers\mup.sys (Multiple UNC Provider driver/Microsoft Corporation) 8A56F000-8A57E000 (61440 bytes)
Module \SystemRoot\System32\drivers\ecache.sys (Special Memory Device Cache/Microsoft Corporation) 8A57E000-8A5A5000 (159744 bytes)
Module \SystemRoot\system32\drivers\disk.sys (PnP Disk Driver/Microsoft Corporation) 8A5A5000-8A5B6000 (69632 bytes)
Module \SystemRoot\system32\drivers\CLASSPNP.SYS (SCSI Class System Dll/Microsoft Corporation) 8A5B6000-8A5D7000 (135168 bytes)
Module \SystemRoot\system32\drivers\crcdisk.sys (Disk Block Verification Filter Driver/Microsoft Corporation) 8A5D7000-8A5E0000 (36864 bytes)
Module \SystemRoot\system32\DRIVERS\tunnel.sys (Microsoft Tunnel Interface Driver/Microsoft Corporation) 8A316000-8A321000 (45056 bytes)
Module \SystemRoot\system32\DRIVERS\tunmp.sys (Microsoft Tunnel Interface Driver/Microsoft Corporation) 8A321000-8A32A000 (36864 bytes)
Module \SystemRoot\system32\DRIVERS\intelppm.sys (Processor Device Driver/Microsoft Corporation) 8A32A000-8A339000 (61440 bytes)
Module \SystemRoot\system32\DRIVERS\igdkmd32.sys (Intel Graphics Kernel Mode Driver/Intel Corporation) 8E206000-8E8C1000 (7057408 bytes)
Module \SystemRoot\System32\drivers\dxgkrnl.sys (DirectX Graphics Kernel/Microsoft Corporation) 8E8C1000-8E962000 (659456 bytes)
Module \SystemRoot\System32\drivers\watchdog.sys (Watchdog Driver/Microsoft Corporation) 8E962000-8E96E000 (49152 bytes)
Module \SystemRoot\system32\DRIVERS\e1e6032.sys (Intel® PRO/1000 Adapter NDIS 6 deserialized driver/Intel Corporation) 8E96E000-8E9A9000 (241664 bytes)
Module \SystemRoot\system32\DRIVERS\usbuhci.sys (UHCI USB Miniport Driver/Microsoft Corporation) 8E9A9000-8E9B4000 (45056 bytes)
Module \SystemRoot\system32\DRIVERS\USBPORT.SYS (USB 1.1 & 2.0 Port Driver/Microsoft Corporation) 8E9B4000-8E9F2000 (253952 bytes)
Module \SystemRoot\system32\DRIVERS\usbehci.sys (EHCI eUSB Miniport Driver/Microsoft Corporation) 8A339000-8A348000 (61440 bytes)
Module \SystemRoot\system32\DRIVERS\HDAudBus.sys (High Definition Audio Bus Driver/Microsoft Corporation) 8A348000-8A3D5000 (577536 bytes)
Module \SystemRoot\system32\DRIVERS\HSXHWBS2.sys (HSF_HWB2 WDM driver/Conexant Systems, Inc.) 8EA05000-8EA4F000 (303104 bytes)
Module \SystemRoot\system32\DRIVERS\ks.sys (Kernel CSA Library/Microsoft Corporation) 8EA4F000-8EA79000 (172032 bytes)
Module \SystemRoot\system32\DRIVERS\HSX_DPV.sys (HSF_DP driver/Conexant Systems, Inc.) 8EA79000-8EB7C000 (1060864 bytes)
Module \SystemRoot\system32\DRIVERS\HSX_CNXT.sys (HSF_CNXT driver/Conexant Systems, Inc.) 8EE09000-8EEBD000 (737280 bytes)
Module \SystemRoot\system32\drivers\modem.sys (Modem Device Driver/Microsoft Corporation) 8EEBD000-8EECA000 (53248 bytes)
Module \SystemRoot\system32\DRIVERS\ohci1394.sys (1394 OpenHCI Port Driver/Microsoft Corporation) 8EECA000-8EEDA000 (65536 bytes)
Module \SystemRoot\system32\DRIVERS\1394BUS.SYS (1394 Bus Device Driver/Microsoft Corporation) 8EEDA000-8EEE8000 (57344 bytes)
Module \SystemRoot\system32\DRIVERS\fdc.sys (Floppy Disk Controller Driver/Microsoft Corporation) 8EEE8000-8EEF3000 (45056 bytes)
Module \SystemRoot\System32\DRIVERS\dvd43llh.sys (dvd43llh.sys/RIF) 8EEF3000-8EEF8000 (20480 bytes)
Module \SystemRoot\system32\DRIVERS\cdrom.sys (SCSI CD-ROM Driver/Microsoft Corporation) 8EEF8000-8EF10000 (98304 bytes)
Module \SystemRoot\System32\Drivers\GEARAspiWDM.sys (CD DVD Filter/GEAR Software Inc.) 8EF10000-8EF13000 (12288 bytes)
Module \SystemRoot\system32\DRIVERS\msiscsi.sys (Microsoft iSCSI Initiator Driver/Microsoft Corporation) 8EF13000-8EF42000 (192512 bytes)
Module \SystemRoot\system32\DRIVERS\storport.sys (Microsoft Storage Port Driver/Microsoft Corporation) 8EF42000-8EF83000 (266240 bytes)
Module \SystemRoot\system32\DRIVERS\TDI.SYS (TDI Wrapper/Microsoft Corporation) 8EF83000-8EF8E000 (45056 bytes)
Module \SystemRoot\System32\Drivers\RootMdm.sys (Legacy Non-Pnp Modem Device Driver/Microsoft Corporation) 8EF8E000-8EF96000 (32768 bytes)
Module \SystemRoot\system32\DRIVERS\rasl2tp.sys (RAS L2TP mini-port/call-manager driver/Microsoft Corporation) 8EF96000-8EFAD000 (94208 bytes)
Module \SystemRoot\system32\DRIVERS\ndistapi.sys (NDIS 3.0 connection wrapper driver/Microsoft Corporation) 8EFAD000-8EFB8000 (45056 bytes)
Module \SystemRoot\system32\DRIVERS\ndiswan.sys (MS PPP Framing Driver (Strong Encryption)/Microsoft Corporation) 8EFB8000-8EFDB000 (143360 bytes)
Module \SystemRoot\system32\DRIVERS\raspppoe.sys (RAS PPPoE mini-port/call-manager driver/Microsoft Corporation) 8EFDB000-8EFEA000 (61440 bytes)
Module \SystemRoot\system32\DRIVERS\raspptp.sys (Peer-to-Peer Tunneling Protocol/Microsoft Corporation) 8EFEA000-8EFFE000 (81920 bytes)
Module \SystemRoot\system32\DRIVERS\rassstp.sys (RAS SSTP Miniport Call Manager/Microsoft Corporation) 8EB7C000-8EB91000 (86016 bytes)
Module \SystemRoot\System32\Drivers\pcouffin.sys (low level access layer for CD/DVD/BD devices/VSO Software) 8EB91000-8EB9D000 (49152 bytes)
Module \SystemRoot\system32\DRIVERS\RimSerial.sys (RIM Virtual Serial Driver/Research in Motion Ltd) 8EE00000-8EE07000 (28672 bytes)
Module \SystemRoot\system32\DRIVERS\termdd.sys (Terminal Server Driver/Microsoft Corporation) 8EB9D000-8EBAD000 (65536 bytes)
Module \SystemRoot\system32\DRIVERS\kbdclass.sys (Keyboard Class Driver/Microsoft Corporation) 8EBAD000-8EBB8000 (45056 bytes)
Module \SystemRoot\system32\DRIVERS\mouclass.sys (Mouse Class Driver/Microsoft Corporation) 8EBB8000-8EBC3000 (45056 bytes)
Module \SystemRoot\system32\DRIVERS\swenum.sys (Plug and Play Software Device Enumerator/Microsoft Corporation) 8EE07000-8EE09000 (8192 bytes)
Module \SystemRoot\system32\DRIVERS\mssmbios.sys (System Management BIOS Driver/Microsoft Corporation) 8EBC3000-8EBCD000 (40960 bytes)
Module \SystemRoot\system32\DRIVERS\umbus.sys (User-Mode Bus Enumerator/Microsoft Corporation) 8EBCD000-8EBDA000 (53248 bytes)
Module \SystemRoot\system32\DRIVERS\usbhub.sys (Default Hub Driver for USB/Microsoft Corporation) 8F205000-8F23A000 (217088 bytes)
Module \SystemRoot\System32\Drivers\NDProxy.SYS (NDIS Proxy/Microsoft Corporation) 8F23A000-8F24B000 (69632 bytes)
Module \SystemRoot\system32\drivers\RTKVHDA.sys (Realtek® High Definition Audio Function Driver/Realtek Semiconductor Corp.) 8F400000-8F5F5000 (2052096 bytes)
Module \SystemRoot\system32\drivers\portcls.sys (Port Class (Class Driver for Port/Miniport Devices)/Microsoft Corporation) 8F24B000-8F278000 (184320 bytes)
Module \SystemRoot\system32\drivers\drmk.sys (Microsoft Kernel DRM Descrambler Filter/Microsoft Corporation) 8F278000-8F29D000 (151552 bytes)
Module \SystemRoot\system32\DRIVERS\wdcsam.sys (WD SCSI Architecture Model (SAM) driver/Western Digital Technologies) 8F5F5000-8F5F8000 (12288 bytes)
Module \SystemRoot\system32\DRIVERS\usbccgp.sys (USB Common Class Generic Parent Driver/Microsoft Corporation) 8F29D000-8F2B4000 (94208 bytes)
Module \SystemRoot\system32\DRIVERS\USBD.SYS (Universal Serial Bus Driver/Microsoft Corporation) 8F5F8000-8F5FA000 (8192 bytes)
Module \SystemRoot\system32\DRIVERS\USBSTOR.SYS (USB Mass Storage Class Driver/Microsoft Corporation) 8F2B4000-8F2C9000 (86016 bytes)
Module \SystemRoot\system32\DRIVERS\hidusb.sys (USB Miniport Driver for Input Devices/Microsoft Corporation) 8F2C9000-8F2D2000 (36864 bytes)
Module \SystemRoot\system32\DRIVERS\HIDCLASS.SYS (Hid Class Library/Microsoft Corporation) 8F2D2000-8F2E2000 (65536 bytes)
Module \SystemRoot\system32\DRIVERS\HIDPARSE.SYS (Hid Parsing Library/Microsoft Corporation) 8F2E2000-8F2E9000 (28672 bytes)
Module \SystemRoot\system32\DRIVERS\usbscan.sys (USB Scanner Driver/Microsoft Corporation) 8F2E9000-8F2F6000 (53248 bytes)
Module \SystemRoot\system32\DRIVERS\usbprint.sys (USB Printer driver/Microsoft Corporation) 8F2F6000-8F300000 (40960 bytes)
Module \SystemRoot\system32\DRIVERS\HPZius12.sys (1284.4<->Usb Datalink Driver (Windows 2000)/HP) 8F5FA000-8F600000 (24576 bytes)
Module \SystemRoot\system32\DRIVERS\kbdhid.sys (HID Keyboard Filter Driver/Microsoft Corporation) 8F300000-8F309000 (36864 bytes)
Module \SystemRoot\system32\DRIVERS\NuidFltr.sys (Filter Driver for Microsoft Hardware HID Non-User Input Data/Microsoft Corporation) 8F309000-8F310000 (28672 bytes)
Module \SystemRoot\system32\DRIVERS\mouhid.sys (HID Mouse Filter Driver/Microsoft Corporation) 8F310000-8F318000 (32768 bytes)
Module \SystemRoot\system32\DRIVERS\HPZid412.sys (IEEE-1284.4-1999 Driver (Windows 2000)/HP) 8F318000-8F325000 (53248 bytes)
Module \SystemRoot\system32\DRIVERS\HPZipr12.sys (IEEE-1284.4-1999 Print Class Driver/HP) 8F325000-8F329000 (16384 bytes)
Module \SystemRoot\System32\Drivers\Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation) 8F329000-8F332000 (36864 bytes)
Module \SystemRoot\System32\Drivers\Null.SYS (NULL Driver/Microsoft Corporation) 8F332000-8F339000 (28672 bytes)
Module \SystemRoot\System32\Drivers\Beep.SYS (BEEP Driver/Microsoft Corporation) 8F339000-8F340000 (28672 bytes)
Module \SystemRoot\System32\drivers\vga.sys (VGA/Super VGA Video Driver/Microsoft Corporation) 8F340000-8F34C000 (49152 bytes)
Module \SystemRoot\System32\drivers\VIDEOPRT.SYS (Video Port Driver/Microsoft Corporation) 8F34C000-8F36D000 (135168 bytes)
Module \SystemRoot\System32\DRIVERS\RDPCDD.sys (RDP Miniport/Microsoft Corporation) 8F36D000-8F375000 (32768 bytes)
Module \SystemRoot\system32\drivers\rdpencdd.sys (RDP Miniport/Microsoft Corporation) 8F375000-8F37D000 (32768 bytes)
Module \SystemRoot\System32\Drivers\Msfs.SYS (Mailslot driver/Microsoft Corporation) 8F37D000-8F388000 (45056 bytes)
Module \SystemRoot\System32\Drivers\Npfs.SYS (NPFS Driver/Microsoft Corporation) 8F388000-8F396000 (57344 bytes)
Module \SystemRoot\System32\DRIVERS\rasacd.sys (RAS Automatic Connection Driver/Microsoft Corporation) 8F396000-8F39F000 (36864 bytes)
Module \SystemRoot\system32\DRIVERS\tdx.sys (TDI Translation Driver/Microsoft Corporation) 8F39F000-8F3B5000 (90112 bytes)
Module \SystemRoot\system32\DRIVERS\smb.sys (SMB Transport driver/Microsoft Corporation) 8F3B5000-8F3C9000 (81920 bytes)
Module \SystemRoot\System32\Drivers\aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) 8F3C9000-8F3D3000 (40960 bytes)
Module \SystemRoot\system32\drivers\afd.sys (Ancillary Function Driver for WinSock/Microsoft Corporation) 8F600000-8F648000 (294912 bytes)
Module \SystemRoot\System32\Drivers\aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software) 8F648000-8F64C000 (16384 bytes)
Module \SystemRoot\System32\DRIVERS\netbt.sys (MBT Transport driver/Microsoft Corporation) 8F64C000-8F67E000 (204800 bytes)
Module \SystemRoot\system32\DRIVERS\pacer.sys (QoS Packet Scheduler/Microsoft Corporation) 8F67E000-8F694000 (90112 bytes)
Module \SystemRoot\system32\DRIVERS\netbios.sys (NetBIOS interface driver/Microsoft Corporation) 8F694000-8F6A2000 (57344 bytes)
Module \SystemRoot\system32\DRIVERS\wanarp.sys (MS Remote Access and Routing ARP Driver/Microsoft Corporation) 8F6A2000-8F6B5000 (77824 bytes)
Module \SystemRoot\system32\DRIVERS\rdbss.sys (Redirected Drive Buffering SubSystem Driver/Microsoft Corporation) 8F6B5000-8F6F1000 (245760 bytes)
Module \SystemRoot\system32\drivers\nsiproxy.sys (NSI Proxy/Microsoft Corporation) 8F6F1000-8F6FB000 (40960 bytes)
Module \SystemRoot\System32\Drivers\dfsc.sys (DFS Namespace Client Driver/Microsoft Corporation) 8F6FB000-8F712000 (94208 bytes)
Module \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) 8F712000-8F733000 (135168 bytes)
Module \SystemRoot\System32\Drivers\crashdmp.sys (Crash Dump Driver/Microsoft Corporation) 8F733000-8F740000 (53248 bytes)
Module \SystemRoot\System32\Drivers\dump_dumpata.sys 8F740000-8F74B000 (45056 bytes)
Module \SystemRoot\System32\Drivers\dump_atapi.sys 8F74B000-8F753000 (32768 bytes)
Module \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation) 97C10000-97E12000 (2105344 bytes)
Module \SystemRoot\System32\drivers\Dxapi.sys (DirectX API Driver/Microsoft Corporation) 8F753000-8F75D000 (40960 bytes)
Module \SystemRoot\system32\DRIVERS\monitor.sys (Monitor Driver/Microsoft Corporation) 8F75D000-8F76C000 (61440 bytes)
Module \SystemRoot\System32\TSDDD.dll (Framebuffer Display Driver/Microsoft Corporation) 97E30000-97E39000 (36864 bytes)
Module \SystemRoot\System32\cdd.dll (Canonical Display Driver/Microsoft Corporation) 97E50000-97E5E000 (57344 bytes)
Module \SystemRoot\system32\drivers\luafv.sys (LUA File Virtualization Filter Driver/Microsoft Corporation) 8F76C000-8F787000 (110592 bytes)
Module \SystemRoot\system32\DRIVERS\aswMonFlt.sys (avast! File System Minifilter for Windows 2003/Vista/ALWIL Software) 8F787000-8F79E000 (94208 bytes)
Module \SystemRoot\system32\DRIVERS\aswFsBlk.sys (avast! File System Access Blocking Driver/ALWIL Software) 8F79E000-8F7A6000 (32768 bytes)
Module \SystemRoot\system32\drivers\spsys.sys (security processor/Microsoft Corporation) A9E02000-A9EB2000 (720896 bytes)
Module \SystemRoot\system32\DRIVERS\lltdio.sys (Link-Layer Topology Mapper I/O Driver/Microsoft Corporation) A9EB2000-A9EC2000 (65536 bytes)
Module \SystemRoot\system32\DRIVERS\nwifi.sys (NativeWiFi Miniport Driver/Microsoft Corporation) A9EC2000-A9EEC000 (172032 bytes)
Module \SystemRoot\system32\DRIVERS\ndisuio.sys (NDIS User mode I/O driver/Microsoft Corporation) A9EEC000-A9EF6000 (40960 bytes)
Module \SystemRoot\system32\DRIVERS\pnarp.sys (Address Resolution Protocol Driver/Pure Networks, Inc.) A9EF6000-A9F00000 (40960 bytes)
Module \SystemRoot\system32\DRIVERS\purendis.sys (NDIS Relay Driver/Pure Networks, Inc.) A9F00000-A9F0A000 (40960 bytes)
Module \SystemRoot\system32\DRIVERS\rspndr.sys (Link-Layer Topology Responder Driver for NDIS 6/Microsoft Corporation) A9F0A000-A9F1D000 (77824 bytes)
Module \SystemRoot\system32\drivers\HTTP.sys (HTTP Protocol Stack/Microsoft Corporation) A9F1D000-A9F8A000 (446464 bytes)
Module \SystemRoot\System32\DRIVERS\srvnet.sys (Server Network driver/Microsoft Corporation) A9F8A000-A9FA7000 (118784 bytes)
Module \SystemRoot\system32\DRIVERS\bowser.sys (NT Lan Manager Datagram Receiver Driver/Microsoft Corporation) A9FA7000-A9FC0000 (102400 bytes)
Module \SystemRoot\System32\drivers\mpsdrv.sys (Microsoft Protection Service Driver/Microsoft Corporation) A9FC0000-A9FD5000 (86016 bytes)
Module \SystemRoot\system32\drivers\mrxdav.sys (Windows NT WebDav Minirdr/Microsoft Corporation) A9FD5000-A9FF6000 (135168 bytes)
Module \SystemRoot\system32\DRIVERS\mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation) 8F7A6000-8F7C5000 (126976 bytes)
Module \SystemRoot\system32\DRIVERS\mrxsmb10.sys (Longhorn SMB Downlevel SubRdr/Microsoft Corporation) 8F7C5000-8F7FE000 (233472 bytes)
Module \SystemRoot\system32\DRIVERS\mrxsmb20.sys (Longhorn SMB 2.0 Redirector/Microsoft Corporation) 8F3D3000-8F3EB000 (98304 bytes)
Module \SystemRoot\System32\DRIVERS\srv2.sys (Smb 2.0 Server driver/Microsoft Corporation) 8A3D5000-8A3FC000 (159744 bytes)
Module \SystemRoot\System32\DRIVERS\srv.sys (Server driver/Microsoft Corporation) ADA0F000-ADA5B000 (311296 bytes)
Module \SystemRoot\system32\DRIVERS\mdmxsdk.sys (Diagnostic Interface x86 Driver/Conexant) ADA5B000-ADA5F000 (16384 bytes)
Module \SystemRoot\system32\drivers\peauth.sys (Protected Environment Authentication and Authorization Export Driver/Microsoft Corporation) ADA5F000-ADB3D000 (909312 bytes)
Module \SystemRoot\System32\Drivers\fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation) ADB3D000-ADB65000 (163840 bytes)
Module \SystemRoot\System32\Drivers\secdrv.SYS (Macrovision SECURITY Driver/Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) ADB65000-ADB6F000 (40960 bytes)
Module \SystemRoot\System32\drivers\tcpipreg.sys (TCP/IP Registry Compatibility Driver/Microsoft Corporation) ADB6F000-ADB7B000 (49152 bytes)
Module \SystemRoot\system32\DRIVERS\WUDFRd.sys (Windows Driver Foundation - User-mode Driver Framework Reflector/Microsoft Corporation) ADB7B000-ADB90000 (86016 bytes)
Module \SystemRoot\system32\DRIVERS\WUDFPf.sys (Windows Driver Foundation - User-mode Driver Framework Platform Driver/Microsoft Corporation) ADB90000-ADBA2000 (73728 bytes)
Module \SystemRoot\system32\DRIVERS\xaudio.sys (Modem Audio Device Driver/Conexant Systems, Inc.) ADBA2000-ADBAA000 (32768 bytes)
Module \SystemRoot\system32\DRIVERS\ipnat.sys (IP Network Address Translator/Microsoft Corporation) ADBAA000-ADBD0000 (155648 bytes)
Module \SystemRoot\system32\DRIVERS\cdfs.sys (CD-ROM File System Driver/Microsoft Corporation) ADBD0000-ADBE6000 (90112 bytes)
Module \??\C:\Users\JOSHGR~1\AppData\Local\Temp\pflcrfoc.sys (GMER) ADBE6000-ADBFD000 (94208 bytes)
Module \Windows\System32\ntdll.dll (NT Layer DLL/Microsoft Corporation) 77410000-77537000 (1208320 bytes)

---- EOF - GMER 1.0.15 ----


#4 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:08:48 AM

Posted 24 January 2010 - 06:34 AM

Thanks for the feedback.

We are going to take care of the error at start up and run Malwarebyes.
  1. You have the program Spybot S&D (Teatimer option) running on your machine. We need to disable TeaTimer so it does not interfere with the fixes we are about to do. This will only take a few seconds.
    1. First disable TeaTimer:
      • Run Spybot-S&D
      • Go to the Mode menu, and make sure Advanced Mode is selected
      • On the left hand side, choose Tools -> Resident
      • Uncheck Resident TeaTimer and OK any prompts
      • Restart your computer.
      Instruction is also here: How to disable TeaTimer during HijackThis Cleanup
      Note:If teatimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.
    2. Then download ResetTeaTimer.exe to your desktop.
      • Doubleclick ResetTeaTimer.exe and let it run.
    Note: The Teatimer should be kept disabled until I give you the clean sign.

  2. Go to start > Run copy and paste the following line in the run box and click OK:

    cmd /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v notepad /f

    A window flashes it is normal.

  3. Please download Malwarebytes' Anti-Malware from one of these locations:
    malwarebytes.org
    majorgeeks.com
    • Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the MBAM log.

    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
.

#5 socain

socain
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:48 PM

Posted 24 January 2010 - 01:00 PM

farbar

Thank you for keeping up on this, im really suprised that you do this asking nothing in return, your great. Everything seems to have gone as you said. After the final restart prompted by the Malwarebytes program the error is gone. I have not changed any of the setting back, but i did notice that the the Windows defender was back on. Thought would let you know.

Malwarebytes' Anti-Malware 1.44
Database version: 3627
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

1/24/2010 9:47:33 AM
mbam-log-2010-01-24 (09-47-33).txt

Scan type: Quick Scan
Objects scanned: 106123
Time elapsed: 4 minute(s), 24 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 4
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
C:\Windows\System32\explorer32\winsysmngr32.exe (Backdoor.Bot) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a3ed5288-f558-4f6e-8d5c-740cb6f89029} (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\System32\Explorer32\winsysmngr32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winload32 (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\System32\Explorer32\winload32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winload (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\Explorer32\winsysmngr32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Users\Josh Graves\AppData\Local\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\Explorer32\winload32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Windows\System32\winload.exe (Backdoor.Bot) -> Quarantined and deleted successfully.


#6 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:08:48 AM

Posted 24 January 2010 - 01:17 PM

Hi socain,

Along the way the tools we use might remove some of the key logger files. In this case I see Malwarebytes removed one of them. You may install again when we are done.

One or more of the identified infections is a backdoor trojan.

A backdoor Trojan can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs.

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified, because of it's backdoor functionality, your PC is very likely compromised. some experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the Operating System. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

You have the choice of going for a reformat reinstall or continue cleaning the system. In the latter case as you see Malwarebytes removed the backdoor file and entries and we are going to make sure nothing is left behind.

Removal Instructions
  1. We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
    • Go to Start > Control Panel > Windows Defender.
    • Open Windows Defender.
    • Click on Tools, Options.
    • At the bottom of the Window Defender's page, under Administrator Options uncheck "use Windows Defender" and then Save.
    • Click Close.

    Note:When everything is done and your log is clean again, you can enable it again.

  2. Download ComboFix from one of these locations:

    Link 1
    Link 2
    Link 3

    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Information on A/V control HERE)
    • Double click on ComboFix.exe & follow the prompts.

    When finished, it shall produce a log for you. Please copy and paste the C:\ComboFix.txt in your next reply.


#7 socain

socain
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:48 PM

Posted 24 January 2010 - 01:58 PM

farbar
Well i guess this is a bitter sweet situation, sounds really bad but i guess progress is better than nothing, and it seems like we are making good of the time. I do have several questions, if you dont mind. I will ask them when you say that we are done.

ComboFix 10-01-23.06 - Josh Graves 01/24/2010 10:41:57.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3060.2013 [GMT -8:00]
Running from: c:\users\Josh Graves\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1901334417-2172799006-2031599645-500
c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\users\Josh Graves\AppData\Roaming\inst.exe
c:\windows\system32\explorer32
c:\windows\system32\explorer32\alertopen.wav
c:\windows\system32\explorer32\application.config
c:\windows\system32\explorer32\closewindow.wav
c:\windows\system32\explorer32\explorer.chm
c:\windows\system32\explorer32\FireFox15.dll
c:\windows\system32\explorer32\goodbye.wav
c:\windows\system32\explorer32\IdleTime.ocx
c:\windows\system32\explorer32\Install.xpi
c:\windows\system32\explorer32\MonthView.ocx
c:\windows\system32\explorer32\msn6mngr.exe
c:\windows\system32\explorer32\mssecurity.exe
c:\windows\system32\explorer32\Netlogon.exe
c:\windows\system32\explorer32\olSecurity.dll
c:\windows\system32\explorer32\PCTT.exe
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10184782743.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10238546133.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10268491506.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10269278287.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10283303260.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10314762592.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10436826944.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10588628053.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10603475570.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10667544603.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10695952177.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10720849037.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10723853111.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c10827511548.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11063581705.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11074167490.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11084949970.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11148846149.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11222708225.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11396700143.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11505943536.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11556917428.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11558669805.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11580592393.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11656719446.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11730337142.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11737906932.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11749345064.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c11940151453.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12068533897.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12120318412.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12141829729.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12201893329.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12202602624.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12276285886.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1234251260.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12391704320.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12834024429.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c12872618436.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1299327611.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13008213043.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13046771287.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13058137893.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13067674636.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13150799274.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1315760612.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13195258378.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1321220397.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13214915990.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13416963815.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13427668809.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13456892967.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1346176862.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13489270210.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13559585809.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13565742969.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13594019412.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13635659217.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13731747865.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13906419277.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c13990294933.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14069044589.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1407194137.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14121174812.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14136683940.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14166331291.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14195227622.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1424741744.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14266109466.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14289236068.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14474344253.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14519983530.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14557874202.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14565593004.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1468539237.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14746028184.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c14936298131.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15018892288.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15082865953.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15126341581.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15136861801.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1516753435.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1524955034.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15296214818.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15426641702.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15440934896.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15554302930.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15629225969.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15642285346.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15794217586.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15834724903.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15901648998.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15905183553.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15905761718.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c15937548875.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16196841001.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16233938932.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16247463226.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16285079717.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16324585676.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16356402635.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16535025835.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16613858938.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16629326343.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16682636737.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16689306497.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1673287153.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16901034116.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16917467117.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c169378519.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c16998875141.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17024934291.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1707166433.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1709645986.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17173171043.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17330861091.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17358940839.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17367690801.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17383629083.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17426401376.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17699283361.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17711073160.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17734825611.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17743951082.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1781433820.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17983269691.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c17986381053.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18005061149.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18097120523.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18124961853.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18143200874.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18191224336.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18335670232.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18336403369.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18414020538.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18571370840.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18574255704.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18631917238.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18733990192.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18929165601.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18965870141.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c18985134363.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1910626888.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19176810979.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1926213502.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c1927685737.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19321870803.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19337123632.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19353991746.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19382047653.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19446754455.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19479799270.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19524234533.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19805753231.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19811403751.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19842934608.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19859087467.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19926625490.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19957917928.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c19996702671.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20078104734.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20124608278.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20160084962.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20168817043.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20206397771.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20224589109.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20252496004.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20318913459.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20334208011.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20343959331.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20381546020.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20392376184.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20416450500.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20418572425.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20509558916.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20535606145.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20591223239.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20650738477.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20789927244.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20861542224.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c20997798442.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21072459220.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2126705646.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2138817310.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21434414386.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21469640731.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21476203203.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21692425012.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21726250648.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21807092428.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21836310625.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2191954851.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21962797641.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c21997606754.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22116082906.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22133558988.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22137856483.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22146952152.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22157222032.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22188025712.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22206300497.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22559726238.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22599482536.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2268987894.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22730493545.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22772002220.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22837758064.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c22876244783.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23024964332.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23050820827.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23105585575.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23108732700.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23275375366.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23287367820.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23287600278.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23312610387.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c233215093.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23386269807.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23418027162.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23451900482.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23522639274.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23702758550.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23719471693.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23774802684.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23823821544.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23827135562.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23885703086.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c23946809768.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24013239145.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24069571495.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24101185798.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24181503057.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24245852231.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2425682544.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2442902326.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24583083391.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24644756317.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24668425321.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24697184562.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24786412715.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2479863166.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c24911260604.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25059586763.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25164306163.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25179183483.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25246214866.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25335818529.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25356638431.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25375312566.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25415760278.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25462800264.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25492018461.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25579506158.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25726288557.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25751554965.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25818526744.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25927180051.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25976788997.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c25992661714.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26017862558.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2621841430.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26262772083.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26263409852.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2642613649.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26439619064.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26457661390.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26568830013.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26860058307.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26942026615.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2697741985.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26982206106.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c26992207765.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27178198099.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c272351503.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2724397182.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27347749471.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27580684423.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27586299180.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27624034881.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27716600894.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27875655889.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27890777587.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27892929315.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c27962315082.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28048992156.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28049081563.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2809178829.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28108966350.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28256565332.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28326028585.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28416669368.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28460931777.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28504365682.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28564095497.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28663337230.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28691595792.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28708529472.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28774595260.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28798264265.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28836405277.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28841996192.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28875178098.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c28877979516.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29047268629.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29150992631.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29153817892.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29154360294.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29232925176.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29239255189.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29275131225.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29314219951.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29346889257.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29528111219.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29539364576.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29678958654.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29696142673.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29765027761.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c2977794408.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29784321784.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29812830686.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c29921680688.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3003090620.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30109888315.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30130124092.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30229818820.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30285114049.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3032237291.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30383592844.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3041172027.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30500859022.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30530315637.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30627918243.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30661904811.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30677783489.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30732011795.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30741816759.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30862766504.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30922079086.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30960202217.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c30974781513.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31014233827.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31045472621.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31063181161.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31081509590.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31190693378.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3125071525.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31298887729.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31349480152.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31378209590.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31433153152.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31462639570.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3150314092.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31519591808.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31606376171.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3161495923.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31759864091.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31824898719.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3189605474.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31919574737.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3192800283.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31930673122.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31932461261.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31953090429.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c31959998607.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32039171457.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32056432962.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32083266973.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3221261501.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32307249307.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32392501831.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32407456636.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32519841194.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32669520378.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32709461450.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32792150974.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32807230949.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32891845703.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32930183410.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32946515083.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c32957130670.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33008086681.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33038938045.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33067899942.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33119612932.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33151763677.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33157777786.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33319371938.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33319652080.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33372020721.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33415937423.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33432036638.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33557331562.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33663952350.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33694589138.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33730834722.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33781546354.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33789324760.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c33922588825.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34113925695.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34119403362.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34185969829.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3419065475.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34356105327.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34466201066.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34481865167.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34491920471.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3450071811.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34521639347.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34527480602.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34564226865.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34583860635.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34642475843.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34648883342.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34675776958.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34692305326.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34704589843.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c34889805316.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35023391246.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35081940889.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35149395465.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c353807210.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35466933250.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35482263565.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35587072372.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35595983266.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35607582330.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35729128122.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35754227638.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35760319232.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c35839271545.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36015897989.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36016118526.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36036467552.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36263149976.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36363172531.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36384248733.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36448150873.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36454397439.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36567509174.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36597293615.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36705887317.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3678238391.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36801242828.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36833864450.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36865091323.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36925071477.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36993497610.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c36995911598.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37137192487.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37189662456.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37374210357.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37403011322.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3741711378.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37481796741.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37618857622.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37677472829.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37693566083.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3779286146.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3779953718.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37839424610.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37879300117.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37921029329.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37945431470.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c37966251373.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38005715608.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38129150867.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38159918785.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38231295347.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38268589973.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38280695676.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38338929414.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38345730304.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38505429029.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38558608293.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c38708579540.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c39017617702.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c39029693603.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c39109128713.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c39200466871.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c39211523532.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c39290934801.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3933572769.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c39386451244.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c3998571634.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40013295412.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40121906995.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40179985761.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40241867303.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40359503030.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40599304437.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c406455993.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40746152400.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40791398286.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4080957174.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40815556049.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40891861915.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c40900331735.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41063034534.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41127485036.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41172039508.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41258251667.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41273486614.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41359221935.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41417509317.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41453617811.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41507416963.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41554772853.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4169791936.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4170364141.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41818302869.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c41929525136.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42050886154.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42140102386.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42359304428.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42379361391.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42417836189.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42460137605.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42472696304.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42752373218.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42793798446.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c42908495664.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43083345890.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43206161260.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43354600667.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4360395669.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43646162748.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43665415048.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43667185306.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43689203262.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4371756315.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43730670213.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43778210878.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43792396783.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43925309181.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43953180313.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c43963867425.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44041180610.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44139057397.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44276225566.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44290888309.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44336903095.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44463080167.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44466680288.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44567167758.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44576185941.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44771653413.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44788068532.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c44836616516.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4488080739.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45004594326.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45070022344.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45100247859.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45130205154.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45265543460.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45394456386.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45414483547.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45425701141.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45643442869.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45664387941.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45824706554.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45859402418.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4586756229.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45880734920.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45930510759.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c45954591035.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46207314729.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46207779645.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46211725473.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46237301826.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4635828733.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46526837348.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46685278415.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46722686290.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46728879213.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46799391508.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46956598758.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c46979987621.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47067773342.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47075623273.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47160178422.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47261559963.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47269105911.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47275751829.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47288322448.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47294139862.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47333765029.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47517699003.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47533273696.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47695988416.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c47967302799.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48062759637.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48080760240.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4808753728.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48111802339.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48255068063.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48307758569.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48325836658.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48336476087.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48523700237.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48661208152.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48692947626.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48783642053.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48829925060.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48865723609.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48888200521.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c48910546302.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49023717641.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49038404226.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4905968904.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49110853672.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49197441339.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49235206842.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49381828308.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c4956823587.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49612784385.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49798262119.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49833405017.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49926865100.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c49990320205.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50179409980.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50299274921.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50300490856.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50317925214.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50440460443.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50510036945.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50585651397.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50625443458.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50819420814.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5084180831.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c50843775272.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c51086622476.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c51245385408.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5148810148.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c51525455713.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c51625728607.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c51759225130.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c51801866292.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c51805591583.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5195230245.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52171945571.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52260923385.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52377414703.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52386063337.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5239969491.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52593648433.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52595633268.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52749502658.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52765113115.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52959442138.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c52971482276.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53097575902.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53111135959.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53126472234.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53208690881.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53210246562.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53261864185.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53278005123.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53395414352.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5340510606.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53558254241.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53609013557.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53646284341.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5368775129.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5370336771.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53762465715.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53862011432.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53916132450.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c53968161344.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54013675451.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c540947914.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54120683670.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54186302423.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54221528768.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54318624734.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54439330101.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54452383518.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54453569650.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54492491483.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54526770114.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54576760530.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c54622352123.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55080837011.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55152440071.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55205291509.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55229312181.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55248647928.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55328530073.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55492752790.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55522423982.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55530458688.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5579173564.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55840057134.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55850744247.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55859017372.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55952584743.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c55993443727.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c56235760450.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c56265836954.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c56312972307.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c56340819597.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c56373274326.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c56441587209.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c56645619869.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57114225625.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57169586420.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57196784019.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57256656885.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57319211959.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57429039478.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57436448335.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57460796833.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57479441165.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57551556825.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57586055994.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57647550106.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57844984531.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57873308658.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57895380258.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57920247316.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5793052911.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5795401334.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57958269119.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c57975929975.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58132100105.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58161258697.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58419197797.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58433198928.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58440095186.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5845922231.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58462774753.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5847823619.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58478385210.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58530592918.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5855619907.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58587729930.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58722674846.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c5882579088.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58828675746.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58934110403.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58985632658.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c58988589048.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59058821201.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59082186222.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59088844060.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59160614013.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59260988235.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59271103143.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59322375059.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59347718954.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c593781471.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59398829936.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59434139728.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59670901298.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59675425291.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59726572036.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59785026311.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59829241037.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59852296113.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59869545698.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59895986318.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59936738014.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c59992623329.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6001353263.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60077852010.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6012743711.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60173940658.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60250604152.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60387843847.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60397303104.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60448604822.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60517203807.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60523778200.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6054389476.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6056874990.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60700690746.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60700893402.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60746026039.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60771465301.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6079226732.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60823720693.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60906755924.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c60980021953.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61062306165.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61069744825.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61160373687.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61175692081.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6118720769.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61291593313.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61416465044.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61581152677.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61628842353.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61683374643.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61687195301.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61780166625.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61807417869.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6191784143.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61923813819.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61974984407.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c61982697248.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62071651220.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62147825956.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62160652875.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62199652194.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62369257211.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6246477365.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62492471933.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6250220537.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62590450048.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62631297111.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62641704082.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62708765268.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62962508201.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62970119714.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c62998306751.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63003486394.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63084036111.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6309837102.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63140398263.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6323415040.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63236117362.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63264524936.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63267099857.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63346880674.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63732230663.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63737249374.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63741505146.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63874721527.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63893514871.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c63967490196.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64103537797.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64216077327.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64271664619.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64382153749.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64526212215.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64572393894.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6463438272.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64719015359.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64725154638.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64776301383.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64807099103.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c64919775724.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65052777528.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6506329774.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65104675292.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65300184488.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65300267934.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65317207574.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65339052677.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65346407890.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65393614768.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65398043394.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65453290939.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65552496910.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65557330846.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65612143278.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65656054019.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65665531158.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c65715217590.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66009789705.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66165393590.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6620311737.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66218352317.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66245210170.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66283768415.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66397058963.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66491240262.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66771697998.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66812825202.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66848939657.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66868591308.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c66976547241.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6706768274.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67113530635.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67119163274.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67142879962.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67166346311.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67433297634.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67435866594.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67457962036.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67714762687.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67786449193.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67840790748.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67861109972.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67868375778.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67993140220.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c67997521162.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68027693033.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68104118108.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68119865655.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68204820156.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68240171670.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68242490291.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68362742662.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68373173475.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68442857265.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68581354618.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6887334585.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68877214193.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c68993133306.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69067555665.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69125396013.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69301402568.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69371950626.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69424760341.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69428515434.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69482570886.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69612443447.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69623726606.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69634437561.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69648289680.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69737607240.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c6979697942.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c69848257303.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70114487409.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70207667350.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7027566432.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70305579900.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70368748903.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70484501123.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70554751157.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70555531978.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70655429363.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70809668302.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70824462175.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70896130800.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c70973575115.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71003299951.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71086126565.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71167820692.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7120805978.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71289139986.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71388792991.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71396571397.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71425306797.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71435374021.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7148337364.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71528935432.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71573263406.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71615451574.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71651071310.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71658891439.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71763467788.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71773773431.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71789962053.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71866482496.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71882283687.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71888726949.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c71936231851.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72004282474.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72026878595.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72052907943.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7210361957.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72178083658.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72232747077.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72310346364.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72360986471.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7243365049.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72499406337.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7251805067.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72610986232.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72645652294.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7289153337.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72913450002.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72915500402.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72923988103.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c72999036312.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7305365800.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73100507259.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73155838251.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73169380426.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73283362388.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73385220766.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73457521200.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7353550195.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73539978265.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73591190576.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73836398124.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73837989568.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73840117454.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73939728736.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73940640687.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73946177959.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c73984187841.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74084913730.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74216377735.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74349331855.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74399662017.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74474328756.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74661386013.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7467442750.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74702799320.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74915879964.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c74952918291.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75013053417.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75251758098.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75415837764.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75568425655.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75585007667.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75607341527.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75804626941.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75836730003.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75875955820.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75926703214.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75928318500.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75941085815.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c75956505537.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76068258285.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76121860742.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76147586107.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76242697238.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76291191577.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76299875974.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76371502876.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76443499326.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76579207181.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76585441827.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76597535610.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76597827672.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76651042699.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76696878671.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76814508438.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76896196603.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76956552267.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c76973396539.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77015221118.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7704418897.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77086329460.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7713067531.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77188330888.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77204078435.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77332931756.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77495044469.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77503299713.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77551227807.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77551746368.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77574700117.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7759118080.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77619880437.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77665555477.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77775526046.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77782666683.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77870041131.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77908319234.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c77931451797.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78023999929.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78156983852.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78162759542.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78218859434.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78291881084.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78383952379.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7839447259.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78447562456.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78450989723.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78521716594.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78667062520.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78682154417.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78703081607.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78874856233.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78971379995.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78973948955.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c78993600606.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79141557216.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79151886701.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79347771406.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7939773797.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79447323083.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c7957983016.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79609191417.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79632526636.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79642343521.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79721009731.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79765659570.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79801988601.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79925829172.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c79994094371.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80029714107.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80035501718.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8008992671.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80108749866.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8016735315.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80185854434.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80256134271.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80323642492.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80357593297.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80428886413.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80440825223.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80713146924.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80725967884.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80734318494.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80734711885.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80907809734.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80911171436.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c80949282646.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81101870536.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81145536899.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81155157089.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81270527839.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81345170736.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81353259086.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81458312273.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81481063365.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81586670875.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81651145219.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81655734777.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81733697652.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81786495447.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81983536481.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c81997793912.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82063180208.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82239848375.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82261580228.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82392495870.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82421827316.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8259838819.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82606798410.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82619637250.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82658255100.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8278042078.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82834774255.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c82990354299.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83031105995.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83044481277.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83154541254.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83194673061.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83295553922.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83296000957.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8331274986.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83317828178.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83380842208.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83417952060.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83488023281.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83496582508.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83502256870.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83558636903.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83569705486.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83745902776.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83751899003.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83760505914.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83794271945.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c83993124961.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84115624427.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84119999408.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84133279323.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84418612718.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84473490715.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84646290540.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84720206260.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c84856915473.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85004490613.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85057699680.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85073107481.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85142034292.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85214251279.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85410714149.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85504412651.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85504549741.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85606485605.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85698747634.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8570706844.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85805636644.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c85832768678.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86058491468.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86162310838.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86204564571.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86236834526.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86343866586.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8635818958.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86567038297.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86694800853.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86705756187.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86749923229.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86768603324.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86807030439.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86825066804.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86942762136.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c86992621421.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87046581506.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87090456485.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87134397029.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87151348590.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87169444561.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87235087156.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87353259325.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87360930442.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87398153543.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87453269958.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87538403272.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87796205282.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87817782163.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87831407785.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c878560543.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87857627868.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87981820106.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c87983775138.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88000380992.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88015758991.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88077753782.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88091504573.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88118869066.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88165086507.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88211053609.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88270831108.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88355618715.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8858406543.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88597607612.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88623535633.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8866053819.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8868485689.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88743352890.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88756388425.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c8885383605.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c88930797576.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89015787839.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89169675111.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89196497201.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89263266324.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c893831253.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89442646503.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89482152462.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89544284343.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89559853076.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89690089225.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c89846700429.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90120267868.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90164816379.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90227895975.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90318584442.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90394806861.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90543645620.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90566521883.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90581697225.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90623724460.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90737277269.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90837717056.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90849381685.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90937101840.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90970534086.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c90974080562.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91070508956.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91094517707.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91119110584.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91196399927.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9119820594.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91263532638.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91469168663.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91498595476.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91521877050.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91688966751.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91780924797.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91805911064.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91850596666.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c91922503709.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92056721448.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92128992080.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92146056890.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92195171117.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92374777793.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92563033103.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92572456598.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92643636465.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92830073833.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92862433195.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c92981845140.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93121039867.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93175768852.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93199908733.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93292599916.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93479681015.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93603694438.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93633162975.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c936806201.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93696063756.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93935662508.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93953877687.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93958514928.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c93976628780.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94098377227.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94144189357.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94189131259.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94213789701.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94334292411.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94578242301.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94581270217.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94667983055.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9467220306.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94720417261.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94802337884.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94885444641.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c94932186603.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95078212022.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95117431879.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95161038637.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95366638898.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9540748596.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95450383424.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95525425672.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95574849843.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95692515373.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95735085010.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95924901962.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95953750610.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c95953869819.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96138298511.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9639346599.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96490192413.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96526050567.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96629929542.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96689909696.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96850621700.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96913582086.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c96932506561.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97099471092.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9711104631.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97367966175.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97369801998.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97390079498.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9739494323.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9739840030.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9755152463.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9777063131.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97862797975.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97877871990.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97880387306.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c97932320833.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9800356626.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98062044382.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98067992925.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98072361946.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98158407211.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98231446743.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98296129703.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9848523139.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98505908250.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98607838153.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98666012287.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98756790161.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98783516883.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98832756280.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c988495349.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98881280422.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9888333082.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c98970603942.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99108499288.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c9916180372.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99172085523.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99298459291.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99351090192.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99485260248.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99515366554.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99559271335.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99599558115.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99844288825.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99897122383.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99946200847.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\c99995505809.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non15786653757.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non22318392992.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non24256640672.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non26581180095.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non35977876186.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non42222613096.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non51439517736.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non54051369428.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non58724635839.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non62501025199.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non68372702598.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non68819969892.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non70554751157.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non72958070039.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non86763852834.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non88518154621.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non94613718986.dxc
c:\windows\system32\explorer32\Recycle\010510\Josh Graves\non96574115753.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c17449146509.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c20112013816.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c20894569158.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c21083170175.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c23513871431.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c25010496377.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c29028260707.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c29940217733.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c35432934761.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c37012243270.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c43202108144.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c46541196107.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c54448008537.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c56335562467.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c58299475908.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c59380215406.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c63672649860.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c69366121292.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c6937205791.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c71115767955.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c71383255720.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c74613249301.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c76327157020.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c82839310169.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c8324676752.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c88206142187.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c9069156646.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\c99575650691.dxc
c:\windows\system32\explorer32\Recycle\010610\Josh Graves\non70554751157.dxc
c:\windows\system32\explorer32\Recycle\clipboard.log
c:\windows\system32\explorer32\Recycle\clipboard10582697391.txt
c:\windows\system32\explorer32\Recycle\clipboard10600787401.txt
c:\windows\system32\explorer32\Recycle\clipboard1170855760.txt
c:\windows\system32\explorer32\Recycle\clipboard13170588016.txt
c:\windows\system32\explorer32\Recycle\clipboard13748896121.txt
c:\windows\system32\explorer32\Recycle\clipboard16570246219.txt
c:\windows\system32\explorer32\Recycle\clipboard17596942186.txt
c:\windows\system32\explorer32\Recycle\clipboard18209040164.txt
c:\windows\system32\explorer32\Recycle\clipboard18559771776.txt
c:\windows\system32\explorer32\Recycle\clipboard19344073534.txt
c:\windows\system32\explorer32\Recycle\clipboard19756281375.txt
c:\windows\system32\explorer32\Recycle\clipboard19966632127.txt
c:\windows\system32\explorer32\Recycle\clipboard20130121707.txt
c:\windows\system32\explorer32\Recycle\clipboard21425372362.txt
c:\windows\system32\explorer32\Recycle\clipboard21744501590.txt
c:\windows\system32\explorer32\Recycle\Clipboard21765697002.txt
c:\windows\system32\explorer32\Recycle\clipboard21799212694.txt
c:\windows\system32\explorer32\Recycle\clipboard22496759891.txt
c:\windows\system32\explorer32\Recycle\clipboard23677569627.txt
c:\windows\system32\explorer32\Recycle\clipboard2451288700.txt
c:\windows\system32\explorer32\Recycle\clipboard24544268846.txt
c:\windows\system32\explorer32\Recycle\clipboard24959528446.txt
c:\windows\system32\explorer32\Recycle\clipboard25952875614.txt
c:\windows\system32\explorer32\Recycle\clipboard26236468553.txt
c:\windows\system32\explorer32\Recycle\clipboard2722895145.txt
c:\windows\system32\explorer32\Recycle\clipboard27655756473.txt
c:\windows\system32\explorer32\Recycle\clipboard27832758426.txt
c:\windows\system32\explorer32\Recycle\clipboard28394061326.txt
c:\windows\system32\explorer32\Recycle\Clipboard2940267324.txt
c:\windows\system32\explorer32\Recycle\clipboard30261737108.txt
c:\windows\system32\explorer32\Recycle\clipboard30351763963.txt
c:\windows\system32\explorer32\Recycle\clipboard30567133426.txt
c:\windows\system32\explorer32\Recycle\clipboard30777704715.txt
c:\windows\system32\explorer32\Recycle\clipboard31163752079.txt
c:\windows\system32\explorer32\Recycle\clipboard31386309862.txt
c:\windows\system32\explorer32\Recycle\clipboard31688433885.txt
c:\windows\system32\explorer32\Recycle\clipboard31999933719.txt
c:\windows\system32\explorer32\Recycle\clipboard32231646776.txt
c:\windows\system32\explorer32\Recycle\clipboard33830988407.txt
c:\windows\system32\explorer32\Recycle\clipboard34241449832.txt
c:\windows\system32\explorer32\Recycle\clipboard348407030.txt
c:\windows\system32\explorer32\Recycle\clipboard34961444139.txt
c:\windows\system32\explorer32\Recycle\clipboard35059100389.txt
c:\windows\system32\explorer32\Recycle\clipboard36972552537.txt
c:\windows\system32\explorer32\Recycle\clipboard37044268846.txt
c:\windows\system32\explorer32\Recycle\clipboard37656146287.txt
c:\windows\system32\explorer32\Recycle\clipboard3812152147.txt
c:\windows\system32\explorer32\Recycle\clipboard38591510057.txt
c:\windows\system32\explorer32\Recycle\clipboard38739740848.txt
c:\windows\system32\explorer32\Recycle\clipboard41870623826.txt
c:\windows\system32\explorer32\Recycle\clipboard42987567186.txt
c:\windows\system32\explorer32\Recycle\clipboard44159442186.txt
c:\windows\system32\explorer32\Recycle\clipboard44688922166.txt
c:\windows\system32\explorer32\Recycle\clipboard44802057743.txt
c:\windows\system32\explorer32\Recycle\clipboard44858294725.txt
c:\windows\system32\explorer32\Recycle\Clipboard45123946666.txt
c:\windows\system32\explorer32\Recycle\clipboard45161944627.txt
c:\windows\system32\explorer32\Recycle\clipboard46004450321.txt
c:\windows\system32\explorer32\Recycle\clipboard46248370409.txt
c:\windows\system32\explorer32\Recycle\clipboard46378290653.txt
c:\windows\system32\explorer32\Recycle\clipboard46661883592.txt
c:\windows\system32\explorer32\Recycle\clipboard4843866825.txt
c:\windows\system32\explorer32\Recycle\clipboard50677996873.txt
c:\windows\system32\explorer32\Recycle\clipboard51640826463.txt
c:\windows\system32\explorer32\Recycle\clipboard5182391405.txt
c:\windows\system32\explorer32\Recycle\clipboard5220758914.txt
c:\windows\system32\explorer32\Recycle\clipboard52223712205.txt
c:\windows\system32\explorer32\Recycle\Clipboard53342401981.txt
c:\windows\system32\explorer32\Recycle\clipboard53435260057.txt
c:\windows\system32\explorer32\Recycle\clipboard53504145145.txt
c:\windows\system32\explorer32\Recycle\clipboard5411273241.txt
c:\windows\system32\explorer32\Recycle\clipboard54214984178.txt
c:\windows\system32\explorer32\Recycle\clipboard5478411912.txt
c:\windows\system32\explorer32\Recycle\clipboard54810076951.txt
c:\windows\system32\explorer32\Recycle\clipboard57465326786.txt
c:\windows\system32\explorer32\Recycle\clipboard57646906375.txt
c:\windows\system32\explorer32\Recycle\clipboard58685809373.txt
c:\windows\system32\explorer32\Recycle\clipboard61037409305.txt
c:\windows\system32\explorer32\Recycle\clipboard61936151981.txt
c:\windows\system32\explorer32\Recycle\clipboard62277948856.txt
c:\windows\system32\explorer32\Recycle\clipboard62309992313.txt
c:\windows\system32\explorer32\Recycle\clipboard62712603807.txt
c:\windows\system32\explorer32\Recycle\clipboard63458979129.txt
c:\windows\system32\explorer32\Recycle\clipboard63532000780.txt
c:\windows\system32\explorer32\Recycle\clipboard64676409959.txt
c:\windows\system32\explorer32\Recycle\clipboard64809161424.txt
c:\windows\system32\explorer32\Recycle\clipboard65015155076.txt
c:\windows\system32\explorer32\Recycle\Clipboard65237671136.txt
c:\windows\system32\explorer32\Recycle\clipboard6551104784.txt
c:\windows\system32\explorer32\Recycle\clipboard66655695438.txt
c:\windows\system32\explorer32\Recycle\clipboard67053729295.txt
c:\windows\system32\explorer32\Recycle\clipboard67470514774.txt
c:\windows\system32\explorer32\Recycle\clipboard68079119920.txt
c:\windows\system32\explorer32\Recycle\clipboard68706476688.txt
c:\windows\system32\explorer32\Recycle\clipboard69420367479.txt
c:\windows\system32\explorer32\Recycle\Clipboard70554751157.txt
c:\windows\system32\explorer32\Recycle\clipboard71607172489.txt
c:\windows\system32\explorer32\Recycle\clipboard71683466434.txt
c:\windows\system32\explorer32\Recycle\clipboard71913653612.txt
c:\windows\system32\explorer32\Recycle\clipboard73140680789.txt
c:\windows\system32\explorer32\Recycle\clipboard73334246873.txt
c:\windows\system32\explorer32\Recycle\clipboard74474298954.txt
c:\windows\system32\explorer32\Recycle\clipboard74689227342.txt
c:\windows\system32\explorer32\Recycle\clipboard74960833787.txt
c:\windows\system32\explorer32\Recycle\clipboard76422846317.txt
c:\windows\system32\explorer32\Recycle\clipboard76692706346.txt
c:\windows\system32\explorer32\Recycle\clipboard77919512987.txt
c:\windows\system32\explorer32\Recycle\clipboard8067828416.txt
c:\windows\system32\explorer32\Recycle\clipboard81111651659.txt
c:\windows\system32\explorer32\Recycle\clipboard81763201951.txt
c:\windows\system32\explorer32\Recycle\clipboard82304888963.txt
c:\windows\system32\explorer32\Recycle\clipboard86542475223.txt
c:\windows\system32\explorer32\Recycle\clipboard87827044725.txt
c:\windows\system32\explorer32\Recycle\clipboard87888079881.txt
c:\windows\system32\explorer32\Recycle\clipboard87952166795.txt
c:\windows\system32\explorer32\Recycle\clipboard88329279422.txt
c:\windows\system32\explorer32\Recycle\clipboard8895075321.txt
c:\windows\system32\explorer32\Recycle\clipboard89461261034.txt
c:\windows\system32\explorer32\Recycle\clipboard89636957645.txt
c:\windows\system32\explorer32\Recycle\clipboard91170245409.txt
c:\windows\system32\explorer32\Recycle\clipboard92363703250.txt
c:\windows\system32\explorer32\Recycle\clipboard92990618944.txt
c:\windows\system32\explorer32\Recycle\clipboard94080096483.txt
c:\windows\system32\explorer32\Recycle\clipboard94167292118.txt
c:\windows\system32\explorer32\Recycle\clipboard94504290819.txt
c:\windows\system32\explorer32\Recycle\clipboard94730120897.txt
c:\windows\system32\explorer32\Recycle\clipboard94892084598.txt
c:\windows\system32\explorer32\Recycle\clipboard9665644168.txt
c:\windows\system32\explorer32\Recycle\clipboard96727496385.txt
c:\windows\system32\explorer32\Recycle\clipboard97610980272.txt
c:\windows\system32\explorer32\Recycle\clipboard99161273241.txt
c:\windows\system32\explorer32\Recycle\clipboard99909174442.txt
c:\windows\system32\explorer32\Recycle\k1049430.kbp
c:\windows\system32\explorer32\Recycle\k1049990.kbp
c:\windows\system32\explorer32\Recycle\k1116126.kbp
c:\windows\system32\explorer32\Recycle\k131194.kbp
c:\windows\system32\explorer32\Recycle\k196724.kbp
c:\windows\system32\explorer32\Recycle\k2950020.kbp
c:\windows\system32\explorer32\Recycle\k460192.kbp
c:\windows\system32\explorer32\Recycle\k5965446.kbp
c:\windows\system32\explorer32\Recycle\k65658.kbp
c:\windows\system32\explorer32\Recycle\k66070.kbp
c:\windows\system32\explorer32\Recycle\k67292.kbp
c:\windows\system32\explorer32\Recycle\k67438.kbp
c:\windows\system32\explorer32\Recycle\NoChat.html
c:\windows\system32\explorer32\Recycle\NoClipboard.htm
c:\windows\system32\explorer32\Recycle\NoEmails.htm
c:\windows\system32\explorer32\Recycle\NoHistory.htm
c:\windows\system32\explorer32\Recycle\upgradebrowser.htm
c:\windows\system32\explorer32\Recycle\web.log
c:\windows\system32\explorer32\Recycle\webwatch.log
c:\windows\system32\explorer32\Recycle\Windows.log
c:\windows\system32\explorer32\regnow.chm
c:\windows\system32\explorer32\rollopen.wav
c:\windows\system32\explorer32\rollover.wav
c:\windows\system32\explorer32\start.wav
c:\windows\system32\explorer32\stop.wav
c:\windows\system32\explorer32\svchost.exe
c:\windows\system32\explorer32\win32nls.dll
c:\windows\system32\zip32.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-24 to 2010-01-24 )))))))))))))))))))))))))))))))
.

2010-01-24 17:41 . 2010-01-24 17:41 -------- d-----w- c:\users\Josh Graves\AppData\Roaming\Malwarebytes
2010-01-24 17:41 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-24 17:41 . 2010-01-24 17:41 -------- d-----w- c:\programdata\Malwarebytes
2010-01-24 17:41 . 2010-01-24 17:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-24 17:41 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-22 09:57 . 2009-12-16 11:44 834048 ----a-w- c:\windows\system32\wininet.dll
2010-01-22 09:57 . 2009-12-18 13:01 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-15 15:47 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-15 15:47 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-22 15:35 . 2009-10-25 06:25 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 20:58 . 2009-02-25 02:11 -------- d-----w- c:\users\Josh Graves\AppData\Roaming\LimeWire
2010-01-15 15:54 . 2009-07-21 01:52 -------- d-----w- c:\programdata\Microsoft Help
2010-01-15 15:54 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-15 15:34 . 2008-10-05 18:25 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-14 19:12 . 2009-10-03 09:02 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-07 18:45 . 2008-04-15 00:12 -------- d-----w- c:\program files\Azureus
2010-01-07 18:45 . 2008-04-15 00:13 -------- d-----w- c:\users\Josh Graves\AppData\Roaming\Azureus
2010-01-02 06:50 . 2008-10-05 18:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-10 11:39 . 2009-12-10 11:39 -------- d-----w- c:\program files\Audacity
2009-12-06 22:22 . 2009-12-06 22:22 635 ----a-w- c:\program files\Common Files\tempeml.html
2009-12-03 21:18 . 2009-12-03 21:18 -------- d-----w- c:\program files\dvd43
2009-12-03 21:18 . 2008-04-15 04:20 18816 ----a-w- c:\windows\system32\drivers\dvd43llh.sys
2009-12-03 21:15 . 2009-12-03 21:15 -------- d-----w- c:\program files\DVD Decrypter
2009-12-03 21:03 . 2008-04-15 01:56 -------- d-----w- c:\users\Josh Graves\AppData\Roaming\Vso
2009-12-03 21:03 . 2009-12-03 21:03 -------- d-----w- c:\program files\LG Software Innovations
2009-12-03 04:00 . 2008-03-13 16:50 -------- d-----w- c:\program files\Microsoft Works
2009-12-03 03:52 . 2009-10-22 05:59 -------- d-----w- c:\program files\Common Files\Outlook Security Manager
2009-12-01 07:30 . 2009-10-09 23:24 256 ----a-w- c:\windows\system32\pool.bin
2009-11-30 01:10 . 2008-04-13 21:36 117304 ----a-w- c:\users\Josh Graves\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-30 01:00 . 2009-11-30 01:00 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-11-30 01:00 . 2008-03-13 16:39 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-11-30 01:00 . 2008-03-13 16:39 -------- d-----w- c:\program files\Roxio
2009-11-30 00:59 . 2008-03-13 16:39 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-11-30 00:59 . 2008-03-13 16:41 -------- d-----w- c:\programdata\Roxio
2009-11-30 00:47 . 2009-11-30 00:47 -------- d-----w- c:\programdata\Research In Motion
2009-11-24 23:54 . 2008-12-11 01:15 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2008-12-11 01:15 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-12-11 01:15 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2008-12-11 01:15 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2008-12-11 01:15 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2008-12-11 01:15 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2008-12-11 01:15 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-17 11:19 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-16 16:09 . 2008-12-21 19:59 940 ----a-w- c:\users\Josh Graves\AppData\Roaming\wklnhst.dat
2009-11-09 12:31 . 2009-12-09 02:24 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 02:24 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 02:24 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-11-25 11:01 2048 ----a-w- c:\windows\system32\tzres.dll
2006-05-31 16:14 . 2006-05-31 16:14 108056 ----a-w- c:\program files\Common Files\secman.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2008-10-24 206112]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-05-16 648504]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-05-22 451896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"D-Link D-Link Xtreme N Dual Band DWA-160 "="c:\program files\D-Link\DWA-160\AirNCFG.exe" [2008-03-21 1675264]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-20 623960]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-24 827904]

c:\users\Josh Graves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-7-8 385024]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-3-13 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(cool.gif:e6,f2,4e,09,dc,3b,ca,01

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [12/10/2008 5:15 PM 114768]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\System32\AERTSrv.exe [12/5/2007 6:17 AM 77824]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [12/10/2008 5:15 PM 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [12/10/2008 5:15 PM 53328]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [1/1/2010 10:48 PM 1153368]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\System32\drivers\wdcsam.sys [4/16/2008 7:27 AM 11520]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 6:23 PM 21504]
S3 libusb0;LibUsb-Win32 - Kernel Driver 08/27/2006, 0.1.12.0;c:\windows\System32\drivers\libusb0.sys [2/18/2008 3:36 PM 33792]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr28u.sys [3/15/2009 8:52 PM 599040]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-HijackThis - c:\users\Josh Graves\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2DTQMEUZ\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-24 10:50
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-24 10:53:21
ComboFix-quarantined-files.txt 2010-01-24 18:53

Pre-Run: 230,164,832,256 bytes free
Post-Run: 230,133,395,456 bytes free

- - End Of File - - 9DEF5A3F8CE4B9D0803D9B3FDC064956

#8 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:08:48 AM

Posted 24 January 2010 - 02:08 PM

QUOTE
I do have several questions, if you dont mind. I will ask them when you say that we are done.

Sure we attend to the questions at the end. thumbup2.gif

Please make sure you set ESET to remove what it finds.

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
  • Check
  • Click the button.
  • Accept any security warnings from your browser.
  • Check
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push
  • Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the button.
  • Push

A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

#9 socain

socain
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:48 PM

Posted 24 January 2010 - 03:11 PM

farbar

Ok all done with that one. I am posting both the log and the results of what was deleted. Thanks.

C:\Qoobox\Quarantine\C\Windows\System32\explorer32\svchost.exe.vir probably unknown NewHeur_PE virus deleted - quarantined
C:\Users\Josh Graves\Documents\LimeWire\Incomplete\T-5186975-prayer to peter st.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan cleaned - quarantined

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.16386 (vista_rtm.061101-2205)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=3c667aa50ad9524bb062870a0b8e7b7d
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-01-24 08:03:49
# local_time=2010-01-24 12:03:49 (-0800, Pacific Standard Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=769 16775165 100 98 0 199728171 0 0
# compatibility_mode=5892 16776574 100 100 0 100968945 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=129833
# found=2
# cleaned=2
# scan_time=2011
C:\Qoobox\Quarantine\C\Windows\System32\explorer32\svchost.exe.vir probably unknown NewHeur_PE virus (deleted - quarantined) 00000000000000000000000000000000 C
C:\Users\Josh Graves\Documents\LimeWire\Incomplete\T-5186975-prayer to peter st.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C


#10 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:08:48 AM

Posted 24 January 2010 - 03:49 PM

  1. Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
    • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
    • Look for "Java Runtime Environment (JRE)" JRE 6 Update 18.
    • Click the Download button to the right.
    • Select your Platform: "Windows".
    • Select your Language: "Multi-language".
    • Read the License Agreement, and then check the box that says: "Accept License Agreement".
    • Click Continue and the page will refresh.
    • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
    • Close any programs you may have running - especially your web browser.
    Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
    • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u18-windows-i586.exe to install the newest version.

  2. We are going to uninstall ComboFix next post. Tell me how is your computer running and fire up your questions please.


#11 socain

socain
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:48 PM

Posted 24 January 2010 - 04:37 PM

farbar

Ok uninstalled old version and installed new, all went well. The start up error was gone several steps ago. The overall start time seems to have decreased a bit. But i can understand why it takes a while to start, i have several programs set to start automatically, i might change a few of those. Thanks. I guess i will ask a few questions now.

1. How could i have avoided these problems? I have and have always had all security settings on and up to date.
2. How do programs like avast and spybot, and even the windows defender malware scan miss things that you were able to find?
3. To be infected with these problems do i have to actually download them, or can i get them just from being on a site?
4. In your personal opinion, do you suggest that i do the OS reformat, reinstall? And if so is that something you can help with?
5. The PcTattleTale program is in fact not operating now, "pctattletale can not be located". What steps do i take to get it up again?
6. I noticed that one of the files that was located and deleted in one of the last scans was a "temp file for prayer to saint peter". That is a song that was downloaded through lime wire. Should i just get rid of that program all together or is there a possibility that i dont have it configured properly security wise? Can you tell exactally how the viruses, bots got in to begin with, is there a way to track them somehow?
7. What do you suggest that i do to avoid this in the future?

#12 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:08:48 AM

Posted 24 January 2010 - 05:49 PM

It is important to uninstall ComboFix.

Go to Start => Run => copy and paste next command in the field then hit enter:

ComboFix /Uninstall

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

It makes a clean Restore Point and clears all the old restore points in order to prevent possible reinfection from an old one through system restore.

*********
QUOTE
1. How could i have avoided these problems? I have and have always had all security settings on and up to date.

As I already mentioned I thought it was through those p2p programs.

QUOTE
2. How do programs like avast and spybot, and even the windows defender malware scan miss things that you were able to find?

Even the best antivirus\antispyware can miss things.

QUOTE
3. To be infected with these problems do i have to actually download them, or can i get them just from being on a site?

Most of the times you have to download them. In some cases going to a bad site might infect you.

QUOTE
4. In your personal opinion, do you suggest that i do the OS reformat, reinstall? And if so is that something you can help with?

I don't think it is needed. However, better safe than sorry. In case you do banking with the computer, it will be better to reformat.
To reformat and reinstall you read the tutorials or open a topic here, there are plenty who can help you:

Windows Vista

QUOTE
5. The PcTattleTale program is in fact not operating now, "pctattletale can not be located". What steps do i take to get it up again?

Reinstall it. Run Malwarbytes again, but don't select to remove anything it found and select to ignore and it will put what found to Ignore List. That way you can use Malwarebytes again if needed, without removing the key-logger.

QUOTE
6. I noticed that one of the files that was located and deleted in one of the last scans was a "temp file for prayer to saint peter". That is a song that was downloaded through lime wire. Should i just get rid of that program all together or is there a possibility that i dont have it configured properly security wise? Can you tell exactally how the viruses, bots got in to begin with, is there a way to track them somehow?

Either you find a safe way to use p2p or get rid of it totally. Even with every precaution you may get infected when you download something from p2p. To tell you the ways you might get infected I have to tell all I know about malware and that is impossible for me to do and is beyond this forum.

QUOTE
7. What do you suggest that i do to avoid this in the future?

Avast is a decent free antivirus, but I prefer Avira. If you wanted to switch:

Click Avira
Download the installer from softpedia.com link as it has a secure download mirror.
Uninstall Avast then install Avira and update it.


Recommendations:
  1. I recommend using Site Advisor for safe surfing. It is a free extension both for Internet Explorer and Firefox. When you search a site it gives you an indication of how safe a site is.

  2. I recommend installing this small application for safe surfing: Javacools© SpywareBlaster
    SpywareBlaster will add a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
    • Download and install it.
    • Update it manually by clicking on Updates in the left pane and then Check for Updates.
    • Then enable all the protections by clicking on Protection Status on the left pane. Then click on Enable All Protection.
    • The free version doesn't have an automatic update. Update it once in two or three weeks and enable all protection again.

Please consult this article by Miekiemoes on How To Prevent Malware.

*************

Happy Surfing. smile.gif

#13 socain

socain
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:48 PM

Posted 24 January 2010 - 07:10 PM

farbar
Thanks for all your help. I will look into the format and reinstall of OS. I guess as long as i dont lose anything from my computer than all im out is a little time to do it right. I am in the process of redownloading the PCTT. For some reason my password does not work anymore, it might have been a bi product of the the tools we used like you said. I obviously noticed the notice for ComboFix. I mean wow, bugs are everywhere hu. This has been a very sobering experience for me. I was wondering if this thread will remain open, or active so i can use it as reference in the future. Thanks for all your help.

#14 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:08:48 AM

Posted 25 January 2010 - 01:53 AM

Hi socain,

You are very welcome. smile.gif

The thread will be closed now. But you can keep the link to it for the future reference.

If you should have a new issue please start a new topic.







0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users