Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I believe i have a rootkit virus effecting sites like ebay!


  • This topic is locked This topic is locked
19 replies to this topic

#1 Shocker1245

Shocker1245

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 24 February 2010 - 07:20 PM

I'm sure this is not a new topic, but I have searched through other topics and it seemed like some worked for the people and some didn't. I will start off by saying I am not very good with computers, but I will do my best to follow the instruction given. My problem began a few days ago. The first thing that was odd was my computer shut down by itself out of no where. Shortly after I don't remember how long, but within a day or so id guess, I went to ebay...logged in as usual...and came to that screen asking me for a lot of personal info, which I immediately recognized as BS and didn't divulge. I have tried a couple programs to remove it. But nothing really finds it except prevx 3.0, which wanted me to pay for it to remove it. However i wasn't confident it would, so before i spent the $ i wanted to find out! Someone has to have some experience with this, as like i said i seen other threads, but some were older, some I wasn't sure bout the software needed in them, i dunno...any help?!?!!? The 2nd posted log below did make it go away when I did the cmd prompt window typed in the "mbr.exe -f" then "exit" then restarted....then re-ran this program....but since i believe this virus or w/e it is tied into my startup somehow, it just comes back.

Prevx info if this helps:
Name: $mbr.0 in c:\ then under threat identified: RootKit.MBR.

Pretty confident this is whats causing it. I also ran this..

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\ACPI -> 0x8a018d50
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x897e6640
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0995C69A
malicious code @ sector 0x0995C69D !
PE file found in sector at 0x0995C6B3 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

Edited by Orange Blossom, 24 February 2010 - 07:33 PM.
Move to log forum. ~ OB


BC AdBot (Login to Remove)

 


#2 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:05:06 PM

Posted 26 February 2010 - 09:46 PM

Hello,

My name is Syler and I will be helping you to solve your Malware issues. If you have since resolved your issues I would appreciate if you
would let me no so I can close this topic, if you still need help please let me no what issues you are still having, in your next reply.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)


  1. Please download GMER from one of the following locations, and save it to your desktop:
    • Main Mirror
      This version will download a randomly named file (Recommended)
    • Zip Mirror
      This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  2. Disconnect from the Internet and close all running programs, as this process may crash your computer.
  3. Temporarily disable any real-time active protection so your security program drivers will not conflict with gmer's driver.
  4. Double click on Gmer to run it.
  5. Allow the gmer.sys driver to load if asked.
  6. You may see a rootkit warning window, If you do, click No.
  7. Untick the following boxes on the right side of the Gmer screen.
    Sections
    IAT/EAT
    Files
    Show All
  8. Click on and wait for the scan to finish.
  9. If you see a rootkit warning window, click OK.
  10. Push and save the logfile to your desktop.
  11. Copy and Paste the contents of that file in your next post.



Then please post back here with the following:
  • log.txt
  • info.txt
  • Gmer log

Thanks

unite.jpg


#3 Shocker1245

Shocker1245
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 27 February 2010 - 12:24 AM

First of its not resolved. I will tell you I ran prevx 3.0 and it found a rootkit.mbr. Why i figured that was it, haha. Anyhow main problems are on sites like paypal, ebay, etc...when i try to log in it asks for my personal info/bank info, etc. Couple other issues i have noticed that may or may not be related is 1) internet runs kinda slow, and has been acting up as of late prior to realizing i had this or it rearin its ugly head, 2) PC randomly shut down other day, right after this was first time i noticed the ebay problem, 3) On some sites, things like reply buttons on a forum which are normally a lil picture that says reply will just say reply underlined, or avatars will just say "So n So's avatar" UNLESS i click refresh then itll be normal, but it goes back and forth from messed up to normal. Anyhow here is logs.


log.txt

Logfile of random's system information tool 1.06 (written by random/random)
Run by Sean Canfield at 2010-02-27 00:08:06
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 40 GB (51%) free of 79 GB
Total RAM: 2046 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:08:13 AM, on 2/27/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Creative\Shared Files\CTSched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Documents and Settings\Sean Canfield\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Sean Canfield.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fleaflicker.com/nfl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Software Update] "C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe" /Silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: TestPokerStars.com - {809132AF-89D2-4d52-AA03-AB4E35BBDC5B} - C:\Program Files\PokerStars.TEST\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_b...sreqlab_srl.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup...15108/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8322 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-02-21 1484056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2008-12-18 76304]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-01-05 413696]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2009-03-04 19456]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2010-02-23 815184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-05-20 98304]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"=C:\Program Files\Creative\Shared Files\CTSched.exe [2006-11-17 53341]
"SetDefaultMIDI"=C:\WINDOWS\system32\MIDIDef.exe [2009-03-04 28672]
"Creative Software Update"=C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe [2007-01-04 481200]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [2005-10-31 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe [2008-05-15 356864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files\steam\steam.exe [2010-02-21 1217872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-01-05 2002160]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-02-21 12464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-02-18 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\steamapps\stinker123105\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\stinker123105\counter-strike\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Disabled:Steam 732897"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\AVG\AVG9\avgemc.exe"="C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

======List of files/folders created in the last 1 months======

2010-02-27 00:08:06 ----D---- C:\rsit
2010-02-26 19:56:02 ----A---- C:\rootkitrepeal.txt
2010-02-26 19:55:32 ----A---- C:\RootRepeal report 02-26-10 (19-55-32).txt
2010-02-26 19:40:33 ----A---- C:\ComboFix.txt
2010-02-26 19:31:18 ----A---- C:\Boot.bak
2010-02-26 19:31:11 ----RASHD---- C:\cmdcons
2010-02-26 19:30:35 ----A---- C:\WINDOWS\zip.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\SWSC.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\SWREG.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\sed.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\PEV.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\MBR.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\grep.exe
2010-02-26 19:30:28 ----D---- C:\WINDOWS\ERDNT
2010-02-26 19:23:29 ----D---- C:\Qoobox
2010-02-26 18:01:45 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\WinRAR
2010-02-26 18:01:26 ----D---- C:\Program Files\WinRAR
2010-02-26 17:46:07 ----A---- C:\WINDOWS\{00000000-00000000-00000009-00001102-00000004-20061102}.BAK
2010-02-24 19:33:54 ----D---- C:\Program Files\Trend Micro
2010-02-24 18:29:30 ----D---- C:\Program Files\HiddenFinder
2010-02-24 17:32:44 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\Malwarebytes
2010-02-24 17:32:19 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-02-24 17:32:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-24 16:32:37 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-24 16:32:26 ----D---- C:\Program Files\SUPERAntiSpyware
2010-02-24 16:32:26 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\SUPERAntiSpyware.com
2010-02-24 16:04:15 ----A---- C:\WINDOWS\wininit.ini
2010-02-24 15:20:41 ----D---- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2010-02-24 13:53:29 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-24 13:53:29 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-24 13:53:29 ----A---- C:\WINDOWS\system32\java.exe
2010-02-24 02:58:27 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-02-23 02:39:30 ----HDC---- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-21 21:22:41 ----D---- C:\$AVG
2010-02-21 21:22:24 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-02-21 21:22:03 ----D---- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
2010-02-21 21:21:43 ----D---- C:\Program Files\AVG
2010-02-21 21:21:42 ----D---- C:\Documents and Settings\All Users\Application Data\avg9
2010-02-21 21:21:17 ----D---- C:\WINDOWS\SxsCaPendDel
2010-02-21 20:15:41 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\Disk Cleaner
2010-02-11 00:29:01 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZisn12.dll
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZipt12.dll
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZipr12.dll
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZipm12.exe
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZinw12.exe
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZidr12.dll
2010-02-11 00:27:23 ----A---- C:\WINDOWS\IsUninst.exe
2010-02-11 00:27:07 ----D---- C:\Program Files\HP
2010-02-11 00:26:52 ----D---- C:\Config.Msi
2010-02-11 00:26:22 ----A---- C:\WINDOWS\system32\hpzjsn01.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\HPZc3212.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\hpovst08.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\hpotscl.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\hpgwiamd.dll
2010-02-11 00:26:10 ----A---- C:\WINDOWS\system32\hpzlnt12.dll
2010-02-11 00:26:08 ----A---- C:\WINDOWS\system32\hpzcon12.dll
2010-02-11 00:26:08 ----A---- C:\WINDOWS\system32\hpzcoi12.dll
2010-02-10 19:53:00 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 19:52:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 19:51:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 19:51:03 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 19:50:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 19:50:45 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 19:50:33 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$

======List of files/folders modified in the last 1 months======

2010-02-27 00:08:13 ----D---- C:\WINDOWS\Prefetch
2010-02-26 23:53:17 ----SD---- C:\WINDOWS\Tasks
2010-02-26 23:53:15 ----D---- C:\WINDOWS\Temp
2010-02-26 23:52:37 ----D---- C:\Program Files\Mozilla Firefox
2010-02-26 23:49:56 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-26 20:51:04 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-26 20:23:25 ----D---- C:\WINDOWS\system32\drivers
2010-02-26 20:23:25 ----D---- C:\WINDOWS\system32
2010-02-26 20:23:13 ----SHD---- C:\WINDOWS\Installer
2010-02-26 19:38:44 ----D---- C:\WINDOWS
2010-02-26 19:38:44 ----A---- C:\WINDOWS\system.ini
2010-02-26 19:36:55 ----D---- C:\WINDOWS\AppPatch
2010-02-26 19:36:51 ----D---- C:\Program Files\Common Files
2010-02-26 19:31:18 ----RASH---- C:\boot.ini
2010-02-26 19:30:34 ----SHD---- C:\System Volume Information
2010-02-26 19:30:34 ----D---- C:\WINDOWS\system32\Restore
2010-02-26 18:19:49 ----RD---- C:\Program Files
2010-02-26 15:42:07 ----ASD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-02-25 21:54:38 ----D---- C:\Program Files\Steam
2010-02-24 18:05:41 ----A---- C:\WINDOWS\win.ini
2010-02-24 17:44:48 ----D---- C:\WINDOWS\system32\CatRoot_bak
2010-02-24 17:44:48 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-24 17:44:28 ----HD---- C:\WINDOWS\inf
2010-02-24 17:28:07 ----D---- C:\WINDOWS\SoftwareDistribution
2010-02-24 16:32:09 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-02-24 13:59:23 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-24 13:53:25 ----D---- C:\Program Files\Java
2010-02-23 02:41:12 ----A---- C:\WINDOWS\system32\lsdelete.exe
2010-02-23 02:39:38 ----D---- C:\WINDOWS\WinSxS
2010-02-23 02:39:38 ----D---- C:\Program Files\Lavasoft
2010-02-22 02:05:22 ----D---- C:\WINDOWS\system32\config
2010-02-21 21:19:44 ----SD---- C:\Documents and Settings\Sean Canfield\Application Data\Microsoft
2010-02-21 21:03:24 ----D---- C:\WINDOWS\Debug
2010-02-21 20:04:36 ----D---- C:\Documents and Settings
2010-02-20 16:42:17 ----D---- C:\Program Files\REAPER
2010-02-11 00:29:09 ----D---- C:\WINDOWS\twain_32
2010-02-11 00:04:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-10 19:52:59 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-01 14:26:20 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-02-21 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-02-21 28424]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-02-21 360584]
R1 BIOS;BIOS; \??\C:\WINDOWS\system32\drivers\BIOS.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-02-28 36096]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
R2 LBeepKE;LBeepKE; C:\WINDOWS\System32\Drivers\LBeepKE.sys [2008-12-18 10384]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-02-28 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-25 3565568]
R3 COMMONFX.SYS;COMMONFX.SYS; C:\WINDOWS\System32\drivers\COMMONFX.SYS [2009-03-04 99352]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2009-03-04 511000]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2009-03-04 528408]
R3 CTAUDFX.SYS;CTAUDFX.SYS; C:\WINDOWS\System32\drivers\CTAUDFX.SYS [2009-03-04 555032]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2009-03-04 14360]
R3 CTSBLFX.SYS;CTSBLFX.SYS; C:\WINDOWS\System32\drivers\CTSBLFX.SYS [2009-03-04 566296]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2009-03-04 157208]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2009-03-04 92696]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2005-06-22 43008]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2009-03-04 798744]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2009-03-04 162840]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2008-12-18 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2008-12-18 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2008-12-18 37392]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2008-12-18 28816]
R3 MAUSBFT;Service for M-Audio Fast Track USB (WDM); C:\WINDOWS\system32\DRIVERS\mausbft.sys [2007-11-13 132096]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-02-28 61824]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2009-03-04 127512]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2006-02-28 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-02-28 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-02-28 57600]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-02-28 20480]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
S3 catchme;catchme; \??\C:\DOCUME~1\SEANCA~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 COMMONFX;COMMONFX; C:\WINDOWS\system32\drivers\COMMONFX.SYS [2009-03-04 99352]
S3 CTAUDFX;CTAUDFX; C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2009-03-04 555032]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2009-03-04 347080]
S3 CTERFXFX.SYS;CTERFXFX.SYS; C:\WINDOWS\System32\drivers\CTERFXFX.SYS [2009-03-04 100888]
S3 CTERFXFX;CTERFXFX; C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2009-03-04 100888]
S3 CTSBLFX;CTSBLFX; C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2009-03-04 566296]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera; C:\WINDOWS\System32\Drivers\ubVeo532.sys [2002-07-01 95232]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2009-03-04 189464]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 KProcWatch;KProcWatch; \??\C:\WINDOWS\system32\drivers\KProcWatch.sys []
S3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2008-12-18 63248]
S3 LMouKE;SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2008-12-18 79248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys []
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-03-26 36864]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-25 602112]
R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-02-21 906520]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-02-21 285392]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2009-01-08 307200]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-23 1229232]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-10-11 38912]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-05-15 593920]
S3 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-26 132424]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-06-01 79360]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-02-18 121360]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


info.txt

info.txt logfile of random's system information tool 1.06 2010-02-27 00:08:16

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /nolog/l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /nolog/l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /nolog/l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /nolog/l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /nolog/l0x0009
-->"C:\Program Files\Creative\SBAudigy\Program\Setup.exe" /S /U /W
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32B4B536-4443-42F0-9676-98373BE9114F}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32B4B536-4443-42F0-9676-98373BE9114F}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34EBD418-B8E6-4E86-89C4-33B72CF5663F}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34EBD418-B8E6-4E86-89C4-33B72CF5663F}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52338F65-A1C3-4CDC-B733-50051682B297}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52338F65-A1C3-4CDC-B733-50051682B297}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9194237B-7B58-40B4-A739-184AD59531A2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9194237B-7B58-40B4-A739-184AD59531A2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C64409FA-42A7-49C6-837A-D2E5D813BD57}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C64409FA-42A7-49C6-837A-D2E5D813BD57}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}\setup.exe" -l0x9 /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Ad-Aware Email Scanner for Outlook-->MsiExec.exe /I{338F08AB-C262-42C7-B000-34DE1A475273}
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Apple Mobile Device Support-->MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x5357
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVG Free 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Catalyst Control Center - Branding-->MsiExec.exe /I{D3B1C799-CB73-42DE-BA0F-2344793A095C}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
Counter-Strike: Source-->"C:\Program Files\Steam\steam.exe" steam://uninstall/240
Counter-Strike-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10
Creative Audio Console-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x9 /remove
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\setup.exe" -l0x9 /remove
Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9 /remove
Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
Creative WaveStudio 7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9 /remove
EZdrummer-->MsiExec.exe /I{43E8D9E7-AFC9-4BA3-8106-B95E02B87AB7}
EZXCocktail-->MsiExec.exe /I{147567F0-8575-4BE0-B5B3-62706C67FA5A}
Fast Track USB-->C:\Program Files\InstallShield Installation Information\{07D4A7C5-C55C-45B5-9E86-D8068D25EF40}\setup.exe -runfromtemp -l0x0009 -removeonly
ffdshow [rev 2527] [2008-12-19]-->"C:\Program Files\ffdshow\unins000.exe"
Haali Media Splitter-->"C:\Program Files\Haali\MatroskaSplitter\uninstall.exe"
Hidden Finder 1.5.6-->"C:\Program Files\HiddenFinder\unins000.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB954708)-->"C:\WINDOWS\$NtUninstallKB954708$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB979306)-->"C:\WINDOWS\$NtUninstallKB979306$\spuninst\spuninst.exe"
HP PSC & OfficeJet 5.3.B-->"C:\Program Files\HP\Digital Imaging\{49FB31C1-26EC-44c6-AB47-73C66E2BC41E}\setup\hpzscr01.exe" -datfile hposcr07.dat
Interlok driver setup x32-->MsiExec.exe /X{25613C10-27D2-410B-942B-D922D5C3A7BE}
iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
Java™ 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014FF}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
Logitech SetPoint-->"C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe" -runfromtemp -l0x0009 -removeonly
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Mozilla Firefox (3.0.18)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
PokerStars-->"C:\Program Files\PokerStars\PokerStarsUninstall.exe" /u:PokerStars
QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
REAPER-->"C:\Program Files\REAPER\Uninstall.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958470)-->"C:\WINDOWS\$NtUninstallKB958470$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969897)-->"C:\WINDOWS\$NtUninstallKB969897$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
Security Update for Windows XP (KB972260)-->"C:\WINDOWS\$NtUninstallKB972260$\spuninst\spuninst.exe"
Security Update for Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974455)-->"C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Security Update for Windows XP (KB976325)-->"C:\WINDOWS\$NtUninstallKB976325$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Session-->C:\Program Files\InstallShield Installation Information\{8417AD12-1A5A-4E45-B8F2-D2E92B0FF921}\setup.exe -runfromtemp -l0x0009 -removeonly
Sound Blaster Audigy-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}\SETUP.EXE" -l0x9 /remove
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Switch Sound File Converter-->C:\Program Files\NCH Swift Sound\Switch\uninst.exe
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TestPokerStars.com-->"C:\Program Files\PokerStars.TEST\PokerStarsUninstall.exe" /u:TestPokerStars.com
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB925720)-->"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
Update for Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Update for Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Update for Windows XP (KB976749)-->"C:\WINDOWS\$NtUninstallKB976749$\spuninst\spuninst.exe"
Update for Windows XP (KB978207)-->"C:\WINDOWS\$NtUninstallKB978207$\spuninst\spuninst.exe"
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VIA Platform Device Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Waves Guitar Solo 3.5-->"C:\Program Files\InstallShield Installation Information\{60800021-C561-4E32-99EB-3C5AD3683A70}\setup.exe" -runfromtemp -l0x0009 -removeonly
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}
Windows Live Family Safety-->MsiExec.exe /X{139E303E-1050-497F-98B1-9AE87B15C463}
Windows Live Mail-->MsiExec.exe /I{6412CECE-8172-4BE5-935B-6CECACD2CA87}
Windows Live Messenger-->MsiExec.exe /X{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
Windows Live Photo Gallery-->MsiExec.exe /X{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}
Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
Windows Live Sync-->MsiExec.exe /X{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}
Windows Live Toolbar-->MsiExec.exe /X{995F1E2E-F542-4310-8E1D-9926F5A279B3}
Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Windows Live Writer-->MsiExec.exe /X{178832DE-9DE0-4C87-9F82-9315A9B03985}
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

======Security center information======

AV: AVG Anti-Virus Free

======System event log======

Computer Name: J-46642B5CB4F24
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 11477
Source Name: W32Time
Time Written: 20100109231633.000000-300
Event Type: warning
User:

Computer Name: J-46642B5CB4F24
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 11428
Source Name: W32Time
Time Written: 20100107223335.000000-300
Event Type: warning
User:

Computer Name: J-46642B5CB4F24
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 11379
Source Name: W32Time
Time Written: 20100105215737.000000-300
Event Type: warning
User:

Computer Name: J-46642B5CB4F24
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 11352
Source Name: W32Time
Time Written: 20100104222511.000000-300
Event Type: warning
User:

Computer Name: J-46642B5CB4F24
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 11325
Source Name: W32Time
Time Written: 20100104000437.000000-300
Event Type: warning
User:

=====Application event log=====


gmer log

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-27 00:16:05
Windows 5.1.2600 Service Pack 2
Running: 6uvshw3m.exe; Driver: C:\DOCUME~1\SEANCA~1\LOCALS~1\Temp\kfliifod.sys


---- System - GMER 1.0.15 ----

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF764787E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF7647BFE]

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\ACPI \Device\00000051 8A042E30
Device \Driver\ACPI \Device\00000061 8A042E30

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\ACPI \Device\00000062 8A042E30
Device \Driver\ACPI \Device\00000063 8A042E30
Device \Driver\ACPI \Device\00000057 8A042E30
Device \Driver\ACPI \Device\00000064 8A042E30
Device \Driver\ACPI \Device\00000065 8A042E30
Device \Driver\ACPI \Device\00000066 8A042E30
Device \Driver\ACPI \Device\0000004b 8A042E30
Device \Driver\ACPI \Device\0000004c 8A042E30
Device \Driver\ACPI \Device\0000005a 8A042E30
Device \Driver\ACPI \Device\0000004d 8A042E30
Device \Driver\ACPI \Device\0000005b 8A042E30
Device \Driver\ACPI \Device\0000004e 8A042E30
Device \Driver\ACPI \Device\0000005c 8A042E30

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\ACPI \Device\0000005d 8A042E30

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\ACPI \Device\0000006a 8A042E30
Device \Driver\ACPI \Device\0000005e 8A042E30
Device \Driver\ACPI \Device\0000006b 8A042E30
Device \Driver\ACPI \Device\0000006c 8A042E30
Device \Driver\ACPI \Device\0000006d 8A042E30
Device \FileSystem\Fastfat \Fat A8AE2C8A

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

#4 Shocker1245

Shocker1245
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 27 February 2010 - 12:37 AM

Forgot to say thanks too! lol. Im terrible with comps, id probably mess it up even worse then it is if i tried to go at it myself, LOL! Just wanna get rid of this w/e it is.

#5 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:05:06 PM

Posted 27 February 2010 - 03:24 PM

your welcome, let's see if we can get this cleaned up.

I see that you have already been running combofix, please post the log it produce at C:\ComboFix.txt don't run it again yet.

unite.jpg


#6 Shocker1245

Shocker1245
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 27 February 2010 - 04:11 PM

ComboFix 10-02-26.01 - Sean Canfield 02/26/2010 19:33:56.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1308 [GMT -5:00]
Running from: c:\documents and settings\Sean Canfield\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe

.
original MBR restored successfully !
.
((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.

2010-02-25 00:33 . 2010-02-25 00:33 -------- d-----w- c:\program files\Trend Micro
2010-02-24 23:29 . 2010-02-24 23:29 -------- d-----w- c:\program files\HiddenFinder
2010-02-24 23:29 . 2006-02-24 03:03 8576 ----a-w- c:\windows\system32\drivers\KProcWatch.sys
2010-02-24 23:12 . 2010-02-26 22:58 0 ----a-w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\prvlcl.dat
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-24 21:33 . 2010-02-24 21:33 52224 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-24 21:33 . 2010-02-24 21:33 117760 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com
2010-02-24 20:22 . 2009-11-25 18:01 1230080 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-02-24 20:21 . 2010-02-24 20:21 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG IDS
2010-02-24 20:20 . 2010-02-24 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2010-02-24 18:57 . 2010-02-24 18:58 39451456 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative Sound Blaster Audigy series driver 2.18.0011__\SBAX_PCDRV_LB_2_18_0011.exe
2010-02-24 18:55 . 2010-02-24 18:56 37634288 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.26.02__\CMS5_PCAPP_LB_5_26_02.exe
2010-02-24 18:55 . 2010-02-24 18:55 12907880 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative WaveStudio 7.12.00__\WAVESTD_PCAPP_LB_7_12_00.exe
2010-02-24 18:54 . 2010-02-24 18:55 10995608 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative CD Burner Plugin 5.01.44 for Creative MediaSource 5 Player_Organizer__\CMS5_BRNR_PCAPP_LB_5_01_44.exe
2010-02-24 18:52 . 2010-02-24 18:52 152576 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-24 18:52 . 2010-02-24 18:52 79488 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 598368 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-02-23 07:41 . 2010-02-23 07:41 566608 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-02-23 07:41 . 2010-02-23 07:41 221408 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-02-23 07:41 . 2010-02-23 07:41 1230160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-23 07:41 . 2010-02-23 07:41 247120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-23 07:40 . 2010-02-23 07:40 17480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-23 07:39 . 2010-02-23 07:39 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-23 07:39 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-22 02:25 . 2010-02-22 02:25 -------- d-----w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\AVG Security Toolbar
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- C:\$AVG
2010-02-22 02:22 . 2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-22 02:22 . 2010-02-22 02:22 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-22 02:22 . 2010-02-22 02:22 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-22 02:22 . 2010-02-22 02:22 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-22 02:22 . 2010-02-26 22:43 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-22 02:21 . 2010-02-24 20:21 -------- d-----w- c:\program files\AVG
2010-02-22 02:21 . 2010-02-22 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-22 02:21 . 2010-02-22 03:16 -------- d-----w- c:\windows\SxsCaPendDel
2010-02-22 01:15 . 2010-02-25 04:57 -------- d-----w- c:\documents and settings\HelpAssistant\Tracing
2010-02-22 01:15 . 2010-02-22 01:15 -------- d-----w- c:\documents and settings\HelpAssistant\UserData
2010-02-22 01:15 . 2010-02-22 01:54 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Disk Cleaner
2010-02-22 01:06 . 2010-02-22 01:06 -------- d-----w- c:\documents and settings\HelpAssistant\Contacts
2010-02-11 05:29 . 2010-02-11 05:29 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-02-11 05:27 . 2004-09-29 17:15 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2010-02-11 05:27 . 2004-09-29 17:14 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2010-02-11 05:27 . 2004-09-29 17:12 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2010-02-11 05:27 . 2004-09-29 17:09 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2010-02-11 05:27 . 2004-09-29 17:09 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2010-02-11 05:27 . 2004-09-29 17:08 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2010-02-11 05:27 . 1998-10-29 21:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-02-11 05:27 . 2010-02-11 05:27 -------- d-----w- c:\program files\HP
2010-02-11 05:04 . 2004-08-04 04:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-02-11 05:04 . 2004-08-04 04:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 02:54 . 2009-07-04 03:03 -------- d-----w- c:\program files\Steam
2010-02-24 21:32 . 2009-04-08 04:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-24 18:59 . 2009-04-08 02:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-24 18:53 . 2009-06-15 01:24 -------- d-----w- c:\program files\Java
2010-02-23 07:41 . 2009-06-21 13:19 884176 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-02-23 07:41 . 2009-06-21 13:28 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 393896 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-02-23 07:41 . 2009-06-21 13:19 211064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-02-23 07:41 . 2009-12-06 00:27 562272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-02-23 07:41 . 2009-06-21 13:19 390320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-23 07:41 . 2009-06-21 13:19 167312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-02-23 07:41 . 2009-06-21 13:19 6330848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-02-23 07:41 . 2009-06-21 13:19 329048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 94712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-02-23 07:40 . 2009-06-21 13:18 961984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 835312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-23 07:40 . 2009-06-21 13:18 842992 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-23 07:40 . 2009-06-21 13:18 1593320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-23 07:40 . 2009-06-21 13:18 815184 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-23 07:40 . 2009-06-21 13:18 1229232 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-23 07:39 . 2009-06-21 13:13 -------- d-----w- c:\program files\Lavasoft
2010-02-20 21:42 . 2009-06-06 05:35 -------- d-----w- c:\program files\REAPER
2010-02-11 05:29 . 2010-02-11 05:26 102262 ----a-w- c:\windows\hpoins05.dat
2010-02-05 00:28 . 2009-09-27 13:19 3803208 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-04 15:53 . 2009-06-21 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-27 18:28 . 2009-06-21 13:19 8 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-21 13:13 . 2009-09-15 23:53 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 14:10 . 2010-01-19 22:49 -------- d-----w- c:\program files\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\Haali
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\ffdshow
2009-12-31 16:14 . 2006-02-28 12:00 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2006-02-28 12:00 662016 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2009-04-08 02:16 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2006-02-28 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 14:41 . 2006-02-28 12:00 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"SetDefaultMIDI"="MIDIDef.exe" [2009-03-04 28672]
"Creative Software Update"="c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe" [2007-01-04 481200]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"CTHelper"="CTHELPER.EXE" [2009-03-04 19456]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-02-23 815184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"AVGIDS"="c:\program files\AVG\Identity Protection\agent\bin\AVGIDSUI.exe" [2009-10-09 1640968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-8 809488]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-10-31 14:51 57344 ------w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 20:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
2008-05-15 21:45 356864 ----a-w- c:\windows\system32\M-AudioTaskBarIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-02-21 05:36 1217872 ----a-w- c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-01-05 12:56 2002160 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\stinker123105\\counter-strike\\hl.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"9510:TCP"= 9510:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"3696:TCP"= 3696:TCP:Services

R0 AVGIDSErHr;AVGIDSErHr;c:\windows\system32\drivers\AVGIDSEH.sys [10/9/2009 3:02 PM 25608]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/21/2009 8:19 AM 64288]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys --> c:\windows\system32\drivers\pxscan.sys [?]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys --> c:\windows\system32\drivers\pxsec.sys [?]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [4/7/2009 9:33 PM 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/21/2010 9:22 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/21/2010 9:22 PM 360584]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [4/7/2009 9:31 PM 13696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2/21/2010 9:21 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2/21/2010 9:21 PM 285392]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/15/2009 6:52 PM 54752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 10:52 AM 1229232]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [4/8/2009 9:12 PM 10384]
R3 AVGIDSDriver;AVGIDSDriver;c:\program files\AVG\Identity Protection\agent\driver\platform_XP\AVGIDSDriver.sys [10/9/2009 3:02 PM 122376]
R3 AVGIDSFilter;AVGIDSFilter;c:\program files\AVG\Identity Protection\agent\driver\platform_XP\AVGIDSFilter.sys [10/9/2009 3:02 PM 30216]
R3 AVGIDSShim;AVGIDSShim;c:\program files\AVG\Identity Protection\agent\driver\platform_XP\AVGIDSShim.sys [10/9/2009 3:02 PM 25736]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
R3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);c:\windows\system32\drivers\mausbft.sys [6/1/2009 6:37 PM 132096]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe [10/9/2009 3:02 PM 5832712]
S2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\AVG\Identity Protection\agent\Bin\AVGIDSWatcher.exe [10/9/2009 3:02 PM 559624]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [6/1/2009 5:38 PM 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [7/1/2002 6:30 PM 95232]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
S3 KProcWatch;KProcWatch;c:\windows\system32\drivers\KProcWatch.sys [2/24/2010 6:29 PM 8576]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - PXSEC
*Deregistered* - CSIScanner
.
Contents of the 'Scheduled Tasks' folder

2010-02-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 07:40]

2010-02-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.fleaflicker.com/nfl
uInternet Settings,ProxyOverride = *.local
IE: {{809132AF-89D2-4d52-AA03-AB4E35BBDC5B} - c:\program files\PokerStars.TEST\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\Sean Canfield\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

AddRemove-Vivitar Experience Image Manager - c:\program files\Vivitar Experience Image Manager\uninstaller.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-26 19:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x89891C28]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf763bfc3
\Driver\ACPI -> 0x89891c28
\Driver\atapi -> atapi.sys @ 0xf74c67b4
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0084
ParseProcedure -> ntoskrnl.exe @ 0x8056f07e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0084
ParseProcedure -> ntoskrnl.exe @ 0x8056f07e
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x89771640
PacketIndicateHandler -> NDIS.sys @ 0xf7461b21
SendHandler -> NDIS.sys @ 0xf743f87b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0995C69A
malicious code @ sector 0x0995C69D !
PE file found in sector at 0x0995C6B3 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2010-02-26 19:40:32
ComboFix-quarantined-files.txt 2010-02-27 00:40

Pre-Run: 42,077,364,224 bytes free
Post-Run: 42,106,740,736 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 3E230C6CB542F43D22F4DE3A62834998


Yea i ran it, but i never did anything else with it.

Edited by Shocker1245, 27 February 2010 - 04:12 PM.


#7 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:05:06 PM

Posted 27 February 2010 - 04:30 PM

Download and save HelpAsst_mebroot_fix.exe
Double click to run the tool.
Wait for it to finish then go to the next step.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

CODE
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"=-
"52344:TCP"=-
"2479:TCP"=-
"9510:TCP"=-
"3389:TCP"=-
"3696:TCP"=-
MBR::


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

unite.jpg


#8 Shocker1245

Shocker1245
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 27 February 2010 - 05:11 PM

ComboFix 10-02-27.04 - Sean Canfield 02/27/2010 16:52:51.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1372 [GMT -5:00]
Running from: c:\documents and settings\Sean Canfield\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sean Canfield\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.

2010-02-27 05:08 . 2010-02-27 05:16 -------- d-----w- C:\rsit
2010-02-25 00:33 . 2010-02-25 00:33 -------- d-----w- c:\program files\Trend Micro
2010-02-24 23:29 . 2010-02-24 23:29 -------- d-----w- c:\program files\HiddenFinder
2010-02-24 23:29 . 2006-02-24 03:03 8576 ----a-w- c:\windows\system32\drivers\KProcWatch.sys
2010-02-24 23:12 . 2010-02-27 04:58 0 ----a-w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\prvlcl.dat
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-24 21:33 . 2010-02-24 21:33 52224 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-24 21:33 . 2010-02-24 21:33 117760 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com
2010-02-24 20:22 . 2009-11-25 18:01 1230080 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-02-24 20:20 . 2010-02-24 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2010-02-24 18:57 . 2010-02-24 18:58 39451456 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative Sound Blaster Audigy series driver 2.18.0011__\SBAX_PCDRV_LB_2_18_0011.exe
2010-02-24 18:55 . 2010-02-24 18:56 37634288 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.26.02__\CMS5_PCAPP_LB_5_26_02.exe
2010-02-24 18:55 . 2010-02-24 18:55 12907880 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative WaveStudio 7.12.00__\WAVESTD_PCAPP_LB_7_12_00.exe
2010-02-24 18:54 . 2010-02-24 18:55 10995608 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative CD Burner Plugin 5.01.44 for Creative MediaSource 5 Player_Organizer__\CMS5_BRNR_PCAPP_LB_5_01_44.exe
2010-02-24 18:52 . 2010-02-24 18:52 152576 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-24 18:52 . 2010-02-24 18:52 79488 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 598368 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-02-23 07:41 . 2010-02-23 07:41 566608 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-02-23 07:41 . 2010-02-23 07:41 221408 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-02-23 07:41 . 2010-02-23 07:41 1230160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-23 07:41 . 2010-02-23 07:41 247120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-23 07:40 . 2010-02-23 07:40 17480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-23 07:39 . 2010-02-23 07:39 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-23 07:39 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-22 02:25 . 2010-02-22 02:25 -------- d-----w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\AVG Security Toolbar
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- C:\$AVG
2010-02-22 02:22 . 2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-22 02:22 . 2010-02-22 02:22 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-22 02:22 . 2010-02-22 02:22 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-22 02:22 . 2010-02-22 02:22 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-22 02:22 . 2010-02-26 22:43 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-22 02:21 . 2010-02-24 20:21 -------- d-----w- c:\program files\AVG
2010-02-22 02:21 . 2010-02-22 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-22 02:21 . 2010-02-22 03:16 -------- d-----w- c:\windows\SxsCaPendDel
2010-02-22 01:15 . 2010-02-22 01:54 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Disk Cleaner
2010-02-11 05:29 . 2010-02-11 05:29 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-02-11 05:27 . 2004-09-29 17:15 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2010-02-11 05:27 . 2004-09-29 17:14 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2010-02-11 05:27 . 2004-09-29 17:12 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2010-02-11 05:27 . 2004-09-29 17:09 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2010-02-11 05:27 . 2004-09-29 17:09 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2010-02-11 05:27 . 2004-09-29 17:08 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2010-02-11 05:27 . 1998-10-29 21:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-02-11 05:27 . 2010-02-11 05:27 -------- d-----w- c:\program files\HP
2010-02-11 05:04 . 2004-08-04 04:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-02-11 05:04 . 2004-08-04 04:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 02:54 . 2009-07-04 03:03 -------- d-----w- c:\program files\Steam
2010-02-24 21:32 . 2009-04-08 04:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-24 18:59 . 2009-04-08 02:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-24 18:53 . 2009-06-15 01:24 -------- d-----w- c:\program files\Java
2010-02-23 07:41 . 2009-06-21 13:19 884176 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-02-23 07:41 . 2009-06-21 13:28 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 393896 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-02-23 07:41 . 2009-06-21 13:19 211064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-02-23 07:41 . 2009-12-06 00:27 562272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-02-23 07:41 . 2009-06-21 13:19 390320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-23 07:41 . 2009-06-21 13:19 167312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-02-23 07:41 . 2009-06-21 13:19 6330848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-02-23 07:41 . 2009-06-21 13:19 329048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 94712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-02-23 07:40 . 2009-06-21 13:18 961984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 835312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-23 07:40 . 2009-06-21 13:18 842992 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-23 07:40 . 2009-06-21 13:18 1593320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-23 07:40 . 2009-06-21 13:18 815184 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-23 07:40 . 2009-06-21 13:18 1229232 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-23 07:39 . 2009-06-21 13:13 -------- d-----w- c:\program files\Lavasoft
2010-02-20 21:42 . 2009-06-06 05:35 -------- d-----w- c:\program files\REAPER
2010-02-11 05:29 . 2010-02-11 05:26 102262 ----a-w- c:\windows\hpoins05.dat
2010-02-05 00:28 . 2009-09-27 13:19 3803208 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-04 15:53 . 2009-06-21 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-27 18:28 . 2009-06-21 13:19 8 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-21 13:13 . 2009-09-15 23:53 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 14:10 . 2010-01-19 22:49 -------- d-----w- c:\program files\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\Haali
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\ffdshow
2009-12-31 16:14 . 2006-02-28 12:00 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2006-02-28 12:00 662016 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2009-04-08 02:16 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2006-02-28 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 14:41 . 2006-02-28 12:00 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"SetDefaultMIDI"="MIDIDef.exe" [2009-03-04 28672]
"Creative Software Update"="c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe" [2007-01-04 481200]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"CTHelper"="CTHELPER.EXE" [2009-03-04 19456]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-02-23 815184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-8 809488]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-10-31 14:51 57344 ------w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 20:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
2008-05-15 21:45 356864 ----a-w- c:\windows\system32\M-AudioTaskBarIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-02-21 05:36 1217872 ----a-w- c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-01-05 12:56 2002160 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\stinker123105\\counter-strike\\hl.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3930:TCP"= 3930:TCP:Services
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3246:TCP"= 3246:TCP:Services

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/21/2009 8:19 AM 64288]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [4/7/2009 9:33 PM 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/21/2010 9:22 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/21/2010 9:22 PM 360584]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [4/7/2009 9:31 PM 13696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2/21/2010 9:21 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2/21/2010 9:21 PM 285392]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/15/2009 6:52 PM 54752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 10:52 AM 1229232]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [4/8/2009 9:12 PM 10384]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
R3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);c:\windows\system32\drivers\mausbft.sys [6/1/2009 6:37 PM 132096]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [6/1/2009 5:38 PM 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [7/1/2002 6:30 PM 95232]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
S3 KProcWatch;KProcWatch;c:\windows\system32\drivers\KProcWatch.sys [2/24/2010 6:29 PM 8576]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2010-02-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 07:40]

2010-02-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.fleaflicker.com/nfl
uInternet Settings,ProxyOverride = *.local
IE: {{809132AF-89D2-4d52-AA03-AB4E35BBDC5B} - c:\program files\PokerStars.TEST\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\Sean Canfield\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-27 17:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x89898E70]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf763bfc3
\Driver\ACPI -> 0x89898e70
\Driver\atapi -> atapi.sys @ 0xf74c67b4
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0084
ParseProcedure -> ntoskrnl.exe @ 0x8056f07e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0084
ParseProcedure -> ntoskrnl.exe @ 0x8056f07e
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x8967d640
PacketIndicateHandler -> NDIS.sys @ 0xf744fb21
SendHandler -> NDIS.sys @ 0xf742d87b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0995C69A
malicious code @ sector 0x0995C69D !
PE file found in sector at 0x0995C6B3 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(3680)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2010-02-27 17:09:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-27 22:09
ComboFix2.txt 2010-02-27 00:40

Pre-Run: 42,496,942,080 bytes free
Post-Run: 42,472,427,520 bytes free

- - End Of File - - 248ECA4E7EA9AFCB64A810B72141F046

#9 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:05:06 PM

Posted 27 February 2010 - 05:56 PM

Reboot your computer.

On the black screen with the startup menu select Microsoft Windows Recovery Console.

When the recovery console has started there is a menu where your asked to select which windows installation you want to login to, usually there is only one:

1. C:\WINDOWS

select the number and press Enter

If it ask you to type the administrator password, do so then press Enter.

It should then come up with C:\WINDOWS>

Now type in the following line, then press Enter.

fixmbr

You will then get a warning about running fixmbr, press Y then Enter.

Then type EXIT and press Enter to reboot the machine.



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

CODE
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3930:TCP"=-
"65533:TCP"=-
"52344:TCP"=-
"2479:TCP"=-
"3246:TCP"=-


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

unite.jpg


#10 Shocker1245

Shocker1245
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 27 February 2010 - 08:30 PM

Hey syler! I followed those instructions to a T. However upon exit of the windows recovery console, my computer didnt fully reboot, got stuck on a black screen for a while and i had to just do a power shut down, LOL. Hope this is ok! Did start back up fine the 2nd time. Anyhow here is the combofix. I gotta run out for a few, probably be back around 12/est. I will check back in see ya got back to this or not, thanks again!



ComboFix 10-02-27.04 - Sean Canfield 02/27/2010 20:18:33.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1433 [GMT -5:00]
Running from: c:\documents and settings\Sean Canfield\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sean Canfield\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-01-28 to 2010-02-28 )))))))))))))))))))))))))))))))
.

2010-02-27 22:12 . 2010-02-27 22:14 -------- d-----w- c:\documents and settings\HelpAssistant
2010-02-27 05:08 . 2010-02-27 05:16 -------- d-----w- C:\rsit
2010-02-25 00:33 . 2010-02-25 00:33 -------- d-----w- c:\program files\Trend Micro
2010-02-24 23:29 . 2010-02-24 23:29 -------- d-----w- c:\program files\HiddenFinder
2010-02-24 23:29 . 2006-02-24 03:03 8576 ----a-w- c:\windows\system32\drivers\KProcWatch.sys
2010-02-24 23:12 . 2010-02-27 22:58 0 ----a-w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\prvlcl.dat
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-24 21:33 . 2010-02-24 21:33 52224 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-24 21:33 . 2010-02-24 21:33 117760 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com
2010-02-24 20:22 . 2009-11-25 18:01 1230080 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-02-24 20:20 . 2010-02-24 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2010-02-24 18:57 . 2010-02-24 18:58 39451456 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative Sound Blaster Audigy series driver 2.18.0011__\SBAX_PCDRV_LB_2_18_0011.exe
2010-02-24 18:55 . 2010-02-24 18:56 37634288 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.26.02__\CMS5_PCAPP_LB_5_26_02.exe
2010-02-24 18:55 . 2010-02-24 18:55 12907880 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative WaveStudio 7.12.00__\WAVESTD_PCAPP_LB_7_12_00.exe
2010-02-24 18:54 . 2010-02-24 18:55 10995608 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative CD Burner Plugin 5.01.44 for Creative MediaSource 5 Player_Organizer__\CMS5_BRNR_PCAPP_LB_5_01_44.exe
2010-02-24 18:52 . 2010-02-24 18:52 152576 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-24 18:52 . 2010-02-24 18:52 79488 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 598368 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-02-23 07:41 . 2010-02-23 07:41 566608 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-02-23 07:41 . 2010-02-23 07:41 221408 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-02-23 07:41 . 2010-02-23 07:41 1230160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-23 07:41 . 2010-02-23 07:41 247120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-23 07:40 . 2010-02-23 07:40 17480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-23 07:39 . 2010-02-23 07:39 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-23 07:39 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-22 02:25 . 2010-02-22 02:25 -------- d-----w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\AVG Security Toolbar
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- C:\$AVG
2010-02-22 02:22 . 2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-22 02:22 . 2010-02-22 02:22 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-22 02:22 . 2010-02-22 02:22 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-22 02:22 . 2010-02-22 02:22 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-22 02:22 . 2010-02-27 23:56 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-22 02:21 . 2010-02-24 20:21 -------- d-----w- c:\program files\AVG
2010-02-22 02:21 . 2010-02-22 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-22 02:21 . 2010-02-22 03:16 -------- d-----w- c:\windows\SxsCaPendDel
2010-02-22 01:15 . 2010-02-22 01:54 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Disk Cleaner
2010-02-11 05:29 . 2010-02-11 05:29 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-02-11 05:27 . 2004-09-29 17:15 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2010-02-11 05:27 . 2004-09-29 17:14 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2010-02-11 05:27 . 2004-09-29 17:12 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2010-02-11 05:27 . 2004-09-29 17:09 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2010-02-11 05:27 . 2004-09-29 17:09 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2010-02-11 05:27 . 2004-09-29 17:08 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2010-02-11 05:27 . 1998-10-29 21:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-02-11 05:27 . 2010-02-11 05:27 -------- d-----w- c:\program files\HP
2010-02-11 05:04 . 2004-08-04 04:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-02-11 05:04 . 2004-08-04 04:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 02:54 . 2009-07-04 03:03 -------- d-----w- c:\program files\Steam
2010-02-24 21:32 . 2009-04-08 04:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-24 18:59 . 2009-04-08 02:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-24 18:53 . 2009-06-15 01:24 -------- d-----w- c:\program files\Java
2010-02-23 07:41 . 2009-06-21 13:19 884176 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-02-23 07:41 . 2009-06-21 13:28 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 393896 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-02-23 07:41 . 2009-06-21 13:19 211064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-02-23 07:41 . 2009-12-06 00:27 562272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-02-23 07:41 . 2009-06-21 13:19 390320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-23 07:41 . 2009-06-21 13:19 167312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-02-23 07:41 . 2009-06-21 13:19 6330848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-02-23 07:41 . 2009-06-21 13:19 329048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 94712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-02-23 07:40 . 2009-06-21 13:18 961984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 835312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-23 07:40 . 2009-06-21 13:18 842992 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-23 07:40 . 2009-06-21 13:18 1593320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-23 07:40 . 2009-06-21 13:18 815184 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-23 07:40 . 2009-06-21 13:18 1229232 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-23 07:39 . 2009-06-21 13:13 -------- d-----w- c:\program files\Lavasoft
2010-02-20 21:42 . 2009-06-06 05:35 -------- d-----w- c:\program files\REAPER
2010-02-11 05:29 . 2010-02-11 05:26 102262 ----a-w- c:\windows\hpoins05.dat
2010-02-05 00:28 . 2009-09-27 13:19 3803208 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-04 15:53 . 2009-06-21 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-27 18:28 . 2009-06-21 13:19 8 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-21 13:13 . 2009-09-15 23:53 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 14:10 . 2010-01-19 22:49 -------- d-----w- c:\program files\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\Haali
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\ffdshow
2009-12-31 16:14 . 2006-02-28 12:00 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2006-02-28 12:00 662016 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2009-04-08 02:16 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2006-02-28 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 14:41 . 2006-02-28 12:00 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-02-27_00.38.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-28 01:10 . 2010-02-28 01:10 16384 c:\windows\Temp\Perflib_Perfdata_6d4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"SetDefaultMIDI"="MIDIDef.exe" [2009-03-04 28672]
"Creative Software Update"="c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe" [2007-01-04 481200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"CTHelper"="CTHELPER.EXE" [2009-03-04 19456]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-02-23 815184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-8 809488]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-10-31 14:51 57344 ------w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 20:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
2008-05-15 21:45 356864 ----a-w- c:\windows\system32\M-AudioTaskBarIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-02-21 05:36 1217872 ----a-w- c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-01-05 12:56 2002160 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\stinker123105\\counter-strike\\hl.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/21/2009 8:19 AM 64288]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [4/7/2009 9:33 PM 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/21/2010 9:22 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/21/2010 9:22 PM 360584]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [4/7/2009 9:31 PM 13696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2/21/2010 9:21 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2/21/2010 9:21 PM 285392]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/15/2009 6:52 PM 54752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 10:52 AM 1229232]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [4/8/2009 9:12 PM 10384]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
R3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);c:\windows\system32\drivers\mausbft.sys [6/1/2009 6:37 PM 132096]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [6/1/2009 5:38 PM 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [7/1/2002 6:30 PM 95232]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
S3 KProcWatch;KProcWatch;c:\windows\system32\drivers\KProcWatch.sys [2/24/2010 6:29 PM 8576]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2010-02-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 07:40]

2010-02-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.fleaflicker.com/nfl
uInternet Settings,ProxyOverride = *.local
IE: {{809132AF-89D2-4d52-AA03-AB4E35BBDC5B} - c:\program files\PokerStars.TEST\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\Sean Canfield\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-27 20:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(680)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2204)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2010-02-27 20:25:54
ComboFix-quarantined-files.txt 2010-02-28 01:25
ComboFix2.txt 2010-02-27 22:09
ComboFix3.txt 2010-02-27 00:40

Pre-Run: 42,285,813,760 bytes free
Post-Run: 42,251,792,384 bytes free

- - End Of File - - 4EAF1AB52694EA910763BE0643496404

#11 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:05:06 PM

Posted 27 February 2010 - 09:07 PM

Hi Shocker1245,

That's no problem it loos like it went ok smile.gif

Please download and run http://noahdfear.net/downloads/termsrv.exe
This will not take long to complete and no other action is required.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

CODE
Folder::
c:\documents and settings\HelpAssistant
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"=-


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Please download Malwarebytes' Anti-Malware from Here

Note: If you already have Malwarebytes' Anti-Malware, just update then run it.
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan (the scan may take some time to finish, so please be patient).
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply .
Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Then please post back here with the following logs:
  • Combofix.txt
  • MBAM log

Thanks

unite.jpg


#12 Shocker1245

Shocker1245
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 28 February 2010 - 12:49 AM

ComboFix 10-02-27.04 - Sean Canfield 02/28/2010 0:21.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1436 [GMT -5:00]
Running from: c:\documents and settings\Sean Canfield\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sean Canfield\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HelpAssistant
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\AdobeCMapFnt09.lst
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\AdobeSysFnt09.lst
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\JavaScripts\glob.js
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\JavaScripts\glob.settings.js
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\Security\addressbook.acrodata
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\SharedDataEvents
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\TMDocs.sav
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\TMGrpPrm.sav
c:\documents and settings\HelpAssistant\Application Data\Adobe\Acrobat\9.0\UserCache.bin
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\077BA3FD3A24318B67B13F8297375C8DF03582D8.heu
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\077BA3FD3A24318B67B13F8297375C8DF03582D8.swz
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.heu
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.swz
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\1C04C61346A1FA3139A37D860ED92632AA13DECF.heu
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\1C04C61346A1FA3139A37D860ED92632AA13DECF.swz
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\6557145DE8B1B668BC50FD0350F191AC33E0C33D.heu
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\6557145DE8B1B668BC50FD0350F191AC33E0C33D.swz
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\AF07B46903A6C5D87A24725CB7D50DE352A0383C.heu
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\AF07B46903A6C5D87A24725CB7D50DE352A0383C.swz
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\cacheSize.txt
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\F7536EF0D78A77B889EEBE98BF96BA5321A1FDE0.heu
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\F7536EF0D78A77B889EEBE98BF96BA5321A1FDE0.swz
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\FF56DCA4C4D6043F3D639EFF51BF9A2934B7456B.heu
c:\documents and settings\HelpAssistant\Application Data\Adobe\Flash Player\AssetCache\6YCS2C8H\FF56DCA4C4D6043F3D639EFF51BF9A2934B7456B.swz
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\iTunes\CD Info.cidb
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\iTunes\iPod Updater Logs\iPodUpdater 1.log
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\iTunes\iPod Updater Logs\iPodUpdater.log
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\iTunes\iTunesPrefs.xml
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Lockdown\02acf81b4a6939d3a6d4dbd455d24639e83872b9.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Lockdown\0952be03aec10865954f37c18c3fd73f195c0ba2.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Lockdown\3ca5a07291a36e6c117316cd302d01e1865757d5.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\CrashReporter\MobileDevice\Jim's Ipod\Stackshot_2009-05-26-064738_Jim-s-Ipod.log
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\CrashReporter\MobileDevice\Sean Canfields iPod\mediaserverd_2009-07-25-222325_iPod-touch.crash
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\CrashReporter\MobileDevice\Sean Canfields iPod\mediaserverd_2009-07-25-222335_iPod-touch.crash
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\CrashReporter\MobileDevice\Sean Canfields iPod\Panics\2009-07-25-222855.panic.crash
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\CrashReporter\MobileDevice\Sean Canfields iPod\ResetCounter.crash
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\CrashReporter\MobileDevice\Sean Canfields iPod\SpringBoard_2009-07-25-222520_iPod-touch.crash
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\CrashReporter\MobileDevice\Sean Canfields iPod\SpringBoard_2009-07-25-222722_iPod-touch.crash
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\DeviceLink\MDCrashReportTool.exe.00.log
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Logs\MobileSync\AppleMobileBackup.exe.00.log
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\06c3464b4968eebebf1427b92e04f9eeecc8bad7.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\06c3464b4968eebebf1427b92e04f9eeecc8bad7.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0aa0f6c159f0bc74d03d1bb93633b9c534c74e66.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0aa0f6c159f0bc74d03d1bb93633b9c534c74e66.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0b68edc697a550c9b977b77cd012fa9a0557dfcb.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0b68edc697a550c9b977b77cd012fa9a0557dfcb.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0dc926a1810f7aee4e8f38793ed788701f93bf9d.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0dc926a1810f7aee4e8f38793ed788701f93bf9d.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0fb54654b97099d34461570fab859a2b0570ed1f.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\0fb54654b97099d34461570fab859a2b0570ed1f.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\1107041dfe997fed991d9a5421788bd94f94f940.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\1107041dfe997fed991d9a5421788bd94f94f940.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\1d6740792a2b845f4c1e6220c43906d7f0afe8ab.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\1d6740792a2b845f4c1e6220c43906d7f0afe8ab.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\1dd07f2fbb1169bed93c21047ca5616371ea4a04.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\1dd07f2fbb1169bed93c21047ca5616371ea4a04.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2041457d5fe04d39d0ab481178355df6781e6858.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2041457d5fe04d39d0ab481178355df6781e6858.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\251bbb305b3ace4faee86a24fc9e248a66f67121.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\251bbb305b3ace4faee86a24fc9e248a66f67121.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2b70b844834321b9f4e9760531ce76db7819afd3.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2b70b844834321b9f4e9760531ce76db7819afd3.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2ee4bd1058b567873e1caa0c760216e3e266d07c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2ee4bd1058b567873e1caa0c760216e3e266d07c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2fdcd655b0ad22cb9c4caf388f44fe6185f9556c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\2fdcd655b0ad22cb9c4caf388f44fe6185f9556c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\31bb7ba8914766d4ba40d6dfb6113c8b614be442.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\31bb7ba8914766d4ba40d6dfb6113c8b614be442.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\34f7f8423d8f77bc812dd8d70f84c33a5caacbe8.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\34f7f8423d8f77bc812dd8d70f84c33a5caacbe8.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\360c307e7fd202b37f1c03e9d49e6b515850a894.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\360c307e7fd202b37f1c03e9d49e6b515850a894.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\36eb88809db6179b2fda77099cefce12792f0889.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\36eb88809db6179b2fda77099cefce12792f0889.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\38e53366ec982eb8bedcfc4df67c27cf305c4774.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\38e53366ec982eb8bedcfc4df67c27cf305c4774.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\3c54cb1e89c54d3c09664c5b8311c0a00f9ea06e.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\3c54cb1e89c54d3c09664c5b8311c0a00f9ea06e.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\3d0d7e5fb2ce288813306e4d4636395e047a3d28.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\3d0d7e5fb2ce288813306e4d4636395e047a3d28.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\4f6a6e175b8b087c833905bcc4e304d1389ae7b4.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\4f6a6e175b8b087c833905bcc4e304d1389ae7b4.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\52c03edfc4da9eba398684afb69ba503a2709667.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\52c03edfc4da9eba398684afb69ba503a2709667.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\57abe97189047a814cc335cde2d720f619672c74.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\57abe97189047a814cc335cde2d720f619672c74.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\592cafbdd50dac53453f5672f325ff37d1843d29.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\592cafbdd50dac53453f5672f325ff37d1843d29.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\59445c4fae86445d6326f08d3c3bcf7b60ac54d3.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\59445c4fae86445d6326f08d3c3bcf7b60ac54d3.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\5cfa9db121949c3bf3b889caefc8d5ba766dbd09.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\5cfa9db121949c3bf3b889caefc8d5ba766dbd09.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\5d04e8e7049cdf56df0bf824820cddb1db08a8e2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\5d04e8e7049cdf56df0bf824820cddb1db08a8e2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\61c8b15a0110ab17d1b7467c3a042eb1458426c6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\61c8b15a0110ab17d1b7467c3a042eb1458426c6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\631e60f16fdb96ac2dea025ba07e858a3095efa6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\631e60f16fdb96ac2dea025ba07e858a3095efa6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\63e928471d296cb47a6ffb5343b40b90a0e5d92b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\63e928471d296cb47a6ffb5343b40b90a0e5d92b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\64852404d8347fafdc95c5d68f7629995baef161.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\64852404d8347fafdc95c5d68f7629995baef161.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\662bc19b13aecef58a7e855d0316e4cf61e2642b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\662bc19b13aecef58a7e855d0316e4cf61e2642b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\691fe25b949227d26b6c59432bf108f6e3ec54ec.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\691fe25b949227d26b6c59432bf108f6e3ec54ec.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\7354d391d6afddc09cc9fd7c1196aec38ba29e7c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\7354d391d6afddc09cc9fd7c1196aec38ba29e7c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\740b7eaf93d6ea5d305e88bb349c8e9643f48c3b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\740b7eaf93d6ea5d305e88bb349c8e9643f48c3b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\76fb3c685d422334fd25d9777d64db74af7cb25a.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\76fb3c685d422334fd25d9777d64db74af7cb25a.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\8acbff93b5b72c39dd26bcc49ea7771b3e9f3c6f.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\8acbff93b5b72c39dd26bcc49ea7771b3e9f3c6f.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\925f72f76d88b512381e984df3f6bdc428044418.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\925f72f76d88b512381e984df3f6bdc428044418.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\9281049ff1d27f1129c0bd17a95c863350e6f5a2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\9281049ff1d27f1129c0bd17a95c863350e6f5a2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\9c6c86c6f16c807065b0d3d1cb560ee71685a207.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\9c6c86c6f16c807065b0d3d1cb560ee71685a207.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\9fc7ddb3fd4ac6012b3ac27de43a197844ffca2e.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\9fc7ddb3fd4ac6012b3ac27de43a197844ffca2e.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\a30335a2c0f0316c9610d868a527b2ade1911542.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\a30335a2c0f0316c9610d868a527b2ade1911542.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\a5cfd10e00e1c8c6e7bb2edd0b6cd0911daf2e70.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\a5cfd10e00e1c8c6e7bb2edd0b6cd0911daf2e70.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\a6cc3787332f50a2b824b1783fe7a7314cb33aee.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\a6cc3787332f50a2b824b1783fe7a7314cb33aee.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\b5873ebf0d585cced2c71a8cf07697588d245c4b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\b5873ebf0d585cced2c71a8cf07697588d245c4b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\bd2931080a29e96b5428097da5feda30db7e8b59.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\bd2931080a29e96b5428097da5feda30db7e8b59.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\bd38afa30b5a43c146db02a46ee11d82cdc817fe.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\bd38afa30b5a43c146db02a46ee11d82cdc817fe.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ca8bff963333eecdb5063359d068b94daf67ac88.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ca8bff963333eecdb5063359d068b94daf67ac88.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ccdd6b3bbdef4fe38688080ca1b918397b0e2e07.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ccdd6b3bbdef4fe38688080ca1b918397b0e2e07.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\d31765340d5c7bbd466a97d53fba619df2c4e6ba.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\d31765340d5c7bbd466a97d53fba619df2c4e6ba.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\d351344f01cbe4900c9e981d1fb7ea5614e7c2e5.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\d351344f01cbe4900c9e981d1fb7ea5614e7c2e5.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\d67ab43d1c47dd60d7cf3a7a3939775f6938a8ef.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\d67ab43d1c47dd60d7cf3a7a3939775f6938a8ef.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\df5d54974eda6ca619f981969dbb0ce8131bc479.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\df5d54974eda6ca619f981969dbb0ce8131bc479.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\e452abcdc1c5829fc16884318df4b8b14d3532a2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\e452abcdc1c5829fc16884318df4b8b14d3532a2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ec01c34e8a0d76bc380d042620f415fd57102fd3.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ec01c34e8a0d76bc380d042620f415fd57102fd3.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\f30d6ef41c65177e0d949cbbefa7e114bb39a212.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\f30d6ef41c65177e0d949cbbefa7e114bb39a212.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\f339262796d9a856f2d35c2e74f8f1217f58cf30.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\f339262796d9a856f2d35c2e74f8f1217f58cf30.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\f82e1283590af44ac7ee545dbca6dcd014267e32.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\f82e1283590af44ac7ee545dbca6dcd014267e32.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ff1324e6b949111b2fb449ecddb50c89c3699a78.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\ff1324e6b949111b2fb449ecddb50c89c3699a78.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\Info.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\Manifest.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\02acf81b4a6939d3a6d4dbd455d24639e83872b9\Status.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\0b68edc697a550c9b977b77cd012fa9a0557dfcb.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\0b68edc697a550c9b977b77cd012fa9a0557dfcb.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\0dc926a1810f7aee4e8f38793ed788701f93bf9d.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\0dc926a1810f7aee4e8f38793ed788701f93bf9d.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\0fb54654b97099d34461570fab859a2b0570ed1f.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\0fb54654b97099d34461570fab859a2b0570ed1f.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\1107041dfe997fed991d9a5421788bd94f94f940.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\1107041dfe997fed991d9a5421788bd94f94f940.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\1d6740792a2b845f4c1e6220c43906d7f0afe8ab.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\1d6740792a2b845f4c1e6220c43906d7f0afe8ab.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\1dd07f2fbb1169bed93c21047ca5616371ea4a04.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\1dd07f2fbb1169bed93c21047ca5616371ea4a04.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2041457d5fe04d39d0ab481178355df6781e6858.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2041457d5fe04d39d0ab481178355df6781e6858.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2274fd59ee7553594a64822d08abccbf5b94df27.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2274fd59ee7553594a64822d08abccbf5b94df27.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\27faf6203f7890ea10834c8a95c38b87bb473a52.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\27faf6203f7890ea10834c8a95c38b87bb473a52.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2a747a5715b557b933cd5ca9c3adc7a40c4e14f8.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2a747a5715b557b933cd5ca9c3adc7a40c4e14f8.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2ee4bd1058b567873e1caa0c760216e3e266d07c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2ee4bd1058b567873e1caa0c760216e3e266d07c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2fdcd655b0ad22cb9c4caf388f44fe6185f9556c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\2fdcd655b0ad22cb9c4caf388f44fe6185f9556c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\31bb7ba8914766d4ba40d6dfb6113c8b614be442.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\31bb7ba8914766d4ba40d6dfb6113c8b614be442.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\34f7f8423d8f77bc812dd8d70f84c33a5caacbe8.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\34f7f8423d8f77bc812dd8d70f84c33a5caacbe8.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\36eb88809db6179b2fda77099cefce12792f0889.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\36eb88809db6179b2fda77099cefce12792f0889.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\3c54cb1e89c54d3c09664c5b8311c0a00f9ea06e.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\3c54cb1e89c54d3c09664c5b8311c0a00f9ea06e.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\3d0d7e5fb2ce288813306e4d4636395e047a3d28.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\3d0d7e5fb2ce288813306e4d4636395e047a3d28.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\4cc5d09bd38e7bd39bc7eea54ff6d04485b874bb.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\4cc5d09bd38e7bd39bc7eea54ff6d04485b874bb.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\4f6a6e175b8b087c833905bcc4e304d1389ae7b4.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\4f6a6e175b8b087c833905bcc4e304d1389ae7b4.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\57abe97189047a814cc335cde2d720f619672c74.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\57abe97189047a814cc335cde2d720f619672c74.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\592cafbdd50dac53453f5672f325ff37d1843d29.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\592cafbdd50dac53453f5672f325ff37d1843d29.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\59445c4fae86445d6326f08d3c3bcf7b60ac54d3.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\59445c4fae86445d6326f08d3c3bcf7b60ac54d3.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\5cfa9db121949c3bf3b889caefc8d5ba766dbd09.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\5cfa9db121949c3bf3b889caefc8d5ba766dbd09.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\5d04e8e7049cdf56df0bf824820cddb1db08a8e2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\5d04e8e7049cdf56df0bf824820cddb1db08a8e2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\61c8b15a0110ab17d1b7467c3a042eb1458426c6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\61c8b15a0110ab17d1b7467c3a042eb1458426c6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\631e60f16fdb96ac2dea025ba07e858a3095efa6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\631e60f16fdb96ac2dea025ba07e858a3095efa6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\63e928471d296cb47a6ffb5343b40b90a0e5d92b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\63e928471d296cb47a6ffb5343b40b90a0e5d92b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\64852404d8347fafdc95c5d68f7629995baef161.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\64852404d8347fafdc95c5d68f7629995baef161.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\662bc19b13aecef58a7e855d0316e4cf61e2642b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\662bc19b13aecef58a7e855d0316e4cf61e2642b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\691fe25b949227d26b6c59432bf108f6e3ec54ec.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\691fe25b949227d26b6c59432bf108f6e3ec54ec.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\7354d391d6afddc09cc9fd7c1196aec38ba29e7c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\7354d391d6afddc09cc9fd7c1196aec38ba29e7c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\76fb3c685d422334fd25d9777d64db74af7cb25a.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\76fb3c685d422334fd25d9777d64db74af7cb25a.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\81cf6abc45e4666a26ff7039a8fc9f25dd23cfbb.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\81cf6abc45e4666a26ff7039a8fc9f25dd23cfbb.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\8f9034a850966522bef09de44537eab0cd316803.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\8f9034a850966522bef09de44537eab0cd316803.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\9281049ff1d27f1129c0bd17a95c863350e6f5a2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\9281049ff1d27f1129c0bd17a95c863350e6f5a2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\998f870a4c2723567f3c5e4439ef8265844459b6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\998f870a4c2723567f3c5e4439ef8265844459b6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\a30335a2c0f0316c9610d868a527b2ade1911542.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\a30335a2c0f0316c9610d868a527b2ade1911542.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\b60c382887dfa562166f099f24797e55c12a94e4.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\b60c382887dfa562166f099f24797e55c12a94e4.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\b88b75bddaa69139b66d948b7cbd4f41d9dd416d.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\b88b75bddaa69139b66d948b7cbd4f41d9dd416d.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\bd38afa30b5a43c146db02a46ee11d82cdc817fe.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\bd38afa30b5a43c146db02a46ee11d82cdc817fe.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\c4ddc82c8bbf50dbd5802db9042344f6b8775346.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\c4ddc82c8bbf50dbd5802db9042344f6b8775346.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\d351344f01cbe4900c9e981d1fb7ea5614e7c2e5.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\d351344f01cbe4900c9e981d1fb7ea5614e7c2e5.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\d67ab43d1c47dd60d7cf3a7a3939775f6938a8ef.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\d67ab43d1c47dd60d7cf3a7a3939775f6938a8ef.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\e452abcdc1c5829fc16884318df4b8b14d3532a2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\e452abcdc1c5829fc16884318df4b8b14d3532a2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\f30d6ef41c65177e0d949cbbefa7e114bb39a212.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\f30d6ef41c65177e0d949cbbefa7e114bb39a212.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\f82e1283590af44ac7ee545dbca6dcd014267e32.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\f82e1283590af44ac7ee545dbca6dcd014267e32.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\ff1324e6b949111b2fb449ecddb50c89c3699a78.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\ff1324e6b949111b2fb449ecddb50c89c3699a78.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\Info.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\Manifest.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\0952be03aec10865954f37c18c3fd73f195c0ba2\Status.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\0b68edc697a550c9b977b77cd012fa9a0557dfcb.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\0b68edc697a550c9b977b77cd012fa9a0557dfcb.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\0dc926a1810f7aee4e8f38793ed788701f93bf9d.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\0dc926a1810f7aee4e8f38793ed788701f93bf9d.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\0fb54654b97099d34461570fab859a2b0570ed1f.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\0fb54654b97099d34461570fab859a2b0570ed1f.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\1107041dfe997fed991d9a5421788bd94f94f940.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\1107041dfe997fed991d9a5421788bd94f94f940.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\1d6740792a2b845f4c1e6220c43906d7f0afe8ab.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\1d6740792a2b845f4c1e6220c43906d7f0afe8ab.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\1dd07f2fbb1169bed93c21047ca5616371ea4a04.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\1dd07f2fbb1169bed93c21047ca5616371ea4a04.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2041457d5fe04d39d0ab481178355df6781e6858.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2041457d5fe04d39d0ab481178355df6781e6858.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2274fd59ee7553594a64822d08abccbf5b94df27.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2274fd59ee7553594a64822d08abccbf5b94df27.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\27faf6203f7890ea10834c8a95c38b87bb473a52.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\27faf6203f7890ea10834c8a95c38b87bb473a52.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2a747a5715b557b933cd5ca9c3adc7a40c4e14f8.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2a747a5715b557b933cd5ca9c3adc7a40c4e14f8.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2ee4bd1058b567873e1caa0c760216e3e266d07c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2ee4bd1058b567873e1caa0c760216e3e266d07c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2fdcd655b0ad22cb9c4caf388f44fe6185f9556c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\2fdcd655b0ad22cb9c4caf388f44fe6185f9556c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\31bb7ba8914766d4ba40d6dfb6113c8b614be442.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\31bb7ba8914766d4ba40d6dfb6113c8b614be442.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\34f7f8423d8f77bc812dd8d70f84c33a5caacbe8.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\34f7f8423d8f77bc812dd8d70f84c33a5caacbe8.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\360c307e7fd202b37f1c03e9d49e6b515850a894.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\360c307e7fd202b37f1c03e9d49e6b515850a894.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\36eb88809db6179b2fda77099cefce12792f0889.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\36eb88809db6179b2fda77099cefce12792f0889.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\3c54cb1e89c54d3c09664c5b8311c0a00f9ea06e.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\3c54cb1e89c54d3c09664c5b8311c0a00f9ea06e.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\3d0d7e5fb2ce288813306e4d4636395e047a3d28.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\3d0d7e5fb2ce288813306e4d4636395e047a3d28.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\4cc5d09bd38e7bd39bc7eea54ff6d04485b874bb.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\4cc5d09bd38e7bd39bc7eea54ff6d04485b874bb.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\4f6a6e175b8b087c833905bcc4e304d1389ae7b4.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\4f6a6e175b8b087c833905bcc4e304d1389ae7b4.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\57abe97189047a814cc335cde2d720f619672c74.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\57abe97189047a814cc335cde2d720f619672c74.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\592cafbdd50dac53453f5672f325ff37d1843d29.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\592cafbdd50dac53453f5672f325ff37d1843d29.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\59445c4fae86445d6326f08d3c3bcf7b60ac54d3.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\59445c4fae86445d6326f08d3c3bcf7b60ac54d3.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\5cfa9db121949c3bf3b889caefc8d5ba766dbd09.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\5cfa9db121949c3bf3b889caefc8d5ba766dbd09.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\5d04e8e7049cdf56df0bf824820cddb1db08a8e2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\5d04e8e7049cdf56df0bf824820cddb1db08a8e2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\61c8b15a0110ab17d1b7467c3a042eb1458426c6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\61c8b15a0110ab17d1b7467c3a042eb1458426c6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\631e60f16fdb96ac2dea025ba07e858a3095efa6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\631e60f16fdb96ac2dea025ba07e858a3095efa6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\63e928471d296cb47a6ffb5343b40b90a0e5d92b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\63e928471d296cb47a6ffb5343b40b90a0e5d92b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\64852404d8347fafdc95c5d68f7629995baef161.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\64852404d8347fafdc95c5d68f7629995baef161.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\662bc19b13aecef58a7e855d0316e4cf61e2642b.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\662bc19b13aecef58a7e855d0316e4cf61e2642b.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\691fe25b949227d26b6c59432bf108f6e3ec54ec.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\691fe25b949227d26b6c59432bf108f6e3ec54ec.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\7354d391d6afddc09cc9fd7c1196aec38ba29e7c.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\7354d391d6afddc09cc9fd7c1196aec38ba29e7c.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\76fb3c685d422334fd25d9777d64db74af7cb25a.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\76fb3c685d422334fd25d9777d64db74af7cb25a.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\81cf6abc45e4666a26ff7039a8fc9f25dd23cfbb.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\81cf6abc45e4666a26ff7039a8fc9f25dd23cfbb.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\8acbff93b5b72c39dd26bcc49ea7771b3e9f3c6f.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\8acbff93b5b72c39dd26bcc49ea7771b3e9f3c6f.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\8f9034a850966522bef09de44537eab0cd316803.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\8f9034a850966522bef09de44537eab0cd316803.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\9281049ff1d27f1129c0bd17a95c863350e6f5a2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\9281049ff1d27f1129c0bd17a95c863350e6f5a2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\998f870a4c2723567f3c5e4439ef8265844459b6.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\998f870a4c2723567f3c5e4439ef8265844459b6.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\9c6c86c6f16c807065b0d3d1cb560ee71685a207.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\9c6c86c6f16c807065b0d3d1cb560ee71685a207.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\9fc7ddb3fd4ac6012b3ac27de43a197844ffca2e.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\9fc7ddb3fd4ac6012b3ac27de43a197844ffca2e.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\a30335a2c0f0316c9610d868a527b2ade1911542.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\a30335a2c0f0316c9610d868a527b2ade1911542.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\a6cc3787332f50a2b824b1783fe7a7314cb33aee.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\a6cc3787332f50a2b824b1783fe7a7314cb33aee.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\b60c382887dfa562166f099f24797e55c12a94e4.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\b60c382887dfa562166f099f24797e55c12a94e4.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\b88b75bddaa69139b66d948b7cbd4f41d9dd416d.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\b88b75bddaa69139b66d948b7cbd4f41d9dd416d.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\bd38afa30b5a43c146db02a46ee11d82cdc817fe.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\bd38afa30b5a43c146db02a46ee11d82cdc817fe.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\c4ddc82c8bbf50dbd5802db9042344f6b8775346.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\c4ddc82c8bbf50dbd5802db9042344f6b8775346.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\d31765340d5c7bbd466a97d53fba619df2c4e6ba.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\d31765340d5c7bbd466a97d53fba619df2c4e6ba.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\d351344f01cbe4900c9e981d1fb7ea5614e7c2e5.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\d351344f01cbe4900c9e981d1fb7ea5614e7c2e5.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\d67ab43d1c47dd60d7cf3a7a3939775f6938a8ef.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\d67ab43d1c47dd60d7cf3a7a3939775f6938a8ef.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\e452abcdc1c5829fc16884318df4b8b14d3532a2.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\e452abcdc1c5829fc16884318df4b8b14d3532a2.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\eed5f3877bafdc40768e39f75ad11f3fdc185df3.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\eed5f3877bafdc40768e39f75ad11f3fdc185df3.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\f30d6ef41c65177e0d949cbbefa7e114bb39a212.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\f30d6ef41c65177e0d949cbbefa7e114bb39a212.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\f82e1283590af44ac7ee545dbca6dcd014267e32.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\f82e1283590af44ac7ee545dbca6dcd014267e32.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\ff1324e6b949111b2fb449ecddb50c89c3699a78.mddata
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\ff1324e6b949111b2fb449ecddb50c89c3699a78.mdinfo
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\Info.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\Manifest.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\MobileSync\Backup\3ca5a07291a36e6c117316cd302d01e1865757d5\Status.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Preferences\ByHost\com.apple.syncservices.{656c0fc0-23bf-11de-9fde-806d6172696f}.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\Preferences\com.apple.MobileDeviceCrashCopy.plist
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\admin.syncdb
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\cleanup.time
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\clientdata\0bca7fc8b7117fa83080cfd5e17e09bd83fa016d\clientname.txt
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\clientdata\352340fc1280163e9adf24c655737a5d9bf4c5ed\clientname.txt
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\clientdata\ebf0f86d30f0f15eb295a85fd1c590756e81420a\clientname.txt
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\data.syncdb
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\data.version
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\schemas.adminarchive
c:\documents and settings\HelpAssistant\Application Data\Apple Computer\SyncServices\Local\SyncingClients.plist
c:\documents and settings\HelpAssistant\Application Data\Creative\Media Database\MTDT_1.dmd
c:\documents and settings\HelpAssistant\Application Data\Creative\Media Database\PCML_1.dpm
c:\documents and settings\HelpAssistant\Application Data\Creative\Media Database\PCML_1.pld
c:\documents and settings\HelpAssistant\Application Data\desktop.ini
c:\documents and settings\HelpAssistant\Application Data\Disk Cleaner\dcsettings.ini
c:\documents and settings\HelpAssistant\Application Data\Logitech\SetPoint\gamelist.xml
c:\documents and settings\HelpAssistant\Application Data\Logitech\SetPoint\user.xml
c:\documents and settings\HelpAssistant\Application Data\Macromedia\Flash Player\macromedia.com\redirectSO.sol
c:\documents and settings\HelpAssistant\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
c:\documents and settings\HelpAssistant\Application Data\Macromedia\Flash Player\suitesmart.com\6thElement.sol
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Address Book\Sean Canfield.wab
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Address Book\Sean Canfield.wab~
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\0897206B35294097C3660E62BCDB227C
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\303572DF538EDD8B1D606185F1D559B8
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\3130B1871A126520A8C47861EFE3ED4D
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\3C19F8F5C2A69BEC912EF5B953293907
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\3C83474D61E624A4F9844DF935AFE217
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\486CC6AFD08942336C61FCD401C4A1D1
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\4FBCC318A8151CF1AE475D863AC55BC1
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\570FB14ABC805C46708F32F92F10C3B4
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\71644221AC231DBD2359C18EBB2118DC
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\74BFD122C0875EC75DBE5C6DB4C59019
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\79841F8EF00FBA86D33CC5A47696F165
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\904590238400AD963F77FAAAADC9BAB5
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\931F63C42C1784C5F855E737CDD61996
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\C554DCF706A5AAB8B360FAD227EAB9C7
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\C571B417AAF1F617555A0486AB3F5361
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\E04822AD18D472EA5B582E6E6F8C6B9A
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\Content\E8974A4669383843486E5AFDB09650F5
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\0897206B35294097C3660E62BCDB227C
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\303572DF538EDD8B1D606185F1D559B8
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\3130B1871A126520A8C47861EFE3ED4D
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\3C19F8F5C2A69BEC912EF5B953293907
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\3C83474D61E624A4F9844DF935AFE217
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\486CC6AFD08942336C61FCD401C4A1D1
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\4FBCC318A8151CF1AE475D863AC55BC1
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\570FB14ABC805C46708F32F92F10C3B4
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\71644221AC231DBD2359C18EBB2118DC
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\74BFD122C0875EC75DBE5C6DB4C59019
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\79841F8EF00FBA86D33CC5A47696F165
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\7B2238AACCEDC3F1FFE8E7EB5F575EC9
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\904590238400AD963F77FAAAADC9BAB5
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\931F63C42C1784C5F855E737CDD61996
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\C554DCF706A5AAB8B360FAD227EAB9C7
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\C571B417AAF1F617555A0486AB3F5361
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\E04822AD18D472EA5B582E6E6F8C6B9A
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735
c:\documents and settings\HelpAssistant\Application Data\Microsoft\CryptnetUrlCache\MetaData\E8974A4669383843486E5AFDB09650F5
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1644491937-1383384898-839522115-1004\6b29ae44e85efac3c72ff4d1865d73f1_351dc6ca-848f-4771-a3c9-30a27a5e03c3
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1644491937-1383384898-839522115-1004\83aa4cc77f591dfc2374580bbd95f6ba_351dc6ca-848f-4771-a3c9-30a27a5e03c3
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1644491937-1383384898-839522115-1004\962f90f7772d42228bf9a94fa6085dbc_351dc6ca-848f-4771-a3c9-30a27a5e03c3
c:\documents and settings\HelpAssistant\Application Data\Microsoft\HTML Help\hh.dat
c:\documents and settings\HelpAssistant\Application Data\Microsoft\IdentityCRL\Production\MetaConfig.xml
c:\documents and settings\HelpAssistant\Application Data\Microsoft\IdentityCRL\Production\ppcrlconfig.dll
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Installer\{147567F0-8575-4BE0-B5B3-62706C67FA5A}\ARPPRODUCTICON.exe
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Installer\{43E8D9E7-AFC9-4BA3-8106-B95E02B87AB7}\ARPPRODUCTICON.exe
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\brndlog.bak
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\brndlog.txt
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Desktop.htt
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.lnk
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\TestPokerStars.com.lnk
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Media Player\036877BE.wpl
c:\documents and settings\HelpAssistant\Application Data\Microsoft\MMC\dfrg
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Protect\CREDHIST
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Protect\S-1-5-21-1644491937-1383384898-839522115-1004\7a0bdc61-7936-4287-b656-921eeaa06a16
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Protect\S-1-5-21-1644491937-1383384898-839522115-1004\9a015075-378e-4671-997e-4e08987a180a
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Protect\S-1-5-21-1644491937-1383384898-839522115-1004\d9b9e489-05bc-4f4f-8574-d8a441ec981b
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Protect\S-1-5-21-1644491937-1383384898-839522115-1004\f294b0b4-1268-41a5-b385-937043361b10
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Protect\S-1-5-21-1644491937-1383384898-839522115-1004\Preferred
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Speech\Files\UserLexicons\SP_96978B53FE7C4E498D64D8ABBDBB258A.dat
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Custom Buttons\microsoft.windowslive.news.btn\button.xml
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Custom Buttons\microsoft.windowslive.news.btn\news.bmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Custom Buttons\microsoft.windowslive.translator.btn\button.xml
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Custom Buttons\microsoft.windowslive.translator.btn\translator.png
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\index.xml
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rss10.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rss11.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rss30.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rss3E.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rssB.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rssC.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rssD3.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rssD4.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rssD5.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rssE.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\Feeds\rssF.tmp
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows Live\Toolbar\toolbar.config
c:\documents and settings\HelpAssistant\Application Data\Microsoft\Windows\Themes\Custom.theme
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009032609
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009040821
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009042316
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009060215
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009070611
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009073022
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009082707
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009101601
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009120208
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009122116
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2010020220
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\LastCrash
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Crash Reports\submit.log
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\profiles.ini
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\blocklist.xml
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\bookmarkbackups\bookmarks-2010-02-21.json
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\bookmarkbackups\bookmarks-2010-02-23.json
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\bookmarkbackups\bookmarks-2010-02-24.json
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\bookmarkbackups\bookmarks-2010-02-25.json
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\bookmarkbackups\bookmarks-2010-02-26.json
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\bookmarkbackups\bookmarks-2010-02-27.json
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\bookmarks.html
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\chrome\userChrome-example.css
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\chrome\userContent-example.css
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\compatibility.ini
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\compreg.dat
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions.cache
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions.ini
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions.rdf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome.manifest
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome\chrome_user.jar
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences\defaults.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\install.rdf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\cache\030ci70c4vv_o\feed
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\cache\106643irq7ed_o\feed
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\cache\default\feed
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\cache\searchHistory.xml
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\chrome.manifest
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\chrome\ytoolbar.jar
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\nsYahooDomBuilder.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\nsYahooDomBuilder.xpt
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\nsYahooFeedNode.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\nsYahooFeedNode.xpt
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\nsYahooFeedProcessor.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\nsYahooFeedProcessor.xpt
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\defaults\preferences\yahoo.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\install.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\install.rdf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\LICENSE.txt
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\META-INF\manifest.mf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\META-INF\zigbert.rsa
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\META-INF\zigbert.sf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}\chrome.manifest
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}\chrome\reloadevery.jar
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}\install.rdf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\localstore.rdf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\mimeTypes.rdf
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\pluginreg.dat
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\pluginreg.dat.bak
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\prefs.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\prefs.js.BAK
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\secmod.db
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\sessionstore.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\signons3.txt
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\urlclassifierkey3.txt
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\user.js
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\user.js.BAK
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\webappsstore.sqlite
c:\documents and settings\HelpAssistant\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\xpti.dat
c:\documents and settings\HelpAssistant\Application Data\NCH Swift Sound\Switch\WavCodec.wff
c:\documents and settings\HelpAssistant\Application Data\PACE Anti-Piracy\CpdNNyVx83VC\H1KOF1FC83gDFV.020
c:\documents and settings\HelpAssistant\Application Data\PACE Anti-Piracy\rybXKSijH\uSw2a2NF25HKAt.rtf
c:\documents and settings\HelpAssistant\Application Data\PACE Anti-Piracy\vq3ifCEXdf\qSVF824mzE0OkG.tmp
c:\documents and settings\HelpAssistant\Application Data\REAPER\reaper-dxplugins.ini
c:\documents and settings\HelpAssistant\Application Data\REAPER\reaper-midihw.ini
c:\documents and settings\HelpAssistant\Application Data\REAPER\reaper-recentfx.ini
c:\documents and settings\HelpAssistant\Application Data\REAPER\reaper-reginfo2.ini
c:\documents and settings\HelpAssistant\Application Data\REAPER\reaper-vstplugins.ini
c:\documents and settings\HelpAssistant\Application Data\REAPER\reaper-vstshells.ini
c:\documents and settings\HelpAssistant\Application Data\REAPER\REAPER.ini
c:\documents and settings\HelpAssistant\Application Data\Sun\Java\Deployment\deployment.properties
c:\documents and settings\HelpAssistant\Application Data\Sun\Java\Deployment\security\trusted.certs
c:\documents and settings\HelpAssistant\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
c:\documents and settings\HelpAssistant\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
c:\documents and settings\HelpAssistant\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
c:\documents and settings\HelpAssistant\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-2-24-2010( 16-32-37 ).SDB
c:\documents and settings\HelpAssistant\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-2-24-2010( 17-12-45 ).SDB
c:\documents and settings\HelpAssistant\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 02-24-2010 - 17-09-12.log
c:\documents and settings\HelpAssistant\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.ZIP
c:\documents and settings\HelpAssistant\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
c:\documents and settings\HelpAssistant\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\documents and settings\HelpAssistant\Application Data\Ventrilo\chatlogs\shinedown\calciumtypefragcom\GlobalChat.log
c:\documents and settings\HelpAssistant\Application Data\Ventrilo\chatlogs\shinedown\noidea\GlobalChat.log
c:\documents and settings\HelpAssistant\Application Data\Ventrilo\default.vet
c:\documents and settings\HelpAssistant\Application Data\Ventrilo\ventrilo.log
c:\documents and settings\HelpAssistant\Application Data\Ventrilo\ventrilo2.ini
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\GTRSoloAirMixer.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\GTRSoloAmp.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\GTRSoloTuner.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLChorus.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLDelay.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLDistortion.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLEQ.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLFlanger.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLGateComp.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLOverDrive.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLPhaser.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLPitcher.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLSpring.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLVibrolo.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLVolume.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSolo\StompSLWahWah.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\GTRSoloToolRack.dll\XWMC\1000.dll
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpen409OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpen409OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpen421OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpen421OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpen57OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpen57OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpenA84OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpenVM1OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\12inchOpenBack\12inchOpenVM1OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_409OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_409OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_421OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_421OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_57OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_57OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_A84OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_A84OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_RE20OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12InchClosedBack\2_12inch_VM1OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12inchOpenBack\2_12Open_409OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12inchOpenBack\2_12Open_421OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12inchOpenBack\2_12Open_421OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12inchOpenBack\2_12Open_57OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12inchOpenBack\2_12Open_A84OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\2_12inchOpenBack\2_12Open_RE20OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_409OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_409OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_421OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_421OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_57OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_57OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_A84OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_A84OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_RE20OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_10InchOpenBack\4_10Open_VM1OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_409_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_409_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_421_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_421_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_57_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_57_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_RE20_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_RE20_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_Ribb84_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_Ribb84_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_VM1_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchStandard\4_12ST_VM1_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_409_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_409_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_421_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_421_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_57_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_57_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_R84_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_R84_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_RE20_OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_RE20_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\4_12inchVintage\4_12V_VM1_OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_12inch_Custom\ACME12C_CondVM1OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_12inch_Custom\ACME12C_Dyn409OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_12inch_Custom\ACME12C_Dyn421OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_12inch_Custom\ACME12C_Dyn57OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_12inch_Custom\ACME12C_Dyn57OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_12inch_Custom\ACME12C_PDCustom.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_12inch_Custom\ACME12C_Ribbon44.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_4_12inch_Vintage\ACME412_CondVM1OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_4_12inch_Vintage\ACME412_Dyn409OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_4_12inch_Vintage\ACME412_Dyn421OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_4_12inch_Vintage\ACME412_Dyn57OffX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_4_12inch_Vintage\ACME412_Dyn57OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_4_12inch_Vintage\ACME412_PDCustom.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_4_12inch_Vintage\ACME412_Ribbon44.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_8inch_OpenBack\ACME8_Dyn421OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_8inch_OpenBack\ACME8_Dyn57OnX.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\ACME_8inch_OpenBack\ACME8_Ribbon44.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\BASS_810\B810_Coil88p1.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\BASS_810\B810_Cond87p1.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\BASS_810\B810_CondGRp1.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\BASS_810\B810_CondGRp2.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\BASS_810\B810_Dyn57p1.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\BASS_810\B810_DynRE20p1.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Caches\C\Program Files\Waves\Plug-Ins\WavesGTR\Cabinets\BASS_810\B810_Ribb122p2.96000.cache
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Preferences\GTRSolo_Preferences_3.5
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Preferences\GTRSolo_Preferences_3.5_LastSetupPref
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Preferences\GTRToolRack_Preferences
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Preferences\GuitarToolRack_Scan_Preferences
c:\documents and settings\HelpAssistant\Application Data\Waves Audio\Preferences\WaveShell-VST_Preferences_6.0.7
c:\documents and settings\HelpAssistant\Application Data\WinRAR\version.dat
c:\documents and settings\HelpAssistant\CCCInstall_200904072314257812.log
c:\documents and settings\HelpAssistant\Contacts\Desktop.ini
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\041BC2D3-F343-4B15-A2AE-77EEF504DDD8.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\07F3AFCB-3AB9-4D2D-8BC6-94313C9361F2.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\080CF0D2-5246-48EE-AABC-0C5A8C7A6A9D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\09677E09-5779-4081-AC60-2AFF31822A6D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\096E6651-6028-43A4-9620-143FA55051C0.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\0A06F43B-64CA-4B14-8BD0-E41234D61C59.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\0CE6E755-A99B-4D2A-9749-6254F5CFCB5B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\0D2520AD-0C74-4962-817E-B610332905A1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\0E3752DC-874E-436A-8651-5897A7E1AB93.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\107008D8-D4C6-4279-B434-C447BF0D5845.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\1194FFAB-CA38-4AC5-A88D-C1F8E721129E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\13318A84-9DE5-4B69-94E3-E0D150D9982F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\13C9082F-4EA9-4B91-8D01-D9B43123783E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\1A317D2E-41B9-4841-8DAC-F8F5672D7D59.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\1BCD5CED-3F8E-427C-AEDA-39A365D628EE.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\1BED09A4-C440-41DF-9FA0-A01D7B45B848.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\1F846693-9E9C-4E7D-89B8-64BC03D37CEF.WindowsLiveGroup
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\1FE81843-1D7E-4E5C-B113-65355DDF20FF.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\20DCE53E-1D14-486F-9444-903168BEFCB5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\239AB623-5703-4A47-B6C4-89B375BC3459.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\24EA00DE-3D3D-4CA8-9F9C-C418CF0FF02A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\25219D9C-D1A6-4DF1-A567-886FF6EDFD6E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\26DEEBA7-2F73-4157-AEF4-389255B4CBF6.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\297392C2-677E-4508-822F-FDBA382600E0.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\2CF6F750-8B4F-44B9-B063-E13A4E36C0FA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\2EF03417-9876-4FA6-BF6C-80D2B450E3B7.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\3A15023D-C725-4D07-AC82-ECBD892DDEB4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\3A194B12-EDF7-4E9D-931B-96780EA04E16.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\3A4DB657-7373-48A4-A82E-60F4A0EC3311.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\3AE3E4EF-9620-4ACE-9B27-2CAC100F4AAA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\3E128183-CDDA-4735-B93C-23F6D8C294F2.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\421BE9AE-6015-458A-B74A-D5B345974500.WindowsLiveGroup
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\46DB4796-FCA8-496C-BF13-139AE6D88025.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\48A9D3BC-499A-4A20-8AB9-3CDAB6106D6A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\4E6B9EFF-2E96-403E-AC3D-65304781AAD9.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\4F048A7C-8D7D-43FC-8DB8-8634C8E09EDC.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\4F29C989-A564-4C07-9A69-96843725388E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\5233AAE7-667D-463F-9069-CA26C1CF1103.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\568B5BF8-DC19-4FEA-8488-1464D9BCE502.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\5827AE95-3282-4C09-8A84-4D6A12DFB7F4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\593566BE-3FFE-4D39-87D0-4EC9A3BDEF74.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\5B81E682-9F4B-4221-9B8B-511920453D4B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\5E98C24F-F639-458B-9326-49A53E65090B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\61DB07F3-ACFD-43FB-9CE8-FC461873ADE4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\6506CD7E-F660-41E0-B774-EACA3BC0B559.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\69921145-A30C-436F-B717-E4BEA69EFC4B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\6BDBA998-6327-4BAA-94A0-3181512472C7.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\6C08E19D-5776-4099-BE52-EE6C5DF356DB.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\6C60692E-E970-4AED-980D-6CFEE0DE2D9F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\6C68DC21-3F07-4FDD-8707-C9F62B6D1A9E.WindowsLiveGroup
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\6E5BCF3E-F0A2-4A46-98E4-BF1C790C6C10.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\6FD0D551-BE97-4BAC-B493-E96A7178C50C.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\7412AA2A-AB9A-479B-9D00-B9D92D9A9384.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\82E220F1-D746-468F-A153-B4B0CFF70869.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\8782910D-CD1A-4374-8F68-F13E54B41D7F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\900AE7E0-E9D9-48F4-BED7-C9D8A5C68345.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\91011F22-016B-49CE-B86A-4ADA2A626DF3.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\91C55614-BD0A-4C43-9817-67266CAA3719.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\92170E1D-1F53-4B72-8D5A-81B4A01D9C93.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\93F24CCA-976E-4C40-BCF6-2378172399B5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\9412BF0A-744B-4A6E-8D3C-FB159D9A1599.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\9494A518-F2AE-4C97-9FE5-05DF83D5376F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\95191937-863E-4867-BD6F-4C9257FA6E23.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\95BB1E4F-4E70-4720-946C-D3FFA17F5D45.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\96668AB1-96EC-4508-AC6C-E670F1EADAE1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\9943E0FB-8514-4F1B-87D0-BCF93040ED39.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\9A1901F5-46E7-46AF-B099-825022752914.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\9B11CFF6-BE54-485E-A4E7-AE00F64885D1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\9EE98339-7FB3-4C24-8155-6EE181EE2D6E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\9FCF7EAB-89E3-4D98-8C56-F511120E253D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\A2B36931-85A4-4654-AF7B-194ACE1D6AA6.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\A7D50918-DC7D-4266-ADEF-BA4A51E1A0EA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\A818ABCF-044D-4E75-AF20-1EE7C8E6F28D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\AA4AC32A-8C71-4B9F-878E-884604264198.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\AB1EE807-4982-419B-9A19-85F2BA4DD958.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\AD380F0C-1522-4951-B893-F180F757671F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B089084D-6CAA-45E8-ACB4-CC02EF5D31B1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B11AA941-A1CF-4B19-AEBA-67175F671312.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B2F031E5-EBC2-4548-8C3A-6EAB282909D4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B4A7C425-3911-4B30-934A-447E3CA58268.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B5ED550A-B5CB-4301-81E4-2085A0F3789E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B62E5ABB-A793-4874-AF16-97D9A7C6A92E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B639AC5A-1818-4907-ADA7-D74B935FE883.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\B80A9212-9356-46E8-920C-872257AB0746.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\BEEEC630-52E9-4EDB-851F-EB783F0FE0CF.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\C25A3AD0-3BB7-446E-89B1-9ECDD64EFC65.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\C533D61D-5B5A-45A2-BBB9-A108E98A35E2.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\C5B6E89F-3138-4984-83FB-AAB3CFFABE89.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\C798C1E6-B514-478E-826A-8D1378677BD1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\C8986AF6-0599-4277-9ECE-A727BD9C0782.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\CC1C1CD1-CF28-4D15-93BB-07EE8D43EFBA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\CFD7CF74-2373-47A5-A447-1E0A3836DACB.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\CFF3088B-2824-468B-B850-F0F8CECEBD73.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\contactcoll.cache
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\D36FA6E6-4F09-4AFB-81C1-6AE5E1306E6F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\D67D0261-81EC-42F1-AD66-7DCA5422C7C7.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\D8BA31EB-3AE0-461C-9D5F-489EC8C48D8A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\D9DA3BAD-AEA8-48A4-BEA7-C723488AC2E6.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\E076A4B7-FA8A-4A8E-ABF3-868330B12CF3.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\EA4ECA67-FD58-4094-80E9-BEF37DB7F5E4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\EA6475F0-FB43-4F5B-BE7E-6FD1075E0323.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\EA77E6DA-52B7-452C-B0EC-525A02D7F5F4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\EA8E7390-C335-438C-82FF-DAA2365CC15A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\EC1D6DD5-8F5E-4EA5-9B82-6E182FC8095B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\EC52BCA6-ABA9-4419-873C-FF573E3F8EF5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\F040F8A5-C702-4C4F-81A4-4C29E49CAB3B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\F327E772-C9EE-4C6C-B308-CD5A5E35376A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\F7501F14-9FFF-4ACF-99A8-9BE166A46450.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\FB5D8B4A-9A3C-4B59-8FE1-CD3935FC08C0.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\FC59D0FE-971F-44F0-B600-27C85D4E1A07.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\FF84DF8B-3749-492E-8EEB-79D49772E8C5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Contacts\messiah123_321@hotmail.com\FFAA5D89-FB82-486A-BCE7-0D20D4416312.WindowsLiveContact
c:\documents and settings\HelpAssistant\Cookies\sean canfield@abmr[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@ads.bleepingcomputer[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@ads.gmodules[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@ak[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@answers.yahoo[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@aol[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@bing[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@bleepingcomputer[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@c.live[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@c.msn[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@google[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@intellitxt[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@invitemedia[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@live[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@login.live[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@mail.live[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@medifast1[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@messenger.msn[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@msn[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@pubmatic[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@quantserve[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@rad.msn[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@scorecardresearch[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@server.iad.liveperson[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@t.msn[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@verify[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@wilderssecurity[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@windowsmarketplace[2].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@www.bing[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@www.bleepingcomputer[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@yahoo[1].txt
c:\documents and settings\HelpAssistant\Cookies\sean canfield@zune[2].txt
c:\documents and settings\HelpAssistant\Desktop\'Folding@Home'.lnk
c:\documents and settings\HelpAssistant\Desktop\100_2328.JPG
c:\documents and settings\HelpAssistant\Desktop\6uvshw3m.exe
c:\documents and settings\HelpAssistant\Desktop\Adobe Reader 9 Installer\abcpy.ini
c:\documents and settings\HelpAssistant\Desktop\Adobe Reader 9 Installer\Setup.exe
c:\documents and settings\HelpAssistant\Desktop\Adobe Reader 9 Installer\setup.ini
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\audacity-1.2-help.htb
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\af\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\ar\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\bg\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\bn\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\ca\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\cs\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\cy\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\da\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\de\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\el\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\es\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\eu\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\fi\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\fr\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\ga\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\gl\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\hu\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\it\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\ja\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\lt\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\mk\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\nb\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\nl\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\pl\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\pt\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\ro\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\ru\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\sk\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\sl\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\sv\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\tr\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\uk\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\zh\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Languages\zh_TW\Audacity.mo
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\LICENSE.txt
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\bug.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\dspprims.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\evalenv.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\follow.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\init.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\misc.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\nyinit.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\nyqmisc.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\nyquist.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\printrec.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\profile.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\seq.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\seqfnint.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\seqmidi.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\sndfnint.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\system.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\test.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Nyquist\xlinit.lsp
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\analyze.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\beat.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\clicktrack.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\crossfadein.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\crossfadeout.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\delay.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\fadein.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\fadeout.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\GVerb.dll
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\Hard Limiter.dll
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\highpass.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\lowpass.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\pluck.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\sc4.dll
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\SilenceMarker.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\tremolo.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\Plug-ins\undcbias.ny
c:\documents and settings\HelpAssistant\Desktop\audacity-win-1.2.6\Audacity\README.txt
c:\documents and settings\HelpAssistant\Desktop\Audigy SE Users Guide English.chm
c:\documents and settings\HelpAssistant\Desktop\avg_free_stb_all_8_32_cnet.exe
c:\documents and settings\HelpAssistant\Desktop\avg_free_stb_all_9_40_cnet.exe
c:\documents and settings\HelpAssistant\Desktop\CCleaner.lnk
c:\documents and settings\HelpAssistant\Desktop\Counter-Strike Source.lnk
c:\documents and settings\HelpAssistant\Desktop\Counter-Strike.lnk
c:\documents and settings\HelpAssistant\Desktop\CRVRidgeVent-install.pdf
c:\documents and settings\HelpAssistant\Desktop\dfsetup113.exe
c:\documents and settings\HelpAssistant\Desktop\download-userguide.php
c:\documents and settings\HelpAssistant\Desktop\EZdrummer_WIN_116\EZdrummer_WIN_116\ReadMe.rtf
c:\documents and settings\HelpAssistant\Desktop\gmerlog.log
c:\documents and settings\HelpAssistant\Desktop\GRSretirement.xls
c:\documents and settings\HelpAssistant\Desktop\halenish.mp3
c:\documents and settings\HelpAssistant\Desktop\HelpAsst_mebroot_fix.exe
c:\documents and settings\HelpAssistant\Desktop\HiddenFinder.lnk
c:\documents and settings\HelpAssistant\Desktop\HiddenFinder_setup.exe
c:\documents and settings\HelpAssistant\Desktop\HijackThis.lnk
c:\documents and settings\HelpAssistant\Desktop\HijackThisInstaller.exe
c:\documents and settings\HelpAssistant\Desktop\HLSS 3.0.zip
c:\documents and settings\HelpAssistant\Desktop\HLSS 3.0\HLSS 3.00.ini
c:\documents and settings\HelpAssistant\Desktop\HLSS 3.0\log.txt
c:\documents and settings\HelpAssistant\Desktop\HLSS 3.0\ReadMe.txt
c:\documents and settings\HelpAssistant\Desktop\HLSS 3.00.exe
c:\documents and settings\HelpAssistant\Desktop\HLSS 3.00.ini
c:\documents and settings\HelpAssistant\Desktop\IMAG0052.JPG
c:\documents and settings\HelpAssistant\Desktop\IMAG0055.JPG
c:\documents and settings\HelpAssistant\Desktop\Internet.lnk
c:\documents and settings\HelpAssistant\Desktop\jre-6u14-windows-i586-iftw(2).exe
c:\documents and settings\HelpAssistant\Desktop\jre-6u14-windows-i586-iftw.exe
c:\documents and settings\HelpAssistant\Desktop\log.txt
c:\documents and settings\HelpAssistant\Desktop\mbr.exe
c:\documents and settings\HelpAssistant\Desktop\mbr.log
c:\documents and settings\HelpAssistant\Desktop\PREVXCSIFREE.EXE
c:\documents and settings\HelpAssistant\Desktop\REAPER.lnk
c:\documents and settings\HelpAssistant\Desktop\RepealScan.txt
c:\documents and settings\HelpAssistant\Desktop\RootRepeal.exe
c:\documents and settings\HelpAssistant\Desktop\rrr.aup
c:\documents and settings\HelpAssistant\Desktop\rrr_data\b00069.au
c:\documents and settings\HelpAssistant\Desktop\RSIT.exe
c:\documents and settings\HelpAssistant\Desktop\Scanner and Camera Wizard.lnk
c:\documents and settings\HelpAssistant\Desktop\Shortcut to 100_2328.lnk
c:\documents and settings\HelpAssistant\Desktop\Shortcut to msnmsgr.lnk
c:\documents and settings\HelpAssistant\Desktop\switchsetup.exe
c:\documents and settings\HelpAssistant\Desktop\tn.jpg
c:\documents and settings\HelpAssistant\Desktop\townshipordinance.pdf
c:\documents and settings\HelpAssistant\Desktop\Vivitar Experience Image Manager.lnk
c:\documents and settings\HelpAssistant\Desktop\waves_gtr_solo_3.5\Authorize GTR Solo.pdf
c:\documents and settings\HelpAssistant\Desktop\XM-SD46X_Owners_Manual.pdf
c:\documents and settings\HelpAssistant\dxva_sig.txt
c:\documents and settings\HelpAssistant\Favorites\Desktop.ini
c:\documents and settings\HelpAssistant\Favorites\Links\Customize Links.url
c:\documents and settings\HelpAssistant\Favorites\Links\Free Hotmail.url
c:\documents and settings\HelpAssistant\Favorites\Links\Windows Marketplace.url
c:\documents and settings\HelpAssistant\Favorites\Links\Windows Media.url
c:\documents and settings\HelpAssistant\Favorites\Links\Windows.url
c:\documents and settings\HelpAssistant\Favorites\MSN.com.url
c:\documents and settings\HelpAssistant\Favorites\NCH Audio and Telephony Software.lnk
c:\documents and settings\HelpAssistant\Favorites\Radio Station Guide.url
c:\documents and settings\HelpAssistant\hs_err_pid2756.log
c:\documents and settings\HelpAssistant\identity.txt
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Acrobat\9.0\Cache\AcroFnt09.lst
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Acrobat\9.0\Updater\updater.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Color\ACECache10.lst
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\TypeSupport\AdobeFnt11.lst
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\acrobatPI.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\AdobeUpdaterPrefs.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\aum.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\aumLib.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\AUTrans.sig
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\AUTrans.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\bobcache.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\bobcache.sig
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\crl\BD36AD9DB685113949272282FBCDA989B9A97D63.crl
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\Data\AdobeUpdater.aum
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\Data\AdobeUpdater_meta.txt
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\Data\reader9rdr-en_US.aum
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\Data\reader9rdr-en_US.aup.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Adobe\Updater6\Data\reader9rdr-en_US_meta.txt
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Apple Computer\iTunes\iPodDevices.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Apple Computer\iTunes\iTunesPrefs.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Apple Computer\QuickTime\QuickTime.qtp
c:\documents and settings\HelpAssistant\Local Settings\Application Data\ATI\ACE\Manifest.Bin
c:\documents and settings\HelpAssistant\Local Settings\Application Data\ATI\ACE\Manifest.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\ATI\ACE\Profiles.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\AVG Security Toolbar\cache\overlay.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Identities\{49C2B14E-E1E8-488D-A5C8-457C0AF29826}\Microsoft\Outlook Express\Folders.dbx
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Identities\{49C2B14E-E1E8-488D-A5C8-457C0AF29826}\Microsoft\Outlook Express\Inbox.dbx
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Identities\{49C2B14E-E1E8-488D-A5C8-457C0AF29826}\Microsoft\Outlook Express\Offline.dbx
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Identities\{49C2B14E-E1E8-488D-A5C8-457C0AF29826}\Microsoft\Outlook Express\Outbox.dbx
c:\documents and settings\HelpAssistant\Local Settings\Application Data\M-Audio\Session\UserSettings.ini
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-1644491937-1383384898-839522115-1004\Credentials
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Media Player\wmpfolders.wmdb
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\activesharingfolder.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\H0C+m00zJnUEpqvrpUwmEeNk+m4=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\H0C+m00zJnUEpqvrpUwmEeNk+m4=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\H0C+m00zJnUEpqvrpUwmEeNk+m4=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\IA9vmN0qT34TQ+xiZbPmcxeXUDg=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\IA9vmN0qT34TQ+xiZbPmcxeXUDg=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\IA9vmN0qT34TQ+xiZbPmcxeXUDg=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\lCyhu24yMQt+CJlbGST3Jy9+KEI=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\lCyhu24yMQt+CJlbGST3Jy9+KEI=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\lCyhu24yMQt+CJlbGST3Jy9+KEI=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\SLrvRLRi1MPd8wYUbd6HaeeW5vM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\SLrvRLRi1MPd8wYUbd6HaeeW5vM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\SLrvRLRi1MPd8wYUbd6HaeeW5vM=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\VfEKKH2K+gUzhtlVXHIvzB2twQ0=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\VfEKKH2K+gUzhtlVXHIvzB2twQ0=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\VfEKKH2K+gUzhtlVXHIvzB2twQ0=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\VoP12bdqQyV2pOm1b3Quh6qvYdc=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\VoP12bdqQyV2pOm1b3Quh6qvYdc=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Backgrounds\VoP12bdqQyV2pOm1b3Quh6qvYdc=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\axF7a0ekuiAc7WjQjNmjxYpRX6Q=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\axF7a0ekuiAc7WjQjNmjxYpRX6Q=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\axF7a0ekuiAc7WjQjNmjxYpRX6Q=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\B3VEl5u5DvNzgIua1+Zd4Uxt2FLs=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\B3VEl5u5DvNzgIua1+Zd4Uxt2FLs=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\B3VEl5u5DvNzgIua1+Zd4Uxt2FLs=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\hyiJu8sDcRCbJhl+Ccy2CjQR8lA=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\hyiJu8sDcRCbJhl+Ccy2CjQR8lA=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\DynamicBackgrounds\hyiJu8sDcRCbJhl+Ccy2CjQR8lA=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\objectstore.v2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\++jucJigOYo2I83F1kndMUzkll0=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\++jucJigOYo2I83F1kndMUzkll0=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\++jucJigOYo2I83F1kndMUzkll0=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\0vUr4BnaKGecCroYOU1eWiPPcf0=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\0vUr4BnaKGecCroYOU1eWiPPcf0=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\0vUr4BnaKGecCroYOU1eWiPPcf0=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\2Embh2xPyHrVlic2FwzIlQfMavVA=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\2Embh2xPyHrVlic2FwzIlQfMavVA=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\2Embh2xPyHrVlic2FwzIlQfMavVA=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\6M06zBio9KT2FYxmcaNxCEYU8tcg=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\6M06zBio9KT2FYxmcaNxCEYU8tcg=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\6M06zBio9KT2FYxmcaNxCEYU8tcg=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\9dtCc9u3FWvV9RhxpiEeRV+s2t0=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\9dtCc9u3FWvV9RhxpiEeRV+s2t0=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\9dtCc9u3FWvV9RhxpiEeRV+s2t0=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\D2Fs2FP9edNibi2FUnU68QJp2FHDruQ=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\D2Fs2FP9edNibi2FUnU68QJp2FHDruQ=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\D2Fs2FP9edNibi2FUnU68QJp2FHDruQ=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\DXpmpt9Jq38X274YNCDWReR1uaI=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\DXpmpt9Jq38X274YNCDWReR1uaI=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\DXpmpt9Jq38X274YNCDWReR1uaI=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\FUfTBiQcZLUaElimeDYqLBFw4Ro=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\FUfTBiQcZLUaElimeDYqLBFw4Ro=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\FUfTBiQcZLUaElimeDYqLBFw4Ro=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\GOVBNDmsqcl4YXVZU4kwwbts9kk=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\GOVBNDmsqcl4YXVZU4kwwbts9kk=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\GOVBNDmsqcl4YXVZU4kwwbts9kk=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\Ii3mmfcEfSkQmgvqX4EdjEmvbcE=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\Ii3mmfcEfSkQmgvqX4EdjEmvbcE=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\Ii3mmfcEfSkQmgvqX4EdjEmvbcE=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\o2x7Vq5eeo2F0cF6+F0Uq1SrkqpM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\o2x7Vq5eeo2F0cF6+F0Uq1SrkqpM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\o2x7Vq5eeo2F0cF6+F0Uq1SrkqpM=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\oZ2FGmVfEIBvTdtb+iySYYn56M0E=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\oZ2FGmVfEIBvTdtb+iySYYn56M0E=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\oZ2FGmVfEIBvTdtb+iySYYn56M0E=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\P5HTLASl8yZCeqlqi0CzqtSR3B8=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\P5HTLASl8yZCeqlqi0CzqtSR3B8=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\P5HTLASl8yZCeqlqi0CzqtSR3B8=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\qbNpBw1sS0AVUKCd5PojaF4qWCI=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\qbNpBw1sS0AVUKCd5PojaF4qWCI=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\qbNpBw1sS0AVUKCd5PojaF4qWCI=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\RV2dB5ha2dZzf0I9Ne2VS2m3tAE=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\RV2dB5ha2dZzf0I9Ne2VS2m3tAE=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\RV2dB5ha2dZzf0I9Ne2VS2m3tAE=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\TEH4feoVKy4mAeEcbAfF2FqpZn3w=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\TEH4feoVKy4mAeEcbAfF2FqpZn3w=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\TEH4feoVKy4mAeEcbAfF2FqpZn3w=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\UUsLSPvqbDCMyOSS1i7MHuhvUxo=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\UUsLSPvqbDCMyOSS1i7MHuhvUxo=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\UUsLSPvqbDCMyOSS1i7MHuhvUxo=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\vR3bS3eGkh9QcPo0OvCxKXK98YQ=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\vR3bS3eGkh9QcPo0OvCxKXK98YQ=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\vR3bS3eGkh9QcPo0OvCxKXK98YQ=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\xF7meUN9oVUP44Vu78E6txntjuM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\xF7meUN9oVUP44Vu78E6txntjuM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\xF7meUN9oVUP44Vu78E6txntjuM=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\XixB0QFUcm8WNf28fLewac9gJzM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\XixB0QFUcm8WNf28fLewac9gJzM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\XixB0QFUcm8WNf28fLewac9gJzM=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\YBO2F9u0CZzxm7dBxLdz+5yZlazE=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\YBO2F9u0CZzxm7dBxLdz+5yZlazE=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\YBO2F9u0CZzxm7dBxLdz+5yZlazE=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\z9uCpAG4f9VyERT1J0ky9Olw4h4=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\z9uCpAG4f9VyERT1J0ky9Olw4h4=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Scenes\z9uCpAG4f9VyERT1J0ky9Olw4h4=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\25DO7VS3mn0xsE5BofQrupcz9d8=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\25DO7VS3mn0xsE5BofQrupcz9d8=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\2VdOiRn8R6vgyAo1OuWk82FGrO9g=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\2VdOiRn8R6vgyAo1OuWk82FGrO9g=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\3wE0mbxSN3LedOta4HlGHjUmP2F4=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\3wE0mbxSN3LedOta4HlGHjUmP2F4=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\4lPfcgolfu9SMVQFzBFU8i9HfkM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\4lPfcgolfu9SMVQFzBFU8i9HfkM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\5HsRLCjITSf4dGIpIbB0mdbO4DU=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\5HsRLCjITSf4dGIpIbB0mdbO4DU=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\7viRn2+xU1C56kASuGNBNNyoajE=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\7viRn2+xU1C56kASuGNBNNyoajE=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\8K3fz6ubMAk6ukB21OfMfx3uFAY=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\8K3fz6ubMAk6ukB21OfMfx3uFAY=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\9ceinudLrSdcnb4g35fwHaupzo0=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\9ceinudLrSdcnb4g35fwHaupzo0=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\bDnRnxoiR5pYJQRBuwx4dn3E560=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\bDnRnxoiR5pYJQRBuwx4dn3E560=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\boEYeldjnGzs2FcpwgrHEs8GKP3I=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\boEYeldjnGzs2FcpwgrHEs8GKP3I=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\cmJCJjUVJ+x1g5BUj5TlTOAoFIo=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\cmJCJjUVJ+x1g5BUj5TlTOAoFIo=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\dW0VZfrFH4igpqB+aknu+YLVPQc=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\dW0VZfrFH4igpqB+aknu+YLVPQc=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\efo78ffrVlSr9zfdpsLqiXo9EME=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\efo78ffrVlSr9zfdpsLqiXo9EME=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\eXGWmogZak9R61lyiAgAEW2Fr2U4=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\eXGWmogZak9R61lyiAgAEW2Fr2U4=.id2








Continued, lol...said it was too long..




c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\fNlIATwLy9ENd7XazQRkClzw9gI=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\fNlIATwLy9ENd7XazQRkClzw9gI=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\gYFt2g0+7EY3AWmSL7A9ngKc9dA=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\gYFt2g0+7EY3AWmSL7A9ngKc9dA=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\HYbhW4luo864gdjU7qSMhy3h6e0=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\HYbhW4luo864gdjU7qSMhy3h6e0=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\I5qSGpyq8hhZJ0inX2FbNbG09BCY=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\I5qSGpyq8hhZJ0inX2FbNbG09BCY=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\iMSR7+iz9srezdy7Ug5Lk4rSq2Fk=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\iMSR7+iz9srezdy7Ug5Lk4rSq2Fk=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\iyD2FcB82FO02FOIroc+DEhvb4wfnE=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\iyD2FcB82FO02FOIroc+DEhvb4wfnE=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\JT4+7SJsbCu4GYvPzD4p2FT209fM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\JT4+7SJsbCu4GYvPzD4p2FT209fM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\JVDQmX7wrCTjxJGtKE1zpx7v9HU=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\JVDQmX7wrCTjxJGtKE1zpx7v9HU=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\LAu0QBwPm79H+JUwbSGWTGAe3Yw=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\LAu0QBwPm79H+JUwbSGWTGAe3Yw=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\mK7Sb6JCiac11q2DUIMFewTl2F6g=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\mK7Sb6JCiac11q2DUIMFewTl2F6g=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\MsW4TPDss0Fudp23o1Lorm9wVR8=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\MsW4TPDss0Fudp23o1Lorm9wVR8=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\mW7MfHUhXfGj2FMzw2GAHWck7kvM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\mW7MfHUhXfGj2FMzw2GAHWck7kvM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\nL30s2FenVnv4zMSb8wlMuGlgmnM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\nL30s2FenVnv4zMSb8wlMuGlgmnM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\nqIkbqTXj1KHuQ9LnvASHiuaNNw=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\nqIkbqTXj1KHuQ9LnvASHiuaNNw=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\OAIyPMS4IzDz+uW5YvlfQXJ2FdaE=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\OAIyPMS4IzDz+uW5YvlfQXJ2FdaE=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\OCspCXJeppsiq9Lk3xt4qpYFOwQ=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\OCspCXJeppsiq9Lk3xt4qpYFOwQ=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\OkVhCL3V91f2FiGQsNHomTJWIIcQ=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\OkVhCL3V91f2FiGQsNHomTJWIIcQ=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\pwQPQjvP5B98Kas65nd7yECOnxk=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\pwQPQjvP5B98Kas65nd7yECOnxk=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\Q6ienynzcO2FrQzd5LRwvmFkTG50=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\Q6ienynzcO2FrQzd5LRwvmFkTG50=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\S+c8gyL8O5ZxTtEamXVEcWNlWPg=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\S+c8gyL8O5ZxTtEamXVEcWNlWPg=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\TWc1ZZ1D70WKXEyDb2R3iiu30Sk=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\TWc1ZZ1D70WKXEyDb2R3iiu30Sk=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\udWEuRxQXf0pXamv4zCWfT6y6jM=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\udWEuRxQXf0pXamv4zCWfT6y6jM=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\uVoe8m93jetu0MoaNQvqPAwr1+w=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\uVoe8m93jetu0MoaNQvqPAwr1+w=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\VOiCOo9yjYbP2JvqMKdXagPp+6o=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\VOiCOo9yjYbP2JvqMKdXagPp+6o=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\Vq7aBMblfcTQvfgW5HVaek6VK7k=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\Vq7aBMblfcTQvfgW5HVaek6VK7k=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\WliJzSCj1p0+9+BOKoKSC2FcHKMk=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\WliJzSCj1p0+9+BOKoKSC2FcHKMk=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\YKtEKUt7RODgQfEHSfWDI1U4iPg=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\YKtEKUt7RODgQfEHSfWDI1U4iPg=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\z6PnMTMTClYXU2FNe6HHbW1NfVWE=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\z6PnMTMTClYXU2FNe6HHbW1NfVWE=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\zbtpAQFKwUU8Cw8rokpivG3jiJQ=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\zbtpAQFKwUU8Cw8rokpivG3jiJQ=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\ZDob2Fsn7AOLqsYdqoxObjdV2FNqI=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\ZDob2Fsn7AOLqsYdqoxObjdV2FNqI=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\ZTbE6J8kl20dzoFo9bmIlpOOF90=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\UserTile\ZTbE6J8kl20dzoFo9bmIlpOOF90=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\2FH8ZlCgRS9ylfaoL+gwFHzKeyp8=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\2FH8ZlCgRS9ylfaoL+gwFHzKeyp8=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\72FjqK0b2FzFkbJWZ+BlMs1OxQprI=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\72FjqK0b2FzFkbJWZ+BlMs1OxQprI=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\alxGH2FFbmTzeLEdtRHmv6GBUzdw=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\alxGH2FFbmTzeLEdtRHmv6GBUzdw=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\AzBXDxf+Tcdvcans2TCRnoXh2Fjg=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\AzBXDxf+Tcdvcans2TCRnoXh2Fjg=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\CFMGHHhzvqtshATFxrIj05VlzLY=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\CFMGHHhzvqtshATFxrIj05VlzLY=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\J9+5k2FTpQP6WuWOj5y0n41qN5dc=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\J9+5k2FTpQP6WuWOj5y0n41qN5dc=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\K6lNvx7Z9+N7xKJAEUKjjzPEK3o=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\K6lNvx7Z9+N7xKJAEUKjjzPEK3o=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\lnHW2s0zHIsgKVjOiirk1ZBZ54g=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\lnHW2s0zHIsgKVjOiirk1ZBZ54g=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\lnHW2s0zHIsgKVjOiirk1ZBZ54g=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Nt2FqWL50Iag4EvPJjVS0IoDBFQ4=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Nt2FqWL50Iag4EvPJjVS0IoDBFQ4=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Nt2FqWL50Iag4EvPJjVS0IoDBFQ4=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\rTeUDzJzwMepiafQ4bVfqDvados=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\rTeUDzJzwMepiafQ4bVfqDvados=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\rTeUDzJzwMepiafQ4bVfqDvados=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\rXcZb6ekO9S3jB29KleJkBOXYmY=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\rXcZb6ekO9S3jB29KleJkBOXYmY=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\rXcZb6ekO9S3jB29KleJkBOXYmY=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Sgj64GS+QyVyVxkslxY2FFsRARkg=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Sgj64GS+QyVyVxkslxY2FFsRARkg=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Sgj64GS+QyVyVxkslxY2FFsRARkg=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\xuzmdPrmqAzU7Ebd0TWqBqcGoKA=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\xuzmdPrmqAzU7Ebd0TWqBqcGoKA=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\xuzmdPrmqAzU7Ebd0TWqBqcGoKA=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\y4sf3+OJfBypHvYJRsGeAR2FqVd4=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\y4sf3+OJfBypHvYJRsGeAR2FqVd4=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\y4sf3+OJfBypHvYJRsGeAR2FqVd4=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Zh9cZsOdVXAK4fAulijLqPGggcA=.dt2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Zh9cZsOdVXAK4fAulijLqPGggcA=.id2
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\ObjectStore\Winks3\Zh9cZsOdVXAK4fAulijLqPGggcA=.png
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Logs\Dfsr00001.log.gz
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Logs\Dfsr00002.log.gz
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Logs\Dfsr00003.log.gz
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Logs\Dfsr00004.log.gz
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Logs\Dfsr00005.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\pending.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\volume.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\volume.xml~
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\$db_normal$
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\$db_dirty$
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\fsr.chk
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\fsr.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\fsr002A0.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\fsrtmp.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\res1.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\res2.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SharingMetadata\Working\database_A28C_4168_8C41_37D5\tmp.edb
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Messenger\messiah123_321@hotmail.com\SocialNews\WNResponse.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Search Enhancement Pack\Search Box Extension\history.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\g\i0bz3drcnq34fgsyzcfxkf3wvuk2pdds03nm2f4dz30b23f20gaaafea\id.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\g\i0bz3drcnq34fgsyzcfxkf3wvuk2pdds03nm2f4dz30b23f20gaaafea\quota.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\g\i0bz3drcnq34fgsyzcfxkf3wvuk2pdds03nm2f4dz30b23f20gaaafea\used.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\g\xaglk23bbaoe4do1hgh33nqnsmqr5kmpnqhpva42wvrnu1fhkdaaafda\id.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\g\xaglk23bbaoe4do1hgh33nqnsmqr5kmpnqhpva42wvrnu1fhkdaaafda\quota.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\g\xaglk23bbaoe4do1hgh33nqnsmqr5kmpnqhpva42wvrnu1fhkdaaafda\used.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\i0bz3drcnq34fgsyzcfxkf3wvuk2pdds03nm2f4dz30b23f20gaaafea\f\__LocalSettings
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\i0bz3drcnq34fgsyzcfxkf3wvuk2pdds03nm2f4dz30b23f20gaaafea\group.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\i0bz3drcnq34fgsyzcfxkf3wvuk2pdds03nm2f4dz30b23f20gaaafea\id.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\ni4sjwvnydk3ya4cfhno1jcyj1kiholliyrdi4hlcgwqj5ulmwaaadfa\f\__LocalSettings
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\ni4sjwvnydk3ya4cfhno1jcyj1kiholliyrdi4hlcgwqj5ulmwaaadfa\f\OlympicsPlayer.txt
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\ni4sjwvnydk3ya4cfhno1jcyj1kiholliyrdi4hlcgwqj5ulmwaaadfa\f\PlayerId.txt
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\ni4sjwvnydk3ya4cfhno1jcyj1kiholliyrdi4hlcgwqj5ulmwaaadfa\group.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\is\qemiccm2.3u3\w111gelf.jbw\1\s\ni4sjwvnydk3ya4cfhno1jcyj1kiholliyrdi4hlcgwqj5ulmwaaadfa\id.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Silverlight\mssl.lck
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{4e671a75-5aa4-4cd4-918c-4eb40e7f3dfe}\DBStore\Backup\new\contacts.pat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{4e671a75-5aa4-4cd4-918c-4eb40e7f3dfe}\DBStore\contacts.pat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{4e671a75-5aa4-4cd4-918c-4eb40e7f3dfe}\DBStore\dbstore.ini
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{4e671a75-5aa4-4cd4-918c-4eb40e7f3dfe}\DBStore\edb.chk
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{afc7ab97-1c84-419a-8c09-fbfc76eeb798}\DBStore\Backup\new\contacts.pat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{afc7ab97-1c84-419a-8c09-fbfc76eeb798}\DBStore\contacts.pat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{afc7ab97-1c84-419a-8c09-fbfc76eeb798}\DBStore\dbstore.ini
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\{afc7ab97-1c84-419a-8c09-fbfc76eeb798}\DBStore\edb.chk
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\Desktop.ini
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\real\5adcca98-a15b-4a27-8ee7-ac78b0cd7148.AddressBook
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\real\c8c49e09-f50d-4191-b319-7fb1f8940889.MeContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\real\contactcoll.cache
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\real\members.stg
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\041BC2D3-F343-4B15-A2AE-77EEF504DDD8.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\07F3AFCB-3AB9-4D2D-8BC6-94313C9361F2.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\080CF0D2-5246-48EE-AABC-0C5A8C7A6A9D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\09677E09-5779-4081-AC60-2AFF31822A6D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\096E6651-6028-43A4-9620-143FA55051C0.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\0A06F43B-64CA-4B14-8BD0-E41234D61C59.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\0CE6E755-A99B-4D2A-9749-6254F5CFCB5B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\0D2520AD-0C74-4962-817E-B610332905A1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\0E3752DC-874E-436A-8651-5897A7E1AB93.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\107008D8-D4C6-4279-B434-C447BF0D5845.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\1194FFAB-CA38-4AC5-A88D-C1F8E721129E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\13318A84-9DE5-4B69-94E3-E0D150D9982F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\13C9082F-4EA9-4B91-8D01-D9B43123783E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\1BCD5CED-3F8E-427C-AEDA-39A365D628EE.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\1BED09A4-C440-41DF-9FA0-A01D7B45B848.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\1F846693-9E9C-4E7D-89B8-64BC03D37CEF.WindowsLiveGroup
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\1FE81843-1D7E-4E5C-B113-65355DDF20FF.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\20DCE53E-1D14-486F-9444-903168BEFCB5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\239AB623-5703-4A47-B6C4-89B375BC3459.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\24EA00DE-3D3D-4CA8-9F9C-C418CF0FF02A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\25219D9C-D1A6-4DF1-A567-886FF6EDFD6E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\26DEEBA7-2F73-4157-AEF4-389255B4CBF6.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\297392C2-677E-4508-822F-FDBA382600E0.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\2a8c4450-b095-4be2-a981-4307a1c66727.MeContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\2CF6F750-8B4F-44B9-B063-E13A4E36C0FA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\2EF03417-9876-4FA6-BF6C-80D2B450E3B7.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\3A15023D-C725-4D07-AC82-ECBD892DDEB4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\3A194B12-EDF7-4E9D-931B-96780EA04E16.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\3A4DB657-7373-48A4-A82E-60F4A0EC3311.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\3AE3E4EF-9620-4ACE-9B27-2CAC100F4AAA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\3E128183-CDDA-4735-B93C-23F6D8C294F2.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\421BE9AE-6015-458A-B74A-D5B345974500.WindowsLiveGroup
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\46DB4796-FCA8-496C-BF13-139AE6D88025.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\48A9D3BC-499A-4A20-8AB9-3CDAB6106D6A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\4E6B9EFF-2E96-403E-AC3D-65304781AAD9.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\4F048A7C-8D7D-43FC-8DB8-8634C8E09EDC.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\4F29C989-A564-4C07-9A69-96843725388E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\50E5BCA8-290C-42BD-990F-5C57714E7823.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\5233AAE7-667D-463F-9069-CA26C1CF1103.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\568B5BF8-DC19-4FEA-8488-1464D9BCE502.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\5827AE95-3282-4C09-8A84-4D6A12DFB7F4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\593566BE-3FFE-4D39-87D0-4EC9A3BDEF74.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\5B81E682-9F4B-4221-9B8B-511920453D4B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\5E98C24F-F639-458B-9326-49A53E65090B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\61DB07F3-ACFD-43FB-9CE8-FC461873ADE4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\6506CD7E-F660-41E0-B774-EACA3BC0B559.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\69921145-A30C-436F-B717-E4BEA69EFC4B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\6BDBA998-6327-4BAA-94A0-3181512472C7.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\6C08E19D-5776-4099-BE52-EE6C5DF356DB.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\6C60692E-E970-4AED-980D-6CFEE0DE2D9F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\6C68DC21-3F07-4FDD-8707-C9F62B6D1A9E.WindowsLiveGroup
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\6E5BCF3E-F0A2-4A46-98E4-BF1C790C6C10.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\6FD0D551-BE97-4BAC-B493-E96A7178C50C.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\7412AA2A-AB9A-479B-9D00-B9D92D9A9384.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\82E220F1-D746-468F-A153-B4B0CFF70869.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\8782910D-CD1A-4374-8F68-F13E54B41D7F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\900AE7E0-E9D9-48F4-BED7-C9D8A5C68345.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\91011F22-016B-49CE-B86A-4ADA2A626DF3.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\91C55614-BD0A-4C43-9817-67266CAA3719.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\92170E1D-1F53-4B72-8D5A-81B4A01D9C93.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\93F24CCA-976E-4C40-BCF6-2378172399B5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\9412BF0A-744B-4A6E-8D3C-FB159D9A1599.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\9494A518-F2AE-4C97-9FE5-05DF83D5376F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\95191937-863E-4867-BD6F-4C9257FA6E23.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\95BB1E4F-4E70-4720-946C-D3FFA17F5D45.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\96668AB1-96EC-4508-AC6C-E670F1EADAE1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\9943E0FB-8514-4F1B-87D0-BCF93040ED39.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\9A1901F5-46E7-46AF-B099-825022752914.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\9B11CFF6-BE54-485E-A4E7-AE00F64885D1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\9EE98339-7FB3-4C24-8155-6EE181EE2D6E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\9FCF7EAB-89E3-4D98-8C56-F511120E253D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\A2B36931-85A4-4654-AF7B-194ACE1D6AA6.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\A7D50918-DC7D-4266-ADEF-BA4A51E1A0EA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\A818ABCF-044D-4E75-AF20-1EE7C8E6F28D.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\AA4AC32A-8C71-4B9F-878E-884604264198.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\AB1EE807-4982-419B-9A19-85F2BA4DD958.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\AD380F0C-1522-4951-B893-F180F757671F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B089084D-6CAA-45E8-ACB4-CC02EF5D31B1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B11AA941-A1CF-4B19-AEBA-67175F671312.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B2F031E5-EBC2-4548-8C3A-6EAB282909D4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B4A7C425-3911-4B30-934A-447E3CA58268.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B5ED550A-B5CB-4301-81E4-2085A0F3789E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B62E5ABB-A793-4874-AF16-97D9A7C6A92E.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B639AC5A-1818-4907-ADA7-D74B935FE883.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\B80A9212-9356-46E8-920C-872257AB0746.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\BEEEC630-52E9-4EDB-851F-EB783F0FE0CF.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\C25A3AD0-3BB7-446E-89B1-9ECDD64EFC65.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\C533D61D-5B5A-45A2-BBB9-A108E98A35E2.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\C5B6E89F-3138-4984-83FB-AAB3CFFABE89.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\C798C1E6-B514-478E-826A-8D1378677BD1.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\C8986AF6-0599-4277-9ECE-A727BD9C0782.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\CC1C1CD1-CF28-4D15-93BB-07EE8D43EFBA.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\CFD7CF74-2373-47A5-A447-1E0A3836DACB.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\CFF3088B-2824-468B-B850-F0F8CECEBD73.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\contactcoll.cache
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\D36FA6E6-4F09-4AFB-81C1-6AE5E1306E6F.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\D8BA31EB-3AE0-461C-9D5F-489EC8C48D8A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\D9DA3BAD-AEA8-48A4-BEA7-C723488AC2E6.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\E076A4B7-FA8A-4A8E-ABF3-868330B12CF3.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\EA4ECA67-FD58-4094-80E9-BEF37DB7F5E4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\EA6475F0-FB43-4F5B-BE7E-6FD1075E0323.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\EA77E6DA-52B7-452C-B0EC-525A02D7F5F4.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\EA8E7390-C335-438C-82FF-DAA2365CC15A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\EC1D6DD5-8F5E-4EA5-9B82-6E182FC8095B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\EC52BCA6-ABA9-4419-873C-FF573E3F8EF5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\F040F8A5-C702-4C4F-81A4-4C29E49CAB3B.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\F327E772-C9EE-4C6C-B308-CD5A5E35376A.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\F7501F14-9FFF-4ACF-99A8-9BE166A46450.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\FB5D8B4A-9A3C-4B59-8FE1-CD3935FC08C0.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\FC59D0FE-971F-44F0-B600-27C85D4E1A07.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\FF84DF8B-3749-492E-8EEB-79D49772E8C5.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\FFAA5D89-FB82-486A-BCE7-0D20D4416312.WindowsLiveContact
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Live Contacts\messiah123_321@hotmail.com\shadow\members.stg
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.DTD
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\active-update.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\updates.xml
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\updates\last-update.log
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\05292164d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\05A24F91d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\079E1A7Ed01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\10324959d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\131DB99Cd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\14FA07B7d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\16FFD495d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\1703CB32d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\18BB7FC3d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\1A0C98B0d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\1A62D45Ed01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\1ED0118Bd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\1FDA3DB5d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\221737E1d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\223B3219d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\24CD4F70d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\26C280F6d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\298D5052d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\2AC60770d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\2AC61630d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\2ADFF810d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\2B47097Ed01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\2CE7FC17d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\3285D3D5d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\3328A47Ad01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\3751C61Ad01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\39167088d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\3A2CB6CEd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\3DE90F1Dd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\3F9E282Bd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\401E80E0d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\434DC8F4d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\45614AA6d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\45D2D097d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\46E3B2E5d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\4A4B8451d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\4ACBB04Cd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\4C68C896d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\508CB6C1d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\52A15366d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\53926CD4d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5411B0BFd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\56E4B3E4d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\57A6BA37d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\57FEF2CAd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\581CB6C1d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\59365263d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5AC05469d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5ACC2C00d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5B0E11F1d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5B1E11F1d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5BD40BB4d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5C8FF8EAd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5CDBBCCFd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5D29ACD9d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5E611A48d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\5E7C2687d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\64EB149Bd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\6A6CB6CEd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\6D491629d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\6F7227AAd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\6FD55F56d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\71944166d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\722291C9d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\725291C9d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\726291C9d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\79C731ACd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\7A6CA1F4d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\846D5482d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\8572EEE0d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\8574B2BDd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\885CC25Cd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\896D5313d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\8AC5FE46d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\8FB066FAd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\93549435d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\9BF4F358d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\9C256273d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\9EAB600Cd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\A2887F40d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\A5E18637d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\A7F3DAB4d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\A89F4DBCd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\B4DAA3D8d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\B67666FAd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\B7F24B02d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\B8BACA93d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\BC246CD7d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\BDA64530d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\BE097CEAd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\BF9CD37Ed01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\BFC837BEd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\C0AD9D95d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\C36A82ADd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\C70F1C3Ad01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\CED3E256d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\D07540EDd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\D103036Cd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\D7BEDE19d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\DA0CC59Bd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\DEA77D99d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\E73B1A88d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\E7CB562Ad01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\E9E9313Cd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\EB0FC1A2d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\EB3D8150d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\EE9E4207d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\F54F403Dd01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\F8D0F545d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\FD7A6379d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\FD8B7E8Ed01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\Cache\FFE43314d01
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\OfflineCache\index.sqlite
c:\documents and settings\HelpAssistant\Local Settings\Application Data\prvlcl.dat
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Vivitar Experience Image Manager\Config.txt
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Vivitar Experience Image Manager\Logfile.txt
c:\documents and settings\HelpAssistant\Local Settings\Application Data\Vivitar Experience Image Manager\MediaManager.db
c:\documents and settings\HelpAssistant\Local Settings\desktop.ini
c:\documents and settings\HelpAssistant\Local Settings\History\desktop.ini
c:\documents and settings\HelpAssistant\Local Settings\History\History.IE5\desktop.ini
c:\documents and settings\HelpAssistant\Local Settings\History\History.IE5\index.dat
c:\documents and settings\HelpAssistant\Local Settings\History\History.IE5\MSHist012010022620100227\index.dat
c:\documents and settings\HelpAssistant\Local Settings\History\History.IE5\MSHist012010022720100228\index.dat
c:\documents and settings\HelpAssistant\Local Settings\temp\Combofix2.txt
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[1]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[10]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[11]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[12]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[13]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[14]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[15]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[16]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[17]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[18]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[19]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[2]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[20]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[21]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[22]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[23]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[3]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[4]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[5]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[6]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[7]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[8]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\[9]
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\J7P8IIVF\desktop.ini
c:\documents and settings\HelpAssistant\Local Settings\Temporary Internet Files\desktop.ini
c:\documents and settings\HelpAssistant\My Documents\CamPics\Thumbs.db
c:\documents and settings\HelpAssistant\My Documents\desktop.ini
c:\documents and settings\HelpAssistant\My Documents\golf.txt
c:\documents and settings\HelpAssistant\My Documents\image001.jpg
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition12\Composition12.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition15\Track3_7.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition21\Track3_1.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition28\Composition28.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition30\Composition30.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition32\Composition32.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition33\Composition33.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition34\Composition34.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition34\Track4_82.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition45\Track3_8.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition46\Track4_2.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition48\Composition48.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition49\Composition49.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition49\Track3_1.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition5\Composition5.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition50\Composition50.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition52\Track3_3.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition56\Composition56.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition63\Track3_10.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition63\Track3_18.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition64\Composition64.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition68\Track3_14.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition68\Track3_20.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition68\Track3_23.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition68\Track3_3.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition68\Track3_7.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition68\Track3_8.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition68\Track3_9.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition69\Track3_5.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition70\Composition70.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition71\Composition71.cpj
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition81\Track3_38.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition81\Track3_39.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition84\Track3_19.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition85\Track3_25.wav
c:\documents and settings\HelpAssistant\My Documents\M-Audio Session\Compositions\Composition95\Composition95.cpj
c:\documents and settings\HelpAssistant\My Documents\My Music\11.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\3.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\acousticriff2.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\bluesyrock.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\clean.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition341.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition342.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition47.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition48.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition49lyrics.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition56.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition63.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition64.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition71.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition77.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition85.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition85.wma
c:\documents and settings\HelpAssistant\My Documents\My Music\Composition95.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Davidlee.wma
c:\documents and settings\HelpAssistant\My Documents\My Music\Desktop.ini
c:\documents and settings\HelpAssistant\My Documents\My Music\dxva_sig.txt
c:\documents and settings\HelpAssistant\My Documents\My Music\holyfk.wav
c:\documents and settings\HelpAssistant\My Documents\My Music\HotnCold.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\HotnCold2.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\00\03\03\469998D9EF6D13D2-A774DFFB05778330.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\00\03\08\469998D9EF6D13D2-553EB796812A2830.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\02\03\07\469998D9EF6D13D2-C127B4CB910A7732.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\03\02\09\469998D9EF6D13D2-C3FFF904C3B83923.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\05\14\07\469998D9EF6D13D2-A1874B9AE2D5D7E5.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\07\02\05\469998D9EF6D13D2-68C5FB25331E2527.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\07\11\13\469998D9EF6D13D2-BFA47B511CC1CDB7.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\07\13\01\469998D9EF6D13D2-2CD319526ABF81D7.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\07\15\14\469998D9EF6D13D2-259D74D484835EF7.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\10\03\12\469998D9EF6D13D2-2FEC1674DFC56C3A.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\10\05\15\469998D9EF6D13D2-FFD6E2308B458F5A.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\11\09\15\469998D9EF6D13D2-05CF50B997CC2F9B.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\11\10\11\469998D9EF6D13D2-6A737A8437B19BAB.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\12\02\00\469998D9EF6D13D2-AE2D599C9D2DE02C.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\12\09\07\469998D9EF6D13D2-204A6E279622379C.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\Album Artwork\Cache\469998D9EF6D13D2\13\03\06\469998D9EF6D13D2-E2CC0EFC51C2063D.itc2
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\iTunes Library Extras.itdb
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\iTunes Library Genius.itdb
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\iTunes Library.itl
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\iTunes Music Library.xml
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\iTunes Music\Various Artists\100 Best Classics\Digital Booklet - Best Classics 100.pdf
c:\documents and settings\HelpAssistant\My Documents\My Music\iTunes\sentinel
c:\documents and settings\HelpAssistant\My Documents\My Music\mariodies.wav
c:\documents and settings\HelpAssistant\My Documents\My Music\realtome.wav
c:\documents and settings\HelpAssistant\My Documents\My Music\reaper1.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\riff1.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\riff2.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\Sample Music.lnk
c:\documents and settings\HelpAssistant\My Documents\My Music\solostart.mp3
c:\documents and settings\HelpAssistant\My Documents\My Music\sweetmulah.wav
c:\documents and settings\HelpAssistant\My Documents\My Music\takethese.wav
c:\documents and settings\HelpAssistant\My Documents\My Music\workwithdrums.mp3
c:\documents and settings\HelpAssistant\My Documents\My Pictures\card.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\cardsforcheeeeap.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Desktop.ini
c:\documents and settings\HelpAssistant\My Documents\My Pictures\explore.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\GetAttachment.aspx
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0001.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0002.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0003.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG00033.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG00034.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0004.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0005.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0006.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0008.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0009.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0010.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0011.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0012.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0030.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0031.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0032.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0033.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0034.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\IMAG0035.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\jersey.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\LMFBO.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\page.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\AaronBrownCont.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Contender1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Contender2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Contender3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Contender4.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Contender5.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Delmas1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\DelmasSPauto.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Edelman.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Harvinjersey.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\KSmith1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\KSmith2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\KSmith3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\LemBarneyNT.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Megatron1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\New1OF1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\NewOthers.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\NewPettigrews.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\NewStaffords.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Other1 001.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Other1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Other2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Other3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others10.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others4.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others5.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others6.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others7.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others8.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Others9.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew10.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew11.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew4.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew5.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew6.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew7.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew8.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Pettigrew9.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\PettigrewGEM.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\PettigrewSPauto.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\PlatAuto1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\PlatAuto2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\PlatAuto3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx10.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx11.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx12 001.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx12.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx4.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx5.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx6.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx7.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx8.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\SPx9.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Stafford.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Stafford1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Stafford2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Stafford3.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Stafford4.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Stafford5.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Stafford6.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\StaffordStamp.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Thumbs.db
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Williams1.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\Williams2.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Picture\WilliamsautoPlat.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Sample Pictures.lnk
c:\documents and settings\HelpAssistant\My Documents\My Pictures\scans.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\Thumbs.db
c:\documents and settings\HelpAssistant\My Documents\My Pictures\weird.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\weirdbrowswer.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\wow.jpg
c:\documents and settings\HelpAssistant\My Documents\My Pictures\wtf.JPG
c:\documents and settings\HelpAssistant\My Documents\My Pictures\WTFebay.JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\101_0052.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\acoustab12_5.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\AlbumArt_{43B52515-CEF7-4D50-B675-0EA1247A2A0A}_Large.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\AlbumArt_{43B52515-CEF7-4D50-B675-0EA1247A2A0A}_Small.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\AlbumArt_{A6687D6B-DA33-4EBE-BAF6-93A9D0A76E64}_Large.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\AlbumArt_{A6687D6B-DA33-4EBE-BAF6-93A9D0A76E64}_Small.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\brett_11_17_2009@17_28_49.wav
c:\documents and settings\HelpAssistant\My Documents\My Received Files\bs2.JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\car.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\cards.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\desktop.ini
c:\documents and settings\HelpAssistant\My Documents\My Received Files\DSC02234.JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Evidence.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\ffb.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\FFBtier(1).txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\FFBtier.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Folder.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\highlights.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\hijackthis.log
c:\documents and settings\HelpAssistant\My Documents\My Received Files\image001.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\IMG_0010(1).JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\IMG_0010.JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\IMG_0039.JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\JimsPICKS.JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\lips.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\lol.JPG
c:\documents and settings\HelpAssistant\My Documents\My Received Files\lol1.wav
c:\documents and settings\HelpAssistant\My Documents\My Received Files\lol2.wav
c:\documents and settings\HelpAssistant\My Documents\My Received Files\maid.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\MOVES.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\myteam.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\ndfl.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\ohboy.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\picks.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\pickskevin.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\pimptimes.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\pos7.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\post-6-1088721469.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\rfa's.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\roughin it.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Scan-100208-0003.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Scan-100208-0004.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Scan-100208-0005.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Scan-100208-0006.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Scan-100208-0007.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Scan-100220-0001.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\Scan-100224-0001.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\scores(1).txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\scores.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\song lyric.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\sweeptab.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\teams.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\trade.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\trade1.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\UIA2.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\UIA3.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\UIA4.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\UIA5.txt
c:\documents and settings\HelpAssistant\My Documents\My Received Files\vastLOL.jpg
c:\documents and settings\HelpAssistant\My Documents\My Received Files\weasel#.txt
c:\documents and settings\HelpAssistant\My Documents\My Sharing Folders.lnk
c:\documents and settings\HelpAssistant\newthing.txt
c:\documents and settings\HelpAssistant\NTUSER.DAT
c:\documents and settings\HelpAssistant\NTUSER.DAT.LOG
c:\documents and settings\HelpAssistant\ntuser.ini
c:\documents and settings\HelpAssistant\Recent\CFScript.lnk
c:\documents and settings\HelpAssistant\Recent\ComboFix.lnk
c:\documents and settings\HelpAssistant\Recent\Desktop.ini
c:\documents and settings\HelpAssistant\Recent\explore.lnk
c:\documents and settings\HelpAssistant\Recent\gmerlog.lnk
c:\documents and settings\HelpAssistant\Recent\Local Disk ©.lnk
c:\documents and settings\HelpAssistant\Recent\My Pictures.lnk
c:\documents and settings\HelpAssistant\Recent\Prevx%203.0%20-%20Precracked.lnk
c:\documents and settings\HelpAssistant\Recent\RepealScan.lnk
c:\documents and settings\HelpAssistant\Recent\rootkitrepeal.lnk
c:\documents and settings\HelpAssistant\SendTo\Compressed (zipped) Folder.ZFSendToTarget
c:\documents and settings\HelpAssistant\SendTo\Desktop (create shortcut).DeskLink
c:\documents and settings\HelpAssistant\SendTo\desktop.ini
c:\documents and settings\HelpAssistant\SendTo\Mail Recipient.MAPIMail
c:\documents and settings\HelpAssistant\SendTo\My Documents.mydocs
c:\documents and settings\HelpAssistant\Start Menu\desktop.ini
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Accessibility\desktop.ini
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Address Book.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Command Prompt.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\desktop.ini
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Entertainment\desktop.ini
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Notepad.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Synchronize.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Tour Windows XP.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Accessories\Windows Explorer.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Administrative Tools\desktop.ini
c:\documents and settings\HelpAssistant\Start Menu\Programs\CCleaner\CCleaner Homepage.url
c:\documents and settings\HelpAssistant\Start Menu\Programs\CCleaner\CCleaner.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\desktop.ini
c:\documents and settings\HelpAssistant\Start Menu\Programs\Haali Media Splitter\GDSMux.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Haali Media Splitter\Media Splitter Settings.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Haali Media Splitter\Uninstall.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Internet Explorer.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Outlook Express.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\Install REAPER to USB key or Removable Media.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\ReaMote Slave.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\REAPER (create new project).lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\REAPER (reset configuration to factory defaults).lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\REAPER (ReWire slave mode).lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\REAPER (show audio configuration on startup).lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\REAPER License and User Agreement.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\REAPER.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\Uninstall REAPER.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\REAPER\Whatsnew.txt.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Remote Assistance.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Startup\desktop.ini
c:\documents and settings\HelpAssistant\Start Menu\Programs\Steam\Counter-Strike Source.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Steam\Counter-Strike.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Steam\Steam.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Vivitar Experience Image Manager\Uninstall.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Vivitar Experience Image Manager\Vivitar Experience Image Manager.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\Windows Media Player.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\WinRAR\Console RAR manual.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\WinRAR\WinRAR help.lnk
c:\documents and settings\HelpAssistant\Start Menu\Programs\WinRAR\WinRAR.lnk
c:\documents and settings\HelpAssistant\Templates\amipro.sam
c:\documents and settings\HelpAssistant\Templates\excel.xls
c:\documents and settings\HelpAssistant\Templates\excel4.xls
c:\documents and settings\HelpAssistant\Templates\lotus.wk4
c:\documents and settings\HelpAssistant\Templates\powerpnt.ppt
c:\documents and settings\HelpAssistant\Templates\presenta.shw
c:\documents and settings\HelpAssistant\Templates\quattro.wb2
c:\documents and settings\HelpAssistant\Templates\sndrec.wav
c:\documents and settings\HelpAssistant\Templates\winword.doc
c:\documents and settings\HelpAssistant\Templates\winword2.doc
c:\documents and settings\HelpAssistant\Templates\wordpfct.wpd
c:\documents and settings\HelpAssistant\Templates\wordpfct.wpg
c:\documents and settings\HelpAssistant\UserData\index.dat
c:\documents and settings\HelpAssistant\UserData\YIWBYK81\Tdy58[1].xml
c:\documents and settings\HelpAssistant\UserData\YQBU9TRC\pmocntr[1].xml



.
((((((((((((((((((((((((( Files Created from 2010-01-28 to 2010-02-28 )))))))))))))))))))))))))))))))
.

2010-02-27 05:08 . 2010-02-27 05:16 -------- d-----w- C:\rsit
2010-02-25 00:33 . 2010-02-25 00:33 -------- d-----w- c:\program files\Trend Micro
2010-02-24 23:29 . 2010-02-24 23:29 -------- d-----w- c:\program files\HiddenFinder
2010-02-24 23:29 . 2006-02-24 03:03 8576 ----a-w- c:\windows\system32\drivers\KProcWatch.sys
2010-02-24 23:12 . 2010-02-27 22:58 0 ----a-w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\prvlcl.dat
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-24 22:32 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-24 22:32 . 2010-02-24 22:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-24 21:33 . 2010-02-24 21:33 52224 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-24 21:33 . 2010-02-24 21:33 117760 ----a-w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-24 21:32 . 2010-02-24 21:32 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\SUPERAntiSpyware.com
2010-02-24 20:22 . 2009-11-25 18:01 1230080 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-02-24 20:20 . 2010-02-24 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2010-02-24 18:57 . 2010-02-24 18:58 39451456 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative Sound Blaster Audigy series driver 2.18.0011__\SBAX_PCDRV_LB_2_18_0011.exe
2010-02-24 18:55 . 2010-02-24 18:56 37634288 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.26.02__\CMS5_PCAPP_LB_5_26_02.exe
2010-02-24 18:55 . 2010-02-24 18:55 12907880 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative WaveStudio 7.12.00__\WAVESTD_PCAPP_LB_7_12_00.exe
2010-02-24 18:54 . 2010-02-24 18:55 10995608 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative CD Burner Plugin 5.01.44 for Creative MediaSource 5 Player_Organizer__\CMS5_BRNR_PCAPP_LB_5_01_44.exe
2010-02-24 18:52 . 2010-02-24 18:52 152576 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-24 18:52 . 2010-02-24 18:52 79488 ----a-w- c:\documents and settings\Sean Canfield\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 95024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-02-23 07:41 . 2010-02-23 07:41 598368 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-02-23 07:41 . 2010-02-23 07:41 566608 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-02-23 07:41 . 2010-02-23 07:41 221408 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-02-23 07:41 . 2010-02-23 07:41 1230160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-23 07:41 . 2010-02-23 07:41 247120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-23 07:40 . 2010-02-23 07:40 17480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-23 07:39 . 2010-02-23 07:39 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-23 07:39 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-22 02:25 . 2010-02-22 02:25 -------- d-----w- c:\documents and settings\Sean Canfield\Local Settings\Application Data\AVG Security Toolbar
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- C:\$AVG
2010-02-22 02:22 . 2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-22 02:22 . 2010-02-22 02:22 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-22 02:22 . 2010-02-22 02:22 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-22 02:22 . 2010-02-22 02:22 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-22 02:22 . 2010-02-27 23:56 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-22 02:22 . 2010-02-22 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-22 02:21 . 2010-02-24 20:21 -------- d-----w- c:\program files\AVG
2010-02-22 02:21 . 2010-02-22 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-22 02:21 . 2010-02-22 03:16 -------- d-----w- c:\windows\SxsCaPendDel
2010-02-22 01:15 . 2010-02-22 01:54 -------- d-----w- c:\documents and settings\Sean Canfield\Application Data\Disk Cleaner
2010-02-11 05:29 . 2010-02-11 05:29 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-02-11 05:27 . 2004-09-29 17:15 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2010-02-11 05:27 . 2004-09-29 17:14 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2010-02-11 05:27 . 2004-09-29 17:12 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2010-02-11 05:27 . 2004-09-29 17:09 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2010-02-11 05:27 . 2004-09-29 17:09 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2010-02-11 05:27 . 2004-09-29 17:08 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2010-02-11 05:27 . 1998-10-29 21:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-02-11 05:27 . 2010-02-11 05:27 -------- d-----w- c:\program files\HP
2010-02-11 05:04 . 2004-08-04 04:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-02-11 05:04 . 2004-08-04 04:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 02:54 . 2009-07-04 03:03 -------- d-----w- c:\program files\Steam
2010-02-24 21:32 . 2009-04-08 04:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-24 18:59 . 2009-04-08 02:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-24 18:53 . 2009-06-15 01:24 -------- d-----w- c:\program files\Java
2010-02-23 07:41 . 2009-06-21 13:19 884176 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-02-23 07:41 . 2009-06-21 13:28 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-02-23 07:41 . 2009-06-21 13:19 393896 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-02-23 07:41 . 2009-06-21 13:19 211064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-02-23 07:41 . 2009-12-06 00:27 562272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-02-23 07:41 . 2009-06-21 13:19 390320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-23 07:41 . 2009-06-21 13:19 167312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-02-23 07:41 . 2009-06-21 13:19 6330848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-02-23 07:41 . 2009-06-21 13:19 329048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 94712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-02-23 07:40 . 2009-06-21 13:18 961984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-23 07:40 . 2009-06-21 13:18 835312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-23 07:40 . 2009-06-21 13:18 842992 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-23 07:40 . 2009-06-21 13:18 1593320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-23 07:40 . 2009-06-21 13:18 815184 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-23 07:40 . 2009-06-21 13:18 1229232 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-23 07:39 . 2009-06-21 13:13 -------- d-----w- c:\program files\Lavasoft
2010-02-20 21:42 . 2009-06-06 05:35 -------- d-----w- c:\program files\REAPER
2010-02-11 05:29 . 2010-02-11 05:26 102262 ----a-w- c:\windows\hpoins05.dat
2010-02-05 00:28 . 2009-09-27 13:19 3803208 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-04 15:53 . 2009-06-21 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-27 18:28 . 2009-06-21 13:19 8 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-21 13:13 . 2009-09-15 23:53 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 14:10 . 2010-01-19 22:49 -------- d-----w- c:\program files\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar Experience Image Manager
2010-01-19 22:54 . 2010-01-19 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivitar
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\Haali
2010-01-19 22:49 . 2010-01-19 22:49 -------- d-----w- c:\program files\ffdshow
2009-12-31 16:14 . 2006-02-28 12:00 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2006-02-28 12:00 662016 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2009-04-08 02:16 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2006-02-28 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 14:41 . 2006-02-28 12:00 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-02-27_00.38.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-28 05:13 . 2010-02-28 05:13 16384 c:\windows\Temp\Perflib_Perfdata_7c0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]


[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"SetDefaultMIDI"="MIDIDef.exe" [2009-03-04 28672]
"Creative Software Update"="c:\program files\Creative\Shared Files\Software Update\AutoUpdate.exe" [2007-01-04 481200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"CTHelper"="CTHELPER.EXE" [2009-03-04 19456]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-02-23 815184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-8 809488]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-22 02:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-10-31 14:51 57344 ------w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 20:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
2008-05-15 21:45 356864 ----a-w- c:\windows\system32\M-AudioTaskBarIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-02-21 05:36 1217872 ----a-w- c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-01-05 12:56 2002160 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\stinker123105\\counter-strike\\hl.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/21/2009 8:19 AM 64288]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [4/7/2009 9:33 PM 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/21/2010 9:22 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/21/2010 9:22 PM 360584]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [4/7/2009 9:31 PM 13696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2/21/2010 9:21 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2/21/2010 9:21 PM 285392]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/15/2009 6:52 PM 54752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 10:52 AM 1229232]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [4/8/2009 9:12 PM 10384]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
R3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);c:\windows\system32\drivers\mausbft.sys [6/1/2009 6:37 PM 132096]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [3/4/2009 1:42 PM 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [6/1/2009 5:38 PM 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [3/4/2009 1:42 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [3/4/2009 1:42 PM 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [3/4/2009 1:42 PM 566296]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [7/1/2002 6:30 PM 95232]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
S3 KProcWatch;KProcWatch;c:\windows\system32\drivers\KProcWatch.sys [2/24/2010 6:29 PM 8576]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2010-02-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 07:40]

2010-02-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.fleaflicker.com/nfl
uInternet Settings,ProxyOverride = *.local
IE: {{809132AF-89D2-4d52-AA03-AB4E35BBDC5B} - c:\program files\PokerStars.TEST\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\Sean Canfield\Application Data\Mozilla\Firefox\Profiles\z2b6vv21.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-28 00:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(684)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2010-02-28 00:36:05
ComboFix-quarantined-files.txt 2010-02-28 05:36
ComboFix2.txt 2010-02-28 01:25
ComboFix3.txt 2010-02-27 22:09
ComboFix4.txt 2010-02-27 00:40

Pre-Run: 42,259,333,120 bytes free
Post-Run: 42,208,575,488 bytes free

- - End Of File - - 977EA3555B79E03B1725C37DCEE36E29

MBAM


Malwarebytes' Anti-Malware 1.44
Database version: 3805
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

2/28/2010 12:44:07 AM
mbam-log-2010-02-28 (00-44-07).txt

Scan type: Quick Scan
Objects scanned: 109100
Time elapsed: 3 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#13 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:05:06 PM

Posted 01 March 2010 - 01:42 AM

Hi Shocker1245,

That was a long log, look like we've got it now though, let's do a final check.

You have an older version of java installed it is now at update 18 you should install this latest version which can be found here


Please do a scan with ESET OnlineScan

Note: If you run this in a browser other than IE you will be asked to download and install esetsmartinstaller_enu.exe
  • Click the button.
  • Check
  • Click the button.
  • Accept any security warnings from your browser and allow it to install the ActiveX control.
  • Check
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push
  • Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the button.
  • Push


Then in your next reply, please let me know if you are having any more problems and post back here with the following logs:
  • ESET report
  • New Rsit log

Thanks

unite.jpg


#14 Shocker1245

Shocker1245
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:11:06 AM

Posted 01 March 2010 - 02:00 PM

Hey, i finished the ESET scanner, but there was no option to view/create log as it found 0 infections. My only option was "Finish". Also, yesterday I tried the previously troubled sites like ebay, and it didnt redirect me to the bogus info page at all. Previously it'd do it almost if not everytime. Also the forum buttons i mentioned earlier no longer go from normal to text n back, haha. So i think its SEEMS gone....any other things i should run? Also any of these programs i should remove once this is all finished!


RSIT


Logfile of random's system information tool 1.06 (written by random/random)
Run by Sean Canfield at 2010-03-01 14:03:26
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 40 GB (51%) free of 79 GB
Total RAM: 2046 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:03:33 PM, on 3/1/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Creative\Shared Files\CTSched.exe
C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Documents and Settings\Sean Canfield\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Sean Canfield.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fleaflicker.com/nfl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Software Update] "C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe" /Silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: TestPokerStars.com - {809132AF-89D2-4d52-AA03-AB4E35BBDC5B} - C:\Program Files\PokerStars.TEST\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_b...sreqlab_srl.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup...15108/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8373 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-02-21 1484056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-18 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-18 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2008-12-18 76304]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-01-05 413696]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2009-03-04 19456]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2010-02-23 815184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-05-20 98304]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"=C:\Program Files\Creative\Shared Files\CTSched.exe [2006-11-17 53341]
"SetDefaultMIDI"=C:\WINDOWS\system32\MIDIDef.exe [2009-03-04 28672]
"Creative Software Update"=C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe [2007-01-04 481200]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [2005-10-31 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe [2008-05-15 356864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files\steam\steam.exe [2010-02-21 1217872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-01-05 2002160]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-02-21 12464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-02-18 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\steamapps\stinker123105\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\stinker123105\counter-strike\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Disabled:Steam 732897"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\AVG\AVG9\avgemc.exe"="C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

======List of files/folders created in the last 1 months======

2010-03-01 12:49:13 ----D---- C:\Program Files\ESET
2010-03-01 12:46:54 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-03-01 12:46:53 ----D---- C:\Program Files\Common Files\Java
2010-03-01 12:46:33 ----A---- C:\WINDOWS\system32\javaws.exe
2010-03-01 12:46:33 ----A---- C:\WINDOWS\system32\javaw.exe
2010-03-01 12:46:33 ----A---- C:\WINDOWS\system32\java.exe
2010-02-28 01:09:07 ----SHD---- C:\RECYCLER
2010-02-28 00:36:05 ----A---- C:\ComboFix.txt
2010-02-27 00:08:06 ----D---- C:\rsit
2010-02-26 19:56:02 ----A---- C:\rootkitrepeal.txt
2010-02-26 19:55:32 ----A---- C:\RootRepeal report 02-26-10 (19-55-32).txt
2010-02-26 19:31:18 ----A---- C:\Boot.bak
2010-02-26 19:31:11 ----RASHD---- C:\cmdcons
2010-02-26 19:30:35 ----A---- C:\WINDOWS\zip.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\SWSC.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\SWREG.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\sed.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\PEV.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\MBR.exe
2010-02-26 19:30:35 ----A---- C:\WINDOWS\grep.exe
2010-02-26 19:30:28 ----D---- C:\WINDOWS\ERDNT
2010-02-26 19:23:29 ----D---- C:\Qoobox
2010-02-26 18:01:45 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\WinRAR
2010-02-26 18:01:26 ----D---- C:\Program Files\WinRAR
2010-02-26 17:46:07 ----A---- C:\WINDOWS\{00000000-00000000-00000009-00001102-00000004-20061102}.BAK
2010-02-24 19:33:54 ----D---- C:\Program Files\Trend Micro
2010-02-24 18:29:30 ----D---- C:\Program Files\HiddenFinder
2010-02-24 17:32:44 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\Malwarebytes
2010-02-24 17:32:19 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-02-24 17:32:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-24 16:32:37 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-24 16:32:26 ----D---- C:\Program Files\SUPERAntiSpyware
2010-02-24 16:32:26 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\SUPERAntiSpyware.com
2010-02-24 16:04:15 ----A---- C:\WINDOWS\wininit.ini
2010-02-24 15:20:41 ----D---- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2010-02-24 02:58:27 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-02-23 02:39:30 ----HDC---- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-21 21:22:41 ----D---- C:\$AVG
2010-02-21 21:22:24 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-02-21 21:22:03 ----D---- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
2010-02-21 21:21:43 ----D---- C:\Program Files\AVG
2010-02-21 21:21:42 ----D---- C:\Documents and Settings\All Users\Application Data\avg9
2010-02-21 21:21:17 ----D---- C:\WINDOWS\SxsCaPendDel
2010-02-21 20:15:41 ----D---- C:\Documents and Settings\Sean Canfield\Application Data\Disk Cleaner
2010-02-11 00:29:01 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZisn12.dll
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZipt12.dll
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZipr12.dll
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZipm12.exe
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZinw12.exe
2010-02-11 00:27:24 ----A---- C:\WINDOWS\system32\HPZidr12.dll
2010-02-11 00:27:23 ----A---- C:\WINDOWS\IsUninst.exe
2010-02-11 00:27:07 ----D---- C:\Program Files\HP
2010-02-11 00:26:52 ----D---- C:\Config.Msi
2010-02-11 00:26:22 ----A---- C:\WINDOWS\system32\hpzjsn01.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\HPZc3212.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\hpovst08.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\hpotscl.dll
2010-02-11 00:26:21 ----A---- C:\WINDOWS\system32\hpgwiamd.dll
2010-02-11 00:26:10 ----A---- C:\WINDOWS\system32\hpzlnt12.dll
2010-02-11 00:26:08 ----A---- C:\WINDOWS\system32\hpzcon12.dll
2010-02-11 00:26:08 ----A---- C:\WINDOWS\system32\hpzcoi12.dll
2010-02-10 19:53:00 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 19:52:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 19:51:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 19:51:03 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 19:50:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 19:50:45 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 19:50:33 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$

======List of files/folders modified in the last 1 months======

2010-03-01 14:03:22 ----D---- C:\WINDOWS\Prefetch
2010-03-01 12:49:16 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-03-01 12:49:16 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-01 12:49:16 ----D---- C:\WINDOWS
2010-03-01 12:49:13 ----RD---- C:\Program Files
2010-03-01 12:46:53 ----SHD---- C:\WINDOWS\Installer
2010-03-01 12:46:53 ----D---- C:\Program Files\Common Files
2010-03-01 12:46:34 ----D---- C:\WINDOWS\Temp
2010-03-01 12:46:33 ----D---- C:\WINDOWS\system32
2010-03-01 12:46:29 ----D---- C:\Program Files\Java
2010-03-01 12:43:24 ----D---- C:\Program Files\Mozilla Firefox
2010-03-01 12:20:47 ----SD---- C:\WINDOWS\Tasks
2010-03-01 03:14:19 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-28 22:15:44 ----ASD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-02-28 20:47:10 ----D---- C:\Program Files\Steam
2010-02-28 19:42:11 ----D---- C:\Program Files\REAPER
2010-02-28 00:38:49 ----D---- C:\WINDOWS\system32\drivers
2010-02-28 00:34:14 ----A---- C:\WINDOWS\system.ini
2010-02-28 00:33:50 ----D---- C:\Documents and Settings
2010-02-28 00:25:12 ----D---- C:\WINDOWS\AppPatch
2010-02-27 19:57:16 ----RASH---- C:\boot.ini
2010-02-27 19:57:16 ----A---- C:\WINDOWS\win.ini
2010-02-26 19:30:34 ----SHD---- C:\System Volume Information
2010-02-26 19:30:34 ----D---- C:\WINDOWS\system32\Restore
2010-02-24 17:44:48 ----D---- C:\WINDOWS\system32\CatRoot_bak
2010-02-24 17:44:48 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-24 17:44:28 ----HD---- C:\WINDOWS\inf
2010-02-24 17:28:07 ----D---- C:\WINDOWS\SoftwareDistribution
2010-02-24 16:32:09 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-02-24 13:59:23 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-23 02:41:12 ----A---- C:\WINDOWS\system32\lsdelete.exe
2010-02-23 02:39:38 ----D---- C:\WINDOWS\WinSxS
2010-02-23 02:39:38 ----D---- C:\Program Files\Lavasoft
2010-02-22 02:05:22 ----D---- C:\WINDOWS\system32\config
2010-02-21 21:19:44 ----SD---- C:\Documents and Settings\Sean Canfield\Application Data\Microsoft
2010-02-21 21:03:24 ----D---- C:\WINDOWS\Debug
2010-02-11 00:29:09 ----D---- C:\WINDOWS\twain_32
2010-02-11 00:04:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-10 19:52:59 ----HD---- C:\WINDOWS\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-02-21 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-02-21 28424]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-02-21 360584]
R1 BIOS;BIOS; \??\C:\WINDOWS\system32\drivers\BIOS.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-02-28 36096]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
R2 LBeepKE;LBeepKE; C:\WINDOWS\System32\Drivers\LBeepKE.sys [2008-12-18 10384]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-02-28 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-25 3565568]
R3 COMMONFX.SYS;COMMONFX.SYS; C:\WINDOWS\System32\drivers\COMMONFX.SYS [2009-03-04 99352]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2009-03-04 511000]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2009-03-04 528408]
R3 CTAUDFX.SYS;CTAUDFX.SYS; C:\WINDOWS\System32\drivers\CTAUDFX.SYS [2009-03-04 555032]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2009-03-04 14360]
R3 CTSBLFX.SYS;CTSBLFX.SYS; C:\WINDOWS\System32\drivers\CTSBLFX.SYS [2009-03-04 566296]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2009-03-04 157208]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2009-03-04 92696]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2005-06-22 43008]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2009-03-04 798744]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2009-03-04 162840]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2008-12-18 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2008-12-18 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2008-12-18 37392]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2008-12-18 28816]
R3 MAUSBFT;Service for M-Audio Fast Track USB (WDM); C:\WINDOWS\system32\DRIVERS\mausbft.sys [2007-11-13 132096]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-02-28 61824]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2009-03-04 127512]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2006-02-28 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-02-28 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-02-28 57600]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-02-28 20480]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
S3 catchme;catchme; \??\C:\DOCUME~1\SEANCA~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 COMMONFX;COMMONFX; C:\WINDOWS\system32\drivers\COMMONFX.SYS [2009-03-04 99352]
S3 CTAUDFX;CTAUDFX; C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2009-03-04 555032]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2009-03-04 347080]
S3 CTERFXFX.SYS;CTERFXFX.SYS; C:\WINDOWS\System32\drivers\CTERFXFX.SYS [2009-03-04 100888]
S3 CTERFXFX;CTERFXFX; C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2009-03-04 100888]
S3 CTSBLFX;CTSBLFX; C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2009-03-04 566296]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera; C:\WINDOWS\System32\Drivers\ubVeo532.sys [2002-07-01 95232]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2009-03-04 189464]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 KProcWatch;KProcWatch; \??\C:\WINDOWS\system32\drivers\KProcWatch.sys []
S3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2008-12-18 63248]
S3 LMouKE;SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2008-12-18 79248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys []
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-03-26 36864]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-25 602112]
R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-02-21 906520]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-02-21 285392]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2009-01-08 307200]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-23 1229232]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-10-11 38912]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-05-15 593920]
S3 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-26 132424]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-06-01 79360]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-02-18 121360]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Edited by Shocker1245, 01 March 2010 - 02:05 PM.


#15 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:05:06 PM

Posted 01 March 2010 - 03:56 PM

Your logs look fine to me now, you can follow these final cleanup steps to remove any tools we have used, if any
are left you can manualy remove them.


Uninstall ComboFix
  • Click START then RUN
  • Now type Combofix /uninstall in the run box and click OK. Note the space between the X and the /, it needs to be there.



Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Begin Cleanup Process". Please select Yes.
  • Restart your computer when prompted.


Congratulations! You now appear clean! thumbup.gif

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Update Windows
You don't have the latest service pack for windows, The service packs patch security vulnerabilities found in windows. You should
keep these upto date to keep you protected against malware, that can take advantage of these security vulnerabilities to attack
your system.The latest service pack is SP3, Click on Start >> All programs >> Windows update then select Express
and allow it to install all updates including SP3.
Note: If it prompts you to install an ActiveX control allow it to install it.

Update your AntiVirus Software
It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not
update your antivirus software then it will not be able to catch any of the new variants that may come out. If you
use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your
subscription runs out, you may not be able to update the programs virus definitions.

Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you.
Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly
patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Install a Firewall
I can not stress how important it is that you use a third party Firewall on your computer. Without a firewall your computer is
succeptible to being hacked and taken over. Windows firewall is good for blocking inbound connections but it does not block
outbound connections. So if Malware manages to get onto your computer it will be able to send data out when it wants.
Here are some free firewalls I would recomend, only install one of these.

Zone Alarm
comodo..........Note: Only Install the Firewall as a standalone if you already have an AntiVirus installed on your computer.

After you install the third party firewall, please disable your Windows firewall. Please go to My Computer >> Control Panel >> Windows Firewall
and choose Off (not recommended) option. Then click Apply and Ok.

Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you
from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Use MVPS hosts file
Using a custom host file like the MVPS HOSTS file can help to block ads, banners, 3rd party Cookies,
3rd party page counters, web bugs, and even most hijackers. It doesn't use up any extra system resources
and may even speed up the loading of web pages. You can download and find instructions below.

http://www.mvps.org/winhelp2002/hosts.htm

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Happy surfing smile.gif
Syler

unite.jpg





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users