Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected - Constant Pop-ups - Any Ideas Wot To Do Next?


  • Please log in to reply
10 replies to this topic

#1 mrloveeggs

mrloveeggs

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 15 February 2006 - 07:06 PM

Hey guys, would really appreciate some help on this one.

Constant pop-ups when on the internet.

Have got so far with the problem but unsure what steps to take next .

Have run a full scan with Ewido and performed a Hijack This scan. The results are shown below.

All advice gratefully received, Thanks alot.


---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 23:26:48, 15/02/2006
+ Report-Checksum: 824813CA

+ Scan result:

C:\Documents and Settings\Darren\Cookies\darren@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@paycounter[1].txt -> TrackingCookie.Paycounter : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Darren\Cookies\darren@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Program Files\Tiscali\Tiscali Internet\dlls\InstallDialer.exe/Dialer.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Program Files\Tiscali\Tiscali Internet\dlls\InstallDialer.exe/Dialer.exe -> Heuristic.Win32.Dialer : Cleaned with backup


::Report End


Logfile of HijackThis v1.99.1
Scan saved at 23:38:29, on 15/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BT Broadband\Help\bin\mpbtn.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Darren\LOCALS~1\Temp\Temporary Directory 2 for HijackThis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-24.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

Thanks Again,

Daz

BC AdBot (Login to Remove)

 


m

#2 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:55 AM

Posted 16 February 2006 - 09:37 AM

Hi There! :thumbsup:

I am currently working on your log

I will get back to you as soon as possible.

David :flowers:

#3 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:55 AM

Posted 16 February 2006 - 04:18 PM

Hi mrloveeggs

Your log is looking clean so i am suspicious of the cause of those popups. We need to dig a little deeper into places regular scans cannot reach. To use RootKit Revealer please make sure you are logged in as an Administrator to the computer. Whilst the rootkit revealer scan is running, make sure no other programs are open, and do not open the internet etc...
_____________________________

Although we may not be using HijackThis is the next step, i think we should move the program into the correct location. At the moment it is in a temporary folder. If it stays ther the backups made when items are fixed won't be secure. The easiest way to accomplish this is to reinstall and delete any copies of HijackThis.zip you have saved.

Please download the self-extracting version of HijackThis from here:

HijackThis_sfx download

Save HijackThis_sfx to your desktop.

Double-click the file then click the Unzip button. Then close the Self-Extractor window.

Using My Computer/Windows Explorer, navigate to C:\Program Files\HijackThis and double click on HijackThis.exe to run it. If you would like to make a shortcut for your Desktop so it's more easily accessable, right click HijackThis.exe and choose Send To > Desktop (create shortcut).

Please run the extracted HijackThis.exe from now on. Delete any copies of HijackThis.zip that you have saved.
_____________________________
  • Please download and unzip Rootkit Revealer to your desktop.
  • Please leave the defaults set as they are to:
    • Hide NTFS Metadata Files: this option is on by default
    • Scan Registry: this option is on by default.
  • Launch rootkit revealer on the system and press the Scan button. RootkitRevealer scans the system reporting its actions in a status area at the bottom of its window and noting discrepancies in the output list. It may take a long time please disconnect from the internet and leave the PC to be scanned until it is finished.
  • The log can be very large please edit out the items in the following folders in the log : C:\RECYCLER\NPROTECT and C:\System Volume Information, if in the log, before posting it.
  • Please post the balance of the log here in this thread using Add Reply (please double check that it has all been posted as it may be too long for one post)]
_____________________________

Then Download and Save blacklite to your desktop.
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
Double-click blbeta.exe then accept the agreement.
leave [X]scan through windows explorer checked,
click > scan then > next,
You'll see a list of all items found.
Don't choose for rename yet! I want to see the log first, because legit items can also be present there... like "wbemtest.exe"
There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
Copy and paste this log along with the rootkit revealer log.

David

#4 mrloveeggs

mrloveeggs
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 16 February 2006 - 06:47 PM

Thanks David I will do this overnight. Really appreciate your help.
:thumbsup:

#5 mrloveeggs

mrloveeggs
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 16 February 2006 - 07:30 PM

Hi David here is the Log file requested, Many thanks for your time.




HKLM\S-1-5-21-471828262-1040457341-2626639465-1006\Software\C1Xh3AG5dQt5 19/11/2005 11:05 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\C1Xh3AG5dQt5 28/01/2006 13:52 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\webcal\URL Protocol 16/11/2004 01:31 13 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_WZCHOST 26/11/2005 12:03 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch 16/02/2006 23:34 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DhcpNameServer 16/02/2006 23:37 24 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6C84FAA9-D200-410C-BD80-C75E2D69C0BF}\DhcpRetryTime 16/02/2006 23:37 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6C84FAA9-D200-410C-BD80-C75E2D69C0BF}\DhcpRetryStatus 16/02/2006 23:37 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6C84FAA9-D200-410C-BD80-C75E2D69C0BF}\DhcpNameServer 16/02/2006 23:37 24 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6C84FAA9-D200-410C-BD80-C75E2D69C0BF}\DhcpDefaultGateway 16/02/2006 23:37 26 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6C84FAA9-D200-410C-BD80-C75E2D69C0BF}\DhcpSubnetMaskOpt 16/02/2006 23:37 30 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\wuauserv 16/02/2006 23:10 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\WZChost 16/02/2006 23:10 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\{6C84FAA9-D200-410C-BD80-C75E2D69C0BF}\Parameters\Tcpip\DhcpDefaultGateway 16/02/2006 23:37 26 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\{6C84FAA9-D200-410C-BD80-C75E2D69C0BF}\Parameters\Tcpip\DhcpSubnetMaskOpt 16/02/2006 23:37 30 bytes Hidden from Windows API.
C:\Program Files\Inslorer 16/02/2006 00:00 0 bytes Hidden from Windows API.
C:\Program Files\Inslorer\ace.dll 26/11/2005 12:03 568.00 KB Hidden from Windows API.
C:\Program Files\Inslorer\AI_10-02-2006.log 10/02/2006 15:55 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\AI_11-02-2006.log 11/02/2006 08:43 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\AI_12-02-2006.log 12/02/2006 13:00 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\AI_14-02-2006.log 14/02/2006 18:20 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\AI_15-02-2006.log 15/02/2006 21:05 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\AI_16-02-2006.log 16/02/2006 00:00 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache 16/02/2006 23:47 0 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000001c_43d69724_0008583b 24/01/2006 21:07 9.97 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_438d8a4a_000c28cb 23/01/2006 16:26 12.23 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43a6b765_0003d090 07/02/2006 16:14 12 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43bc0189_00022551 16/02/2006 18:18 2.12 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43c28ee4_0006acfc 16/02/2006 18:14 2.65 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43c77602_000d59f8 01/02/2006 12:32 8.21 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43d4c9ae_000ca2dd 23/01/2006 12:18 3.02 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43d4ddeb_0005f5e1 23/01/2006 13:45 4.79 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43d7a66e_00029f63 25/01/2006 16:25 33.83 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43d7d02c_00094c5f 25/01/2006 19:23 14.28 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43da444f_000e8b25 27/01/2006 16:03 54.04 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43db4e01_000f0537 11/02/2006 08:52 4.76 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43de4887_000501bd 30/01/2006 17:10 339 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43e0a9e2_00039387 16/02/2006 18:14 114 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43e0c0e9_00057bcf 01/02/2006 14:08 4.71 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43e0e2da_00076417 01/02/2006 16:33 2.99 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43e8c7e0_0000aa71 07/02/2006 16:16 4.84 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43ecb7fe_000a7d8c 10/02/2006 15:57 1.00 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43edfa55_00066ff3 11/02/2006 14:53 62.40 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43ef31ae_00044aa2 16/02/2006 23:37 6.73 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43f23043_0008d24d 14/02/2006 19:32 165.77 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43f3af4d_00022551 15/02/2006 22:49 52.17 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43f4c0d5_0007de29 16/02/2006 18:13 24 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000029_43f50c9b_00081b32 16/02/2006 23:36 187 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000035_43d660fe_000632ea 24/01/2006 17:16 124.27 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000035_43df5ef9_0006acfc 31/01/2006 12:58 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000035_43e8d6b1_000d59f8 07/02/2006 17:19 183.82 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000035_43f4c3ee_00094c5f 16/02/2006 18:26 46.28 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000007b_43d69001_00007a12 24/01/2006 20:37 4.65 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000008c_43d68fea_000cdfe6 24/01/2006 20:36 15.91 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000094_43d699c1_000e1113 24/01/2006 21:18 2.76 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43917668_000a4083 14/02/2006 19:35 101.74 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_439475ed_0003d090 07/02/2006 17:06 303 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43c77841_00090f56 10/02/2006 16:03 15.86 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43ce72e4_000e1113 18/01/2006 16:55 227.60 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43d36fe1_000487ab 22/01/2006 11:43 6.27 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43d4e098_0007de29 23/01/2006 14:11 226.68 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43d54511_0007de29 23/01/2006 21:05 81.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43d7a80f_0003567e 25/01/2006 16:32 14.09 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43d8efac_0006ea05 26/01/2006 15:50 3.55 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43da467f_00007a12 27/01/2006 16:12 5.82 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43db7c6f_00000000 28/01/2006 14:15 82.25 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43dcd575_0001e848 29/01/2006 14:47 6.26 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43de5eda_0005f5e1 30/01/2006 18:46 33.13 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43de94b5_000a7d8c 30/01/2006 22:35 410 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43df7dac_000d9701 31/01/2006 15:09 48.36 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43df9bbd_00029f63 31/01/2006 17:17 74.30 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43e8cbfd_0006acfc 07/02/2006 16:34 56.99 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43ea33d2_000a7d8c 08/02/2006 18:09 43.60 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43ecb96b_000dd40a 10/02/2006 16:03 8.40 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43edfc5a_000e1113 11/02/2006 15:01 164.48 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43ef3329_00066ff3 12/02/2006 13:07 3.38 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43f22287_000ebca1 14/02/2006 18:33 392 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43f23b92_00000000 14/02/2006 20:20 4.49 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43f3b233_000d9701 15/02/2006 22:58 713 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000099_43f4c192_000d9701 16/02/2006 18:16 4.67 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000000c1_43d68a51_000ca2dd 24/01/2006 20:13 51.13 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43b964e2_000d1cef 24/01/2006 20:44 21.44 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43d38da5_00026922 22/01/2006 13:50 1.05 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43d50768_0000b71b 23/01/2006 16:42 16.41 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43d65b4a_000c65d4 24/01/2006 16:52 67.06 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43d7c452_000dd40a 25/01/2006 18:32 57.80 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43d8f567_0007a120 26/01/2006 16:14 58.41 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43da4d81_0000b71b 27/01/2006 16:42 240 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43db59a2_0003567e 28/01/2006 11:46 3.91 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43de8822_000d59f8 30/01/2006 21:41 86.43 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43df58b6_000a037a 31/01/2006 12:38 19.35 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43e0abee_000e1113 01/02/2006 12:39 50.55 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43e8cdea_0005f5e1 07/02/2006 16:42 34.75 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43ea37b5_00094c5f 08/02/2006 18:25 117.19 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43ecbb63_000f0537 10/02/2006 16:12 0 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43f2645b_000ec82e 14/02/2006 23:14 219 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43f3baca_0003567e 15/02/2006 23:35 5.83 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000120_43f4c234_0005f5e1 16/02/2006 18:19 4.68 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_439475ed_000cdfe6 07/02/2006 17:06 465 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43b29c04_00022551 25/01/2006 18:34 5.08 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43c77843_00029f63 10/02/2006 16:03 5.07 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43ce72ea_00016e36 18/01/2006 16:55 121.12 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43d36ff1_000ca2dd 22/01/2006 11:43 83.67 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43d54512_0002625a 23/01/2006 21:05 312 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43d65686_000632ea 27/01/2006 16:10 8.09 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43d7a816_00081b32 12/02/2006 13:01 74.49 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43d8efda_000487ab 11/02/2006 14:52 19.70 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43da4689_00031975 27/01/2006 16:12 6.27 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43db5049_00040d99 28/01/2006 11:06 0 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43de94b6_000b71b0 30/01/2006 22:35 3.72 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43df7dc0_00022551 31/01/2006 15:09 45.78 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43df9bbd_0008d24d 31/01/2006 17:17 324 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43ea33e9_0007a120 08/02/2006 18:09 43.05 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43ecb971_0002dc6c 10/02/2006 16:04 8.10 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43edfc5b_0007a120 11/02/2006 15:01 3.73 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43ef3334_0005f5e1 12/02/2006 13:08 2.11 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43f22287_000f36b3 14/02/2006 18:33 2.29 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43f23b9a_00016e36 14/02/2006 20:20 68.53 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43f3b241_0000b71b 15/02/2006 22:59 81.89 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000124_43f4c194_000c65d4 16/02/2006 18:16 104.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000012c_43d69325_00007a12 24/01/2006 20:50 39.65 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000012f_43d6962e_00022551 24/01/2006 21:03 8.46 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000014f_43d694d2_00007a12 24/01/2006 20:57 1.09 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001d3_43df5ef9_000b34a7 31/01/2006 12:58 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001d3_43e8d705_000c65d4 07/02/2006 17:21 107.00 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001e1_43d68bb2_00022551 24/01/2006 20:18 450 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_439175ea_000cdfe6 14/02/2006 19:32 8.54 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_439d6969_00094c5f 08/02/2006 18:28 15.29 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43a9940d_000ec82e 14/02/2006 23:19 39.03 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43ce7169_0005f5e1 23/01/2006 13:52 14.86 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43d36f95_00066ff3 22/01/2006 11:42 266 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43d4e05e_000a7d8c 23/01/2006 13:55 3.73 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43d544ff_000b71b0 23/01/2006 21:05 74.90 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43d65630_00066ff3 24/01/2006 16:30 295 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43d7a729_00016e36 25/01/2006 16:28 30.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43d7d140_00057bcf 25/01/2006 19:28 56.17 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43d8ef49_0006acfc 26/01/2006 15:48 4.10 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43da4630_00022551 27/01/2006 16:11 5.23 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43db4eba_0001e848 28/01/2006 11:00 14.00 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43db7bce_00044aa2 28/01/2006 14:12 5.20 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43dcd4d1_0008583b 29/01/2006 14:44 82.25 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43de5e9f_0002dc6c 30/01/2006 18:44 89.97 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43de945c_0008d24d 30/01/2006 22:34 116.45 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43df5686_0006acfc 31/01/2006 12:22 3.72 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43df7ced_000501bd 31/01/2006 15:06 7.45 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43df9b67_00000000 31/01/2006 17:16 77.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43e0e370_0005b8d8 01/02/2006 16:36 919 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43e8ca71_0007de29 07/02/2006 16:27 4.69 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43ea333a_0004c4b4 08/02/2006 18:06 6.27 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43edfbad_000e1113 11/02/2006 14:58 19.87 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43ef3293_000a037a 12/02/2006 13:05 1 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43f2227f_000162a9 14/02/2006 18:33 1.23 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43f23201_000e8b25 14/02/2006 19:39 93.43 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43f3b06a_0007270e 15/02/2006 22:51 4.84 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43f4c15a_00016e36 16/02/2006 18:15 7.95 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001eb_43f50f1b_00003d09 16/02/2006 23:47 7.62 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000001f7_43d695b4_0002dc6c 24/01/2006 21:01 10.14 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000260_43d69755_000a4083 24/01/2006 21:08 10.26 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000262_43d6940d_0007a120 24/01/2006 20:54 66.55 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000002ee_43d6960e_000ca2dd 24/01/2006 21:03 67.17 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_4391863a_0001312d 23/01/2006 12:21 390 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43d38d96_000afe66 22/01/2006 13:50 33.48 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43d50453_000ec82e 14/02/2006 23:14 9.27 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43d65af3_000632ea 24/01/2006 16:50 142.01 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43d7c447_00076417 25/01/2006 18:32 4.88 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43d8f4d5_000baeb9 26/01/2006 16:12 62.77 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43da4d42_0001e848 27/01/2006 16:41 22 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43de8814_0004c4b4 30/01/2006 21:41 4.03 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43df58b1_00057bcf 31/01/2006 12:32 19.13 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43e8cde0_00089544 07/02/2006 16:42 34.75 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43ea379f_00081b32 08/02/2006 18:25 104.06 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43ecbb61_000d9701 10/02/2006 16:12 147.60 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43f26443_0001312d 15/02/2006 23:01 630 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000030a_43f3ba64_0006acfc 15/02/2006 23:33 3.76 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000036b_43d693ee_000a037a 24/01/2006 20:54 34.11 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000384_43d65ff0_00039387 24/01/2006 17:12 50.99 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000384_43df5dbf_0008d24d 31/01/2006 12:53 105.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000384_43e8d352_0003567e 07/02/2006 17:05 4.29 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000038f_43d69167_000ec82e 24/01/2006 20:43 51.47 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000390_43d68b62_00022551 24/01/2006 20:17 411 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000003f9_43d69416_000ec82e 24/01/2006 20:54 64.49 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000046b_43d69910_000487ab 24/01/2006 21:16 56.78 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000047e_43d3a053_000006c8 22/01/2006 15:10 36.58 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000047e_43d65ef2_000dd40a 24/01/2006 17:08 127.58 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000047e_43df5b4e_000501bd 31/01/2006 12:44 108.36 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000047e_43e8d077_0004c4b4 07/02/2006 16:53 1.95 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000047e_43f3c220_0009c671 16/02/2006 00:06 7.22 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000047e_43f4c37d_000baeb9 16/02/2006 18:25 762 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000004b0_43d69023_00022551 24/01/2006 20:37 4.64 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000004f0_43d69007_000c28cb 24/01/2006 20:37 12.42 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000054b_43d698f2_000a4083 24/01/2006 21:15 135.32 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000588_43d672b5_0002625a 24/01/2006 18:32 81.56 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000065a_43d6902e_00053ec6 24/01/2006 20:38 4.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000065a_43d69234_000632ea 24/01/2006 20:46 51.85 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000665_43d692d4_000af79e 24/01/2006 21:07 44.54 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000672_43d69938_0005b8d8 24/01/2006 21:16 1.21 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000677_438b16db_00093267 11/02/2006 08:52 285.30 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000677_43df5e06_00090f56 31/01/2006 12:54 210.32 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000677_43e8d365_0007a120 07/02/2006 17:05 3.66 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000677_43f4c3c7_0005f5e1 16/02/2006 18:26 105.17 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000006d8_43d693e2_000baeb9 24/01/2006 20:53 1.67 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000006de_43d69760_0008583b 24/01/2006 21:08 10.25 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000006e9_43d69679_00098968 24/01/2006 21:04 64.28 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000728_43d68b62_0003d090 24/01/2006 20:17 2.80 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43918658_0002625a 15/02/2006 22:59 82.25 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43d38da4_00095327 22/01/2006 13:50 35.29 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43d5075e_000632ea 23/01/2006 16:42 15.98 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43d65b17_00007a12 24/01/2006 16:51 295 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43d7c452_00057bcf 25/01/2006 18:32 3.16 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43d8f4e3_0007de29 26/01/2006 16:12 1.32 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43da4d7c_0008d24d 27/01/2006 16:42 54.49 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43db59a1_000b34a7 28/01/2006 11:46 115.17 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43de8822_00076417 30/01/2006 21:41 82.70 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43df58b2_0005f5e1 31/01/2006 12:32 991 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43e0ab6c_0005f5e1 01/02/2006 12:37 56.41 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43e8cde8_000b34a7 07/02/2006 16:42 34.75 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43ecbb63_0003d090 10/02/2006 16:12 8.14 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43f2644a_000487ab 14/02/2006 23:14 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000732_43f3ba6b_000e4e1c 15/02/2006 23:34 752 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_439176f5_0007de29 30/01/2006 21:49 73.40 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43ce732e_000d9701 18/01/2006 16:56 78.14 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43d37010_000ca2dd 22/01/2006 11:44 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43d4e2bb_000dd40a 23/01/2006 14:05 68.50 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43d65810_000dd40a 24/01/2006 16:38 7.74 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43d7a8dd_000a037a 25/01/2006 16:35 303 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43d8f0bc_0006acfc 26/01/2006 15:54 7.16 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43da4bd7_000632ea 27/01/2006 16:35 459 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43db5096_000a4083 28/01/2006 11:08 118.56 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43db7dd7_0009c671 28/01/2006 14:21 102.88 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43de6114_0002625a 30/01/2006 18:55 34.76 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43df577b_000dd40a 31/01/2006 12:26 4.46 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43df7e72_00076417 31/01/2006 15:12 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43df9bdf_0005f5e1 31/01/2006 17:18 416 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43e8cc7b_000baeb9 07/02/2006 16:36 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43ea3588_0004c4b4 08/02/2006 18:16 103.48 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43ecbab1_0002dc6c 11/02/2006 14:53 16.73 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43edfc84_0008d24d 11/02/2006 15:02 416 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43ef33f6_00094c5f 12/02/2006 13:11 0 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43f23ddd_000e1113 14/02/2006 20:30 49.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43f3b2bd_000d9701 15/02/2006 23:01 87.39 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000074d_43f4c1e0_000501bd 16/02/2006 18:18 72.42 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000007c9_43d692f0_0007270e 24/01/2006 20:58 3.59 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000007cf_43df5ef9_0007a120 31/01/2006 12:58 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000007cf_43e8d6b5_000bebc2 07/02/2006 17:19 130.28 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000007cf_43f4c3ef_00016e36 16/02/2006 18:26 3.93 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000007db_43d69919_0001312d 24/01/2006 21:16 75.48 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43babfbf_0003567e 26/01/2006 17:45 36.20 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43c504df_000487ab 11/02/2006 15:03 630 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43d39ff8_000afe66 22/01/2006 15:08 384 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43d5281b_0000f424 23/01/2006 19:01 297 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43d65e1c_000e8b25 24/01/2006 17:04 248 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43d90a32_000af79e 26/01/2006 17:43 3.67 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43da4f3b_00044aa2 27/01/2006 16:50 20.08 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43df59fa_0007a120 31/01/2006 12:38 2.89 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43e8cf8b_0008d24d 07/02/2006 16:49 1.96 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43f26acf_00090f56 14/02/2006 23:42 23.55 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43f3bd34_0001312d 15/02/2006 23:45 7.56 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000822_43f4c302_000aba95 16/02/2006 18:22 105.17 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000828_43d6972f_00090f56 24/01/2006 21:07 9.97 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000084d_43d68fec_00081b32 24/01/2006 20:37 4.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000086a_438b1ea5_000f2848 16/02/2006 18:27 17.06 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000086a_43d67ead_000b34a7 24/01/2006 19:23 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000871_43d68bc7_0006ea05 24/01/2006 20:19 33.47 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000878_43d68bfc_0004c4b4 24/01/2006 20:20 463 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000008af_43d691cb_00090f56 24/01/2006 20:44 55.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000008ff_43d69023_0009c671 24/01/2006 20:37 4.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43c56caf_000c65d4 07/02/2006 16:48 115.83 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43d3a015_000080da 22/01/2006 15:09 323 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43d52903_0006acfc 23/01/2006 19:06 90.02 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43d7c587_000632ea 25/01/2006 18:37 8.39 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43d90bed_000c28cb 26/01/2006 17:50 28.42 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43da500e_000dd40a 27/01/2006 16:53 72.35 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43db748f_000bebc2 28/01/2006 13:41 7.78 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43df5a7b_0003d090 31/01/2006 12:39 16.36 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43e8cfae_00081b32 07/02/2006 16:49 922 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43f3be21_000c28cb 15/02/2006 23:49 8.59 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000902_43f4c313_000b34a7 16/02/2006 18:23 3.80 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000914_43d69024_00016e36 24/01/2006 20:37 4.64 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000093b_43d695bd_000bebc2 24/01/2006 21:01 63.85 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000975_43d669c2_000d1cef 28/01/2006 11:03 8.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000975_43df5f29_00090f56 31/01/2006 12:59 8.35 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000975_43e8d7cc_000632ea 07/02/2006 17:24 324 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000009b3_43d6915d_00007a12 24/01/2006 20:43 21.12 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000009ce_43d674c0_00098968 24/01/2006 18:41 345 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000009ce_43e8db18_00094c5f 07/02/2006 17:38 0 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a1d_43d69490_000c65d4 24/01/2006 20:56 20.41 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a28_43d674bf_000e1113 24/01/2006 18:41 125.04 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a28_43e8db15_000f0537 07/02/2006 17:38 414 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a2f_43d69157_000bebc2 24/01/2006 20:43 66.35 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a41_43d68fff_000e4e1c 24/01/2006 20:37 4.61 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a4a_43d6715a_0007de29 24/01/2006 18:26 3.93 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a4a_43e8da2b_000e4e1c 07/02/2006 17:34 48.74 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000a87_43d68feb_00094c5f 24/01/2006 20:36 4.61 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000b31_43d6968a_00057bcf 24/01/2006 21:05 67.16 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000b7f_43d69732_00053ec6 24/01/2006 21:08 9.97 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000b93_43d690ad_00098968 24/01/2006 20:40 39.86 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_439175ff_00039387 14/02/2006 19:32 6.47 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43baa857_00040d99 24/01/2006 16:39 75.28 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43c55b0e_000c28cb 30/01/2006 21:49 85.34 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43ce719d_0005f5e1 18/01/2006 16:49 22.66 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43d36fae_00007a12 22/01/2006 11:42 127.38 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43d4e06f_0003d090 23/01/2006 13:56 226.41 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43d54500_00090f56 23/01/2006 21:05 297 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43d65635_0003567e 24/01/2006 16:30 115.11 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43d7a731_000b71b0 25/01/2006 16:28 5.49 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43d8ef5e_000e4e1c 26/01/2006 15:48 18.49 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43da4630_000b71b0 27/01/2006 16:11 391 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43db4eba_00089544 28/01/2006 11:00 2.35 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43db7bce_000632ea 28/01/2006 14:12 2.87 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43dcd4dc_000a037a 29/01/2006 14:44 90.20 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43de5ea3_000487ab 30/01/2006 18:44 240 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43df5687_00044aa2 31/01/2006 12:22 790 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43df7ced_0006ea05 31/01/2006 15:06 29 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43df9b67_00053ec6 31/01/2006 17:16 3.72 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43e0aa6f_000baeb9 01/02/2006 12:32 72.79 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43e0e370_000b71b0 01/02/2006 16:36 1.71 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43e8caf6_00044aa2 07/02/2006 16:29 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43ea3345_000b71b0 08/02/2006 18:07 46.27 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43ecb8bc_000d59f8 10/02/2006 16:01 8.00 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43edfbb9_000a037a 11/02/2006 14:59 15.87 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43ef32aa_000d9701 12/02/2006 13:05 92.10 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43f22284_000903c9 14/02/2006 18:33 1.72 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43f2320e_0000b71b 14/02/2006 19:39 2.01 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43f3b082_0008583b 15/02/2006 22:51 57.24 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bb3_43f4c15c_00098968 16/02/2006 18:15 8.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43918650_000a7d8c 15/02/2006 22:58 117.52 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43d38d98_0002e334 22/01/2006 13:50 1.56 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43d65afd_00031975 24/01/2006 16:51 115.59 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43d7c44b_0000b71b 25/01/2006 18:37 1.88 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43da4d73_00076417 27/01/2006 16:42 88.38 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43db5977_0005f5e1 28/01/2006 11:45 1.00 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43de881c_0001e848 30/01/2006 21:41 73.66 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43df58b2_0003567e 31/01/2006 12:32 12.99 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43e8cde3_000c65d4 07/02/2006 16:42 34.75 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43ea37a5_0003d090 08/02/2006 18:25 110.80 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43ecbb62_0007a120 10/02/2006 16:12 3.70 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43f26448_00039387 14/02/2006 23:14 124.70 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000bdb_43f3ba67_0000b71b 15/02/2006 23:33 38.79 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000c15_43d66ad7_00022551 08/02/2006 18:21 908 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000c15_43df605c_00089544 31/01/2006 13:04 7.77 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000c15_43e8d8d1_0008d24d 07/02/2006 17:28 905 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000c7b_438b1865_000f2848 15/02/2006 23:01 240 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000c7b_43d66acf_000af79e 24/01/2006 17:58 49.97 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000c7b_43e8d8bd_00089544 07/02/2006 17:28 4.42 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000c95_43d691ff_000d9701 24/01/2006 20:45 4.69 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ce1_43d68a54_0006ea05 24/01/2006 20:13 9.78 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000d1f_43d697ca_00044aa2 24/01/2006 21:10 123.91 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000d66_43d3a056_000043d1 22/01/2006 15:10 2.10 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000d66_43d65f3e_000e4e1c 24/01/2006 17:09 331.34 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000d66_43df5baa_0008d24d 31/01/2006 12:45 111.31 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000d66_43e8d14c_000501bd 07/02/2006 16:56 4.52 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000d9f_43d68fff_00081b32 24/01/2006 20:37 4.66 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000dc7_43d69719_000aba95 24/01/2006 21:07 1.45 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43d39ec3_0005fca9 22/01/2006 15:03 3.77 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43d527cf_00003d09 23/01/2006 19:00 3.73 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43d65cde_000c65d4 07/02/2006 17:30 9.67 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43d8f75a_000487ab 11/02/2006 08:44 267.74 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43da4e19_000d1cef 27/01/2006 16:45 26 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43db59fa_000ec82e 28/01/2006 11:48 1.59 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43e8ce72_00094c5f 07/02/2006 16:44 69.35 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43ea3820_000cdfe6 08/02/2006 18:27 293 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43ecbf7c_00057bcf 10/02/2006 16:29 151.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43f268db_000487ab 14/02/2006 23:33 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ddc_43f4c28f_000b71b0 16/02/2006 18:21 105.17 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000de5_43d6731f_0001ab3f 24/01/2006 18:34 289 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000de5_43e8db0a_00076417 07/02/2006 17:38 308 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e00_43d6903a_0002625a 24/01/2006 20:38 4.61 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e12_43bac2c2_000af79e 07/02/2006 17:13 56.97 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e12_43d66050_00016e36 24/01/2006 17:13 62.44 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e12_43df5ea9_0002625a 31/01/2006 12:57 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e12_43e8d52a_0000f424 07/02/2006 17:13 82.68 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e12_43f4c3d2_0007a120 16/02/2006 18:26 46.23 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e90_43d6698f_00000000 24/01/2006 17:53 6.47 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e90_43df5ef9_000bebc2 31/01/2006 12:58 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000e99_43d69001_0003567e 24/01/2006 20:37 4.64 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ea9_43d689e4_000b71b0 24/01/2006 20:42 101.46 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ecc_43df5ef9_00098968 31/01/2006 12:58 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ecc_43e8d6f2_000af79e 07/02/2006 17:20 21.96 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ecc_43f4c400_0007de29 16/02/2006 18:27 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ef5_43d694d3_000af79e 24/01/2006 20:57 5.40 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_438d8857_00000000 01/02/2006 14:08 603 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_438dfcdc_0009c671 07/02/2006 16:14 14 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_439475ec_000c28cb 07/02/2006 17:06 472 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43c77837_000ec82e 10/02/2006 16:00 12.08 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43ce72de_0001e848 18/01/2006 16:54 740 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43d36fdd_000d9701 22/01/2006 11:43 3 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43d4e08b_000c28cb 23/01/2006 13:56 3.73 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43d54509_000d1cef 23/01/2006 21:05 320 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43d65668_00039387 24/01/2006 16:31 3.71 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43d8efa6_0007de29 26/01/2006 15:49 1.96 MB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43da467a_00044aa2 27/01/2006 16:12 5.24 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43db7c6e_000b71b0 28/01/2006 14:15 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43dcd570_00031975 29/01/2006 14:47 151.19 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43de5eb8_000aba95 30/01/2006 18:48 103.22 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43df56a1_000baeb9 31/01/2006 12:22 4.69 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43df7d63_000a7d8c 31/01/2006 15:08 1.41 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43df9b91_00000000 31/01/2006 17:17 732 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43ea33bd_00094c5f 14/02/2006 23:24 50.77 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43ecb92b_00089544 10/02/2006 16:02 4.05 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43edfc48_000e4e1c 11/02/2006 15:01 57.38 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43ef3324_000d1cef 12/02/2006 13:11 31.76 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43f22287_000cd459 14/02/2006 18:33 582 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43f23b8a_00044aa2 14/02/2006 20:20 51.79 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43f3b0d4_0006acfc 15/02/2006 22:53 61.05 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000f3e_43f4c191_000ec82e 16/02/2006 18:16 1011 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fbf_43c5052a_00094c5f 11/02/2006 15:03 1.38 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fbf_43d65eed_0002dc6c 24/01/2006 17:07 117.25 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fbf_43df5b2d_000af79e 31/01/2006 12:42 60.56 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fbf_43e8d075_000ec82e 07/02/2006 16:53 27.96 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fbf_43f3c05e_0007270e 15/02/2006 23:59 3.83 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fbf_43f4c378_000d59f8 16/02/2006 18:24 339 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fc9_43d66042_000a7d8c 24/01/2006 17:13 153.50 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fc9_43df5ea9_0000f424 31/01/2006 12:57 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000fc9_43e8d529_000c28cb 07/02/2006 17:13 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00000ff4_43d695a0_00098968 24/01/2006 21:01 9.96 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001030_43d68bb2_0007de29 24/01/2006 20:18 303 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001049_43d67ead_00039387 24/01/2006 19:23 289 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000105a_43d69919_000d59f8 24/01/2006 21:16 3.91 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001075_43d699c9_000f0537 24/01/2006 21:19 3.91 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000010d9_43d68b26_000c28cb 24/01/2006 20:16 5.08 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000010d9_43d68ba3_0005f5e1 24/01/2006 20:18 31.97 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000113e_43d68c4d_00053ec6 24/01/2006 20:22 4.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000117a_43d68bf6_00053ec6 24/01/2006 20:20 98.68 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000011b8_43d69783_00029f63 24/01/2006 21:09 9.95 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000011d5_43d69039_00053ec6 24/01/2006 20:38 4.63 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000011f4_43bac31f_0005f5e1 25/01/2006 18:45 83.50 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000011f4_43d66054_0005b8d8 24/01/2006 17:13 345 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000011f4_43df5ea9_00090f56 31/01/2006 12:57 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000011f4_43e8d675_00044aa2 07/02/2006 17:18 55.59 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43c504e7_0006acfc 11/02/2006 15:03 1.39 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43d3a012_0009cd39 22/01/2006 15:09 57.93 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43d528a8_00022551 23/01/2006 19:06 18.24 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43d7c581_00057bcf 25/01/2006 18:38 7.95 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43d90b8f_00003d09 26/01/2006 17:49 21.60 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43da4f85_0001e848 27/01/2006 16:51 77.28 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43df5a51_00090f56 31/01/2006 12:38 2.87 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43e8cfa9_00031975 07/02/2006 16:51 343 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000121f_43f3bddc_000b34a7 15/02/2006 23:53 52.46 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43a6b979_000632ea 12/02/2006 13:04 104 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43ce73cd_00081b32 18/01/2006 16:58 444 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43d37174_000043d1 22/01/2006 11:50 27.55 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43d4e3ae_000ca2dd 23/01/2006 14:09 3.93 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43d6596f_0007270e 24/01/2006 16:44 47 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43d7c39c_0007a120 25/01/2006 18:29 165.69 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43d8f28a_000e1113 26/01/2006 16:02 71.19 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43da4c01_000ec82e 27/01/2006 16:36 3.64 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43db5563_0003d090 28/01/2006 11:28 273 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43de61d8_00053ec6 30/01/2006 18:58 144.47 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43df5836_0002625a 31/01/2006 12:29 17.59 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43df7f4f_0009c671 31/01/2006 15:16 73.48 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43e0aad5_0005f5e1 01/02/2006 12:34 69.32 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43ecbb45_000a037a 15/02/2006 23:01 1.39 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43edfcde_000b34a7 11/02/2006 15:03 909 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43f223a8_000903c9 14/02/2006 18:43 5.64 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43f26305_00003d09 14/02/2006 23:14 84.73 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43f3b8f2_0006ea05 15/02/2006 23:27 3.84 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001238_43f4c1f7_00040d99 16/02/2006 18:18 74.38 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001243_43d6919b_000a037a 24/01/2006 20:44 59.11 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000127e_43d66093_0000f424 24/01/2006 17:14 69.80 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000127e_43df5ef9_00053ec6 31/01/2006 12:58 4 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\0000127e_43e8d6ac_000bebc2 07/02/2006 17:19 183.47 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\00001289_43d68beb_00003d09 24/01/2006 20:19 109.25 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_438b0fdf_000b34a7 14/02/2006 18:36 194.10 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43c5020c_00098968 26/01/2006 16:12 2.10 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43ce72a7_00029f63 18/01/2006 16:53 5.52 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43d36fc0_000bebc2 22/01/2006 11:42 120.16 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43d54503_00076417 23/01/2006 21:05 392 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43d6563a_00031975 24/01/2006 16:30 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43d7a7b4_000a7d8c 25/01/2006 16:30 4.84 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43d8ef67_000a7d8c 26/01/2006 15:48 23.95 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43da463a_00029f63 27/01/2006 16:11 10.92 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43db4f16_000f0537 28/01/2006 11:01 14.53 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43dcd51b_00029f63 29/01/2006 14:45 298 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43de5ea3_000ec82e 30/01/2006 18:44 86.98 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43de948a_00057bcf 11/02/2006 15:03 472 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43df56a0_000c28cb 31/01/2006 12:22 4.30 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43df7cf8_0008d24d 31/01/2006 15:06 122 bytes Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43df9b8f_000b34a7 31/01/2006 17:17 72.53 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43e0e372_000c65d4 01/02/2006 16:36 5.30 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43e8cb03_0000b71b 07/02/2006 16:29 78.89 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43ea3394_000487ab 08/02/2006 18:08 627.95 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43ecb8df_000a7d8c 14/02/2006 18:48 19.09 KB Hidden from Windows API.
C:\Program Files\Inslorer\Cache\000012db_43edfc37_000aba95 11/02/2006 15:01 15.27 KB Hidden from

#6 mrloveeggs

mrloveeggs
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 16 February 2006 - 07:37 PM

Hi David,

Obviously the first post is not complete, this is huge file can I email it instead?

If not I will put it all on in stages tomorrow.

#7 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:55 AM

Posted 17 February 2006 - 04:32 PM

Thanks mrloveeggs, at the moment i don't need the rest - i've seen enough! We're dealing with an apropos rootkit -quite nasty but relatively easy to clean. Let's get going then:

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download AproposFix from here:
http://swandog46.geekstogo.com/aproposfix.exe

Save it to your desktop but do NOT run it yet.

Then please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop. Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.

When the tool is finished, please reboot back into normal mode, and post a new HijackThis log, along with the entire contents of the log.txt file in the aproposfix folder.

David

#8 mrloveeggs

mrloveeggs
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 20 February 2006 - 05:51 PM

Hi David,


These are the results.

Logfile of HijackThis v1.99.1
Scan saved at 22:47:33, on 20/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\BT Broadband\Help\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\imapi.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-24.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe





Log of AproposFix v1.1

************

Running from directory:
C:\Documents and Settings\Darren\Desktop\aproposfix

************



Registry entries found:

[HKEY_LOCAL_MACHINE\Software\C1Xh3AG5dQt5]
@="DGxOVZahiihiiji6x:6x:hiihxkiD:4y5D9iZfZaLToniKYPcLYZicPKTZPUajZfZ"
"Device"="\\\\.\\PCIPCI"
"DriverPath"="C:\\WINDOWS\\system32\\drivers\\vidmsint.sys"
"DriverName"="WZChost"
"HideUninstallerName"="C:\\Program Files\\Inslorer\\csrtofmt.exe"
"UninstallerPath"="C:\\WINDOWS\\system32\\catgdi.exe"
"UninstallerRegKey"="HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{4C31DFEE-EC81-4D90-AB80-0C5BA0960D95}"
"UninstallerParams"="/CTUN"
"HDll"="C:\\WINDOWS\\system32\\wexdpv11.dll"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="http://adchannel.contextplus.net/legal-note/nonbranded.html"
"PartnerId"="CP.IST2"
"InstallationId"="{X714c1a6-999a-5f3a-188a-bbb2bc9b44b3}"
"PageFiltering"=dword:00000001
"CrMnTmt"=dword:0036ee80

************

Removing hidden service:
Service WZChost removed.

Removing hidden folder:
Deletion of folder Inslorer succeeded!

Deleting files:

Deletion of file C:\WINDOWS\system32\drivers\vidmsint.sys succeeded!
Deletion of file C:\WINDOWS\system32\ltwanmap.exe succeeded!
Deletion of file C:\WINDOWS\system32\wexdpv11.dll succeeded!
Deletion of file C:\WINDOWS\system32\catgdi.exe succeeded!

Backing up files:
Done!

Removing registry entries:

REGEDIT4

[-HKEY_CURRENT_USER\Software\C1Xh3AG5dQt5]
[-HKEY_LOCAL_MACHINE\Software\C1Xh3AG5dQt5]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4C31DFEE-EC81-4D90-AB80-0C5BA0960D95}]

Done!

Finished!


Hope this helps.

Thanks very much for your time in helping me out, I really do appreciate it.

Daz.

#9 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:55 AM

Posted 21 February 2006 - 03:39 AM

Well done! :thumbsup:

How do you feel the system is running? Are you still getting the pop-ups?

David

#10 mrloveeggs

mrloveeggs
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 21 February 2006 - 11:53 AM

Thanks David,

Everything is running much faster and the pop ups problem has totally disappeared.

Fantastic and thanks very much again.

Daz.

:thumbsup:

#11 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:55 AM

Posted 22 February 2006 - 06:58 PM

Hi mrloveeggs

Please advise on any problems you may still have, and don't hesitate to ask any questions.
_____________________________

Now that you are clean, lets reset your system restore points please follow these simple steps in order

Now turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn System Restore back on and create a restore point.

To create a restore point:

Single-click Start and point to All Programs.
Mouse over Accessories, then System Tools, and select System Restore.In the System Restore wizard, select the box next the text labeled "Create a restore point" and click the Next button.
Type a description for your new restore point. Something like "After trojan/spyware cleanup". Click Create and you're done.
_____________________________

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialise and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
_____________________________

Use an Anti Virus Software- It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
Click here for more information on -> Computer Safety On line - Anti-Virus

I would recommend Grisofts© AVG or AVAST©. As these are the more secure and better ones.

Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
_____________________________

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
Click here for more information on -> Computer Safety On line - Software Firewalls
I would recommend ZoneAlarm© as a firewall as it's easy to use. But for a more secure firewall, Sunbelts Kerio© is the one.
_____________________________

Visit Microsoft's Windows Update Site Frequently It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Next, if they're not already present, I would recommend the download and installation of some or all of the following programs (all free), and the updating of them regularly
_____________________________

Install Spybot© - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here: Click here for more info -->Instructions for - Spybot S & D and Ad-aware
_____________________________

Install Lavasofts© Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here: Click here for more info -->Instructions for - Spybot S & D and Ad-aware
_____________________________

Install Javacools© SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here: Click here for more info --Computer Safety on line - Anti-Malware
_____________________________

Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you will not be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically. Remember, A clean computer isn't a bleeping computer :thumbsup:

David




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users