Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cid Pop Ups Have Lowed My Pc To Virtually Zero


  • Please log in to reply
15 replies to this topic

#1 mhurley142

mhurley142

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 15 May 2007 - 12:13 AM

Hi
my 19 year old son and 16 year old daughter have admitted they have been logging on with my password whilst I am away and I have had all kinds of viruses and applications installed from games to porn viewers. I have run Adaware, AVG anti virus and anything else that might have solved the problems but the pc has got slower and slower with screens taking minutes to refresh and the system appearing to have hung but with the task manager showing full processor use. Pop ups regularly appear despite having blockers installed and active. The whole system seems to go to sleep for ages and then a new pop up appears. I installed Mozilla and have used this and dont seem to get so many pop ups but the system is so slow to refresh or do anything unless I reboot every few minutes. Please help I don't know what else to do. I dont want to reformat and start again. I have run AVG spyware and hijack this the results are below
thanks


Logfile of HijackThis v1.99.1
Scan saved at 05:51:27, on 15/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\KService\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Onfolio\onfserv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\MELVIN~1\LOCALS~1\Temp\Rar$EX03.032\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://signin.ebay.co.uk/ws/eBayISAPI.dll?...p;pageType=1883
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirec...rch&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [OnfolioStorage] "C:\Program Files\Onfolio\onfserv.exe" nosignal
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Owns extra enc byte] C:\Documents and Settings\All Users\Application Data\Soft mix owns extra\Ante copy.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Diskeeper 9 Professional Edition Registration.lnk = C:\Program Files\Executive Software\Diskeeper\ESIRegister.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Capture Page to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddLinkEntryFromDocument.html
O8 - Extra context menu item: Add to &Windows Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Capt&ure Target to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture &Snippet to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentSelection.html
O8 - Extra context menu item: Capture Ima&ge to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture Page and Selected &Links to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteSnippetFromDocumentSelection.html
O8 - Extra context menu item: Capture Selected Ite&ms to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddMultipleEntriesFromDocumentSelection.html
O8 - Extra context menu item: Capture Site to &Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteFromDocument.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200610...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110w.bay110.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl...lscbase5059.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1139078608670
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1139095873921
O16 - DPF: {77F539E4-3C23-48D9-960B-B6E62905C113} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://chat2.j2.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...769/mcfscan.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

AVG Spyware report
--------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 15:10:37 07/05/2007

+ Scan result:



C:\WINDOWS\azesearch.bmp -> Adware.Azesearch : Cleaned.
C:\Documents and Settings\Faye Hurley\Local Settings\Temporary Internet Files\Content.IE5\7DJFM090\installcasino[1].exe -> Adware.Casino : Cleaned.
C:\Program Files\Trust Cleaner -> Adware.TrustCleaner : Cleaned.
C:\Program Files\Trust Cleaner\TrustCleaner_log.txt -> Adware.TrustCleaner : Cleaned.
H:\System Volume Information\_restore{E77CCA0A-A3F3-4AC7-809B-D65B8EB2DBD9}\RP222\A0068128.exe -> Backdoor.Hupigon : Cleaned.
H:\Documents\downloaded\To retain for Compaq\WinFax Pro 10\Crack\Win Fax Pro 10.0 CRK TNT.exe -> Backdoor.Theef.111 : Cleaned.
C:\Program Files\Common Files\rffq\rffqd\vocabulary -> Downloader.TSUpdate.j : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie hurley@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.173:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.200:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Anneke Hurley\Application Data\Mozilla\Firefox\Profiles\bykufq84.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Anneke Hurley\Application Data\Mozilla\Firefox\Profiles\bykufq84.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.67:C:\Documents and Settings\Julie Hurley\Application Data\Mozilla\Firefox\Profiles\n83nm2le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@maxis.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@meetupcom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@ostg.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@stpetersburgtimes.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@tsn.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@atoc.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@hertz.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@livenation.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@msnclassifieds.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@atoc.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@amazonnba.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@gettyimages.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@maxis.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Julie Hurley\Cookies\julie hurley@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Julie Hurley\Cookies\julie hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@66.220.17[2].txt -> TrackingCookie.66.220.17.154 : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@66.220.17[2].txt -> TrackingCookie.66.220.17.154 : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@adserver.71i[1].txt -> TrackingCookie.71i : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@7search[2].txt -> TrackingCookie.7search : Cleaned.
:mozilla.234:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.235:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@adbrite[3].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@axa.addcontrol[1].txt -> TrackingCookie.Addcontrol : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ad.admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@www.adobe[2].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.adobe[2].txt -> TrackingCookie.Adobe : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adorigin[1].txt -> TrackingCookie.Adorigin : Cleaned.
:mozilla.66:C:\Documents and Settings\Julie Hurley\Application Data\Mozilla\Firefox\Profiles\n83nm2le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@netli.media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@z1.adserver[2].txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.61:C:\Documents and Settings\Julie Hurley\Application Data\Mozilla\Firefox\Profiles\n83nm2le.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.62:C:\Documents and Settings\Julie Hurley\Application Data\Mozilla\Firefox\Profiles\n83nm2le.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.91:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.92:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@adtech[1].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie hurley@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4E.tmp -> TrackingCookie.Adtech : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adtech[1].txt -> TrackingCookie.Adtech : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adtech[1].txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.34:C:\Documents and Settings\Anneke Hurley\Application Data\Mozilla\Firefox\Profiles\bykufq84.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.35:C:\Documents and Settings\Anneke Hurley\Application Data\Mozilla\Firefox\Profiles\bykufq84.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.36:C:\Documents and Settings\Anneke Hurley\Application Data\Mozilla\Firefox\Profiles\bykufq84.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.37:C:\Documents and Settings\Anneke Hurley\Application Data\Mozilla\Firefox\Profiles\bykufq84.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.63:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.64:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.65:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.66:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4F.tmp -> TrackingCookie.Advertising : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.157:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@adviva[1].txt -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@adviva[1].txt -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq50.tmp -> TrackingCookie.Adviva : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.26:C:\Documents and Settings\Julie Hurley\Application Data\Mozilla\Firefox\Profiles\n83nm2le.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.43:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp -> TrackingCookie.Atdmt : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
F:\Documents and Settings\Julie Hurley\Cookies\julie hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq52.tmp -> TrackingCookie.Burstnet : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.73:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.74:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.75:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.76:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.77:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.78:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.79:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie hurley@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@casinotropez[2].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@www.casinotropez[1].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@casinotropez[1].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.casinotropez[2].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@cz4.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@cz4.clickzs[1].txt -> TrackingCookie.Clickzs : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@cz8.clickzs[1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@ads.guardian.co[1].txt -> TrackingCookie.Co : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.guardian.co[2].txt -> TrackingCookie.Co : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.guardian.co[1].txt -> TrackingCookie.Co : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.guardian.co[2].txt -> TrackingCookie.Co : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq53.tmp -> TrackingCookie.Com : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@com[2].txt -> TrackingCookie.Com : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@builder.com[1].txt -> TrackingCookie.Com : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@com[2].txt -> TrackingCookie.Com : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@com[2].txt -> TrackingCookie.Com : Cleaned.
:mozilla.204:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.205:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.206:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@connextra[4].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@connextra[3].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@connextra[3].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke hurley@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@test.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.93:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Julie Hurley\Cookies\julie_hurley@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq54.tmp -> TrackingCookie.Doubleclick : Cleaned.
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
F:\Documents and Settings\Julie Hurley\Cookies\julie hurley@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye hurley@e-2dj6wgmigjazmdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@e-2dj6wakisnazwdp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@e-2dj6wflienajcdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@e-2dj6wflogpczoco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@e-2dj6wflosjdzafq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@e-2dj6wgkosiajsgo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@e-2dj6wjl4qodjccp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Thomas Hurley\Cookies\thomas_hurley@e-2dj6wjlysgcpwdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@e-2dj6wjk4kjc5obo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@e-2dj6wjlookdzcaq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@e-2dj6wjloqhdjkap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.100:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.101:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.102:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.103:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.104:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.105:C:\Documents and Settings\Hannah Hurley\Application Data\Mozilla\Firefox\Profiles\dkwp0lq9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Hannah Hurley&#

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 15 May 2007 - 03:15 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum mhurley142 :thumbsup:

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

Click 'Exit' on the Main menu to close the program.

*************************

Download Deljob.exe and save it on your desktop.
Double click on Deljob.exe.

A log,(logit.txt) should open afterwards.
This log will be present on your desktop.
Post the contents of the logfile into your next reply,along with a new Hijack This log.
Posted Image
Posted Image

#3 mhurley142

mhurley142
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 03 June 2007 - 10:51 AM

Hi thanks for your help the logit file is:
--------------------------------------------------------
File(s) moved to C:\deljob

8DC7EE6381949187.job
--------------------------------------------------------
Files remaining after cleaning

AppleSoftwareUpdate.job
Check Updates for Windows Live Toolbar.job
--------------------------------------------------------
App data folders

Volume in drive C has no label.
Volume Serial Number is 4CDA-4164

Directory of C:\Documents and Settings\Melvin Hurley\Application Data

04/05/2007 22:15 <DIR> .
04/05/2007 22:15 <DIR> ..
13/01/2007 10:59 <DIR> Adobe
13/01/2007 10:42 <DIR> AdobeUM
11/02/2006 11:56 <DIR> Ahead
19/02/2006 15:24 <DIR> APPLEC~1 Apple Computer
03/06/2007 12:56 <DIR> AVG7
04/11/2006 10:22 <DIR> DivX
10/05/2006 01:10 <DIR> EPSON
26/11/2006 12:44 <DIR> Google
13/02/2006 02:48 <DIR> Help
29/10/2001 13:03 <DIR> IDENTI~1 Identities
29/10/2001 13:26 <DIR> INTERT~1 InterTrust
10/02/2006 01:16 <DIR> KAZAAL~1 Kazaa Lite
16/02/2006 19:47 <DIR> Kontiki
05/02/2006 01:39 <DIR> Lavasoft
11/07/2006 13:32 <DIR> LEADER~1 Leadertech
03/12/2006 23:15 <DIR> MACROM~1 Macromedia
02/03/2007 19:17 <DIR> MICROS~1 Microsoft
27/10/2006 23:26 <DIR> Mozilla
02/03/2007 19:24 <DIR> NCHSWI~1 NCH Swift Sound
11/02/2006 22:51 <DIR> Ofoto
03/06/2007 13:27 <DIR> Onfolio
09/07/2006 22:56 <DIR> Opera
24/12/2006 19:55 <DIR> Real
05/07/2006 22:03 <DIR> RECORD~1 RecordPad
06/05/2007 23:54 <DIR> SCREEN~1 Screenshot Sender
12/02/2006 02:04 <DIR> Snapfish
08/03/2006 15:49 <DIR> Sun
05/02/2006 01:36 <DIR> Symantec
21/04/2007 10:33 <DIR> Talkback
28/05/2006 21:11 <DIR> warez
16/03/2006 14:07 <DIR> WINDOW~1 Windows Desktop Search
30/04/2006 13:12 <DIR> WINDOW~2 Windows Live Safety Center
16/07/2006 01:34 <DIR> Yahoo!
0 File(s) 0 bytes
35 Dir(s) 11,836,411,904 bytes free
Volume in drive C has no label.
Volume Serial Number is 4CDA-4164

Directory of C:\Documents and Settings\All Users\Application Data

15/04/2007 11:30 <DIR> .
15/04/2007 11:30 <DIR> ..
13/01/2007 10:29 <DIR> Adobe
11/02/2006 12:34 <DIR> ADOBES~1 Adobe Systems
25/12/2006 14:19 <DIR> APPLEC~1 Apple Computer
15/04/2007 11:42 <DIR> Avg7
12/02/2006 23:19 <DIR> BVRPSO~1 BVRP Software
25/11/2006 14:45 <DIR> Google
15/04/2007 11:30 <DIR> Grisoft
11/02/2006 12:06 <DIR> Kazaa
17/02/2006 23:42 <DIR> MACROM~1 Macromedia
05/04/2006 10:57 <DIR> MESSEN~1 Messenger Plus!
09/05/2007 05:39 <DIR> MICROS~1 Microsoft
06/07/2006 20:18 <DIR> MSN6
05/07/2006 22:03 <DIR> NCHSWI~1 NCH Swift Sound
22/06/2006 11:26 <DIR> NVIDIA
22/06/2006 11:36 <DIR> NVIEW_~1 nView_Profiles
29/04/2006 13:14 <DIR> OFFICE~1 Office Genuine Advantage
28/02/2006 00:30 <DIR> QUICKT~1 QuickTime
25/02/2007 15:48 <DIR> SOFTMI~1 Soft mix owns extra
11/08/2006 21:31 <DIR> SONYER~1 Sony Ericsson
25/11/2006 19:43 <DIR> Symantec
03/05/2006 23:16 <DIR> UDL
04/02/2006 23:58 <DIR> WINDOW~1 Windows Genuine Advantage
27/12/2006 02:13 <DIR> Yahoo!
0 File(s) 0 bytes
25 Dir(s) 11,836,407,808 bytes free
--------------------------------------------------------

my hijack this txt file is this:

Logfile of HijackThis v1.99.1
Scan saved at 16:42:08, on 03/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\KService\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQInet.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Onfolio\onfserv.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Melvin Hurley\Desktop\ATF-Cleaner.exe
C:\Documents and Settings\Melvin Hurley\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://signin.ebay.co.uk/ws/eBayISAPI.dll?...p;pageType=1883
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirec...rch&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [OnfolioStorage] "C:\Program Files\Onfolio\onfserv.exe" nosignal
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Owns extra enc byte] C:\Documents and Settings\All Users\Application Data\Soft mix owns extra\Ante copy.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Diskeeper 9 Professional Edition Registration.lnk = C:\Program Files\Executive Software\Diskeeper\ESIRegister.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Capture Page to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddLinkEntryFromDocument.html
O8 - Extra context menu item: Add to &Windows Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Capt&ure Target to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture &Snippet to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentSelection.html
O8 - Extra context menu item: Capture Ima&ge to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture Page and Selected &Links to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteSnippetFromDocumentSelection.html
O8 - Extra context menu item: Capture Selected Ite&ms to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddMultipleEntriesFromDocumentSelection.html
O8 - Extra context menu item: Capture Site to &Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteFromDocument.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200610...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110w.bay110.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl...lscbase5059.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1139078608670
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1139095873921
O16 - DPF: {77F539E4-3C23-48D9-960B-B6E62905C113} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://chat2.j2.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...769/mcfscan.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

I hope you can help resolve my problems with this information

thanks
Melvin

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 17 June 2007 - 06:38 AM

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Owns extra enc byte] C:\Documents and Settings\All Users\Application Data\Soft mix owns extra\Ante copy.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe

Exit Hijackthis.

Find and delete:
C:\Documents and Settings\All Users\Application Data\Soft mix owns extra

Launch SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#5 mhurley142

mhurley142
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 23 June 2007 - 04:23 PM

Hi

I have followed the instructions I am not sure if CiC pop ups have gone and have not yet seen them but the PC is still exceptionally slow including booting I have posted the new hijack this log and superantispyware logs below. Can you suggest anything to speed the PC up?

thanks

Melvin Hurley

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/23/2007 at 08:45 PM

Application Version : 3.8.1002

Core Rules Database Version : 3260
Trace Rules Database Version: 1271

Scan type : Complete Scan
Total Scan Time : 08:15:37

Memory items scanned : 20
Memory threats detected : 0
Registry items scanned : 7434
Registry threats detected : 0
File items scanned : 90550
File threats detected : 242

Adware.Tracking Cookie
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@tradedoubler[1].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@ad.uk.tangozebra[1].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@doubleclick[1].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@atdmt[2].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@msnportal.112.2o7[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@adopt.euroclick[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@atdmt[2].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@azjmp[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@partygaming.122.2o7[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@partypoker[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@www.yourtracking[1].txt
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@atdmt[1].txt
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@doubleclick[1].txt
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@imrworldwide[2].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@ads.pointroll[1].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@atdmt[2].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@doubleclick[1].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@msnportal.112.2o7[1].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@tradedoubler[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@accelerator-media[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@adlegend[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.a8ww[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.habbogroup[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.habbohotel.co[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.habbohotel[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.itv[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.monster[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.realtechnetwork[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads2.jubii[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@adv.surinter[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@aff.primaryads[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@apmebf[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@atwola[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@banner[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@belnk[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@clicksor[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@clicktorrent[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@dist.belnk[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@etype.adbureau[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@focalex[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@http.edge.vru4[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@interclick[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@m1.webstats4u[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@maxserving[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@partypoker[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@prostats[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@roiservice[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@smileycentral[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@stats[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@toplist[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@tripod.lycos[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@tripod[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@winfixer[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@wizteenads[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@www.dgm2[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@www.nativeamericantraditions[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@www.winfixer[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@xiti[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@xml.bravenetmedianetwork[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@a.websponsors[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@accelerator-media[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ad.zanox[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ad1.emediate[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adknowledge[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adopt.hbmediapro[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adopt.hotbar[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adrevolver[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.a8ww[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.accelerator-media[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.addesktop[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.as4x.tmcs[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.cc214142[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.digitalpoint[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.ecrush[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.expedia[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.habbogroup[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.habbohotel.co[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.itv[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adultfriendfinder[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@apmebf[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@atwola[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@banner[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@belnk[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@clicksor[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@dealtime.co[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@dist.belnk[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@etype.adbureau[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@interclick[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ipt.advertserve[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@jamster.co[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@m1.webstats4u[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@qnsr[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@roiservice[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@sitestats.tiscali.co[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@smileycentral[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@spamblockerutility[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@stats.channel4[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@tripod[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@webstats.channel4[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@winfixer[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.dgm2[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.macromedia[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.winfixer[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.xxcrazyxxchickxxxxxxluvxxya.piczo[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.xxx11tasha11xxx.piczo[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.xxxfairy-dustxxx.piczo[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@xiti[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@accelerator-media[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ad.cibleclick[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ad.zanox[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ad1.emediate[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adcentriconline[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adknowledge[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adopt.hbmediapro[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.a8ww[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.accelerator-media[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.addesktop[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.as4x.tmcs[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.contactmusic[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.goyk[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.habbogroup[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.habbohotel.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.i-am-bored[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.itv[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.pitchforkmedia[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.realtechnetwork[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.telegraph.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.us.e-planning[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.vnuemedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads2.drivelinemedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adserver.akqa[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adserver.scaratec[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adserver.virgin[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adv.webmd[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adverts.digitalspy.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@apmebf[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ath.belnk[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@atwola[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@banners.nbcupromotes[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@banner[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@belnk[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@bizrate[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@cassava[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@clickability[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@counter[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@dist.belnk[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@easy-hit-counters[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@etype.adbureau[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@fixionmedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@gostats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@interclick[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@m1.webstats4u[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@maxserving[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@media.hpana[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@monster.gostats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@montgomeryadvertiser[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@okcounter[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@pacificpoker[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@phpistats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@pitchforkmedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@r-kimedia.co[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@roiservice[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@s.clickability[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@server.cpmstar[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@sitestats.tiscali.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats.channel4[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats24[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@teenspot[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@tracking.foxnews[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@tripod[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@windowsmedia[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@winfixer[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.0stats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.comprabanner[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.dgm2[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.expertsexchange[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.searchenginetracking[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.sexwildcards[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.teenspot[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.teentoday.co[1].txt
F:\Documents and Settings\Julie Hurley\Cookies\julie hurley@smileycentral[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@accelerator-media[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ad.tbnet.bb[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adopt.hbmediapro[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.as4x.tmcs.ticketmaster[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.as4x.tmcs[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.channel4[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.ft[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.habbogroup[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.habbohotel.co[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.habbohotel[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.integraclick[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.linksponsor[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.thestar[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.tripod.lycos.co[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.vnuemedia[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adultfriendfinder[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adultrevenueservice[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@banners[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@Banner[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@belnk[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@click.absoluteagency[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@counter.aport[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@directtrack[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@dist.belnk[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@focalex[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@freebannertrade[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@gozing.directtrack[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@hi-media[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@interclick[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@jamster.co[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@mediamgr.ugo[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@megastats[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@members.tripod[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@nosepilot[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@pennyweb[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@pennyweb[3].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@phpistats[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@publishers.clickbooth[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@teenagerstoday[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@teen[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@teen[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@toplist[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@webpower[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@windowsmedia[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@windowsmedia[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@windowsmedia[3].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@winfixer[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.dgm2[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.dgm2[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.mysexysluts[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.screensavers[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.teenidols4you[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.ticketsnow2[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.xxxdailydozen[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@xiti[2].txt

Adware.ZToolbar
C:\WINDOWS\system32\azebar.xml

Adware.Lop-Gen
C:\DOCUMENTS AND SETTINGS\ANNEKE HURLEY\APPLICATION DATA\GRIM MEOW SOAP\OPENBAGSOBJSHOW.EXE
C:\DOCUMENTS AND SETTINGS\ANNEKE HURLEY\APPLICATION DATA\GRIM MEOW SOAP\TDAQRFWL.EXE

Browser Hijacker.Liporn
C:\WINDOWS\FORM.JS


Logfile of HijackThis v1.99.1
Scan saved at 21:12:55, on 23/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\KService\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Onfolio\onfserv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\COMPAQ\CPQINET\CPQInet.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\MSN Messenger\usnsvc.exe
H:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
C:\Documents and Settings\Melvin Hurley\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://signin.ebay.co.uk/ws/eBayISAPI.dll?...p;pageType=1883
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirec...rch&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [OnfolioStorage] "C:\Program Files\Onfolio\onfserv.exe" nosignal
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\MELVIN~1\LOCALS~1\Temp\MsgPlusUninstall.exe" /Cleanup
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Diskeeper 9 Professional Edition Registration.lnk = C:\Program Files\Executive Software\Diskeeper\ESIRegister.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Capture Page to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddLinkEntryFromDocument.html
O8 - Extra context menu item: Add to &Windows Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Capt&ure Target to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture &Snippet to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentSelection.html
O8 - Extra context menu item: Capture Ima&ge to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture Page and Selected &Links to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteSnippetFromDocumentSelection.html
O8 - Extra context menu item: Capture Selected Ite&ms to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddMultipleEntriesFromDocumentSelection.html
O8 - Extra context menu item: Capture Site to &Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteFromDocument.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200610...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110w.bay110.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl...lscbase5059.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1139078608670
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1139095873921
O16 - DPF: {77F539E4-3C23-48D9-960B-B6E62905C113} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://chat2.j2.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...769/mcfscan.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 24 June 2007 - 04:31 AM

Run 'BitDefender Online Scanner' using Internet Explorer:
http://www.bitdefender.com/scan8/ie.html
Read the 'END USER SOFTWARE LICENSE AGREEMENT' then click 'I agree'.
You'll be prompted to install the activex control,please do so.
Once installed,disable your current antivirus program,then click the 'Click here to scan' button.
The virus signatures will then load.
Once loaded the scan will start.
The scan will take quite some time so please be patient.
Once the scan has finished select the 'Detected Problems' tab.
Click on 'Click here to export scan'.
Save the file as an HTML file to your desktop.
Then click on the saved file and allow it to open with your browser.
Go to 'Edit'/'Select All' then copy and paste that log into your next reply.
*Note*
Don't forget to re-enable your antivirus program.

-------------------------------

Please download Combofix and save to your desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.


Also post a new Hijackthis log please.
Posted Image
Posted Image

#7 mhurley142

mhurley142
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 25 June 2007 - 09:43 AM

Hi Richie

your suggested action is below. I did this and have attached the resulting scans below for:
SuperAntiSpyware
Bitdefender
Combofix
Hijackthis

Please advise what I need to do next

Thanks

Melvin Hurley

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Owns extra enc byte] C:\Documents and Settings\All Users\Application Data\Soft mix owns extra\Ante copy.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe
Exit Hijackthis.

Find and delete:
C:\Documents and Settings\All Users\Application Data\Soft mix owns extra

Launch SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Please download Combofix and save to your desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Also post a new Hijackthis log please.

SuperAntiSpyware Scan Log
UPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/23/2007 at 08:45 PM

Application Version : 3.8.1002

Core Rules Database Version : 3260
Trace Rules Database Version: 1271

Scan type : Complete Scan
Total Scan Time : 08:15:37

Memory items scanned : 20
Memory threats detected : 0
Registry items scanned : 7434
Registry threats detected : 0
File items scanned : 90550
File threats detected : 242

Adware.Tracking Cookie
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@tradedoubler[1].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@ad.uk.tangozebra[1].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@doubleclick[1].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@atdmt[2].txt
C:\Documents and Settings\Melvin Hurley\Cookies\melvin_hurley@msnportal.112.2o7[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@adopt.euroclick[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@atdmt[2].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@azjmp[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@partygaming.122.2o7[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@partypoker[1].txt
C:\Documents and Settings\Anneke Hurley\Cookies\anneke_hurley@www.yourtracking[1].txt
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@atdmt[1].txt
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@doubleclick[1].txt
C:\Documents and Settings\Faye Hurley\Cookies\faye_hurley@imrworldwide[2].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@ads.pointroll[1].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@atdmt[2].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@doubleclick[1].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@msnportal.112.2o7[1].txt
C:\Documents and Settings\Hannah Hurley\Cookies\hannah_hurley@tradedoubler[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@accelerator-media[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@adlegend[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.a8ww[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.habbogroup[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.habbohotel.co[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.habbohotel[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.itv[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.monster[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads.realtechnetwork[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@ads2.jubii[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@adv.surinter[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@aff.primaryads[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@apmebf[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@atwola[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@banner[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@belnk[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@clicksor[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@clicktorrent[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@dist.belnk[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@etype.adbureau[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@focalex[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@http.edge.vru4[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@interclick[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@m1.webstats4u[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@maxserving[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@partypoker[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@prostats[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@roiservice[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@smileycentral[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@stats[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@toplist[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@tripod.lycos[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@tripod[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@winfixer[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@wizteenads[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@www.dgm2[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@www.nativeamericantraditions[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@www.winfixer[2].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@xiti[1].txt
F:\Documents and Settings\Anneke Hurley\Cookies\anneke sarah@xml.bravenetmedianetwork[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@a.websponsors[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@accelerator-media[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ad.zanox[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ad1.emediate[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adknowledge[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adopt.hbmediapro[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adopt.hotbar[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adrevolver[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.a8ww[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.accelerator-media[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.addesktop[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.as4x.tmcs[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.cc214142[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.digitalpoint[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.ecrush[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.expedia[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.habbogroup[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.habbohotel.co[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ads.itv[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@adultfriendfinder[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@apmebf[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@atwola[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@banner[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@belnk[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@clicksor[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@dealtime.co[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@dist.belnk[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@etype.adbureau[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@interclick[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@ipt.advertserve[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@jamster.co[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@m1.webstats4u[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@qnsr[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@roiservice[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@sitestats.tiscali.co[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@smileycentral[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@spamblockerutility[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@stats.channel4[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@tripod[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@webstats.channel4[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@winfixer[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.dgm2[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.macromedia[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.winfixer[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.xxcrazyxxchickxxxxxxluvxxya.piczo[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.xxx11tasha11xxx.piczo[1].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@www.xxxfairy-dustxxx.piczo[2].txt
F:\Documents and Settings\Faye Hurley\Cookies\faye hurley@xiti[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@accelerator-media[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ad.cibleclick[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ad.zanox[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ad1.emediate[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adcentriconline[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adknowledge[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adopt.hbmediapro[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.a8ww[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.accelerator-media[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.addesktop[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.as4x.tmcs[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.contactmusic[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.goyk[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.habbogroup[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.habbohotel.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.i-am-bored[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.itv[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.pitchforkmedia[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.realtechnetwork[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.telegraph.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.us.e-planning[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads.vnuemedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ads2.drivelinemedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adserver.akqa[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adserver.scaratec[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adserver.virgin[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adv.webmd[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@adverts.digitalspy.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@apmebf[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@ath.belnk[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@atwola[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@banners.nbcupromotes[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@banner[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@belnk[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@bizrate[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@cassava[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@clickability[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@counter[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@dist.belnk[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@easy-hit-counters[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@etype.adbureau[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@fixionmedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@gostats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@interclick[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@m1.webstats4u[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@maxserving[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@media.hpana[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@monster.gostats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@montgomeryadvertiser[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@okcounter[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@pacificpoker[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@phpistats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@pitchforkmedia[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@r-kimedia.co[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@roiservice[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@s.clickability[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@server.cpmstar[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@sitestats.tiscali.co[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats.channel4[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats24[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@stats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@teenspot[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@tracking.foxnews[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@tripod[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@windowsmedia[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@winfixer[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.0stats[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.comprabanner[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.dgm2[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.expertsexchange[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.searchenginetracking[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.sexwildcards[2].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.teenspot[1].txt
F:\Documents and Settings\Hannah Hurley\Cookies\hannah hurley@www.teentoday.co[1].txt
F:\Documents and Settings\Julie Hurley\Cookies\julie hurley@smileycentral[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@accelerator-media[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ad.tbnet.bb[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adopt.hbmediapro[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.as4x.tmcs.ticketmaster[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.as4x.tmcs[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.channel4[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.ft[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.habbogroup[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.habbohotel.co[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.habbohotel[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.integraclick[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.linksponsor[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.thestar[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.tripod.lycos.co[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@ads.vnuemedia[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adultfriendfinder[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@adultrevenueservice[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@banners[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@Banner[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@belnk[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@click.absoluteagency[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@counter.aport[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@directtrack[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@dist.belnk[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@focalex[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@freebannertrade[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@gozing.directtrack[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@hi-media[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@interclick[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@jamster.co[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@mediamgr.ugo[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@megastats[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@members.tripod[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@nosepilot[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@pennyweb[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@pennyweb[3].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@phpistats[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@publishers.clickbooth[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@teenagerstoday[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@teen[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@teen[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@toplist[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@webpower[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@windowsmedia[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@windowsmedia[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@windowsmedia[3].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@winfixer[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.dgm2[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.dgm2[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.mysexysluts[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.screensavers[2].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.teenidols4you[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.ticketsnow2[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@www.xxxdailydozen[1].txt
F:\Documents and Settings\Thomas Hurley\Cookies\thomas hurley@xiti[2].txt

Adware.ZToolbar
C:\WINDOWS\system32\azebar.xml

Adware.Lop-Gen
C:\DOCUMENTS AND SETTINGS\ANNEKE HURLEY\APPLICATION DATA\GRIM MEOW SOAP\OPENBAGSOBJSHOW.EXE
C:\DOCUMENTS AND SETTINGS\ANNEKE HURLEY\APPLICATION DATA\GRIM MEOW SOAP\TDAQRFWL.EXE

Browser Hijacker.Liporn
C:\WINDOWS\FORM.JS

BitDefender Log


BitDefender Online Scanner







Scan report generated at: Mon, Jun 25, 2007 - 02:34:40









Scan path: A:\;C:\;D:\;E:\;F:\;G:\;H:\;M:\;















Statistics

Time


09:26:41

Files


611924

Folders


16170

Boot Sectors


6

Archives


12841

Packed Files


30874







Results

Identified Viruses


13

Infected Files


19

Suspect Files


0

Warnings


0

Disinfected


0

Deleted Files


27







Engines Info

Virus Definitions


571180

Engine build


AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27)

Scan plugins


14

Archive plugins


38

Unpack plugins


6

E-mail plugins


6

System plugins


1







Scan Settings

First Action


Disinfect

Second Action


Delete

Heuristics


Yes

Enable Warnings


Yes

Scanned Extensions


*;

Exclude Extensions




Scan Emails


Yes

Scan Archives


Yes

Scan Packed


Yes

Scan Files


Yes

Scan Boot


Yes








Scanned File


Status

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35=>NewSecurityClassLoader.class


Infected with: Java.Trojan.Exploit.Byteverify.G

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35=>NewSecurityClassLoader.class


Disinfection failed

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35=>NewSecurityClassLoader.class


Deleted

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35


Updated

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35=>NewURLClassLoader.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35=>NewURLClassLoader.class


Disinfection failed

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35=>NewURLClassLoader.class


Deleted

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-1d1fdc35


Updated

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip=>NewSecurityClassLoader.class


Infected with: Java.Trojan.Exploit.Byteverify.G

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip=>NewSecurityClassLoader.class


Disinfection failed

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip=>NewSecurityClassLoader.class


Deleted

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip


Updated

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip=>NewURLClassLoader.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip=>NewURLClassLoader.class


Disinfection failed

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip=>NewURLClassLoader.class


Deleted

C:\Documents and Settings\Hannah Hurley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f904a27.zip


Updated

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)=>lzma_solid_nsis0006


Infected with: Trojan.Downloader.Zlob.ZVA

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)=>lzma_solid_nsis0006


Disinfection failed

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)=>lzma_solid_nsis0006


Deleted

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)


Update failed

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)=>lzma_solid_nsis0008=>(NSIS g)=>lzma_solid_nsis0000


Infected with: Trojan.Downloader.Zlob.ZVN

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)=>lzma_solid_nsis0008=>(NSIS g)=>lzma_solid_nsis0000


Disinfection failed

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)=>lzma_solid_nsis0008=>(NSIS g)=>lzma_solid_nsis0000


Deleted

C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe=>(NSIS o)=>lzma_solid_nsis0008=>(NSIS g)


Update failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\04A23876.txt=>(Quarantine-2)


Infected with: Generic.Malware.SFdldg.D4C0D050

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\04A23876.txt=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\04A23876.txt=>(Quarantine-2)


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\05017A0E.txt=>(Quarantine-2)


Infected with: Trojan.StartPage.MB

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\05017A0E.txt=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\05017A0E.txt=>(Quarantine-2)


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2F9D777E.wmf=>(Quarantine-2)


Infected with: Exploit.Win32.WMF-PFV

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2F9D777E.wmf=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2F9D777E.wmf=>(Quarantine-2)


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\40C16165.tmp=>(Quarantine-2)


Infected with: Java.Trojan.Exploit.Bytverify

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\40C16165.tmp=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\40C16165.tmp=>(Quarantine-2)


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\518C2E51.tmp=>(Quarantine-2)


Infected with: Trojan.Downloader.Java.Openconnection.AJ

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\518C2E51.tmp=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\518C2E51.tmp=>(Quarantine-2)


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57CA4000.wmf=>(Quarantine-2)


Infected with: Exploit.Win32.WMF-PFV

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57CA4000.wmf=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57CA4000.wmf=>(Quarantine-2)


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>GetAccess.class


Infected with: Trojan.Exploit.Byteverify.O

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>GetAccess.class


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>GetAccess.class


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)


Updated

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>InsecureClassLoader.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>InsecureClassLoader.class


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>InsecureClassLoader.class


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)


Updated

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>Dummy.class


Infected with: Trojan.Java.Classloader.Dummy.A

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>Dummy.class


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>Dummy.class


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)


Updated

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>Installer.class


Infected with: Java.Trojan.OpenConnection.F

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>Installer.class


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)=>Installer.class


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip=>(Quarantine-2)


Updated

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D43DF5.zip


Update failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5BA13331.tmp=>(Quarantine-2)


Infected with: Trojan.Exploit.ByteVerify.L

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5BA13331.tmp=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5BA13331.tmp=>(Quarantine-2)


Deleted

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5BA45D2E.tmp=>(Quarantine-2)


Infected with: Trojan.Exploit.ByteVerify.L

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5BA45D2E.tmp=>(Quarantine-2)


Disinfection failed

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5BA45D2E.tmp=>(Quarantine-2)


Deleted

C:\RECYCLER\S-1-5-21-67682326-891307005-2424629274-1006\Dc1.exe


Infected with: DeepScan:Generic.Malware.BA!!.D7CC585D

C:\RECYCLER\S-1-5-21-67682326-891307005-2424629274-1006\Dc1.exe


Disinfection failed

C:\RECYCLER\S-1-5-21-67682326-891307005-2424629274-1006\Dc1.exe


Deleted


Combofix Log
"Melvin Hurley" - 2007-06-25 6:26:29 - ComboFix 07-06-25.2 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\windows
C:\uniq
C:\WINDOWS\keyboard231.dat
C:\WINDOWS\system32\msxml3a.dll


((((((((((((((((((((((((( Files Created from 2007-05-25 to 2007-06-25 )))))))))))))))))))))))))))))))


2007-06-25 06:00 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-24 17:02 <DIR> d-------- C:\WINDOWS\LastGood
2007-06-24 17:02 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-06-23 11:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-23 11:55 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-06-23 11:55 <DIR> d-------- C:\DOCUME~1\MELVIN~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-23 11:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-03 13:49 <DIR> d-------- C:\deljob
2007-06-01 04:59 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 05:22:09 -------- d-----w C:\DOCUME~1\MELVIN~1\APPLIC~1\Onfolio
2007-06-24 15:48:49 -------- d-----w C:\Program Files\Plaxo
2007-06-24 15:48:31 -------- d-----w C:\Program Files\MSN Messenger
2007-06-23 20:00:21 -------- d-----w C:\DOCUME~1\MELVIN~1\APPLIC~1\Lavasoft
2007-06-23 11:11:52 -------- d-----w C:\Program Files\Virtools Web Player 3.5
2007-06-01 03:57:36 -------- d-----w C:\Program Files\Windows Live Toolbar
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-10 03:52:57 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-06 22:54:16 -------- d-----w C:\DOCUME~1\MELVIN~1\APPLIC~1\Screenshot Sender
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 17:07:15 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 21:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 21:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 21:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{2F85D76C-0569-466F-A488-493E6BD0E955}=C:\Program Files\Windows Desktop Search\dsWebAllow.dll [2006-03-26 23:44]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-04-07 00:02]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-20 00:55]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 15:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WCOLOREAL"="C:\Program Files\COMPAQ\Coloreal\coloreal.exe" [2001-08-14 18:19]
"Smapp"="Smtray.exe" [2001-05-31 20:32 C:\WINDOWS\system32\SMTray.exe]
"CPQEASYACC"="C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe" [2001-08-15 11:50]
"srmclean"="C:\Cpqs\Scom\srmclean.exe" [2001-07-24 22:34]
"nwiz"="nwiz.exe" [2006-06-01 17:22 C:\WINDOWS\system32\nwiz.exe]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-10-08 13:31]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-10-08 13:24]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 21:52]
"@"="" []
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 02:51]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 02:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"OnfolioStorage"="C:\Program Files\Onfolio\onfserv.exe" [2006-03-07 14:53]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"DiskeeperSystray"="C:\Program Files\Executive Software\Diskeeper\DkIcon.exe" [2005-07-26 17:52]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-24 11:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-12-12 01:36]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-04-21 09:19]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 19:25]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" [2006-11-16 13:42]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-12-01 05:21]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-05-23 10:12]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"="C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 14:11]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
"OfotoNow USB Detection"=C:\WINDOWS\system32\RunDLL32.exe C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL,WatchForConnection OfotoNow
"PlaxoUpdate"=C:\Program Files\Plaxo\2.8.1.2\PlaxoHelper.exe -a
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime


Contents of the 'Scheduled Tasks' folder
2007-06-11 18:55:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-25 05:38:00 C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-25 06:36:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-25 6:38:55
C:\ComboFix-quarantined-files.txt ... 2007-06-25 06:38

--- E O F ---

Hijackthis Log
Logfile of HijackThis v1.99.1
Scan saved at 07:07:26, on 25/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\KService\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Onfolio\onfserv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQInet.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Melvin Hurley\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://signin.ebay.co.uk/ws/eBayISAPI.dll?...p;pageType=1883
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirec...rch&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [OnfolioStorage] "C:\Program Files\Onfolio\onfserv.exe" nosignal
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Diskeeper 9 Professional Edition Registration.lnk = C:\Program Files\Executive Software\Diskeeper\ESIRegister.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Capture Page to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddLinkEntryFromDocument.html
O8 - Extra context menu item: Add to &Windows Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Capt&ure Target to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture &Snippet to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentSelection.html
O8 - Extra context menu item: Capture Ima&ge to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture Page and Selected &Links to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteSnippetFromDocumentSelection.html
O8 - Extra context menu item: Capture Selected Ite&ms to Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddMultipleEntriesFromDocumentSelection.html
O8 - Extra context menu item: Capture Site to &Onfolio... - res://C:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddSiteFromDocument.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200610...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110w.bay110.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl...lscbase5059.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1139078608670
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1139095873921
O16 - DPF: {77F539E4-3C23-48D9-960B-B6E62905C113} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://chat2.j2.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...769/mcfscan.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 25 June 2007 - 09:56 AM

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

Your log is clean,hows your pc running now please.
Posted Image
Posted Image

#9 mhurley142

mhurley142
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 25 June 2007 - 10:51 AM

Hi Richie I've made the changes and it is still slower than a slug on salt. Any more suggestions I would hate to have to reformat and start again.

thanks

Melvin

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 25 June 2007 - 12:16 PM

Download and scan with the free 15 day trial of Counterspy V2
Save the report when it's finished:
1.Once Counterspy has done scanning,the 'Scan Results' box will appear.
2.Click on 'View Results'.
3.Under (Recommended Action),using the drop down menus at the side of each entry found,set EVERYTHING to 'Remove'.
4.Then click on 'Take Action'.
5.Once everything has been removed,click on 'View Details'.
6.Copy and Paste those details into your next reply.

*************************

Download AVG Anti-Rootkit and save to your desktop
1. Double click avgarkt-setup-1.1.0.42.exe to install. By default it will install to C:\Program Files\GRISOFT\AVG Anti-Rootkit.
2. Accept the license and follow the prompts to install.
3. You will be asked to reboot to finish the installation so click "Finish".
4. After rebooting, double-click the icon for AVG Anti-Rootkit on your desktop.
5. You will see a window with four buttons at the bottom.
6. Click "Search For Rootkits" and the scan will begin.
7. You will see the progress bar moving from left to right. The scan will take some so be patient and let it finish.
8. When the scan has finished, a small window will open so you can view the results.
9. Right click and select "Save Result To File".
10. By default the file will be saved with a .csv extension. (You can use notepad to open the .cvs file). Copy and paste the results in your next reply.
11. If anything was found, click "Remove selected items"
12. If nothing was found, please click the "Perform in-depth Search" saving anything found to file as before.
Posted Image
Posted Image

#11 mhurley142

mhurley142
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 27 June 2007 - 03:37 AM

I've run the applications suggested and it is still slug on salt slow. Typing comes up on screen after with lines of delays booting is 4-5 minutes. Word takes about 2 minutes to load and everything else is as slow. The log is below for CounterSpy AVG Anti-Rootkit found nothing on either scan.

Any other suggestions?

thanks

Melvin

Scan History Details
Start Date: 25/06/2007 17:48:57
End Date: 25/06/2007 20:48:08
Total Time: 179 Min 11 Sec
Detected security risks

Cookie: ATDMT.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\documents and settings\melvin hurley\cookies\melvin_hurley@atdmt[2].txt


Cookie: Bluestreak.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\documents and settings\melvin hurley\cookies\melvin_hurley@bluestreak[1].txt


Cookie: DoubleClick Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\documents and settings\melvin hurley\cookies\melvin_hurley@doubleclick[1].txt


KaZaA P2P Program more information...
Details: KaZaA is a peer-to-peer (P2P) application that allows its users to join together in a network via the Internet and share files from each other's hard drives.
Status: Ignored

Registry entries detected
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Advanced
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Advanced
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Advanced
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Advanced
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\InstantMessaging
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\InstantMessaging
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\InstantMessaging
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\k-lite
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\k-lite
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Application
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ApplicationWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Audio
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\AudioWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnOrder
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnOrder
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnOrder
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnOrder
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnOrder
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnOrder
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates1
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates1
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates1
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates1
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates1
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates1
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates2
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates2
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates2
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates2
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates2
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnSortStates2
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnWidths
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnWidths
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnWidths
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnWidths
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnWidths
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\ColumnWidths
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\CombinedSortedColumns
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\CombinedSortedColumns
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\CombinedSortedColumns
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\CombinedSortedColumns
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\CombinedSortedColumns
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\CombinedSortedColumns
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Order
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Download Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Everything
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\EverythingWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Recent File List
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Settings
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Order
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Upload Width
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\Video
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Kazaa Lite Resurrection\VideoWidth
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\LocalContent
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\LocalContent
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\LocalContent
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\ResultsFilter
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\ResultsFilter
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\ResultsFilter
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\ResultsFilter
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\ResultsFilter
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\ResultsFilter
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\ResultsFilter
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Search
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Skins
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\SOCKS
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\SOCKS
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\Transfer
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\UserDetails
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\UserDetails
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\UserDetails
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\UserDetails
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\UserDetails
HKEY_USERS\S-1-5-21-67682326-891307005-2424629274-1006\SOFTWARE\KAZAA\UserDetails


Cookie: Mediaplex.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\documents and settings\melvin hurley\cookies\melvin_hurley@mediaplex[1].txt


Cookie: QuestionMarket.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\documents and settings\melvin hurley\cookies\melvin_hurley@questionmarket[2].txt


Cookie: adrevolver Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\documents and settings\melvin hurley\cookies\melvin_hurley@adrevolver[1].txt


Messenger Plus! Adware Bundler more information...
Details: Messenger Plus! is a add-on for MSN Messenger. Messenger Plus! installs an OPTIONAL adware called C2Media which is also known as LOP.com.
Status: Ignored

Files detected
C:\Documents and Settings\Anneke Hurley\Application Data\MessengerPlus! 3\Detoured.dll
C:\Documents and Settings\Anneke Hurley\Application Data\MessengerPlus! 3\Lame_enc.dll
C:\Documents and Settings\Anneke Hurley\Application Data\MessengerPlus! 3\Libsndfile.dll
C:\Documents and Settings\Anneke Hurley\Application Data\MessengerPlus! 3\MsgPlus.exe


InternetOffers Adware (General) more information...
Details: InternetOffers is an adware application that spawns pop-ups on the desktop. displays popup advertisements with no attribution and installs without consent.
Status: Quarantined

Files detected
C:\Program Files\Common Files\rffq\rffqd\class-barrel


Cookie: Radar Spy Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\documents and settings\melvin hurley\cookies\melvin_hurley@tradedoubler[1].txt


CoolOnlineOffers.ScreenSaver Adware Bundler more information...
Details: CoolOnlineOffers.ScreenSaver is a program which delivers advertisiment on you computer depending on your surfing behaviour.
Status: Ignored

Files detected
C:\WINDOWS\system32\Holding Pattern dir\expire.scf


Haxdoor.Fam Trojan more information...
Details: Haxdoor.Fam is a group of backdoor trojans that allow a remote attacker to gain access and control the computer. Haxdoor is also used to download additional malware.
Status: Quarantined

Files detected
C:\WINDOWS\system32\lps.dat


Trojan-Downloader.Zlob.Media-Codec Trojan Downloader more information...
Details: Trojan-Downloader.Zlob.Media-Codec is a program that typically purports to be a needed upgrade to Windows Media Player in order to view adult oriented videos on certain websites. However, Trojan-Downloader.Zlob.Media-Codec actually downloads and installs additional malware on the user's machine.
Status: Quarantined

Files detected
C:\Documents and Settings\Hannah Hurley\Desktop\setup.exe

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 27 June 2007 - 08:01 AM

Please download HaxFix.exe:
http://users.telenet.be/marcvn/tools/haxfix.exe
Save it to the Desktop.
Double click on haxfix.exe to install.
Check: Create a Desktop icon
Click: Next
When the installation is completed, make sure "Launch HaxFix" is checked.
Click Finish
A red "DOS window" opens with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix
Select Option 2, Run auto fix by typing 2 and then pressing Enter
If malware is found, a message to close all other open windows appears.
Close all open windows except the red DOS window from HaxFix
Press Enter
The computer reboots, and after rebooting, a logfile opens: C:\haxfix.txt

Please post the contents of C:\haxfix.txt

----------------------------------

Download SmitfraudFix (by S!Ri), to your desktop.
Double click on Smitfraudfix.cmd
Select option 1 Search, by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy and paste the content of that report into your next reply.

*IMPORTANT*
Do NOT run any other options until you are asked to do so!
Posted Image
Posted Image

#13 mhurley142

mhurley142
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 30 June 2007 - 08:07 AM

Scans run and nothing found but PC still very very slow the clock when Windows loads is on time but then slows and does not refresh it says 12:09 now but it is 14:05. Screen refresh is very very very painfully slow and even typing you have to sit and wait for the copy to appear as if you were typing so fast the buffer could not keep up until you stop and let it catch up after 5-10 seconds.

HAXFIX logfile - by Marckie

version 4.47
30/06/2007 9:27:07.64

--- Checking for Haxdoor ---

checking for a3d files
a3d files not found

checking for matching notify keys
no matching notify keys found

checking for matching services
no matching services found

checking for matching safeboot services
no matching safeboot services found

checking for other Haxdoor-files
no other Haxdoor-files found


--- Checking for Goldun ---

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for other Goldun-files
no other Goldun-files found

checking iexplore.exe
iexplore.exe is not infected


--- Catchme logfile - thank you Gmer ---

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-30 09:27:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\craziebabes@msn.com\DFSR\Staging\CS{C080F30A-F870-ED96-1E71-6A5C3970097D}\01\33-{C080F30A-F870-ED96-1E71-6A5C3970097D}-v1-{6B3602B8-5468-4C27-AC7D-DF9FDCB0C405}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\francess_x@hotmail.co.uk\DFSR\Staging\CS{8ACF877F-E09A-837E-3535-222135D156A2}\01\30-{8ACF877F-E09A-837E-3535-222135D156A2}-v1-{6B3602B8-5468-4C27-AC7D-DF9FDCB0C405}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{6C758602-581F-F41C-776E-EC51387D8CFA}\01\10-{6C758602-581F-F41C-776E-EC51387D8CFA}-v1-{6B3602B8-5468-4C27-AC7D-DF9FDCB0C405}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\01\102-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v101-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v102-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6690 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\01\102-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v101-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v102-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 736 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\01\13-{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}-v1-{6B3602B8-5468-4C27-AC7D-DF9FDCB0C405}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\03\104-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v103-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6510 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\03\104-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v103-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\05\106-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v105-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v106-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5970 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\05\106-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v105-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v106-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 672 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\07\108-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v107-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v108-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7284 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\07\108-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v107-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v108-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\09\110-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v109-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5124 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\09\110-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v109-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 568 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\11\112-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v111-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v112-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5484 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\11\112-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v111-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v112-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 616 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\13\114-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v113-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v114-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6762 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\13\114-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v113-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v114-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\15\116-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v115-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v116-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5142 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\15\116-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v115-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v116-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 568 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\17\118-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v117-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4800 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\17\118-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v117-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 536 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\19\120-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v119-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v120-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7194 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\19\120-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v119-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v120-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\21\122-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v121-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v122-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6852 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\21\122-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v121-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v122-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\23\124-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v123-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v124-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 736 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\25\126-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v125-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v126-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\27\128-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v127-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v128-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\29\130-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v129-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v130-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 712 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\30\30-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v30-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9318 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\30\30-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v30-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1568 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\31\132-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v131-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\31\31-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v31-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 822 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\31\31-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v31-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 88 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\32\32-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v32-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7356 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\32\32-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v32-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\33\134-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v133-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 568 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\33\33-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v33-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7482 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\33\33-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v33-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 832 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\34\34-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v34-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5106 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\34\34-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v34-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 576 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\35\136-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v135-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\35\35-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v35-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5736 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\35\35-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v35-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 656 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\36\36-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v36-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7788 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\36\36-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v36-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\37\138-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v137-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 520 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\37\37-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v37-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6996 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\37\37-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v37-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\38\38-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v38-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9228 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\38\38-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v38-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1024 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\39\140-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v139-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v140-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\39\39-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v39-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8004 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\39\39-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v39-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\40\40-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v40-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7104 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\40\40-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v40-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\41\41-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v41-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7770 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\41\41-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v41-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\42\42-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v42-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7428 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\42\42-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v42-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\44\44-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v44-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7662 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\44\44-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v44-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 856 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\47\47-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v47-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v47-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7122 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\47\47-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v47-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v47-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\48\48-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v48-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v48-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8292 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\48\48-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v48-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v48-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 936 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\51\51-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v51-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 11388 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\51\51-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v51-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1256 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\61\61-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v61-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 88 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\71\71-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v71-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1002 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\71\71-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v71-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\72\72-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v72-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1992 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\72\72-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v72-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 216 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\89\89-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v89-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 26778 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\89\89-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v89-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1920 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\89\89-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v89-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2896 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\90\90-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v90-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v90-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 26526 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\90\90-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v90-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v90-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1884 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\90\90-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v90-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v90-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2960 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\91\92-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v91-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v92-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3972 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\91\92-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v91-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v92-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 496 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\93\94-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v93-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6132 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\93\94-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v93-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 704 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\95\96-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v95-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v96-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6114 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\95\96-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v95-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v96-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\97\98-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v97-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v98-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5358 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\97\98-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v97-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v98-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 600 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\99\100-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v99-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5916 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\anneke---x@hotmail.co.uk\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{5ACBC054-A0ED-60F0-B569-E1CFDC0E47D9}\99\100-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v99-{0B58C187-D6A9-4954-AAC2-57862AAC1204}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\georgielu@hotmail.co.uk\DFSR\Staging\CS{73F1AFA0-9BEF-C613-4D08-DB6E18C44EB7}\01\10-{73F1AFA0-9BEF-C613-4D08-DB6E18C44EB7}-v1-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\01\24-{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}-v1-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\23\29-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v23-{8ECA5505-E8A0-41B9-A632-D1B1B6ABE428}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1792 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\25\25-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v25-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1408 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\26\26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1596 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\26\26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 156 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\26\26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2312 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\01\12-{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}-v1-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\13\39-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v13-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8076 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\13\39-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v13-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\18\32-{50038588-FD98-4788-8C75-810EAFFAD929}-v18-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1488 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\18\32-{50038588-FD98-4788-8C75-810EAFFAD929}-v18-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 168 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\20\36-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v20-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6582 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\20\36-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v20-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\31\29-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v31-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 318 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\31\29-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v31-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 936 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\32\33-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v32-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 804 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\32\33-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v32-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 80 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\33\38-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v33-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7230 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\33\38-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v33-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 928 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\punkkrockker@hotmail.co.uk\DFSR\Staging\CS{CEE96D7D-32C9-0BED-B48F-D57ED2A1367A}\59\59-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v59-{FD7C77F4-A876-4066-ADDC-7528543C6BB9}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 88 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\01\10-{E9CB024A-C957-4342-CB54-ED9A98D4154C}-v1-{A723F875-48DB-4EBB-B9BD-08153FFA40AC}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\13\13-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v13-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3408 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\14\14-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v14-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3016 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\15\15-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v15-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2336 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\16\16-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v16-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3128 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\17\17-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v17-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2616 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\18\18-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v18-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v18-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\20\20-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v20-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3112 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\21\21-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v21-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2024 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\22\22-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v22-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6464 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\25\25-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v25-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3880 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Application Data\Microsoft\Messenger\tara---x@hotmail.co.uk\SharingMetadata\anneke---x@hotmail.co.uk\DFSR\Staging\CS{E9CB024A-C957-4342-CB54-ED9A98D4154C}\26\26-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v26-{CF5E0E36-7EDA-4E7F-9496-64C210E67169}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3296 bytes hidden from API
C:\Documents and Settings\Anneke Hurley\Local Settings\Temp\AntiPhishing\FDE76B9D-4657-4B28-AE87-04EFD23D4EB6.dat
C:\Documents and Settings\Anneke Hurley\Local Settings\Temporary Internet Files\AntiPhishing\2997C193-A464-4307-88C9-F9C00083CD16.dat
C:\Documents and Settings\Anneke Hurley\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat
C:\Documents and Settings\Anneke Hurley\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
C:\Documents and Settings\Faye Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\01\16-{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}-v1-{B93D9155-B245-43AC-949B-853F22B529BF}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Faye Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\23\29-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v23-{8ECA5505-E8A0-41B9-A632-D1B1B6ABE428}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1792 bytes hidden from API
C:\Documents and Settings\Faye Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\25\25-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v25-{1D3929F0-CE08-4073-BAEB-9D4C65F85E55}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1408 bytes hidden from API
C:\Documents and Settings\Faye Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\marianne@mkcheznous.fsnet.co.uk\DFSR\Staging\CS{2DF0C062-6DB7-B3F7-F06A-1C817D14EE0F}\26\26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-{4DFFAEA1-2E87-46FC-856E-05BA065E4FF1}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2312 bytes hidden from API
C:\Documents and Settings\Faye Hurley\Local Settings\Temp\AntiPhishing\FDE76B9D-4657-4B28-AE87-04EFD23D4EB6.dat
C:\Documents and Settings\Faye Hurley\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat
C:\Documents and Settings\Faye Hurley\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
C:\Documents and Settings\Guest\Local Settings\Temp\AntiPhishing\FDE76B9D-4657-4B28-AE87-04EFD23D4EB6.dat
C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat
C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\adrian_stone14@hotmail.com\DFSR\Staging\CS{BF4CB5EE-35C2-E5F1-FA4A-27133DD28B46}\01\28-{BF4CB5EE-35C2-E5F1-FA4A-27133DD28B46}-v1-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\alanaloud@hotmail.com\DFSR\Staging\CS{83812275-5FB5-3001-38EC-D12230CEBBF2}\01\11-{83812275-5FB5-3001-38EC-D12230CEBBF2}-v1-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\cheap_movies_suk@hotmail.com\DFSR\Staging\CS{235604CC-BA0A-A0E7-145D-E6C3DD6B2131}\01\13-{235604CC-BA0A-A0E7-145D-E6C3DD6B2131}-v1-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\forgetting2remember@hotmail.com\DFSR\Staging\CS{9ABE3390-3998-C5EA-1999-D10F80B2B715}\01\29-{9ABE3390-3998-C5EA-1999-D10F80B2B715}-v1-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\jen_new@hotmail.co.uk\DfsrPrivate\Staging\CS{37DD0A06-BBF7-F158-EF4E-18AFB0CC739C}\01\10-{37DD0A06-BBF7-F158-EF4E-18AFB0CC739C}-v1-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\jen_new@hotmail.co.uk\DfsrPrivate\Staging\CS{37DD0A06-BBF7-F158-EF4E-18AFB0CC739C}\32\32-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v32-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1952 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\jen_new@hotmail.co.uk\DfsrPrivate\Staging\CS{37DD0A06-BBF7-F158-EF4E-18AFB0CC739C}\33\33-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v33-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1256 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\jen_new@hotmail.co.uk\DfsrPrivate\Staging\CS{37DD0A06-BBF7-F158-EF4E-18AFB0CC739C}\34\34-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v34-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2168 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\jen_new@hotmail.co.uk\DfsrPrivate\Staging\CS{37DD0A06-BBF7-F158-EF4E-18AFB0CC739C}\35\35-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v35-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1968 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\jen_new@hotmail.co.uk\DfsrPrivate\Staging\CS{37DD0A06-BBF7-F158-EF4E-18AFB0CC739C}\36\36-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v36-{F91338EC-D0F8-43BF-AF21-26A1B20979B8}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1776 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\vague_armadillo@hotmail.com\DFSR\Staging\CS{FDB33C60-79E3-0D8D-FE5D-B9D3F85C91C8}\01\12-{FDB33C60-79E3-0D8D-FE5D-B9D3F85C91C8}-v1-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\01\15-{43846520-F15B-2A70-D2D0-FC997190854C}-v1-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\11\11-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v11-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\12\12-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v12-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6048 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\13\13-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v13-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5944 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\14\14-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v14-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5384 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\15\15-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v15-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4104 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\16\16-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v16-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3624 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\17\17-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v17-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3896 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\18\18-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v18-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4696 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\19\19-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v19-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3624 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\20\20-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v20-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4320 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\20\20-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v20-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6222 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\20\20-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v20-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 688 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\21\21-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v21-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3960 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\21\21-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v21-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 16572 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\21\21-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v21-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1272 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\21\21-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v21-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1848 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\22\22-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v22-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 11008 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\22\22-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v22-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2928 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\22\22-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v22-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 344 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\23\23-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v23-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4568 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\23\23-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v23-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 19020 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\23\23-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v23-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1362 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\23\23-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v23-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3968 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\24\24-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v24-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4920 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\24\24-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v24-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2424 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\24\24-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v24-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 272 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\25\25-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v25-{899DDF1D-47F4-47B6-9E35-7022449D83F6}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3640 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\25\25-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v25-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 16536 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\25\25-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v25-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1164 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\25\25-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v25-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1848 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\26\26-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v26-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4242 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\26\26-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v26-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\27\27-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v27-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3558 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\han9han@hotmail.com\SharingMetadata\zagafeur@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\27\27-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v27-{96CE13CA-B4BA-4428-BAC3-925C976D61EA}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 408 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\45\145-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v145-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v145-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6256 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\77\14-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v77-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 31116 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\77\14-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v77-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2100 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\77\14-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v77-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3416 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\01\25-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v101-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 66072 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\01\25-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v101-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4458 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\01\25-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v101-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7232 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\15\26-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v115-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8576 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\78\78-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v78-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v78-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8280 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\79\79-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v79-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v79-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 288 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\80\21-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v80-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 10722 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\80\21-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v80-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1192 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\81\81-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v81-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v81-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\82\82-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v82-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v82-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\83\83-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v83-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v83-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\84\18-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v84-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9030 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\84\18-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v84-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1016 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\85\85-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v85-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v85-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1488 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\86\86-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v86-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v86-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3440 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\87\87-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v87-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v87-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4008 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\88\88-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v88-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v88-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3384 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\89\89-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v89-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3672 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\90\90-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v90-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v90-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4184 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\91\91-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v91-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v91-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3088 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\92\92-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v92-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v92-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3592 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\93\93-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v93-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v93-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3816 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\94\94-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v94-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4848 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\95\95-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v95-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v95-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3424 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\96\96-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v96-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v96-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3184 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\97\97-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v97-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v97-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4768 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\98\98-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v98-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v98-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4112 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\99\99-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v99-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v99-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5680 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\25\35-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v125-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 70392 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\25\35-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v125-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4818 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\25\35-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v125-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7824 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\32\132-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v132-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8392 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\33\133-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v133-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v133-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 9032 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\34\134-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v134-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 13656 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\35\135-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v135-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8112 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\36\136-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v136-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 14968 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\37\137-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v137-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5624 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\38\138-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v138-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 9952 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\39\139-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v139-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v139-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5296 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\40\140-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v140-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v140-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6088 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\41\141-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v141-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v141-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3216 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\42\142-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v142-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3408 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\43\143-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v143-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v143-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2688 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\44\144-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v144-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v144-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5392 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\46\146-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v146-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v146-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5288 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\47\147-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v147-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v147-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2992 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\48\148-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v148-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4000 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\49\149-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v149-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v149-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 9088 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\50\150-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v150-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v150-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 944 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\51\151-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v151-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1400 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\52\152-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v152-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1296 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\53\153-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v153-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1848 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\54\154-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v154-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1408 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\55\37-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v155-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21162 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\55\37-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v155-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1578 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\55\37-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v155-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2352 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\56\30-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v156-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9552 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\56\30-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v156-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\57\32-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v157-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 15564 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\57\32-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v157-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1744 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\58\34-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v158-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 33996 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\58\34-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v158-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2424 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\58\34-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v158-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3752 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\59\159-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v159-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4736 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\60\160-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v160-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5872 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\61\161-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v161-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4288 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\62\162-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v162-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4048 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\63\63-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v63-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7696 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\64\64-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v64-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6808 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\65\65-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v65-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v65-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6696 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\67\67-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v67-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v67-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5960 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\68\68-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v68-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1656 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\69\69-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v69-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v69-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1968 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\70\27-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v70-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 81696 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\70\27-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v70-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 5952 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\70\27-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v70-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 9128 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\71\71-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v71-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1936 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\72\172-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v172-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1112 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\72\20-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v72-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 151914 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\72\20-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v72-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 10722 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\72\20-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v72-{3EEED186-5FA6-433C-962C-59E5CE7CD8DE}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 16784 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\73\73-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v73-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1400 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\74\74-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v74-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4296 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\75\75-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v75-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3184 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Application Data\Microsoft\Messenger\zagafeur@hotmail.com\SharingMetadata\han9han@hotmail.com\DFSR\Staging\CS{43846520-F15B-2A70-D2D0-FC997190854C}\76\76-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v76-{243097CF-83BA-41E3-AEA8-71C87EB9DB41}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2584 bytes hidden from API
C:\Documents and Settings\Hannah Hurley\Local Settings\Temp\AntiPhishing\FDE76B9D-4657-4B28-AE87-04EFD23D4EB6.dat
C:\Documents and Settings\Hannah Hurley\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
C:\Documents and Settings\Julie Hurley\Local Settings\Temp\AntiPhishing\FDE76B9D-4657-4B28-AE87-04EFD23D4EB6.dat
C:\Documents and Settings\Julie Hurley\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat
C:\Documents and Settings\Julie Hurley\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
C:\Documents and Settings\Thomas Hurley\Local Settings\Application Data\Microsoft\Messenger\peoplercute4me@hotmail.com\SharingMetadata\georgielu@hotmail.co.uk\DFSR\Staging\CS{73F1AFA0-9BEF-C613-4D08-DB6E18C44EB7}\01\14-{73F1AFA0-9BEF-C613-4D08-DB6E18C44EB7}-v1-{B717FC76-F130-4286-A28D-F0247E608047}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Thomas Hurley\Local Settings\Temp\AntiPhishing\FDE76B9D-4657-4B28-AE87-04EFD23D4EB6.dat
C:\Documents and Settings\Thomas Hurley\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat
C:\Documents and Settings\Thomas Hurley\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 281


--- Analysing Catchme logfile ---

no matching regkeys found


Finished!

SmitFraudFix v2.197

Scan done at 11:05:02.79, 30/06/2007
Run from C:\Program Files\Mozilla Firefox\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\KService\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Program Files\Onfolio\onfserv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\COMPAQ\CPQINET\CPQInet.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\notepad.exe

hosts


C:\


C:\WINDOWS


C:\WINDOWS\system


C:\WINDOWS\Web


C:\WINDOWS\system32


C:\WINDOWS\system32\LogFiles


C:\Documents and Settings\Melvin Hurley


C:\Documents and Settings\Melvin Hurley\Application Data


Start Menu


C:\DOCUME~1\MELVIN~1\FAVORI~1


Desktop


C:\Program Files


Corrupted keys


Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


Rustock



DNS

Description: Intel® PRO/100 VM Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 192.168.0.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{7901E6EE-7599-46C3-84BA-4F388C733D2E}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{7901E6EE-7599-46C3-84BA-4F388C733D2E}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{7901E6EE-7599-46C3-84BA-4F388C733D2E}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1


Scanning for wininet.dll infection


End

#14 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 30 June 2007 - 11:01 AM

If you have the MS Windows XP install disk.
Click Start>Run,type sfc /scannow then press Ok.
Leave a space in between sfc and /scannow
Reboot when you've done.

If still no joy try a Repair Install.
Configure your computer to start from the CD-ROM drive.
[Boot into the Bios and set your CD-Rom drive as first boot device].
For more information about how to do this,refer to your computer's documentation or contact your computer manufacturer.
Then insert your Microsoft Windows XP Setup CD,and restart your computer.
When the 'Press any key to boot from CD' message is displayed on screen, press a key.
Press ENTER when you see the message to setup Windows XP now, and then press ENTER displayed on the 'Welcome to Setup' screen.
Do not choose the option to press R to use the Recovery Console.
In the Windows XP Licensing Agreement, press F8 to agree to the license agreement.
Make sure that your current installation of Windows XP is selected in the box, and then press R to repair Windows XP.
Follow the instructions on the screen to complete Setup.
Posted Image
Posted Image

#15 mhurley142

mhurley142
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:39 PM

Posted 02 July 2007 - 02:35 PM

Thanks Richie I'll give this a try and if it doesn't work start uninstalling applications until the performance improves. Though I suspect I may end up having to reformat and start afresh.

Thank you for your help it is much appreciated.

Melvin




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users