[code] OTScanIt2 logfile created on: 30/01/2009 20:35:23 - Run 2 OTScanIt2 by OldTimer - Version 1.0.7.1 Folder = C:\Documents and Settings\Victor\Desktop\OTScanIt2 Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1023.48 Mb Total Physical Memory | 594.75 Mb Available Physical Memory | 58.11% Memory free 2.86 Gb Paging File | 2.31 Gb Available in Paging File | 80.77% Paging File free Paging file location(s): C:\pagefile.sys 2000 2000; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 149.04 Gb Total Space | 56.89 Gb Free Space | 38.17% Space Free | Partition Type: NTFS Drive D: | 298.02 Gb Total Space | 22.49 Gb Free Space | 7.55% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: VICTOR-3C104101 Current User Name: Victor Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days [Processes - Safe List] applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) avgam.exe -> %ProgramFiles%\AVG\AVG8\avgam.exe -> [2009/01/08 09:43:58 | 00,832,280 | ---- | M] (AVG Technologies CZ, s.r.o.) avgcsrvx.exe -> %ProgramFiles%\AVG\AVG8\avgcsrvx.exe -> [2009/01/08 09:44:00 | 00,687,896 | ---- | M] (AVG Technologies CZ, s.r.o.) avgemc.exe -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2009/01/08 09:43:57 | 00,903,960 | ---- | M] (AVG Technologies CZ, s.r.o.) avgnsx.exe -> %ProgramFiles%\AVG\AVG8\avgnsx.exe -> [2009/01/16 09:31:19 | 00,592,128 | ---- | M] (AVG Technologies CZ, s.r.o.) avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2009/01/08 09:44:01 | 00,484,120 | ---- | M] (AVG Technologies CZ, s.r.o.) avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> [2009/01/08 09:43:49 | 01,601,304 | ---- | M] (AVG Technologies CZ, s.r.o.) avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/01/08 09:43:55 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) cthelper.exe -> %SystemRoot%\system32\CtHelper.exe -> [2008/06/27 17:24:58 | 00,019,456 | ---- | M] (Creative Technology Ltd) e_s4i0c2.exe -> %SystemRoot%\system32\spool\drivers\w32x86\3\E_S4I0C2.EXE -> [2003/09/12 03:00:00 | 00,099,840 | ---- | M] (SEIKO EPSON CORPORATION) googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2008/03/14 04:46:18 | 00,068,856 | ---- | M] (Google Inc.) googleupdaterservice.exe -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/10/09 11:59:09 | 00,168,432 | ---- | M] (Google) ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2008/12/23 23:52:36 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2008/12/23 23:52:36 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) lvprcsrv.exe -> %CommonProgramFiles%\logishrd\LVMVFM\LVPrcSrv.exe -> [2007/02/06 17:45:26 | 00,109,344 | ---- | M] (Logitech Inc.) mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) nbservice.exe -> %CommonProgramFiles%\Nero\Nero BackItUp 4\NBService.exe -> [2008/09/24 14:32:48 | 00,935,208 | ---- | M] (Nero AG) ntuneservice.exe -> %ProgramFiles%\NVIDIA Corporation\nTune\nTuneService.exe -> [2007/09/04 19:25:44 | 00,131,072 | ---- | M] (NVIDIA) nvmixertray.exe -> %ProgramFiles%\NVIDIA Corporation\NvMixer\NvMixerTray.exe -> [2004/12/20 16:12:36 | 00,131,072 | ---- | M] (NVIDIA Corporation) nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2009/01/15 08:19:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/01/26 12:13:22 | 00,485,376 | ---- | M] (OldTimer Tools) pd91agent.exe -> %ProgramFiles%\Raxco\PerfectDisk2008\PD91Agent.exe -> [2008/09/09 12:49:50 | 00,693,512 | ---- | M] (Raxco Software, Inc.) rivatuner.exe -> %ProgramFiles%\RivaTuner v2.11\RivaTuner.exe -> [2008/09/16 17:15:00 | 02,715,648 | ---- | M] () rundll32.exe -> %SystemRoot%\system32\rundll32.exe -> [2008/04/14 00:12:33 | 00,033,280 | ---- | M] (Microsoft Corporation) starwindserviceae.exe -> %ProgramFiles%\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -> [2007/05/28 16:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) utorrent.exe -> %ProgramFiles%\uTorrent\uTorrent.exe -> [2008/11/14 23:23:59 | 00,270,128 | ---- | M] (BitTorrent, Inc.) wscntfy.exe -> %SystemRoot%\system32\wscntfy.exe -> [2008/04/14 00:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) [Win32 Services - Safe List] (Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> [2008/04/04 22:17:28 | 00,072,704 | ---- | M] (Adobe Systems) (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) (avg8emc) AVG8 E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2009/01/08 09:43:57 | 00,903,960 | ---- | M] (AVG Technologies CZ, s.r.o.) (avg8wd) AVG8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/01/08 09:43:55 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) (Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) (FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2007/10/09 12:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) (getPlus(R) Helper) getPlus(R) Helper [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\NOS\bin\getPlus_HelperSvc.exe -> [2008/06/26 09:24:08 | 00,031,592 | ---- | M] (NOS Microsystems Ltd.) (gusvc) Google Updater Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/10/09 11:59:09 | 00,168,432 | ---- | M] (Google) (helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\pchealth\helpctr\binaries\pchsvc.dll -> [2008/04/14 00:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) (idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2007/10/11 09:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) (JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2008/12/23 23:52:36 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) (LVPrcSrv) Process Monitor [Win32_Own | Auto | Running] -> %CommonProgramFiles%\logishrd\LVMVFM\LVPrcSrv.exe -> [2007/02/06 17:45:26 | 00,109,344 | ---- | M] (Logitech Inc.) (LVSrvLauncher) LVSrvLauncher [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\logishrd\SrvLnch\SrvLnch.exe -> [2007/02/06 17:47:12 | 00,105,248 | ---- | M] (Logitech Inc.) (MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) (Nero BackItUp Scheduler 4.0) Nero BackItUp Scheduler 4.0 [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Nero\Nero BackItUp 4\NBService.exe -> [2008/09/24 14:32:48 | 00,935,208 | ---- | M] (Nero AG) (NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2007/10/11 09:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) (nTuneService) nTune Service [Win32_Own | Auto | Running] -> %ProgramFiles%\NVIDIA Corporation\nTune\nTuneService.exe -> [2007/09/04 19:25:44 | 00,131,072 | ---- | M] (NVIDIA) (NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2009/01/15 08:19:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) (ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) (PD91Agent) PD91Agent [Win32_Own | Auto | Running] -> %ProgramFiles%\Raxco\PerfectDisk2008\PD91Agent.exe -> [2008/09/09 12:49:50 | 00,693,512 | ---- | M] (Raxco Software, Inc.) (PD91Engine) PD91Engine [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Raxco\PerfectDisk2008\PD91Engine.exe -> [2008/09/09 12:49:52 | 00,906,504 | ---- | M] (Raxco Software, Inc.) (PD91VMDefrag) PD91VMDefrag [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Raxco\PerfectDisk2008\PD91VMDefrag.exe -> [2008/02/29 10:44:26 | 00,226,568 | ---- | M] (Raxco Software, Inc.) (PostgreSQL) PostgreSQL Database Server [Win32_Own | Auto | Stopped] -> -> File not found (StarWindServiceAE) StarWind AE Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -> [2007/05/28 16:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) (usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) (WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) (WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) (WudfSvc) Windows Driver Foundation - User-mode Driver Framework [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\WudfSvc.dll -> [2006/09/28 18:56:14 | 00,055,808 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (61883) 61883 Unit Device [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\61883.sys -> [2008/04/13 18:46:20 | 00,048,128 | ---- | M] (Microsoft Corporation) (AmdPPM) AMD HwPState Processor Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\AmdPPM.sys -> [2007/04/16 21:46:00 | 00,033,792 | ---- | M] (Advanced Micro Devices) (Avc) AVC Device [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\avc.sys -> [2008/04/13 18:46:20 | 00,038,912 | ---- | M] (Microsoft Corporation) (AvgLdx86) AVG AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avgldx86.sys -> [2009/01/16 09:31:19 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) (AvgMfx86) AVG On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\system32\drivers\avgmfx86.sys -> [2009/01/08 09:44:01 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) (AvgRkx86) avgrkx86.sys [File_System | Boot | Running] -> %SystemRoot%\system32\drivers\avgrkx86.sys -> [2009/01/08 09:43:59 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) (AvgTdiX) AVG8 Network Redirector [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avgtdix.sys -> [2009/01/08 09:43:52 | 00,107,272 | ---- | M] (AVG Technologies CZ, s.r.o.) (CamDrL) Logitech QuickCam Pro 3000(CamDrl) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Camdrl.sys -> [2007/02/03 10:25:56 | 01,075,360 | ---- | M] (Logitech Inc.) (COMMONFX) COMMONFX [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\COMMONFX.sys -> [2008/06/27 19:21:18 | 00,099,352 | ---- | M] (Creative Technology Ltd) (COMMONFX.SYS) COMMONFX.SYS [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\COMMONFX.sys -> [2008/06/27 19:21:18 | 00,099,352 | ---- | M] (Creative Technology Ltd) (ctac32k) Creative AC3 Software Decoder [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctac32k.sys -> [2008/07/07 10:29:58 | 00,511,000 | ---- | M] (Creative Technology Ltd) (ctaud2k) Creative Audio Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctaud2k.sys -> [2008/07/07 10:31:10 | 00,532,376 | ---- | M] (Creative Technology Ltd) (CTAUDFX) CTAUDFX [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\CTAUDFX.sys -> [2008/06/27 19:21:26 | 00,555,032 | ---- | M] (Creative Technology Ltd) (CTAUDFX.SYS) CTAUDFX.SYS [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\CTAUDFX.sys -> [2008/06/27 19:21:26 | 00,555,032 | ---- | M] (Creative Technology Ltd) (ctdvda2k) Creative DVD-Audio Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ctdvda2k.sys -> [2008/07/07 10:31:44 | 00,347,080 | ---- | M] (Creative Technology Ltd) (CTERFXFX) CTERFXFX [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\CTERFXFX.sys -> [2008/06/27 19:21:44 | 00,100,888 | ---- | M] (Creative Technology Ltd) (CTERFXFX.SYS) CTERFXFX.SYS [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\CTERFXFX.sys -> [2008/06/27 19:21:44 | 00,100,888 | ---- | M] (Creative Technology Ltd) (ctprxy2k) Creative Proxy Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctprxy2k.sys -> [2008/07/07 10:33:40 | 00,014,360 | ---- | M] (Creative Technology Ltd) (CTSBLFX) CTSBLFX [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\CTSBLFX.sys -> [2008/06/27 19:21:38 | 00,566,296 | ---- | M] (Creative Technology Ltd) (CTSBLFX.SYS) CTSBLFX.SYS [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\CTSBLFX.sys -> [2008/06/27 19:21:38 | 00,566,296 | ---- | M] (Creative Technology Ltd) (ctsfm2k) Creative SoundFont Management Device Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctsfm2k.sys -> [2008/07/07 10:34:08 | 00,157,208 | ---- | M] (Creative Technology Ltd) (DefragFS) DefragFS [File_System | Boot | Running] -> %SystemRoot%\system32\drivers\DefragFS.sys -> [2008/08/28 12:16:40 | 00,071,184 | ---- | M] (Raxco Software, Inc.) (emupia) E-mu Plug-in Architecture Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\emupia2k.sys -> [2008/07/07 10:35:46 | 00,092,696 | ---- | M] (Creative Technology Ltd) (gameenum) Game Port Enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\gameenum.sys -> [2008/04/13 19:45:30 | 00,010,624 | ---- | M] (Microsoft Corporation) (GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2008/04/17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) (GT680x) GrandTechICNameNT [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gt680x.sys -> [2003/02/18 22:38:04 | 00,017,504 | R--- | M] ( ) (ha10kx2k) Creative Hardware Abstract Layer Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ha10kx2k.sys -> [2008/07/07 10:36:10 | 00,797,720 | ---- | M] (Creative Technology Ltd) (hap16v2k) Creative P16V HAL Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\haP16v2k.sys -> [2008/07/07 10:36:36 | 00,162,840 | ---- | M] (Creative Technology Ltd) (hap17v2k) Creative P17V HAL Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\haP17v2k.sys -> [2008/07/07 10:37:04 | 00,189,464 | ---- | M] (Creative Technology Ltd) (LVcKap) Logitech AEC Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Lvckap.sys -> [2007/02/06 17:42:40 | 01,691,808 | ---- | M] () (LVMVDrv) Logitech Machine Vision Engine Loader [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LVMVdrv.sys -> [2007/02/06 17:44:36 | 01,964,064 | ---- | M] (Logitech Inc.) (LVPr2Mon) Logitech LVPr2Mon Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LVPr2Mon.sys -> [2007/02/06 17:45:04 | 00,025,632 | ---- | M] () (LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LVUSBSta.sys -> [2007/02/03 10:32:36 | 00,041,504 | ---- | M] (Logitech Inc.) (MSDV) Microsoft DV Camera and VCR [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\msdv.sys -> [2008/04/13 18:46:10 | 00,051,200 | ---- | M] (Microsoft Corporation) (ms_mpu401) Microsoft MPU-401 MIDI UART Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\msmpu401.sys -> [2001/08/17 14:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) (nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nv4_mini.sys -> [2009/01/15 08:19:00 | 06,301,248 | ---- | M] (NVIDIA Corporation) (nvata) nvata [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\nvata.sys -> [2006/04/24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) (nvax) Service for NVIDIA(R) nForce(TM) Audio Enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nvax.sys -> [2005/07/26 05:58:30 | 00,053,376 | ---- | M] (NVIDIA Corporation) (NVENETFD) NVIDIA nForce 10/100/1000 Mbps Ethernet [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\NVENETFD.sys -> [2008/08/01 10:36:00 | 00,054,784 | ---- | M] (NVIDIA Corporation) (nvnetbus) NVIDIA Network Bus Enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nvnetbus.sys -> [2008/08/01 10:36:00 | 00,022,016 | ---- | M] (NVIDIA Corporation) (nvnforce) Service for NVIDIA(R) nForce(TM) Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nvapu.sys -> [2005/07/26 06:01:56 | 00,415,360 | ---- | M] (NVIDIA Corporation) (NVR0Dev) NVR0Dev [Kernel | On_Demand | Running] -> %SystemRoot%\nvoclock.sys -> [2007/09/04 19:26:32 | 00,029,696 | ---- | M] (NVidia Corp.) (ossrv) Creative OS Services Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctoss2k.sys -> [2008/07/07 10:33:16 | 00,127,512 | ---- | M] (Creative Technology Ltd.) (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2001/08/23 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2008/02/21 02:05:38 | 00,043,528 | ---- | M] (Sonic Solutions) (RivaTuner32) RivaTuner32 [Kernel | On_Demand | Running] -> %ProgramFiles%\RivaTuner v2.11\RivaTuner32.sys -> [2008/09/16 17:15:00 | 00,009,088 | ---- | M] () (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 10:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sptd.sys -> [2008/10/27 08:21:26 | 00,717,296 | ---- | M] () (SSHDRV76) SSHDRV76 [Kernel | System | Running] -> %SystemRoot%\system32\drivers\SSHDRV76.sys -> [2008/12/27 01:59:59 | 00,053,760 | ---- | M] () (SVKP) SVKP [Kernel | Auto | Running] -> %SystemRoot%\system32\SVKP.sys -> [2008/03/26 21:15:04 | 00,002,368 | ---- | M] (AntiCracking) (usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaudio.sys -> [2008/04/13 18:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> -> HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.startrek-gamers.com/ -> HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> HKEY_CURRENT_USER\: "ProxyOverride" -> *.local -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\] > -> -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\: Main\\"Start Page" -> http://www.startrek-gamers.com/ -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\: "ProxyEnable" -> 0 -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\: "ProxyOverride" -> *.local -> < FireFox Settings [Default Profile] > -> C:\Documents and Settings\Victor\Application Data\Mozilla\FireFox\Profiles\fhw30t2e.default\prefs.js -> browser.startup.homepage -> "http://www.startrek-gamers.com/" -> browser.startup.homepage_override.mstone -> "rv:1.9.0.5" -> extensions.enabledItems -> [removed]:1.3.0 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 -> extensions.enabledItems -> [removed]:1.0 -> extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5 -> < HOSTS File > (291593 bytes and 10087 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> First 25 entries... 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.100888290cs.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.10sek.com 127.0.0.1 10sek.com 127.0.0.1 www.123topsearch.com 127.0.0.1 123topsearch.com 127.0.0.1 www.132.com 127.0.0.1 132.com 127.0.0.1 www.136136.net 127.0.0.1 136136.net 127.0.0.1 www.163ns.com 127.0.0.1 163ns.com < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {00C6482D-C502-44C8-8409-FCE54AD9C208} [HKLM] -> %ProgramFiles%\TechSmith\SnagIt 8\SnagItBHO.dll [SnagIt Toolbar Loader] -> [2007/02/16 17:41:04 | 00,063,048 | ---- | M] (TechSmith Corporation) {18DF081C-E8AD-4283-A596-FA578C2EBDC3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe PDF Link Helper] -> [2008/06/11 21:33:16 | 00,075,128 | ---- | M] (Adobe Systems Incorporated) {22BF413B-C6D2-4d91-82A9-A0F997BA588C} [HKLM] -> %ProgramFiles%\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Skype add-on (mastermind)] -> [2008/11/07 14:31:40 | 01,088,296 | ---- | M] (Skype Technologies S.A.) {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/01/08 09:43:52 | 01,078,552 | ---- | M] (AVG Technologies CZ, s.r.o.) {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2008/09/15 14:25:44 | 01,562,960 | ---- | M] (Safer Networking Limited) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2008/12/23 23:52:36 | 00,320,920 | ---- | M] (Sun Microsystems, Inc.) {7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found {9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2007/09/20 10:30:18 | 00,328,752 | ---- | M] (Microsoft Corporation) {AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [2009/01/10 21:31:11 | 00,251,504 | ---- | M] () {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [Google Toolbar Notifier BHO] -> [2009/01/10 22:09:38 | 00,657,904 | ---- | M] (Google Inc.) {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [Google Dictionary Compression sdch] -> [2009/01/10 21:31:11 | 00,522,224 | ---- | M] (Google Inc.) {DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2008/12/23 23:52:36 | 00,034,816 | ---- | M] (Sun Microsystems, Inc.) {E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2008/12/23 23:52:36 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} [HKLM] -> %SystemRoot%\system32\AlxTB1.dll [AlxTB BHO Class] -> [2006/10/31 00:17:06 | 00,565,248 | ---- | M] (Alexa Internet) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/01/10 21:31:11 | 00,251,504 | ---- | M] () "{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> %ProgramFiles%\DAEMON Tools Toolbar\DTToolbar.dll [DAEMON Tools Toolbar] -> [2008/10/14 13:38:06 | 00,863,688 | ---- | M] () "{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" [HKLM] -> %ProgramFiles%\TechSmith\SnagIt 8\SnagItIEAddin.dll [SnagIt] -> [2007/02/16 17:41:04 | 00,161,352 | ---- | M] (TechSmith Corporation) < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/01/10 21:31:11 | 00,251,504 | ---- | M] () WebBrowser\\"{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> %ProgramFiles%\DAEMON Tools Toolbar\DTToolbar.dll [DAEMON Tools Toolbar] -> [2008/10/14 13:38:06 | 00,863,688 | ---- | M] () WebBrowser\\"{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/01/10 21:31:11 | 00,251,504 | ---- | M] () WebBrowser\\"{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> %ProgramFiles%\DAEMON Tools Toolbar\DTToolbar.dll [DAEMON Tools Toolbar] -> [2008/10/14 13:38:06 | 00,863,688 | ---- | M] () WebBrowser\\"{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/01/08 09:43:49 | 01,601,304 | ---- | M] (AVG Technologies CZ, s.r.o.) "CTHelper" -> %SystemRoot%\system32\CtHelper.exe [CTHELPER.EXE] -> [2008/06/27 17:24:58 | 00,019,456 | ---- | M] (Creative Technology Ltd) "CTxfiHlp" -> %SystemRoot%\system32\CTXFIHLP.EXE [CTXFIHLP.EXE] -> [2006/08/11 14:56:04 | 00,018,944 | ---- | M] (Creative Technology Ltd) "EPSON Stylus C64 Series" -> %SystemRoot%\system32\spool\drivers\w32x86\3\E_S4I0C2.EXE [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0C2.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64"] -> [2003/09/12 03:00:00 | 00,099,840 | ---- | M] (SEIKO EPSON CORPORATION) "iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) "NvCplDaemon" -> %SystemRoot%\system32\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2009/01/15 08:19:00 | 13,680,640 | ---- | M] (NVIDIA Corporation) "NvMediaCenter" -> %SystemRoot%\system32\nvmctray.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2009/01/15 08:19:00 | 00,086,016 | ---- | M] (NVIDIA Corporation) "NVMixerTray" -> %ProgramFiles%\NVIDIA Corporation\NvMixer\NvMixerTray.exe ["C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"] -> [2004/12/20 16:12:36 | 00,131,072 | ---- | M] (NVIDIA Corporation) "nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [2009/01/15 08:19:00 | 01,657,376 | ---- | M] () "QuickTime Task" -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2009/01/05 16:18:48 | 00,413,696 | ---- | M] (Apple Inc.) "RivaTuner" -> %ProgramFiles%\RivaTuner v2.11\RivaTuner.exe ["C:\Program Files\RivaTuner v2.11\RivaTuner.exe" /T] -> [2008/09/16 17:15:00 | 02,715,648 | ---- | M] () "RivaTunerStartupDaemon" -> ["C:\Program Files\RivaTuner v2.11\RivaTuner.exe" /S] -> File not found "SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2008/12/23 23:52:36 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AlcoholAutomount" -> %ProgramFiles%\Alcohol Soft\Alcohol 120\AxCmd.exe ["C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount] -> [2008/02/22 15:58:24 | 00,217,544 | ---- | M] (Alcohol Soft Development Team) "DAEMON Tools Lite" -> %ProgramFiles%\DAEMON Tools Lite\daemon.exe ["C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun] -> [2008/08/08 12:11:12 | 00,490,952 | ---- | M] (DT Soft Ltd) "msnmsgr" -> %ProgramFiles%\Windows Live\Messenger\msnmsgr.exe ["C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background] -> [2007/10/18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) "NVIDIA nTune" -> %ProgramFiles%\NVIDIA Corporation\nTune\nTuneCmd.exe ["C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear] -> [2007/09/04 19:25:38 | 00,081,920 | ---- | M] (NVIDIA) "swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2008/03/14 04:46:18 | 00,068,856 | ---- | M] (Google Inc.) < Run [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AlcoholAutomount" -> %ProgramFiles%\Alcohol Soft\Alcohol 120\AxCmd.exe ["C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount] -> [2008/02/22 15:58:24 | 00,217,544 | ---- | M] (Alcohol Soft Development Team) "DAEMON Tools Lite" -> %ProgramFiles%\DAEMON Tools Lite\daemon.exe ["C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun] -> [2008/08/08 12:11:12 | 00,490,952 | ---- | M] (DT Soft Ltd) "msnmsgr" -> %ProgramFiles%\Windows Live\Messenger\msnmsgr.exe ["C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background] -> [2007/10/18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) "NVIDIA nTune" -> %ProgramFiles%\NVIDIA Corporation\nTune\nTuneCmd.exe ["C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear] -> [2007/09/04 19:25:38 | 00,081,920 | ---- | M] (NVIDIA) "swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2008/03/14 04:46:18 | 00,068,856 | ---- | M] (Google Inc.) < Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk -> %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe -> [1999/11/04 16:06:48 | 00,113,664 | ---- | M] (Adobe Systems, Inc.) < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < Victor Startup Folder > -> C:\Documents and Settings\Victor\Start Menu\Programs\Startup -> %UserProfile%\Start Menu\Programs\Startup\Adobe Gamma.lnk -> %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe -> [1999/11/04 16:06:48 | 00,113,664 | ---- | M] (Adobe Systems, Inc.) < victor1st Startup Folder > -> C:\Documents and Settings\victor1st\Start Menu\Programs\Startup -> < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoFolderOptions" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found \\"NoFolderOptions" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"DisableRegistryTools" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found \\"NoFolderOptions" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"DisableRegistryTools" -> [0] -> File not found < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> Alexa Web Search -> [http://client.alexa.com/holiday/script/actions/search.htm] -> File not found E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation) Get Alexa Data -> [http://client.alexa.com/holiday/script/actions/sitedata.htm] -> File not found Mail to a Friend... -> [http://client.alexa.com/holiday/script/actions/mailto.htm] -> File not found See Related Links -> [http://client.alexa.com/holiday/script/actions/related.htm] -> File not found Write a Review... -> [http://client.alexa.com/holiday/script/actions/review.htm] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> Alexa Web Search -> [http://client.alexa.com/holiday/script/actions/search.htm] -> File not found E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation) Get Alexa Data -> [http://client.alexa.com/holiday/script/actions/sitedata.htm] -> File not found Mail to a Friend... -> [http://client.alexa.com/holiday/script/actions/mailto.htm] -> File not found See Related Links -> [http://client.alexa.com/holiday/script/actions/related.htm] -> File not found Write a Review... -> [http://client.alexa.com/holiday/script/actions/review.htm] -> File not found < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE}:Exec [HKLM] -> %ProgramFiles%\Paltalk Messenger\paltalk.exe [Button: PalTalk] -> [2008/09/10 22:41:11 | 11,713,536 | ---- | M] (AVM Software Inc.) {77BF5300-1474-4EC7-9980-D32B190E9B07}:{77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> %ProgramFiles%\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Button: Skype] -> [2008/11/07 14:31:40 | 01,088,296 | ---- | M] (Skype Technologies S.A.) {92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation) {c95fe080-8f5d-11d2-a20b-00aa003c157a}:C:\WINDOWS\web\related.htm [HKLM] -> %SystemRoot%\Web\related.htm [Button: @shdoclc.dll,-866] -> [2008/06/07 21:45:06 | 00,000,296 | ---- | M] () {c95fe080-8f5d-11d2-a20b-00aa003c157a}:C:\WINDOWS\web\related.htm [HKLM] -> %SystemRoot%\Web\related.htm [Menu: @shdoclc.dll,-864] -> [2008/06/07 21:45:06 | 00,000,296 | ---- | M] () {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2008/09/15 14:25:44 | 01,562,960 | ---- | M] (Safer Networking Limited) {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 18:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5239 domain(s) found. -> 49 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5238 domain(s) found. -> 48 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5238 domain(s) found. -> 48 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5238 domain(s) found. -> 48 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5238 domain(s) found. -> 48 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\] > -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-776561741-796845957-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab [Facebook Photo Uploader 5 Control] -> {166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Shockwave ActiveX Control] -> {1E54D648-B804-468d-BC78-4AFFED8E262E} [HKLM] -> http://www.srtest.com/srl_bin/sysreqlab_srl.cab [System Requirements Lab Class] -> {6414512B-B978-451D-A0D8-FCFDF33E833C} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1231443949578 [WUWebControl Class] -> {67DABFBF-D0AB-41FA-9C46-CC0F21721616} [HKLM] -> http://download.divx.com/player/DivXBrowserPlugin.cab [DivXBrowserPlugin Object] -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231443937531 [MUWebControl Class] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key does not exist or could not be opened.] -> {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab [Java Plug-in 1.6.0_04] -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab [Java Plug-in 1.6.0_05] -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} [HKLM] -> http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab [get_atlcom Class] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {17C7BE81-2F9F-448A-A277-4E00E5C1A05B} -> (1394 Net Adapter) -> {268FAC4D-1D0E-4D9D-BEF8-6FC904B1CE5E} -> () -> {492AEA78-3379-430B-B0BB-6BD1BDE6B7AC} -> (NVIDIA nForce 10/100/1000 Mbps Ethernet ) -> {C6A1B86F-E56A-4BA0-8086-B710B1220E5C} -> (1394 Net Adapter) -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> avgrsstarter -> %SystemRoot%\system32\avgrsstx.dll -> [2009/01/08 09:44:01 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 18:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 00:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 18:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 00:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) "C:\Program Files\Anno 1701\Anno1701.exe" -> C:\Program Files\Anno 1701\Anno1701.exe [C:\Program Files\Anno 1701\Anno1701.exe:*:Enabled:Anno 1701] -> File not found "C:\Program Files\AVG\AVG8\avgemc.exe" -> C:\Program Files\AVG\AVG8\avgemc.exe [C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe] -> [2009/01/08 09:43:57 | 00,903,960 | ---- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG8\avgnsx.exe" -> C:\Program Files\AVG\AVG8\avgnsx.exe [C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe] -> [2009/01/16 09:31:19 | 00,592,128 | ---- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2009/01/16 09:30:57 | 01,032,984 | ---- | M] (AVG Technologies CZ, s.r.o.) "C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) "C:\Program Files\Curious Labs\Poser 6\Poser.exe" -> C:\Program Files\Curious Labs\Poser 6\Poser.exe [C:\Program Files\Curious Labs\Poser 6\Poser.exe:*:Enabled:Poser executable file] -> [2005/03/04 14:25:26 | 12,705,792 | ---- | M] (Curious Labs, Inc.) "C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\ftpte.exe" -> C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\ftpte.exe [C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\ftpte.exe:*:Enabled:FTP Transfer Engine] -> [2008/03/17 20:55:11 | 01,803,264 | ---- | M] (GlobalSCAPE Texas, LP.) "C:\Program Files\Google\Google Talk\googletalk.exe" -> C:\Program Files\Google\Google Talk\googletalk.exe [C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk] -> [2007/01/01 21:22:02 | 03,739,648 | ---- | M] (Google) "C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/11/20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) "C:\Program Files\Mass Effect\Binaries\MassEffect.exe" -> C:\Program Files\Mass Effect\Binaries\MassEffect.exe [C:\Program Files\Mass Effect\Binaries\MassEffect.exe:*:Enabled:Mass Effect Game] -> [2008/12/09 07:38:50 | 48,956,922 | ---- | M] (BioWare) "C:\Program Files\Mass Effect\MassEffectLauncher.exe" -> C:\Program Files\Mass Effect\MassEffectLauncher.exe [C:\Program Files\Mass Effect\MassEffectLauncher.exe:*:Enabled:Mass Effect Launcher] -> [2008/05/07 11:19:36 | 00,730,344 | ---- | M] (BioWare) "C:\Program Files\Paltalk Messenger\paltalk.exe" -> C:\Program Files\Paltalk Messenger\paltalk.exe [C:\Program Files\Paltalk Messenger\paltalk.exe:*:Enabled:PaltalkScene] -> [2008/09/10 22:41:11 | 11,713,536 | ---- | M] (AVM Software Inc.) "C:\Program Files\SecondLife\SecondLife.exe" -> C:\Program Files\SecondLife\SecondLife.exe [C:\Program Files\SecondLife\SecondLife.exe:*:Enabled:Second Life] -> [2008/10/15 00:47:26 | 20,590,592 | ---- | M] (Linden Lab) "C:\Program Files\SecondLife\SLVoice.exe" -> C:\Program Files\SecondLife\SLVoice.exe [C:\Program Files\SecondLife\SLVoice.exe:*:Enabled:SLVoice] -> [2008/10/15 00:41:10 | 00,540,672 | ---- | M] () "C:\Program Files\SecondLifeReleaseCandidate\SecondLifeReleaseCandidate.exe" -> C:\Program Files\SecondLifeReleaseCandidate\SecondLifeReleaseCandidate.exe [C:\Program Files\SecondLifeReleaseCandidate\SecondLifeReleaseCandidate.exe:*:Enabled:Second Life] -> File not found "C:\Program Files\SecondLifeReleaseCandidate\SLVoice.exe" -> C:\Program Files\SecondLifeReleaseCandidate\SLVoice.exe [C:\Program Files\SecondLifeReleaseCandidate\SLVoice.exe:*:Enabled:SLVoice] -> File not found "C:\Program Files\Skype\Phone\Skype.exe" -> C:\Program Files\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath ] -> [2008/11/07 14:31:38 | 21,633,320 | R--- | M] (Skype Technologies S.A.) "C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe" -> C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe [C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe:*:Enabled:SAMBC] -> [2004/12/21 15:54:10 | 05,273,088 | ---- | M] () "C:\Program Files\uTorrent\uTorrent.exe" -> C:\Program Files\uTorrent\uTorrent.exe [C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent] -> [2008/11/14 23:23:59 | 00,270,128 | ---- | M] (BitTorrent, Inc.) "C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 11:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\system32\PnkBstrA.exe" -> C:\WINDOWS\system32\PnkBstrA.exe [C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA] -> File not found "C:\WINDOWS\system32\PnkBstrB.exe" -> C:\WINDOWS\system32\PnkBstrB.exe [C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB] -> File not found < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 18:40:46 | 00,062,976 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2008/03/14 02:33:40 | 00,000,000 | ---- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> [Registry - Additional Scans - Safe List] < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 28/12/2008 22:03:24 Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000 -> Description = Faulting application slvoice.exe, version 0.0.0.0, faulting module vivoxsdk.dll, version 2.0.2961.3323, fault address 0x00074b48. Application [ Error ] 01/01/2009 23:25:53 Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000 -> Description = Faulting application iexplore.exe, version 7.0.6000.16735, faulting module flash9f.ocx, version 9.0.124.0, fault address 0x00033b41. Application [ Error ] 02/01/2009 00:38:18 Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002 -> Description = Hanging application win_crash_logger.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 02/01/2009 00:38:19 Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002 -> Description = Hanging application win_crash_logger.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 08/01/2009 21:26:14 Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002 -> Description = Hanging application Photoshop.exe, version 6.9.9.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 17/01/2009 14:24:50 Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002 -> Description = Hanging application mplayerc.exe, version 6.4.9.1, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 25/01/2009 10:22:59 Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 26/01/2009 07:47:47 Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 28/01/2009 22:08:02 Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000 -> Description = Faulting application wmplayer.exe, version 11.0.5721.5145, faulting module unknown, version 0.0.0.0, fault address 0x6356b5a0. Application [ Error ] 30/01/2009 15:21:47 Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002 -> Description = Hanging application mplayerc.exe, version 6.4.9.1, hang module hungapp, version 0.0.0.0, hang address 0x00000000. System [ Error ] 22/01/2009 19:03:22 Computer Name = VICTOR-3C104101 | Source = Print | ID = 19 -> Description = Sharing printer failed + 1722, Printer SnagIt 8 share name Printer. System [ Error ] 22/01/2009 19:04:14 Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000 -> Description = The NVR0FLASHDev service failed to start due to the following error: %%2 System [ Error ] 22/01/2009 19:04:14 Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000 -> Description = The PostgreSQL Database Server service failed to start due to the following error: %%3 System [ Error ] 25/01/2009 09:34:13 Computer Name = VICTOR-3C104101 | Source = Dhcp | ID = 1002 -> Description = The IP address lease 192.168.1.100 for the Network Card with network address 0011D82D1BD9 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). System [ Error ] 25/01/2009 09:38:32 Computer Name = VICTOR-3C104101 | Source = Print | ID = 19 -> Description = Sharing printer failed + 1722, Printer SnagIt 8 share name Printer. System [ Error ] 25/01/2009 09:39:37 Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000 -> Description = The NVR0FLASHDev service failed to start due to the following error: %%2 System [ Error ] 25/01/2009 09:39:37 Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000 -> Description = The PostgreSQL Database Server service failed to start due to the following error: %%3 System [ Error ] 27/01/2009 07:43:27 Computer Name = VICTOR-3C104101 | Source = Print | ID = 19 -> Description = Sharing printer failed + 1722, Printer SnagIt 8 share name Printer. System [ Error ] 27/01/2009 07:44:22 Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000 -> Description = The NVR0FLASHDev service failed to start due to the following error: %%2 System [ Error ] 27/01/2009 07:44:22 Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000 -> Description = The PostgreSQL Database Server service failed to start due to the following error: %%3 [Files/Folders - Created Within 30 Days] OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/01/30 20:19:14 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/01/30 20:18:53 | 00,656,714 | ---- | C] () dds.scr -> %UserProfile%\Desktop\dds.scr -> [2009/01/30 19:04:34 | 00,368,971 | ---- | C] () Recent -> %UserProfile%\Recent -> [2009/01/30 18:51:34 | 00,000,000 | RH-D | C] bbb.jpg -> %UserProfile%\Desktop\bbb.jpg -> [2009/01/30 17:54:25 | 00,044,639 | ---- | C] () aaa.jpg -> %UserProfile%\Desktop\aaa.jpg -> [2009/01/30 17:46:13 | 00,043,374 | ---- | C] () snapshot20090130174117.jpg -> %UserProfile%\Desktop\snapshot20090130174117.jpg -> [2009/01/30 17:41:27 | 00,041,695 | ---- | C] () snapshot20090130173224.jpg -> %UserProfile%\Desktop\snapshot20090130173224.jpg -> [2009/01/30 17:32:31 | 00,040,290 | ---- | C] () stghead.png -> %UserProfile%\Desktop\stghead.png -> [2009/01/30 16:41:57 | 00,020,049 | ---- | C] () newvicsig1.png -> %UserProfile%\Desktop\newvicsig1.png -> [2009/01/30 16:37:24 | 00,133,237 | ---- | C] () screen_sto_0010.jpg -> %UserProfile%\Desktop\screen_sto_0010.jpg -> [2009/01/30 16:01:35 | 00,193,261 | ---- | C] () Doctor Who - Whole of Seventh Doctor - Sylvester McCoy -> %UserProfile%\Desktop\Doctor Who - Whole of Seventh Doctor - Sylvester McCoy -> [2009/01/29 03:51:56 | 00,000,000 | ---D | C] o-Demonoid.com-o_Doctor_Who_Sylvester_McCoy_1027379.4266.torrent -> %UserProfile%\Desktop\o-Demonoid.com-o_Doctor_Who_Sylvester_McCoy_1027379.4266.torrent -> [2009/01/29 03:48:44 | 00,139,418 | ---- | C] () PDBootState -> %SystemRoot%\System32\PDBootState -> [2009/01/22 23:04:22 | 00,000,280 | ---- | C] () Malwarebytes -> %AppData%\Malwarebytes -> [2009/01/22 21:29:57 | 00,000,000 | ---D | C] Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/01/22 21:29:42 | 00,000,739 | ---- | C] () mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/01/22 21:29:39 | 00,015,504 | ---- | C] (Malwarebytes Corporation) mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/01/22 21:29:36 | 00,038,496 | ---- | C] (Malwarebytes Corporation) Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/01/22 21:29:35 | 00,000,000 | ---D | C] Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2009/01/22 21:29:35 | 00,000,000 | ---D | C] Trend Micro -> %ProgramFiles%\Trend Micro -> [2009/01/22 20:12:49 | 00,000,000 | ---D | C] Second Life.lnk -> %AllUsersProfile%\Desktop\Second Life.lnk -> [2009/01/22 18:53:43 | 00,000,833 | ---- | C] () SecondLife -> %ProgramFiles%\SecondLife -> [2009/01/22 18:53:07 | 00,000,000 | ---D | C] xvid.ax -> %SystemRoot%\System32\xvid.ax -> [2009/01/22 17:52:53 | 00,077,824 | ---- | C] () Xvid -> %ProgramFiles%\Xvid -> [2009/01/22 17:52:53 | 00,000,000 | ---D | C] QuickTime -> %ProgramFiles%\QuickTime -> [2009/01/22 17:48:38 | 00,000,000 | ---D | C] Config.Msi -> %SystemDrive%\Config.Msi -> [2009/01/22 17:48:12 | 00,000,000 | -HSD | C] Alexa Toolbar -> %ProgramFiles%\Alexa Toolbar -> [2009/01/18 09:07:09 | 00,000,000 | ---D | C] letter1.doc -> %UserProfile%\My Documents\letter1.doc -> [2009/01/16 01:36:27 | 00,026,624 | ---- | C] () SecondLife -> %AppData%\SecondLife -> [2009/01/13 16:49:38 | 00,000,000 | ---D | C] Deployment -> %UserProfile%\Local Settings\Application Data\Deployment -> [2009/01/11 10:00:11 | 00,000,000 | ---D | C] Microsoft Silverlight -> %ProgramFiles%\Microsoft Silverlight -> [2009/01/10 21:31:34 | 00,000,000 | ---D | C] Snapshot_001.jpg -> %UserProfile%\Desktop\Snapshot_001.jpg -> [2009/01/10 19:58:10 | 00,510,058 | ---- | C] () khs -> %UserProfile%\khs -> [2009/01/09 22:34:55 | 00,000,000 | RHS- | C] () khs -> %AllUsersProfile%\Documents\khs -> [2009/01/09 22:33:58 | 00,000,000 | RHS- | C] () khs -> %UserProfile%\My Documents\khs -> [2009/01/09 22:31:59 | 00,000,000 | RHS- | C] () khs -> %SystemDrive%\khs -> [2009/01/09 22:29:20 | 00,000,000 | RHS- | C] () MRT.INI -> %SystemRoot%\System32\MRT.INI -> [2009/01/08 19:53:46 | 00,000,346 | ---- | C] () wuapi.dll.mui -> %SystemRoot%\System32\wuapi.dll.mui -> [2009/01/08 19:46:19 | 00,023,576 | ---- | C] (Microsoft Corporation) AlxRes.dll.bak -> %SystemRoot%\System32\AlxRes.dll.bak -> [2009/01/05 17:33:09 | 00,462,848 | ---- | C] () ODBC -> %CommonProgramFiles%\ODBC -> [2009/01/01 00:11:15 | 00,000,000 | ---D | C] [Files/Folders - Modified Within 30 Days] 8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 6 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/01/30 20:18:58 | 00,656,714 | ---- | M] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/01/30 20:16:25 | 00,151,040 | ---- | M] () dds.scr -> %UserProfile%\Desktop\dds.scr -> [2009/01/30 19:04:36 | 00,368,971 | ---- | M] () NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/01/30 18:54:59 | 10,747,904 | -H-- | M] () bbb.jpg -> %UserProfile%\Desktop\bbb.jpg -> [2009/01/30 17:54:26 | 00,044,639 | ---- | M] () aaa.jpg -> %UserProfile%\Desktop\aaa.jpg -> [2009/01/30 17:46:14 | 00,043,374 | ---- | M] () snapshot20090130174117.jpg -> %UserProfile%\Desktop\snapshot20090130174117.jpg -> [2009/01/30 17:41:31 | 00,041,695 | ---- | M] () snapshot20090130173224.jpg -> %UserProfile%\Desktop\snapshot20090130173224.jpg -> [2009/01/30 17:32:33 | 00,040,290 | ---- | M] () stghead.png -> %UserProfile%\Desktop\stghead.png -> [2009/01/30 16:41:57 | 00,020,049 | ---- | M] () newvicsig1.png -> %UserProfile%\Desktop\newvicsig1.png -> [2009/01/30 16:37:24 | 00,133,237 | ---- | M] () screen_sto_0010.jpg -> %UserProfile%\Desktop\screen_sto_0010.jpg -> [2009/01/30 16:01:30 | 00,193,261 | ---- | M] () incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2009/01/30 15:58:12 | 32,598,094 | ---- | M] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2009/01/30 15:58:12 | 00,082,350 | ---- | M] () Thumbs.db -> %UserProfile%\My Documents\Thumbs.db -> [2009/01/29 23:03:39 | 00,958,332 | -HS- | M] () Perflib_Perfdata_13b0.dat -> %UserProfile%\Local Settings\Temp\Perflib_Perfdata_13b0.dat -> [2009/01/29 22:11:09 | 00,016,384 | ---- | M] () o-Demonoid.com-o_Doctor_Who_Sylvester_McCoy_1027379.4266.torrent -> %UserProfile%\Desktop\o-Demonoid.com-o_Doctor_Who_Sylvester_McCoy_1027379.4266.torrent -> [2009/01/29 03:48:44 | 00,139,418 | ---- | M] () GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/01/29 01:48:44 | 00,047,064 | ---- | M] () Second Life.lnk -> %AllUsersProfile%\Desktop\Second Life.lnk -> [2009/01/27 20:59:08 | 00,000,833 | ---- | M] () AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2009/01/27 12:13:24 | 00,000,284 | ---- | M] () sqmdata08.sqm -> %SystemDrive%\sqmdata08.sqm -> [2009/01/27 11:44:33 | 00,000,268 | -H-- | M] () sqmnoopt08.sqm -> %SystemDrive%\sqmnoopt08.sqm -> [2009/01/27 11:44:32 | 00,000,244 | -H-- | M] () Perflib_Perfdata_24c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_24c.dat -> [2009/01/27 11:44:30 | 00,016,384 | ---- | M] () PDBootState -> %SystemRoot%\System32\PDBootState -> [2009/01/27 11:44:23 | 00,000,280 | ---- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/01/27 11:44:22 | 00,002,206 | ---- | M] () nvapps.xml -> %SystemRoot%\System32\nvapps.xml -> [2009/01/27 11:43:44 | 00,201,144 | ---- | M] () Perflib_Perfdata_23c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_23c.dat -> [2009/01/27 11:43:14 | 00,016,384 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/01/27 11:42:59 | 00,000,006 | -H-- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/01/27 11:42:53 | 00,002,048 | --S- | M] () DVCState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> %SystemRoot%\System32\DVCState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> [2009/01/27 01:12:49 | 00,011,564 | ---- | M] () BMXStateBkp-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> %SystemRoot%\System32\BMXStateBkp-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> [2009/01/27 01:12:48 | 00,031,056 | ---- | M] () BMXState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> %SystemRoot%\System32\BMXState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> [2009/01/27 01:12:48 | 00,031,056 | ---- | M] () BMXCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> %SystemRoot%\System32\BMXCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> [2009/01/27 01:12:48 | 00,030,528 | ---- | M] () BMXBkpCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> %SystemRoot%\System32\BMXBkpCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx -> [2009/01/27 01:12:48 | 00,030,528 | ---- | M] () {00000005-00000000-00000008-00001102-00000004-20021102}.CDF -> %SystemRoot%\{00000005-00000000-00000008-00001102-00000004-20021102}.CDF -> [2009/01/27 01:12:00 | 04,958,588 | ---- | M] () sqmdata07.sqm -> %SystemDrive%\sqmdata07.sqm -> [2009/01/25 13:39:49 | 00,000,268 | -H-- | M] () sqmnoopt07.sqm -> %SystemDrive%\sqmnoopt07.sqm -> [2009/01/25 13:39:48 | 00,000,244 | -H-- | M] () sqmdata06.sqm -> %SystemDrive%\sqmdata06.sqm -> [2009/01/22 23:04:53 | 00,000,268 | -H-- | M] () sqmnoopt06.sqm -> %SystemDrive%\sqmnoopt06.sqm -> [2009/01/22 23:04:53 | 00,000,244 | -H-- | M] () Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/01/22 21:29:42 | 00,000,739 | ---- | M] () sqmdata05.sqm -> %SystemDrive%\sqmdata05.sqm -> [2009/01/22 14:31:44 | 00,000,268 | -H-- | M] () sqmnoopt05.sqm -> %SystemDrive%\sqmnoopt05.sqm -> [2009/01/22 14:31:43 | 00,000,244 | -H-- | M] () ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/01/22 14:27:57 | 00,000,178 | -HS- | M] () sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [2009/01/17 07:28:19 | 00,000,268 | -H-- | M] () sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [2009/01/17 07:28:19 | 00,000,244 | -H-- | M] () sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/01/16 09:50:05 | 00,000,268 | -H-- | M] () sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/01/16 09:50:05 | 00,000,244 | -H-- | M] () avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/01/16 09:31:19 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) letter1.doc -> %UserProfile%\My Documents\letter1.doc -> [2009/01/16 01:36:27 | 00,026,624 | ---- | M] () UserCustomPreset_Adobe Premiere Pro 2.0.vpr -> %UserProfile%\UserCustomPreset_Adobe Premiere Pro 2.0.vpr -> [2009/01/16 00:10:46 | 00,006,898 | ---- | M] () nvwdmcpl.dll -> %SystemRoot%\System32\nvwdmcpl.dll -> [2009/01/15 08:19:00 | 01,724,416 | ---- | M] () nwiz.exe -> %SystemRoot%\System32\nwiz.exe -> [2009/01/15 08:19:00 | 01,657,376 | ---- | M] () nview.dll -> %SystemRoot%\System32\nview.dll -> [2009/01/15 08:19:00 | 01,507,328 | ---- | M] () nvdspsch.exe -> %SystemRoot%\System32\nvdspsch.exe -> [2009/01/15 08:19:00 | 01,346,080 | ---- | M] () nvwimg.dll -> %SystemRoot%\System32\nvwimg.dll -> [2009/01/15 08:19:00 | 01,101,824 | ---- | M] () nvshell.dll -> %SystemRoot%\System32\nvshell.dll -> [2009/01/15 08:19:00 | 00,466,944 | ---- | M] () nvappbar.exe -> %SystemRoot%\System32\nvappbar.exe -> [2009/01/15 08:19:00 | 00,449,056 | ---- | M] () keystone.exe -> %SystemRoot%\System32\keystone.exe -> [2009/01/15 08:19:00 | 00,436,768 | ---- | M] () nvapps.nvb -> %SystemRoot%\System32\nvapps.nvb -> [2009/01/15 08:19:00 | 00,206,793 | ---- | M] () nvtuicpl.cpl -> %SystemRoot%\System32\nvtuicpl.cpl -> [2009/01/15 08:19:00 | 00,073,728 | ---- | M] () nvdisp.nvu -> %SystemRoot%\System32\nvdisp.nvu -> [2009/01/15 08:19:00 | 00,018,725 | ---- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/01/14 16:11:32 | 00,038,496 | ---- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/01/14 16:11:28 | 00,015,504 | ---- | M] (Malwarebytes Corporation) desktop.ini -> %UserProfile%\My Documents\desktop.ini -> [2009/01/14 00:09:53 | 00,000,373 | -HS- | M] () Fraps.lnk -> %UserProfile%\Desktop\Fraps.lnk -> [2009/01/11 06:12:58 | 00,000,690 | ---- | M] () Snapshot_001.jpg -> %UserProfile%\Desktop\Snapshot_001.jpg -> [2009/01/10 19:58:10 | 00,510,058 | ---- | M] () khs -> %UserProfile%\khs -> [2009/01/09 22:34:55 | 00,000,000 | RHS- | M] () khs -> %AllUsersProfile%\Documents\khs -> [2009/01/09 22:33:58 | 00,000,000 | RHS- | M] () khs -> %UserProfile%\My Documents\khs -> [2009/01/09 22:31:59 | 00,000,000 | RHS- | M] () khs -> %SystemDrive%\khs -> [2009/01/09 22:29:20 | 00,000,000 | RHS- | M] () sqmdata02.sqm -> %SystemDrive%\sqmdata02.sqm -> [2009/01/08 19:58:22 | 00,000,268 | -H-- | M] () sqmnoopt02.sqm -> %SystemDrive%\sqmnoopt02.sqm -> [2009/01/08 19:58:21 | 00,000,244 | -H-- | M] () MRT.INI -> %SystemRoot%\System32\MRT.INI -> [2009/01/08 19:53:46 | 00,000,346 | ---- | M] () win.ini -> %SystemRoot%\win.ini -> [2009/01/08 19:50:10 | 00,000,603 | ---- | M] () qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/01/08 19:49:05 | 00,004,232 | ---- | M] () qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/01/08 19:49:04 | 00,004,646 | ---- | M] () sqmdata01.sqm -> %SystemDrive%\sqmdata01.sqm -> [2009/01/08 19:44:43 | 00,000,268 | -H-- | M] () sqmnoopt01.sqm -> %SystemDrive%\sqmnoopt01.sqm -> [2009/01/08 19:44:43 | 00,000,244 | -H-- | M] () avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/01/08 09:44:01 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/01/08 09:44:01 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) avgrkx86.sys -> %SystemRoot%\System32\drivers\avgrkx86.sys -> [2009/01/08 09:43:59 | 00,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/01/08 09:43:52 | 00,107,272 | ---- | M] (AVG Technologies CZ, s.r.o.) AlxRes.dll.bak -> %SystemRoot%\System32\AlxRes.dll.bak -> [2009/01/05 17:33:10 | 00,462,848 | ---- | M] () hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2009/01/02 06:22:39 | 00,291,593 | R--- | M] () sqmdata00.sqm -> %SystemDrive%\sqmdata00.sqm -> [2009/01/02 06:17:24 | 00,000,268 | -H-- | M] () sqmnoopt00.sqm -> %SystemDrive%\sqmnoopt00.sqm -> [2009/01/02 06:17:23 | 00,000,244 | -H-- | M] () FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/01/02 06:15:30 | 00,202,528 | ---- | M] () opa11.dat -> %AllUsersProfile%\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2008/03/19 02:42:02 | 00,008,206 | ---- | M] () [Alternate Data Streams] @Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable @Alternate Data Stream - 0 bytes -> %UserProfile%\Thumbs.db:encryptable @Alternate Data Stream - 144 bytes -> %AllUsersProfile%\Application Data\TEMP:05EE1EEF [File - Lop Check] Application Data -> C:\Documents and Settings\Administrator\Application Data -> [2008/03/14 02:24:02 | 00,000,000 | RH-D | M] Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/01/22 21:29:35 | 00,000,000 | RH-D | M] {3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/11/25 16:07:40 | 00,000,000 | ---D | M] Digital Entertainer -> C:\Documents and Settings\All Users\Application Data\Digital Entertainer -> [2008/03/26 20:36:18 | 00,000,000 | ---D | M] Logishrd -> C:\Documents and Settings\All Users\Application Data\Logishrd -> [2008/03/14 04:38:01 | 00,000,000 | ---D | M] TechSmith -> C:\Documents and Settings\All Users\Application Data\TechSmith -> [2008/04/05 15:19:21 | 00,000,000 | ---D | M] TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2009/01/29 02:07:38 | 00,000,000 | ---D | M] Victor -> C:\Documents and Settings\All Users\Application Data\Victor -> [2008/03/26 20:36:51 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\Default User\Application Data -> [2008/03/14 02:24:02 | 00,000,000 | RH-D | M] Application Data -> C:\Documents and Settings\LocalService\Application Data -> [2008/03/14 02:36:42 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\NetworkService\Application Data -> [2008/03/14 02:36:28 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\Victor\Application Data -> [2009/01/30 18:55:45 | 00,000,000 | -H-D | M] Ascaron Entertainment -> C:\Documents and Settings\Victor\Application Data\Ascaron Entertainment -> [2008/12/27 01:59:00 | 00,000,000 | ---D | M] DAEMON Tools -> C:\Documents and Settings\Victor\Application Data\DAEMON Tools -> [2008/10/27 08:21:25 | 00,000,000 | ---D | M] GlobalSCAPE -> C:\Documents and Settings\Victor\Application Data\GlobalSCAPE -> [2008/03/17 20:54:49 | 00,000,000 | ---D | M] LegendCityOnline -> C:\Documents and Settings\Victor\Application Data\LegendCityOnline -> [2008/11/12 17:28:16 | 00,000,000 | ---D | M] LimeWire -> C:\Documents and Settings\Victor\Application Data\LimeWire -> [2009/01/13 16:31:07 | 00,000,000 | ---D | M] Paltalk -> C:\Documents and Settings\Victor\Application Data\Paltalk -> [2008/07/20 02:46:31 | 00,000,000 | ---D | M] SecondLife -> C:\Documents and Settings\Victor\Application Data\SecondLife -> [2009/01/27 21:00:42 | 00,000,000 | ---D | M] SecuROM -> C:\Documents and Settings\Victor\Application Data\SecuROM -> [2008/10/27 08:36:40 | 00,000,000 | RH-D | M] teamspeak2 -> C:\Documents and Settings\Victor\Application Data\teamspeak2 -> [2008/10/27 17:48:47 | 00,000,000 | ---D | M] uTorrent -> C:\Documents and Settings\Victor\Application Data\uTorrent -> [2009/01/30 20:36:10 | 00,000,000 | ---D | M] Xilisoft Corporation -> C:\Documents and Settings\Victor\Application Data\Xilisoft Corporation -> [2008/07/22 17:56:19 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\victor1st\Application Data -> [2008/03/14 02:24:02 | 00,000,000 | RH-D | M] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2008/09/03 22:27:51 | 00,000,000 | --SD | M] AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2009/01/27 12:13:24 | 00,000,284 | ---- | M] () desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2001/08/23 13:00:00 | 00,000,065 | RH-- | M] () SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/01/27 11:42:59 | 00,000,006 | -H-- | M] () [File - Purity Scan] [CatchMe Rootkit Scan by GMER] < Windows folder & sub-folders > scanning hidden processes ... IPC error: 2 The system cannot find the file specified. scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:2df9c43f "s2"=dword:110480d0 "h0"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:e7,c8,ce,c3,43,97,ca,85,cb,f0,d4,5e,30,7e,08,c4,8a,50,3e,47,14,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000001 "khjeh"=hex:12,e1,2c,08,41,b4,51,46,49,a2,da,00,e8,34,8c,30,c6,7c,48,8a,29,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,cb,b0,db,29,21,46,9f,a7,0f,72,bc,9f,0d,bf,cd,b2,dd,.. "khjeh"=hex:bc,f7,76,6e,94,5d,1d,3a,87,44,53,8e,4e,ba,f6,ad,94,40,e6,24,26,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:3d,11,cd,b9,49,d7,c9,05,1d,01,84,19,23,5b,18,0f,d8,56,c0,f6,32,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:e7,c8,ce,c3,43,97,ca,85,cb,f0,d4,5e,30,7e,08,c4,8a,50,3e,47,14,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000001 "khjeh"=hex:12,e1,2c,08,41,b4,51,46,49,a2,da,00,e8,34,8c,30,c6,7c,48,8a,29,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,cb,b0,db,29,21,46,9f,a7,0f,72,bc,9f,0d,bf,cd,b2,dd,.. "khjeh"=hex:bc,f7,76,6e,94,5d,1d,3a,87,44,53,8e,4e,ba,f6,ad,94,40,e6,24,26,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:3d,11,cd,b9,49,d7,c9,05,1d,01,84,19,23,5b,18,0f,d8,56,c0,f6,32,.. scanning hidden registry entries ... scanning hidden files ... C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT 6144 bytes scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 2 < Document and Settings folder & sub folders > scanning hidden files ... IPC error: 2 The system cannot find the file specified. C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF 144 bytes C:\Documents and Settings\Victor\Favorites\Gallery of sovereign-state flags - Wikipedia, the free encyclopedia.url:favicon 318 bytes C:\Documents and Settings\Victor\Favorites\ARIEL'S BLOG - OFFICIAL NUDE WEBSITE OF ARIEL aka FAITH LIGHTSPEED, PIPER FAWN.url:favicon 318 bytes C:\Documents and Settings\Victor\Favorites\Avatar Toolbox - Invisiprims.url:favicon 1150 bytes C:\Documents and Settings\Victor\Favorites\BerryBabes @ All Internet Hot Sexy Babes Raven Riley, Jordan Capri, Brandi Belle, Kate's Playground and other..url:favicon 894 bytes C:\Documents and Settings\Victor\Favorites\Best man wedding speech by andrew bailey.url:favicon 1406 bytes C:\Documents and Settings\Victor\Favorites\Best man wedding speech by Andrew Heathwood.url:favicon 1406 bytes C:\Documents and Settings\Victor\Favorites\BleepingComputer.com - HijackThis Logs and Virus-Trojan-Spyware-Malware Removal.url:favicon 1406 bytes C:\Documents and Settings\Victor\Favorites\Create A Sepia Tone Effect In Photoshop PhotoshopSupport.com.url:favicon 894 bytes C:\Documents and Settings\Victor\Favorites\freeones the Ultimate Supermodels - Celebs - Pornstars Link Site.url:favicon 3638 bytes C:\Documents and Settings\Victor\Favorites\Had enough ( Littlewoods - Penalty Charges Forum.url:favicon 10134 bytes C:\Documents and Settings\Victor\Favorites\JW FLV Media Player.url:favicon 198 bytes C:\Documents and Settings\Victor\Favorites\Maria (YoungPorn) - PeachyForum.url:favicon 1406 bytes C:\Documents and Settings\Victor\Favorites\Pop ups & trojans keep recurring.url:favicon 1406 bytes C:\Documents and Settings\Victor\Favorites\RapidShareData.com - RapidShare Search Engine.url:favicon 3638 bytes C:\Documents and Settings\Victor\Favorites\Request a Model - PeachyForum.url:favicon 1406 bytes C:\Documents and Settings\Victor\Favorites\Script Me!.url:favicon 760 bytes C:\Documents and Settings\Victor\Favorites\shillpages - Doctor Who Image Archive.url:favicon 318 bytes C:\Documents and Settings\Victor\Favorites\Slide.url:favicon 1150 bytes C:\Documents and Settings\Victor\Favorites\slodcast.com - QuickTime Settings.url:favicon 1150 bytes C:\Documents and Settings\Victor\Favorites\Stranded in SL-space.url:favicon 3638 bytes C:\Documents and Settings\Victor\Favorites\Trojan Horse agent AWHU.url:favicon 3638 bytes C:\Documents and Settings\Victor\Favorites\Web Hosting - Shared cPanel Linux Web Hosting.url:favicon 3638 bytes C:\Documents and Settings\Victor\Favorites\www.supportpcs.co.uk - Dalek Voices.url:favicon 3638 bytes C:\Documents and Settings\Victor\Favorites\YouTube - It's a Small Wonder.url:favicon 1150 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Stargate-ga fe2\Junk E-mail\67844AE1-0000011D.eml:OEStandardProperty 1536 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Stargate-ga fe2\Sent Items\038F2D73-00000001.eml:OEStandardProperty 1352 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\00D05E8B-84BC0BA0.eml:OEStandardProperty 2014 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\00F252C1-FCD23CC6.eml:OEStandardProperty 1930 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\0C3069F2-60FF2F87.eml:OEStandardProperty 2014 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\178A7FB7-51F53394.eml:OEStandardProperty 1906 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\18EA5CAA-7001A787.eml:OEStandardProperty 1906 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\1ADF6A49-BEE6458F.eml:OEStandardProperty 1398 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\248029E8-797B4935.eml:OEStandardProperty 1882 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\2B096D5D-44007DEE.eml:OEStandardProperty 2014 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\32573AB6-00B5CB54.eml:OEStandardProperty 1840 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\5355065E-31E9ACE7.eml:OEStandardProperty 2014 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\5357025E-36C05BB2.eml:OEStandardProperty 1840 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\54396513-2577D78B.eml:OEStandardProperty 1906 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\554D3230-3A64BD85.eml:OEStandardProperty 2014 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\5AF7300D-5420FD03.eml:OEStandardProperty 1840 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\5B586B40-6E1A2E49.eml:OEStandardProperty 2140 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\6B074195-D1096028.eml:OEStandardProperty 2014 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\78D75CA0-EDA3239E.eml:OEStandardProperty 2068 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\08-07-2008 5b9\Katie\Inbox\7B033F5D-5106D3B8.eml:OEStandardProperty 2014 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\10-16-2008 29\482318BE-00000001.eml:OEStandardProperty 1652 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\089B3155-00000153.eml:OEStandardProperty 1800 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\0BB32EA6-0000014F.eml:OEStandardProperty 1496 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\0E0D1F49-0000014C.eml:OEStandardProperty 1558 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\12DB153C-00000150.eml:OEStandardProperty 1316 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\14843EC4-0000014B.eml:OEStandardProperty 1372 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\150F33B3-00000149.eml:OEStandardProperty 1500 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\4D6E397C-00000164.eml:OEStandardProperty 1876 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\55107D74-00000163.eml:OEStandardProperty 1890 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\59986E1B-0000015C.eml:OEStandardProperty 1490 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\5AF141BB-00000158.eml:OEStandardProperty 2026 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\65C57607-00000154.eml:OEStandardProperty 1428 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\66583790-00000152.eml:OEStandardProperty 1868 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\66807BF7-0000015D.eml:OEStandardProperty 1312 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\69525F90-00000156.eml:OEStandardProperty 1894 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\7A394F78-00000160.eml:OEStandardProperty 1490 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\7B121801-00000165.eml:OEStandardProperty 1536 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\7E87390C-00000151.eml:OEStandardProperty 1316 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\16496DF1-00000157.eml:OEStandardProperty 1422 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\18703A42-0000014E.eml:OEStandardProperty 1906 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\18BE6784-00000159.eml:OEStandardProperty 1520 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\1FD80211-00000161.eml:OEStandardProperty 1330 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\23484ED2-0000015B.eml:OEStandardProperty 1918 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\2A3B19BF-00000162.eml:OEStandardProperty 1536 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\2C1141EF-0000015A.eml:OEStandardProperty 2186 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\308807A5-00000155.eml:OEStandardProperty 1390 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\33B01AEF-0000015F.eml:OEStandardProperty 1460 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\36145CAB-0000015E.eml:OEStandardProperty 1406 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\3722077E-00000147.eml:OEStandardProperty 1948 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Junk e-mail\43ED5C9E-00000146.eml:OEStandardProperty 2320 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\keep\325B33FE-00000001.eml:OEStandardProperty 1362 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\012722BB-00000005.eml:OEStandardProperty 1264 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\0F802F8A-00000007.eml:OEStandardProperty 1222 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\13D14C0C-00000002.eml:OEStandardProperty 1348 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\291A1821-00000003.eml:OEStandardProperty 1356 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\322501C0-00000004.eml:OEStandardProperty 1558 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\3A9E70BD-00000008.eml:OEStandardProperty 1288 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\3D7D6A54-00000009.eml:OEStandardProperty 1264 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\3F5720F4-00000001.eml:OEStandardProperty 1302 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\4AE13D6C-0000000A.eml:OEStandardProperty 1324 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Vic n Jenny\Sent items\5F550375-00000006.eml:OEStandardProperty 1270 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Victor STG\Junk E-mail\482318BE-0000097C.eml:OEStandardProperty 1672 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Victor STG\Junk E-mail\67844AE1-0000097D.eml:OEStandardProperty 1596 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\33081EDC-00005B14.eml:OEStandardProperty 1930 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\33822079-00005AF8.eml:OEStandardProperty 2182 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\37BE71F2-00005B17.eml:OEStandardProperty 1816 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\432836A1-00005B07.eml:OEStandardProperty 1700 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\43467A36-00005B13.eml:OEStandardProperty 2246 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\43654E38-00005AF5.eml:OEStandardProperty 2016 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\43DB57C2-00005B21.eml:OEStandardProperty 1850 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\44616BC9-00005B10.eml:OEStandardProperty 1966 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\456D7E0E-00005B05.eml:OEStandardProperty 1532 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\46261CDF-00005AFC.eml:OEStandardProperty 1532 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\496326B1-00005AFB.eml:OEStandardProperty 1718 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\49D0123B-00005B1A.eml:OEStandardProperty 2012 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\4AD42CF7-00005AB9.eml:OEStandardProperty 1572 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\4AE13D6C-00005801.eml:OEStandardProperty 1658 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\4AF320A8-00005B15.eml:OEStandardProperty 1972 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\4CFF64A0-00005B19.eml:OEStandardProperty 1802 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\0C1E2120-00005B08.eml:OEStandardProperty 1520 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\0D6A40A5-00005AD6.eml:OEStandardProperty 2044 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\117A6D76-00005AF9.eml:OEStandardProperty 2004 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\12465841-00005B22.eml:OEStandardProperty 1850 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\128950A9-00005AF7.eml:OEStandardProperty 2182 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\12C21003-00005B0A.eml:OEStandardProperty 1862 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\159F4FE2-00005AF1.eml:OEStandardProperty 2196 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\1BD90871-00005AF0.eml:OEStandardProperty 2196 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\1C753106-00005B1B.eml:OEStandardProperty 1828 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\1D112528-00005AD7.eml:OEStandardProperty 2040 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\4D675968-00005AB8.eml:OEStandardProperty 1228 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\527F5A70-00005B25.eml:OEStandardProperty 1652 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\578D78FE-00005B16.eml:OEStandardProperty 1828 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\588266BE-00005B20.eml:OEStandardProperty 1802 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\58C532E7-00005B11.eml:OEStandardProperty 1900 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\5D2B638C-00005B23.eml:OEStandardProperty 1988 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\5F344EBF-00005B01.eml:OEStandardProperty 1544 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\662A7346-00005AF6.eml:OEStandardProperty 2110 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\66B46747-00005AF4.eml:OEStandardProperty 2196 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\676D113E-00005AFE.eml:OEStandardProperty 1736 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\67D054BE-00005B1F.eml:OEStandardProperty 1776 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\6D73084D-00005B1E.eml:OEStandardProperty 1988 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\721D1DCB-00005B09.eml:OEStandardProperty 1716 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\72966512-00005B00.eml:OEStandardProperty 1520 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\773F0A41-00005B0B.eml:OEStandardProperty 2264 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\791B6B28-00005B0F.eml:OEStandardProperty 2080 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\79540786-00005B27.eml:OEStandardProperty 1616 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\1D3F6E89-00005B03.eml:OEStandardProperty 1730 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\1D5E1FF1-00005B04.eml:OEStandardProperty 1730 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\212C008E-00005B12.eml:OEStandardProperty 1994 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\23321295-00005B28.eml:OEStandardProperty 1598 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\246264E0-00005AFF.eml:OEStandardProperty 1556 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\27DA0E29-00005AFD.eml:OEStandardProperty 1760 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\2B0F7514-00005B0D.eml:OEStandardProperty 1682 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\2BA528E2-00005AF2.eml:OEStandardProperty 2196 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\2E396DA6-00005B02.eml:OEStandardProperty 1568 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\2F0C549B-00005AF3.eml:OEStandardProperty 2196 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\008C357E-00005B1C.eml:OEStandardProperty 1788 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\00EB7871-00005B18.eml:OEStandardProperty 2170 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\03FA6F30-00005B24.eml:OEStandardProperty 1610 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\06070784-00005B0C.eml:OEStandardProperty 1988 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\06E30A6C-00005B06.eml:OEStandardProperty 1748 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\087836C2-00005AFA.eml:OEStandardProperty 2008 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\0A875478-00005B1D.eml:OEStandardProperty 1782 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\0AF046A7-00005B26.eml:OEStandardProperty 2074 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\0BB32EA6-0000572A.eml:OEStandardProperty 1570 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\33053765-00005B0E.eml:OEStandardProperty 1840 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Inbox\4D064DB7-00002EC7.eml:OEStandardProperty 1560 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Junk E-mail\3D6C2CD6-0000037E.eml:OEStandardProperty 1516 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\Junk E-mail\72AE6952-0000037F.eml:OEStandardProperty 1830 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\victor1st@g bb2\TBP\02DD150B-00000009.eml:OEStandardProperty 1578 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Deleted Items\35C85A07-00000176.eml:OEStandardProperty 1554 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Deleted Items\67B10707-00000175.eml:OEStandardProperty 1554 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Junk e-mail\18BE6784-00000074.eml:OEStandardProperty 1308 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Junk e-mail\1EED70E8-00000073.eml:OEStandardProperty 1468 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Junk e-mail\4AE13D6C-00000075.eml:OEStandardProperty 1308 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Junk e-mail\7DB51BEC-00000072.eml:OEStandardProperty 1464 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Sent Items\7D110F57-00000001.eml:OEStandardProperty 1494 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\00294823-0000004B.eml:OEStandardProperty 1094 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\00294823-0000004F.eml:OEStandardProperty 1386 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\18BE6784-0000004A.eml:OEStandardProperty 1644 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\18BE6784-0000004C.eml:OEStandardProperty 1094 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\18BE6784-00000052.eml:OEStandardProperty 1368 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\1BCF573F-00000051.eml:OEStandardProperty 1380 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\2CD672AE-0000004E.eml:OEStandardProperty 1094 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\36BB3B5B-00000046.eml:OEStandardProperty 1440 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\447375F1-00000047.eml:OEStandardProperty 1358 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\47623864-00000048.eml:OEStandardProperty 1310 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\4AE13D6C-0000004D.eml:OEStandardProperty 1094 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\4AE13D6C-00000053.eml:OEStandardProperty 1442 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\61407BF7-00000050.eml:OEStandardProperty 1246 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Junk e-mail\69525F90-00000049.eml:OEStandardProperty 1304 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\keep\4586158C-00000001.eml:OEStandardProperty 1458 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\keep\62591645-00000002.eml:OEStandardProperty 1402 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Sent Items\225B4B99-00000003.eml:OEStandardProperty 1330 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Sent Items\297E7DD3-00000002.eml:OEStandardProperty 1330 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Sent Items\3B8C4175-00000005.eml:OEStandardProperty 1400 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Sent Items\59096C30-00000004.eml:OEStandardProperty 1248 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Sent Items\68724B44-00000006.eml:OEStandardProperty 1348 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie\Sent Items\78BC2F16-00000001.eml:OEStandardProperty 1332 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie STG\Inbox\00294823-00000066.eml:OEStandardProperty 1702 bytes C:\Documents and Settings\Victor\Local Settings\Application Data\Microsoft\Windows Live Mail\Katie STG\Inbox\18BE6784-00000011.eml:OEStandardProperty 1578 bytes scan completed successfully hidden files: 385 < End of report > [/code]