Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 02-09-2007, 06:50 AM   #1 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


Trojan can't be removed, Task Manager gone

Hi, experts!
I had a trojan that Norton couldn't do anything with, and I think it's disabled Task Manager and regedit (disabled by admin apparently, but that's me, and I haven't touched it!).
Reading around the forum, I took a HijackThis scan, and here's the log (hope someone can help me!):

Logfile of HijackThis v1.99.1
Scan saved at 12:12:28, on 09/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\svchosts.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\Program Files\ScrubXP\scrubxp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\lexpps.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVW32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link.../?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [sc] C:\Program Files\ScrubXP\scrubxp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ServiceHost] "C:\Program Files\Java\jre1.5.0_06\bin\svchost.exe" ""
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [startkey] C:\WINDOWS\system32\scvhost.exe
O4 - HKLM\..\Run: [Temporary] C:\i386\svchost.exe
O4 - HKLM\..\Run: [1234567] C:\WINDOWS\system32\svcost.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [startkey] C:\WINDOWS\system32\scvhost.exe
O4 - HKCU\..\Run: [1234567] C:\WINDOWS\system32\svcost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Norton System Doctor.LNK = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
O4 - Startup: Pika Backup.lnk = C:\Program Files\PikaOne Software\FlyCASE\PikaBackup.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Fantastic Flame Agent.lnk = C:\Program Files\Fantastic Flame Screensaver\FantasticFlameAgent.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/tech...a/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1134934287140
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/amp...1.11_en_dl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
greyrocker is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Sponsored Links
Old 02-11-2007, 01:32 PM   #2 (permalink)
Mentor, Analyst - Security Team
 
Deckard's Avatar
 
Join Date: May 2006
Location: Oregon
Posts: 2,503
OS: MacOS X, Debian, OpenBSD, Windows


Hello, and welcome to the HijackThis Help Forum.

Apologies for any delay in replying, but we have been rather busy lately. You may wish to Subscribe to this thread so that you are notified when you receive a reply. To do this click Thread Tools (above the first post), then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Since it has been a few days since you first posted, please download ComboScan and save it to your Desktop. Double-click on comboscan.exe and follow the prompts. Please note that some firewalls may warn that sigcheck.exe is trying to access the Internet -- please allow it. When it has finished, ComboScan will open Notepad with a log file -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) this logfile as your reply.

Additionally, a folder will open with two text files. Please attach the Supplementary.txt file with your reply. To attach a file to a new post, simply:
  1. Click the [Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
  2. Copy and paste the following into the "Upload File from your Computer" box:
    C:\ComboScan\Supplementary.txt
  3. Click Upload.

Thank you.
__________________
The chance to begin again in a golden land of opportunity and adventure.

Need HijackThis help? Please read MicroBell's Five Step Process before posting.
Please donate and help keep this site free to all.


UNITE/ASAP: Proud member since 2006
Deckard is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-11-2007, 03:49 PM   #3 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


ComboScan v20070210.13 run by Lee on 2007-02-11 at 21:56:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Successfully created restore point.
Performed disk cleanup.


-- HijackThis log (run as Lee.com) ----------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 21:57:07, on 11/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\svchosts.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\Program Files\ScrubXP\scrubxp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\lexpps.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVW32.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\Lee\Desktop\comboscan.exe
C:\DOCUME~1\Lee\LOCALS~1\Temp\~zpythit.tmp\Lee.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link.../?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [sc] C:\Program Files\ScrubXP\scrubxp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ServiceHost] "C:\Program Files\Java\jre1.5.0_06\bin\svchost.exe" ""
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [startkey] C:\WINDOWS\system32\scvhost.exe
O4 - HKLM\..\Run: [Temporary] C:\i386\svchost.exe
O4 - HKLM\..\Run: [1234567] C:\WINDOWS\system32\svcost.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [startkey] C:\WINDOWS\system32\scvhost.exe
O4 - HKCU\..\Run: [1234567] C:\WINDOWS\system32\svcost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Norton System Doctor.LNK = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
O4 - Startup: Pika Backup.lnk = C:\Program Files\PikaOne Software\FlyCASE\PikaBackup.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Fantastic Flame Agent.lnk = C:\Program Files\Fantastic Flame Screensaver\FantasticFlameAgent.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/tech...a/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1134934287140
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/amp...1.11_en_dl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


-- File Associations ------------------------------------------------------------

.bat - batfile - "%1" %*
.chm - chm.file - "C:\WINDOWS\hh.exe" %1
.com - comfile - "%1" %*
.exe - exefile - "%1" %*
.hlp - hlpfile - %SystemRoot%\System32\winhlp32.exe %1
.inf - inffile - %SystemRoot%\System32\NOTEPAD.EXE %1
.ini - inifile - %SystemRoot%\System32\NOTEPAD.EXE %1
.js - JSFile - %SystemRoot%\System32\WScript.exe "%1" %*
.lnk - lnkfile - {00021401-0000-0000-C000-000000000046}
.pif - piffile - "%1" %*
.reg - regfile - regedit.exe "%1"
.scr - scrfile - "%1" /S
.txt - txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1
.vbs - VBSFile - %SystemRoot%\System32\WScript.exe "%1" %*


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ----------------------

4 abp480n5 - \SystemRoot\system32\DRIVERS\ABP480N5.SYS
4 adpu160m - \SystemRoot\system32\DRIVERS\adpu160m.sys
4 agpCPQ (Compaq AGP Bus Filter) - \SystemRoot\system32\DRIVERS\agpCPQ.sys
4 Aha154x - \SystemRoot\system32\DRIVERS\aha154x.sys
4 aic78u2 - \SystemRoot\system32\DRIVERS\aic78u2.sys
4 aic78xx - \SystemRoot\system32\DRIVERS\aic78xx.sys
4 AliIde - \SystemRoot\system32\DRIVERS\aliide.sys
4 alim1541 (ALI AGP Bus Filter) - \SystemRoot\system32\DRIVERS\alim1541.sys
4 amdagp (AMD AGP Bus Filter Driver) - \SystemRoot\system32\DRIVERS\amdagp.sys
4 amsint - \SystemRoot\system32\DRIVERS\amsint.sys
4 asc - \SystemRoot\system32\DRIVERS\asc.sys
4 asc3350p - \SystemRoot\system32\DRIVERS\asc3350p.sys
4 asc3550 - \SystemRoot\system32\DRIVERS\asc3550.sys
3 ati2mtag - system32\DRIVERS\ati2mtag.sys
1 AVG Anti-Spyware Driver - \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
1 AvgAsCln (AVG Anti-Spyware Clean Driver) - System32\DRIVERS\AvgAsCln.sys
3 BlueletAudio (Bluetooth Audio Service) - system32\DRIVERS\blueletaudio.sys
3 BT (Bluetooth PAN Network Adapter) - system32\DRIVERS\btnetdrv.sys
3 Btcsrusb (Bluetooth USB For Bluetooth Service) - System32\Drivers\btcusb.sys
3 BthEnum (Bluetooth Request Block Driver) - system32\DRIVERS\BthEnum.sys
3 BTHidEnum (Bluetooth HID Enumerator) - system32\DRIVERS\vbtenum.sys
0 BTHidMgr (Bluetooth HID Manager Service) - System32\Drivers\BTHidMgr.sys
3 BthPan (Bluetooth Device (Personal Area Network)) - system32\DRIVERS\bthpan.sys
3 BTHPORT (Bluetooth Port Driver) - System32\Drivers\BTHport.sys
3 BTHUSB (Bluetooth Radio USB Driver) - System32\Drivers\BTHUSB.sys
4 cbidf - \SystemRoot\system32\DRIVERS\cbidf2k.sys
3 CCDECODE (Closed Caption Decoder) - system32\DRIVERS\CCDECODE.sys
4 cd20xrnt - \SystemRoot\system32\DRIVERS\cd20xrnt.sys
4 CmdIde - \SystemRoot\system32\DRIVERS\cmdide.sys
4 Cpqarray - \SystemRoot\system32\DRIVERS\cpqarray.sys
3 ctsfm2k (Creative SoundFont Management Device Driver) - system32\DRIVERS\ctsfm2k.sys
4 dac2w2k - \SystemRoot\system32\DRIVERS\dac2w2k.sys
4 dac960nt - \SystemRoot\system32\DRIVERS\dac960nt.sys
4 dpti2o - \SystemRoot\system32\DRIVERS\dpti2o.sys
3 E100B (Intel(R) PRO Network Connection Driver) - system32\DRIVERS\e100b325.sys
3 GEARAspiWDM - System32\Drivers\GEARAspiWDM.sys
3 HidUsb (Microsoft HID Class Driver) - system32\DRIVERS\hidusb.sys
4 hpn - \SystemRoot\system32\DRIVERS\hpn.sys
3 HSFHWBS2 - system32\DRIVERS\HSFHWBS2.sys
3 HSF_DP - system32\DRIVERS\HSF_DP.sys
4 i2omp - \SystemRoot\system32\DRIVERS\i2omp.sys
1 InCDPass - System32\DRIVERS\InCDPass.sys
4 ini910u - \SystemRoot\system32\DRIVERS\ini910u.sys
1 intelppm (Intel Processor Driver) - system32\DRIVERS\intelppm.sys
1 kbdhid (Keyboard HID Driver) - system32\DRIVERS\kbdhid.sys
3 LLUSBFLT - system32\drivers\llusbflt.sys
2 LXARScan (Lexmark X73 MFP Scanner) - System32\Drivers\Lxarscan.sys
2 mdmxsdk - system32\DRIVERS\mdmxsdk.sys
3 MODEMCSA (Unimodem Streaming Filter Device) - system32\drivers\MODEMCSA.sys
3 mouhid (Mouse HID Driver) - system32\DRIVERS\mouhid.sys
4 mraid35x - \SystemRoot\system32\DRIVERS\mraid35x.sys
3 MSTEE (Microsoft Streaming Tee/Sink-to-Sink Converter) - system32\drivers\MSTEE.sys
3 NABTSFEC (NABTS/FEC VBI Codec) - system32\DRIVERS\NABTSFEC.sys
3 NAVENG - \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070207.017\NAVENG.Sys
3 NAVEX15 - \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070207.017\NavEx15.Sys
3 ndiscm (Motorola SURFboard USB Cable Modem Windows Driver) - system32\DRIVERS\NetMotCM.sys
3 NdisIP (Microsoft TV/Video Connection) - system32\DRIVERS\NdisIP.sys
3 NPDriver (Norton Unerase Protection Driver) - \??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
3 nv - system32\DRIVERS\nv4_mini.sys
1 oreans32 - \??\C:\WINDOWS\system32\drivers\oreans32.sys
3 ossrv (Creative OS Services Driver) - system32\DRIVERS\ctoss2k.sys
3 ovt519 (D-Link VGA Webcam) - System32\Drivers\ov519vid.sys
3 P17 (Sound Blaster Live! 24-bit) - system32\drivers\P17.sys
0 PCIIde - system32\DRIVERS\pciide.sys
3 Pcouffin (Low level access layer for CD devices) - System32\Drivers\Pcouffin.sys
4 perc2 - \SystemRoot\system32\DRIVERS\perc2.sys
4 perc2hib - \SystemRoot\system32\DRIVERS\perc2hib.sys
2 PfModNT - \??\C:\WINDOWS\system32\drivers\PfModNT.sys
3 PLUsbbc2 (High-Speed USB Bridge Cable Driver) - System32\Drivers\usbbc2.sys
0 PxHelp20 - System32\Drivers\PxHelp20.sys
4 ql1080 - \SystemRoot\system32\DRIVERS\ql1080.sys
4 Ql10wnt - \SystemRoot\system32\DRIVERS\ql10wnt.sys
4 ql12160 - \SystemRoot\system32\DRIVERS\ql12160.sys
4 ql1240 - \SystemRoot\system32\DRIVERS\ql1240.sys
4 ql1280 - \SystemRoot\system32\DRIVERS\ql1280.sys
3 QV2KUX (Casio Digital Camera) - system32\DRIVERS\qv2kux.sys
3 RFCOMM (Bluetooth Device (RFCOMM Protocol TDI)) - system32\DRIVERS\rfcomm.sys
3 ROOTMODEM (Microsoft Legacy Modem Driver) - System32\Drivers\RootMdm.sys
3 SAVRT - \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS
1 SAVRTPEL - \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS
4 sisagp (SIS AGP Bus Filter) - \SystemRoot\system32\DRIVERS\sisagp.sys
3 SLIP (BDA Slip De-Framer) - system32\DRIVERS\SLIP.sys
0 snapman (Acronis Snapshots Manager) - system32\DRIVERS\snapman.sys
4 Sparrow - \SystemRoot\system32\DRIVERS\sparrow.sys
1 SPBBCDrv - \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
0 sptd - System32\Drivers\sptd.sys
3 streamip (BDA IPSink) - system32\DRIVERS\StreamIP.sys
4 symc810 - \SystemRoot\system32\DRIVERS\symc810.sys
4 symc8xx - \SystemRoot\system32\DRIVERS\symc8xx.sys
3 SYMDNS - \SystemRoot\System32\Drivers\SYMDNS.SYS
3 SymEvent - \??\C:\Program Files\Symantec\SYMEVENT.SYS
3 SYMFW - \SystemRoot\System32\Drivers\SYMFW.SYS
3 SYMIDS - \SystemRoot\System32\Drivers\SYMIDS.SYS
3 SYMIDSCO - \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20070124.003\symidsco.sys
0 symlcbrd - system32\drivers\symlcbrd.sys
3 SYMNDIS - \SystemRoot\System32\Drivers\SYMNDIS.SYS
3 SYMREDRV - \SystemRoot\System32\Drivers\SYMREDRV.SYS
1 SYMTDI - \SystemRoot\System32\Drivers\SYMTDI.SYS
4 sym_hi - \SystemRoot\system32\DRIVERS\sym_hi.sys
4 sym_u3 - \SystemRoot\system32\DRIVERS\sym_u3.sys
2 tifsfilter (Acronis True Image FS Filter) - system32\DRIVERS\tifsfilt.sys
0 timounter (Acronis True Image Backup Archive Explorer) - system32\DRIVERS\timntr.sys
4 TosIde - \SystemRoot\system32\DRIVERS\toside.sys
4 ultra - \SystemRoot\system32\DRIVERS\ultra.sys
3 usbaudio (USB Audio Driver (WDM)) - system32\drivers\usbaudio.sys
3 usbccgp (Microsoft USB Generic Parent Driver) - system32\DRIVERS\usbccgp.sys
3 usbehci (Microsoft USB 2.0 Enhanced Host Controller Miniport Driver) - system32\DRIVERS\usbehci.sys
3 usbprint (Microsoft USB PRINTER Class) - system32\DRIVERS\usbprint.sys
3 USBSTOR (USB Mass Storage Driver) - system32\DRIVERS\USBSTOR.SYS
3 VComm (Virtual Serial port driver) - system32\DRIVERS\VComm.sys
3 VcommMgr (Bluetooth VComm Manager Service) - System32\Drivers\VcommMgr.sys
4 viaagp (VIA AGP Bus Filter) - \SystemRoot\system32\DRIVERS\viaagp.sys
4 ViaIde - \SystemRoot\system32\DRIVERS\viaide.sys
3 wanatw (WAN Miniport (ATW)) - system32\DRIVERS\wanatw4.sys
3 winachsf - system32\DRIVERS\HSF_CNXT.sys
4 WS2IFSL (Windows Socket 2.0 Non-IFS Service Provider Support Environment) - \SystemRoot\System32\drivers\ws2ifsl.sys
3 WSTCODEC (World Standard Teletext Codec) - system32\DRIVERS\WSTCODEC.SYS
3 WudfPf (Windows Driver Foundation - User-mode Driver Framework Platform Driver) - system32\DRIVERS\WudfPf.sys
3 WudfRd (Windows Driver Foundation - User-mode Driver Framework Reflector) - system32\DRIVERS\wudfrd.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

2 AcrSch2Svc (Acronis Scheduler2 Service) - "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe"
3 aspnet_state (ASP.NET State Service) - %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
2 Ati HotKey Poller - %SystemRoot%\system32\Ati2evxx.exe
2 Automatic LiveUpdate Scheduler - "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
2 AVG Anti-Spyware Guard - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
2 BlueSoleil Hid Service - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
2 BthServ (Bluetooth Support Service) - %SystemRoot%\system32\svchost.exe -k bthsvcs
2 ccEvtMgr (Symantec Event Manager) - "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
2 ccProxy (Symantec Network Proxy) - "C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"
3 ccPwdSvc (Symantec Password Validation) - "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
2 ccSetMgr (Symantec Settings Manager) - "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
2 Creative Service for CDROM Access - C:\WINDOWS\system32\CTsvcCDA.EXE
2 Fax - %systemroot%\system32\fxssvc.exe
3 gusvc (Google Updater Service) - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
3 IDriverT (InstallDriver Table Manager) - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
2 InCDsrv (InCD Helper) - C:\Program Files\Ahead\InCD\InCDsrv.exe
3 iPod Service - "C:\Program Files\iPod\bin\iPodService.exe"
2 ISSVC - "C:\Program Files\Norton Internet Security\ISSVC.exe"
2 LexBceS (LexBce Server) - C:\WINDOWS\system32\LEXBCES.EXE
3 LiveUpdate - "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"
2 navapsvc (Norton AntiVirus Auto-Protect Service) - "C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"
3 NetSvc (Intel NCS NetService) - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
2 NProtectService (Norton Unerase Protection) - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
3 ose (Office Source Engine) - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
3 SAVScan - "C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe"
2 SBService (ScriptBlocking Service) - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
2 SNDSrvc (Symantec Network Drivers Service) - "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
2 SPBBCSvc (Symantec SPBBCSvc) - "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"
2 Speed Disk service - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
2 Symantec Core LC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
2 WinDefend (Windows Defender) - "C:\Program Files\Windows Defender\MsMpEng.exe"
2 WMDM PMSP Service - C:\WINDOWS\system32\MsPMSPSv.exe
3 WMPNetworkSvc (Windows Media Player Network Sharing Service) - "C:\Program Files\Windows Media Player\WMPNetwk.exe"
3 WudfSvc (Windows Driver Foundation - User-mode Driver Framework) - %SystemRoot%\system32\svchost.exe -k WudfServiceGroup


-- Scheduled Tasks --------------------------------------------------------------

2007-02-11 01:57:13 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job<MPSCHE~1.JOB>
2007-02-06 18:38:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job<APPLES~1.JOB>


-- Files created between 2007-01-11 and 2007-02-11 ------------------------------



-- Find3M Report ----------------------------------------------------------------

2007-02-11 21:55:49 0 d-------- C:\Documents and Settings\Lee\Application Data\uTorrent
2007-02-11 12:40:38 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-02-09 16:47:59 0 d-------- C:\Documents and Settings\Lee\Application Data\dvdcss
2007-02-09 13:49:37 0 d-------- C:\Program Files\Grisoft
2007-02-09 12:15:12 0 d-------- C:\Program Files\HijackThis<HIJACK~1>
2007-02-09 10:58:22 0 d-------- C:\Program Files\Norton Internet Security<NORTON~2>
2007-02-08 1811 0 d-------- C:\Program Files\Common Files\{F0A8A7BD-0BB0-1033-1013-05050622002c}<{F0A8A~1>
2007-02-08 13:37:49 0 d-------- C:\Documents and Settings\Lee\Application Data\GetRightToGo<GETRIG~1>
2007-02-08 13:37:30 0 d-------- C:\Program Files\FLVPlayer<FLVPLA~1>
2007-02-03 11:38:25 0 d-------- C:\Program Files\Guild Wars<GUILDW~1>
2007-02-03 08:05:31 0 d-------- C:\Program Files\ToniArts
2007-02-03 08:05:31 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-01-30 09:24:27 0 d-------- C:\Program Files\On2 Technologies<ON2TEC~1>
2007-01-26 23:17:03 0 d-------- C:\Program Files\Google
2007-01-24 20:54:46 0 d-------- C:\Program Files\LexmarkX73<LEXMAR~2>
2007-01-23 09:45:19 51733 --a------ C:\WINDOWS\system32\plugin1.dat
2007-01-17 17:23:57 36864 --a------ C:\WINDOWS\system32\svchosts.exe<Unsigned: n/a>
2007-01-17 17:23:56 2560 --a------ C:\WINDOWS\system32\unsvchosts.exe<UNSVCH~1.EXE><Unsigned: n/a>
2007-01-15 12:36:06 0 d-------- C:\Documents and Settings\Lee\Application Data\AdobeUM
2007-01-14 12:31:54 0 d-------- C:\Program Files\Common Files\{30A8A7BD-0BB0-1033-1013-05050622002c}<{30A8A~1>
2007-01-14 12:23:05 0 d--h----- C:\Program Files\Common Files\Uninstall Information<UNINST~1>
2007-01-14 11:05:07 51733 --a------ C:\WINDOWS\system32\scarddlg.dat
2007-01-05 01:56:53 0 --a------ C:\WINDOWS\system32\winlogin.exe<Unsigned: n/a>
2007-01-03 08:10:46 0 d-------- C:\Documents and Settings\Lee\Application Data\Adobe
2006-12-30 17:42:14 0 d---s---- C:\Documents and Settings\Lee\Application Data\Microsoft<MICROS~1>
2006-12-30 16:32:01 0 d-------- C:\Program Files\Bethesda Softworks<BETHES~1>
2006-12-28 08:58:54 0 d-------- C:\Program Files\AFT software<AFTSOF~1>
2006-12-28 08:55:37 796672 --a------ C:\WINDOWS\GPInstall.exe<GPINST~1.EXE><Unsigned: Qsc>
2006-12-27 14:45:43 0 d-------- C:\Program Files\Ricochet Lost Worlds Recharged<RICOCH~1>
2006-12-27 14:37:06 0 d-------- C:\Program Files\galaxian
2006-12-26 22:33:27 0 d-------- C:\Program Files\TvInternet<TVINTE~1>
2006-12-26 09:45:46 0 d-------- C:\Program Files\Windows Media Connect 2<WI4DF6~1>
2006-12-26 09:25:01 0 d-------- C:\Program Files\iTunes
2006-12-26 09:24:55 0 d-------- C:\Program Files\iPod
2006-12-26 09:24:18 0 d-------- C:\Program Files\QuickTime<QUICKT~1>
2006-12-26 09:22:00 0 d-------- C:\Program Files\Apple Software Update<APPLES~1>
2006-12-24 08:52:28 0 d-------- C:\Program Files\Java
2006-12-12 23:19:26 33952 --a------ C:\WINDOWS\system32\drivers\oreans32.sys<Unsigned: n/a>


-- Registry Dump ----------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"startkey"="C:\\WINDOWS\\system32\\scvhost.exe"
"1234567"="C:\\WINDOWS\\system32\\svcost.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"P17Helper"="Rundll32 P17.dll,P17Helper"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"PC Booster"="C:\\Program Files\\inKline Global\\PC Booster\\pcbooster.exe"
"PrinTray"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\printray.exe"
"sc"="C:\\Program Files\\ScrubXP\\scrubxp.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"ServiceHost"="\"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\svchost.exe\" \"\""
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"startkey"="C:\\WINDOWS\\system32\\scvhost.exe"
"Temporary"="C:\\i386\\svchost.exe"
"1234567"="C:\\WINDOWS\\system32\\svcost.exe"
"TrueImageMonitor.exe"="C:\\Program Files\\Acronis\\TrueImage\\TrueImageMonitor.exe"
"AcronisTimounterMonitor"="C:\\Program Files\\Acronis\\TrueImage\\TimounterMonitor.exe"
"Acronis Scheduler2 Service"="\"C:\\Program Files\\Common Files\\Acronis\\Schedule2\\schedhlp.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~3.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk"
"backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray"
"item"="ATI CATALYST System Tray"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Digital Line Detect.lnk"
"backup"="C:\\WINDOWS\\pss\\Digital Line Detect.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\DIGITA~1\\DLG.exe "
"item"="Digital Line Detect"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
"backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
"command"="C:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE "
"item"="InterVideo WinCinema Manager"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler V3.exeStartup"
"item"="PowerReg Scheduler V3"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"item"="PowerReg Scheduler"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^blueyonder Instant Support Tool.lnk]
"backup"="C:\\WINDOWS\\pss\\blueyonder Instant Support Tool.lnkCommon Startup"
"command"="C:\\PROGRA~1\\BLUEYO~1\\bin\\matcli.exe -boot"
"item"="blueyonder Instant Support Tool"
"location"="Common Startup"
"path"="C:\\DOCUME~1\\ALLUSE~1\\Start Menu\\Programs\\Startup\\blueyonder Instant Support Tool.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AQ3HelperStartUp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AQ3HEL~1"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\AQUATI~1\\AQ3HEL~1.EXE /partner AQ3"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTSysVol"
"hkey"="HKLM"
"command"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
"command"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="InCD"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"hkey"="HKLM"
"inimapping"="0"
"item"="iTunesHelper"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Manager]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACBTNM~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACBTNM~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Monitor]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACMONI~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACMONI~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBLKsk]
"hkey"="HKLM"
"inimapping"="0"
"item"="LXBLKsk"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAGIXautostart]
"command"="G:\\Content\\Software\\Full_Programs\\Music Maker Silver 2005\\mm2005_silver_upgrade_UK.EXE"
"hkey"="HKLM"
"inimapping"="0"
"item"="mm2005_silver_upgrade_UK"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McafWelcome]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcwelcom"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcagent"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcupdate"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
"command"="C:\\Program Files\\Lexmark\\Lexmark Photo Center\\MemoryCardManager.exe -startup"
"hkey"="HKLM"
"inimapping"="0"
"item"="MemoryCardManager"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSKDetct"
"hkey"="HKLM"
"command"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hkey"="HKCU"
"inimapping"="0"
"item"="msmsgs"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"hkey"="HKLM"
"inimapping"="0"
"item"="qttask"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"command"="soundman.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="soundman"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcvsshld"
"hkey"="HKLM"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000001
"DisableRegistryTools"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000001
"NoDispAppearancePage"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispSettingsPage"=dword:00000000
"DisableTaskMgr"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearRecentDocsOnExit"=dword:00000000
"HideClock"=dword:00000000
"NoCDBurning"=dword:00000000
"NoClose"=dword:00000000
"NoCommonGroups"=dword:00000000
"NoFileAssociate"=dword:00000000
"NoFileMenu"=dword:00000000
"NoFind"=dword:00000000
"NoFolderOptions"=dword:00000000
"NoLowDiskSpaceChecks"=dword:00000001
"NoRecentDocsHistory"=dword:00000001
"NoRun"=dword:00000000
"NoShellSearchButton"=dword:00000000
"NoSimpleStartMenu"=dword:00000000
"NoSMHelp"=dword:00000000
"NoToolbarsOnTaskbar"=dword:00000000
"NoTrayContextMenu"=dword:00000000
"NoTrayItemsDisplay"=dword:00000000
"NoViewContextMenu"=dword:00000000
"NoWinKeys"=dword:00000000
"StartMenuLogoff"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"{F0A8A7BD-0BB0-1033-1013-05050622002c}"="\"C:\\Program Files\\Common Files\\{F0A8A7BD-0BB0-1033-1013-05050622002c}\\Update.exe\" mc-110-12-0001377"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
bthsvcs REG_MULTI_SZ BthServ\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVG_ANTI-SPYWARE_DRIVER
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVG_ANTI-SPYWARE_GUARD
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_GUSVC


-- End of ComboScan: finished at 2007-02-11 at 21:57:40 -------------------------
Attached Files
File Type: txt Supplementary.txt (26.9 KB, 3 views)
greyrocker is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-11-2007, 05:07 PM   #4 (permalink)
Mentor, Analyst - Security Team
 
Deckard's Avatar
 
Join Date: May 2006
Location: Oregon
Posts: 2,503
OS: MacOS X, Debian, OpenBSD, Windows


P2P Software
I see you have P2P software (i.e. µTorrent, BitTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation.


Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions. If there is anything you don't understand, please ask BEFORE proceeding with the fixes. Please do these steps in order and do not skip any.


Download CleanUp!
Download and install CleanUp! but do not run it yet. (alternate link if main link isn't working: http://www.greyknight17.com/spy/CleanUp.exe)

WARNING: CleanUp! deletes EVERYTHING out of temporary folders and does not make backups. If you have any documents or programs that are saved in any temporary folders, please make a backup of these before running CleanUp!


Download Brute Force Uninstaller
Please download Brute Force Uninstaller to your desktop.
  1. Right click bfu.zip on your desktop, and choose Extract All. Click "Next".
  2. In the box to choose where to extract the files to, click "Browse".
  3. Click on the + sign next to "My Computer".
  4. Click on "Local Disk (C:) (or whatever your primary drive is).
  5. Click "Make New Folder" and type in BFU. Click "Next".
  6. Uncheck the "Show Extracted Files" box and then click "Finish".
RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download the Alcra PLUS Remover. Save it in the same folder you made earlier (i.e., C:\BFU).

Finally, download the file attached to this post and unzip it into the BFU folder -- the greyrocker.bfu file needs to be with the alcanshorty.bfu file.

Do not do anything with these yet!


Download ComboFix
Please download ComboFix from one of the two locations:
  1. http://www.techsupportforum.com/sectools/Beta/combofix.exe
  2. http://download.bleepingcomputer.com/sUBs/zh/combofix.exe
and save it to your Desktop, but do not do anything with it yet.


Reconfigure AVG Anti-Spyware
Please reconfigure AVG Anti-Spyware to the following settings:
  • Open AVG Anti-Spyware by double-clicking the AVG Anti-Spyware system tray icon.
  • Click the Update tab at the top:
    • Under Manual update, click Start update. After the update finishes, the status bar at the bottom will display "Update successful". If you are having trouble updating, you can also download and run the manual updater.
    • Under Automatic update, change the Update interval to something more reasonable like 12 or 24 hours.
  • Click the Scanner tab at the top and then the Settings sub-tab:
    • Under How to act?, click Recommended actions and select Quarantine.
    • Under Reports, select Automatically generate report after every scan
  • Close AVG Anti-Spyware. Do not run a scan with it yet.

Disable Windows Defender
Please disable your Windows Defender Real-time Protection, as it may hinder the removal of some entries. To disable Defender:
  • Open Windows Defender.
  • Click on Tools, General Settings.
  • Scroll down and uncheck Turn on real-time protection (recommended).
  • After you uncheck this, click on the Save button and close Windows Defender.

Uninstall
Click Start > Control Panel > Add / Remove Programs and uninstall the following programs (if they exist):
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 8
J2SE Runtime Environment 5.0 Update 9
Viewpoint Media Player
Please let me know if any of these were unable to uninstall.


Run ComboFix
Double click combofix.exe & follow the prompts. While ComboFix is running, please do not click or move the window, as this may cause the tool to stall. When the tool has finished, it will produce a log for you and save it as C:\ComboFix.txt. Post that log in your next reply.


Reboot
Reboot your system to Safe Mode by repeatedly tapping the F8 key until the menu appears and choosing Safe Mode from the list. On some systems, this may be the F5 key so try that if F8 doesn't work. Login on with your usual account. Make sure to close any open windows.


Run Brute Force Uninstaller
Please go to Start > My Computer and navigate to the folder you installed BFU in (i.e, C:\BFU).
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Next, click the folder icon again and select greyrocker.bfu. Execute this script.
  • When the "complete script execution" dialog appears, click OK and then press exit to terminate the BFU program.


Run CleanUp!
Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
  • Click "Options..."
  • Move the arrow down to "Custom CleanUp!"
  • Put a check next to the following:
    • Empty Recycle Bins
    • Delete Cookies
    • Delete Prefetch files
    • Cleanup! All Users
    • Click on the "Temporary Files" and make sure the box for "Scan drives for file matching" is unchecked.
    Click OK.
  • Press the CleanUp! button to start the program.
Once it's finished CleanUp! will ask you to logoff/reboot. Please select NO as we will do this later.


Run AVG Anti-Spyware
  • Run AVG Anti-Spyware and click on the Scanner tab at the top and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
  • AVG Anti-Spyware will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action.
  • If Set all elements to is not set to Quarantine (1), please click Recommended Action and choose Quarantine from the popup menu (2).
  • At the bottom of the window, click on the Apply all actions button (3).
  • When it has finished, click the Save Scan Report button (4), then click Save Report As and save the report it to your desktop.
  • Close AVG Anti-Spyware.

Reboot
Reboot your system to Normal Mode.


Online Scan
Perform an online scan with Internet Explorer with Panda ActiveScan.
  1. Click on the "Scan your PC" button located at the bottom of the page. A popup window should appear -- make sure you allow it if you have a popup blocker.
  2. Enter your e-mail address, country, and state and click Scan Now.
  3. Your computer will download Panda's 8 megabyte ActiveX control at this point. Follow the on-screen directions if it asks you to install the ActiveX control.
  4. Begin the scan by selecting My Computer. Note:
    • Please turn off the real time scanner of any existing antivirus program while performing the online scan.
    • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
    • Click on See report then click Save report.
    • It is not necessary to remain online while it's doing the scan, but you will have to re-connect after it has finished to see the report.

With Your Next Post...
Please paste the following with your next reply (in this order please):
  1. The contents of C:\ComboFix.txt,
  2. AVG Anti-Spyware scan report,
  3. Panda ActiveScan report,
  4. a new HiJackThis log taken after Panda finishes.
Attached Files
File Type: zip greyrocker.zip (801 Bytes, 6 views)
__________________
The chance to begin again in a golden land of opportunity and adventure.

Need HijackThis help? Please read MicroBell's Five Step Process before posting.
Please donate and help keep this site free to all.


UNITE/ASAP: Proud member since 2006
Deckard is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-12-2007, 05:55 AM   #5 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


Where are my manners?
I haven't even thanked you for what you've done so far.
I know I'm not well, but that's no excuse!
Thank you, this is much appreciated.
Anyway, here's the ComboFix log, the other reports are too large with this one, so they'll be in the post straight after this !

"Lee" - 07-02-12 9:01:17 Service Pack 2
ComboFix 07-02-11 - Running from: "C:\Documents and Settings\Lee\Desktop"

((((((((( Other Deletions )))))))))


C:\WINDOWS\system32\scvhost.exe
C:\WINDOWS\system32\unsvchosts.exe
C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\system32\winlogin.exe
C:\INSTALL.LOG
C:\WINDOWS\setup.exe
C:\Program Files\Common Files\{30A8A~1
C:\Program Files\Common Files\{F0A8A~1
C:\WINDOWS\system32\svchosts.exe

((((((((( Files Created from 2007-01-12 to 2007-02-12 ))))))


2007-02-12 08:14 <DIR> d-------- C:\BFU
2007-02-11 21:56 <DIR> d-------- C:\ComboScan
2007-02-09 13:49 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-09 13:49 <DIR> d-------- C:\Program Files\Grisoft
2007-02-09 12:10 <DIR> d-------- C:\Program Files\HijackThis
2007-02-08 13:37 <DIR> d-------- C:\Program Files\FLVPlayer
2007-02-08 13:36 <DIR> d-------- C:\Downloads
2007-02-08 13:36 <DIR> d-------- C:\DOCUME~1\Lee\Application Data\GetRightToGo
2007-02-03 08:05 <DIR> d-------- C:\Program Files\ToniArts
2007-01-30 09:24 630,784 --a------ C:\WINDOWS\system32\vp7vfw.dll
2007-01-30 09:24 <DIR> d-------- C:\Program Files\On2 Technologies
2007-01-14 10:59 162,304 --a------ C:\UNWISE.EXE

((((((((( Find3M Report ))))))


2007-02-12 09:04 -------- d-------- C:\Program Files\google
2007-02-12 09:01 -------- d-------- C:\Documents and Settings\Lee\Application Data\utorrent
2007-02-12 08:57 -------- d-------- C:\Program Files\java
2007-02-11 12:40 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-09 16:47 -------- d-------- C:\Documents and Settings\Lee\Application Data\dvdcss
2007-02-09 10:58 -------- d-------- C:\Program Files\norton internet security
2007-02-08 13:37 -------- d-------- C:\Documents and Settings\Lee\Application Data\getrighttogo
2007-02-03 11:38 -------- d-------- C:\Program Files\guild wars
2007-02-03 08:05 -------- d--h----- C:\Program Files\installshield installation information
2007-01-24 20:54 -------- d-------- C:\Program Files\lexmarkx73
2007-01-23 09:45 51733 --a------ C:\WINDOWS\system32\plugin1.dat
2007-01-15 12:36 -------- d-------- C:\Documents and Settings\Lee\Application Data\adobeum
2007-01-14 12:23 -------- d--h----- C:\Program Files\Common Files\uninstall information
2007-01-14 11:05 51733 --a------ C:\WINDOWS\system32\scarddlg.dat
2007-01-03 08:10 -------- d-------- C:\Documents and Settings\Lee\Application Data\adobe
2006-12-30 17:42 -------- d---s---- C:\Documents and Settings\Lee\Application Data\microsoft
2006-12-30 16:32 -------- d-------- C:\Program Files\bethesda softworks
2006-12-28 08:58 -------- d-------- C:\Program Files\aft software
2006-12-28 08:55 796672 --a------ C:\WINDOWS\gpinstall.exe
2006-12-27 14:45 -------- d-------- C:\Program Files\ricochet lost worlds recharged
2006-12-27 14:37 -------- d-------- C:\Program Files\galaxian
2006-12-26 22:33 -------- d-------- C:\Program Files\tvinternet
2006-12-26 09:45 -------- d-------- C:\Program Files\windows media connect 2
2006-12-26 09:25 -------- d-------- C:\Program Files\itunes
2006-12-26 09:24 -------- d-------- C:\Program Files\quicktime
2006-12-26 09:24 -------- d-------- C:\Program Files\ipod
2006-12-26 09:22 -------- d-------- C:\Program Files\apple software update
2006-12-12 23:19 33952 --a------ C:\WINDOWS\system32\drivers\oreans32.sys

(((((( Reg Loading Points )))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"startkey"="C:\\WINDOWS\\system32\\scvhost.exe"
"1234567"="C:\\WINDOWS\\system32\\svcost.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"P17Helper"="Rundll32 P17.dll,P17Helper"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"PC Booster"="C:\\Program Files\\inKline Global\\PC Booster\\pcbooster.exe"
"PrinTray"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\printray.exe"
"sc"="C:\\Program Files\\ScrubXP\\scrubxp.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"ServiceHost"="\"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\svchost.exe\" \"\""
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"startkey"="C:\\WINDOWS\\system32\\scvhost.exe"
"Temporary"="C:\\i386\\svchost.exe"
"1234567"="C:\\WINDOWS\\system32\\svcost.exe"
"TrueImageMonitor.exe"="C:\\Program Files\\Acronis\\TrueImage\\TrueImageMonitor.exe"
"AcronisTimounterMonitor"="C:\\Program Files\\Acronis\\TrueImage\\TimounterMonitor.exe"
"Acronis Scheduler2 Service"="\"C:\\Program Files\\Common Files\\Acronis\\Schedule2\\schedhlp.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~3.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk"
"backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray"
"item"="ATI CATALYST System Tray"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Digital Line Detect.lnk"
"backup"="C:\\WINDOWS\\pss\\Digital Line Detect.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\DIGITA~1\\DLG.exe "
"item"="Digital Line Detect"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
"backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
"command"="C:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE "
"item"="InterVideo WinCinema Manager"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler V3.exeStartup"
"item"="PowerReg Scheduler V3"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"item"="PowerReg Scheduler"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^blueyonder Instant Support Tool.lnk]
"backup"="C:\\WINDOWS\\pss\\blueyonder Instant Support Tool.lnkCommon Startup"
"command"="C:\\PROGRA~1\\BLUEYO~1\\bin\\matcli.exe -boot"
"item"="blueyonder Instant Support Tool"
"location"="Common Startup"
"path"="C:\\DOCUME~1\\ALLUSE~1\\Start Menu\\Programs\\Startup\\blueyonder Instant Support Tool.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AQ3HelperStartUp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AQ3HEL~1"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\AQUATI~1\\AQ3HEL~1.EXE /partner AQ3"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTSysVol"
"hkey"="HKLM"
"command"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
"command"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="InCD"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"hkey"="HKLM"
"inimapping"="0"
"item"="iTunesHelper"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Manager]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACBTNM~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACBTNM~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Monitor]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACMONI~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACMONI~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBLKsk]
"hkey"="HKLM"
"inimapping"="0"
"item"="LXBLKsk"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAGIXautostart]
"command"="G:\\Content\\Software\\Full_Programs\\Music Maker Silver 2005\\mm2005_silver_upgrade_UK.EXE"
"hkey"="HKLM"
"inimapping"="0"
"item"="mm2005_silver_upgrade_UK"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McafWelcome]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcwelcom"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcagent"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcupdate"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
"command"="C:\\Program Files\\Lexmark\\Lexmark Photo Center\\MemoryCardManager.exe -startup"
"hkey"="HKLM"
"inimapping"="0"
"item"="MemoryCardManager"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSKDetct"
"hkey"="HKLM"
"command"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hkey"="HKCU"
"inimapping"="0"
"item"="msmsgs"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"hkey"="HKLM"
"inimapping"="0"
"item"="qttask"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"command"="soundman.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="soundman"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcvsshld"
"hkey"="HKLM"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000001
"DisableRegistryTools"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearRecentDocsOnExit"=dword:00000000
"HideClock"=dword:00000000
"NoCDBurning"=dword:00000000
"NoClose"=dword:00000000
"NoCommonGroups"=dword:00000000
"NoFileAssociate"=dword:00000000
"NoFileMenu"=dword:00000000
"NoFind"=dword:00000000
"NoFolderOptions"=dword:00000000
"NoLowDiskSpaceChecks"=dword:00000001
"NoRecentDocsHistory"=dword:00000001
"NoRun"=dword:00000000
"NoShellSearchButton"=dword:00000000
"NoSimpleStartMenu"=dword:00000000
"NoSMHelp"=dword:00000000
"NoToolbarsOnTaskbar"=dword:00000000
"NoTrayContextMenu"=dword:00000000
"NoTrayItemsDisplay"=dword:00000000
"NoViewContextMenu"=dword:00000000
"NoWinKeys"=dword:00000000
"StartMenuLogoff"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
bthsvcs REG_MULTI_SZ BthServ\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\RECYCLER\NPROTECT
\00496690.rbf 32 bytes
\00496691.rbf 32 bytes
\00496692.rbf 32 bytes
\00496693.rbf 4096 bytes
\00496694.rbf 4096 bytes
\00496695.rbf 4096 bytes
\00496696.rbf 4096 bytes
\00496697.rbf 4096 bytes
\00496698.rbf 4096 bytes
\00496699.rbf 4096 bytes
\00496700.rbf 4096 bytes
\00496701.rbf 4096 bytes
\00496702.rbf 4096 bytes
\00496703.rbf 4096 bytes
\00496704.rbf 4096 bytes
\00496705.rbf 4096 bytes
\00496706.rbf 4096 bytes
\00496707.rbf 4096 bytes
\00496708.rbf 4096 bytes
\00496709.rbf 4096 bytes
\00496710.rbf 4096 bytes
\00496711.rbf 4096 bytes
\00496712.rbf 4096 bytes
\00496713.rbf 4096 bytes
\00496714.rbf 4096 bytes
\00496715.rbf 4096 bytes
\00496716.rbf 4096 bytes
\00496717.rbf 4096 bytes
\00496718.rbf 4096 bytes
\00496719.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496720.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496721.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496722.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496723.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496724.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496725.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496726.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496727.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496728.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496729.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496730.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496731.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496732.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496733.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496734.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496735.rbf 216 bytes
C:\RECYCLER\NPROTECT\00496736.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496737.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496738.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00496739.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00496740.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496741.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496742.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496743.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496744.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496745.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496746.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496747.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496748.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496749.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496750.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496751.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496752.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496753.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496754.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496755.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496756.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496757.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496758.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496759.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496760.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496761.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496762.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496763.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496764.rbf 240 bytes
C:\RECYCLER\NPROTECT\00496765.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496766.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496767.rbf 112 bytes
C:\RECYCLER\NPROTECT\00496768.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496769.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496770.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496771.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496772.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496773.rbf 120 bytes
C:\RECYCLER\NPROTECT\00496774.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496775.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496776.rbf 88 bytes
C:\RECYCLER\NPROTECT\00496777.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496778.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496779.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496780.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496781.rbf 104 bytes
C:\RECYCLER\NPROTECT\00496782.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496783.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496784.rbf 128 bytes
C:\RECYCLER\NPROTECT\00496785.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496786.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496787.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496788.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496789.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496790.rbf 288 bytes
C:\RECYCLER\NPROTECT\00496791.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496792.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496793.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496794.rbf 136 bytes
C:\RECYCLER\NPROTECT\00496795.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496796.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496797.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496798.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00496799.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00496800.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496801.rbf 2035712 bytes
C:\RECYCLER\NPROTECT\00496802.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496803.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496804.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496805.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496806.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496807.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496808.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496809.rbf 765952 bytes
C:\RECYCLER\NPROTECT\00496810.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00496811.rbf 487424 bytes
C:\RECYCLER\NPROTECT\00496812.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496813.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496814.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496815.rbf 999424 bytes
C:\RECYCLER\NPROTECT\00496816.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496817.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00496818.rbf 33759232 bytes
C:\RECYCLER\NPROTECT\00496819.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496820.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496821.rbf 1335296 bytes
C:\RECYCLER\NPROTECT\00496822.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00496823.rbf 196608 bytes
C:\RECYCLER\NPROTECT\00496824.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00496825.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00496826.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00496827.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00496828.rbf 253952 bytes
C:\RECYCLER\NPROTECT\00496829.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00496830.rbf 126976 bytes
C:\RECYCLER\NPROTECT\00496831.rbf 16 bytes
C:\RECYCLER\NPROTECT\00496832.rbf 61440 bytes
C:\RECYCLER\NPROTECT\00496833.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00496834.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496835.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00496836.rbf 122880 bytes
C:\RECYCLER\NPROTECT\00496837.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496838.rbf 49152 bytes
C:\RECYCLER\NPROTECT\00496839.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496840.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00496841.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00496842.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00496843.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00496844.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00496845.rbf 204800 bytes
C:\RECYCLER\NPROTECT\00496846.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00496847.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00496848.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496849.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00496850.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00496851.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496852.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00496853.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00496854.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00496855.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00496856.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00496857.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496858.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496859.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496860.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496861.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00496862.rbf 20480 bytes
C:\RECYCLER\NPROTECT\00496863.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00496864.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00496865.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496866.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496867.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496868.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496869.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496870.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496871.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00496872.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00496873.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496874.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496875.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00496876.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496877.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496878.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496879.rbf 188416 bytes
C:\RECYCLER\NPROTECT\00496880.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00496881.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00496882.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00496883.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00496884.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496885.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00496886.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00496887.rbf 12189696 bytes
C:\RECYCLER\NPROTECT\00496888.rbf 1589248 bytes
C:\RECYCLER\NPROTECT\00496889.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496890.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00496891.rbf 632 bytes
C:\RECYCLER\NPROTECT\00496892.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496893.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00496894.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496895.rbf 160 bytes
C:\RECYCLER\NPROTECT\00496896.rbf 168 bytes
C:\RECYCLER\NPROTECT\00496897.rbf 160 bytes
C:\RECYCLER\NPROTECT\00496898.rbf 168 bytes
C:\RECYCLER\NPROTECT\00496899.rbf 160 bytes
C:\RECYCLER\NPROTECT\00496900.rbf 152 bytes
C:\RECYCLER\NPROTECT\00496901.rbf 160 bytes
C:\RECYCLER\NPROTECT\00496902.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496903.rbf 155648 bytes
C:\RECYCLER\NPROTECT\00496904.rbf 176128 bytes
C:\RECYCLER\NPROTECT\00496905.rbf 700416 bytes
C:\RECYCLER\NPROTECT\00496906.rbf 672 bytes
C:\RECYCLER\NPROTECT\00496907.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00496908.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496909.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496910.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496911.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00496912.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496913.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00496914.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496915.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00496916.rbf 136 bytes
C:\RECYCLER\NPROTECT\00496917.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496918.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496919.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00496920.rbf 3948544 bytes
C:\RECYCLER\NPROTECT\00496921.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00496922.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496923.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00496924.rbs 118784 bytes
C:\RECYCLER\NPROTECT\00496925.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00496926.msi 172032 bytes
C:\RECYCLER\NPROTECT\00496927.MST 380928 bytes
C:\RECYCLER\NPROTECT\00496928.mst 380928 bytes
C:\RECYCLER\NPROTECT\00496930.cpl 53248 bytes
C:\RECYCLER\NPROTECT\00496931.exe 53248 bytes
C:\RECYCLER\NPROTECT\00496932.exe 57344 bytes
C:\RECYCLER\NPROTECT\00496933.exe 131072 bytes
C:\RECYCLER\NPROTECT\00496934.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00496935.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496936.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496937.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496938.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496939.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496940.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496941.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496942.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496943.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496944.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496945.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496946.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00496947.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496948.rbf 184 bytes
C:\RECYCLER\NPROTECT\00496949.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496950.rbf 336 bytes
C:\RECYCLER\NPROTECT\00496951.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496952.rbf 88 bytes
C:\RECYCLER\NPROTECT\00496953.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496954.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496955.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496956.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496957.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496958.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496959.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496960.rbf 216 bytes
C:\RECYCLER\NPROTECT\00496961.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496962.rbf 88 bytes
C:\RECYCLER\NPROTECT\00496963.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496964.rbf 88 bytes
C:\RECYCLER\NPROTECT\00496965.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496966.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496967.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496968.rbf 320 bytes
C:\RECYCLER\NPROTECT\00496969.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496970.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496971.rbf 112 bytes
C:\RECYCLER\NPROTECT\00496972.rbf 104 bytes
C:\RECYCLER\NPROTECT\00496973.rbf 344 bytes
C:\RECYCLER\NPROTECT\00496974.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496975.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496976.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496977.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496978.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496979.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496980.rbf 32 bytes
C:\RECYCLER\NPROTECT\00496981.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496982.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496983.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496984.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496985.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496986.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496987.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496988.rbf 104 bytes
C:\RECYCLER\NPROTECT\00496989.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496990.rbf 96 bytes
C:\RECYCLER\NPROTECT\00496991.rbf 88 bytes
C:\RECYCLER\NPROTECT\00496992.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496993.rbf 80 bytes
C:\RECYCLER\NPROTECT\00496994.rbf 72 bytes
C:\RECYCLER\NPROTECT\00496995.rbf 296 bytes
C:\RECYCLER\NPROTECT\00496996.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496997.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496998.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00496999.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497000.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497001.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497002.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497003.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497004.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497005.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497006.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497007.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497008.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497009.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497010.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00497011.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497012.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497013.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497014.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497015.rbf 464 bytes
C:\RECYCLER\NPROTECT\00497016.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497017.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497018.rbf 544 bytes
C:\RECYCLER\NPROTECT\00497019.rbf 144 bytes
C:\RECYCLER\NPROTECT\00497020.rbf 304 bytes
C:\RECYCLER\NPROTECT\00497021.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497022.rbf 336 bytes
C:\RECYCLER\NPROTECT\00497023.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497024.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497025.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497026.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497027.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497028.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497029.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497030.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497031.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497032.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497033.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497034.rbf 144 bytes
C:\RECYCLER\NPROTECT\00497035.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497036.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497037.rbf 344 bytes
C:\RECYCLER\NPROTECT\00497038.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497039.rbf 512 bytes
C:\RECYCLER\NPROTECT\00497040.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497041.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497042.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497043.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497044.rbf 320 bytes
C:\RECYCLER\NPROTECT\00497045.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497046.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497047.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497048.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497049.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497050.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497051.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497052.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497053.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497054.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497055.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497056.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497057.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497058.rbf 192 bytes
C:\RECYCLER\NPROTECT\00497059.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497060.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497061.rbf 240 bytes
C:\RECYCLER\NPROTECT\00497062.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497063.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497064.rbf 192 bytes
C:\RECYCLER\NPROTECT\00497065.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497066.rbf 400 bytes
C:\RECYCLER\NPROTECT\00497067.rbf 176 bytes
C:\RECYCLER\NPROTECT\00497068.rbf 320 bytes
C:\RECYCLER\NPROTECT\00497069.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497070.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497071.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497072.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497073.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497074.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497075.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497076.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497077.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497078.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497079.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497080.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497081.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497082.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497083.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497084.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497085.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497086.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497087.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497088.rbf 144 bytes
C:\RECYCLER\NPROTECT\00497089.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497090.rbf 304 bytes
C:\RECYCLER\NPROTECT\00497091.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497092.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497093.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497094.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497095.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497096.rbf 488 bytes
C:\RECYCLER\NPROTECT\00497097.rbf 304 bytes
C:\RECYCLER\NPROTECT\00497098.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497099.rbf 208 bytes
C:\RECYCLER\NPROTECT\00497100.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497101.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497102.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497103.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497104.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497105.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497106.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497107.rbf 248 bytes
C:\RECYCLER\NPROTECT\00497108.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497109.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497110.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497111.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497112.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497113.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497114.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497115.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497116.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497117.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497118.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497119.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497120.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497121.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497122.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497123.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497124.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497125.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497126.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497127.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497128.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497129.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497130.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497131.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497132.rbf 544 bytes
C:\RECYCLER\NPROTECT\00497133.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497134.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497135.rbf 544 bytes
C:\RECYCLER\NPROTECT\00497136.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497137.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497138.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497139.rbf 456 bytes
C:\RECYCLER\NPROTECT\00497140.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497141.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497142.rbf 456 bytes
C:\RECYCLER\NPROTECT\00497143.rbf 456 bytes
C:\RECYCLER\NPROTECT\00497144.rbf 272 bytes
C:\RECYCLER\NPROTECT\00497145.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497146.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497147.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497148.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497149.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497150.rbf 488 bytes
C:\RECYCLER\NPROTECT\00497151.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497152.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497153.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497154.rbf 184 bytes
C:\RECYCLER\NPROTECT\00497155.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497156.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497157.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497158.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497159.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497160.rbf 264 bytes
C:\RECYCLER\NPROTECT\00497161.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497162.rbf 208 bytes
C:\RECYCLER\NPROTECT\00497163.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497164.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497165.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497166.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497167.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497168.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497169.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497170.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497171.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497172.rbf 200 bytes
C:\RECYCLER\NPROTECT\00497173.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497174.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497175.rbf 152 bytes
C:\RECYCLER\NPROTECT\00497176.rbf 224 bytes
C:\RECYCLER\NPROTECT\00497177.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497178.rbf 400 bytes
C:\RECYCLER\NPROTECT\00497179.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497180.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497181.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497182.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497183.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497184.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497185.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497186.rbf 464 bytes
C:\RECYCLER\NPROTECT\00497187.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497188.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497189.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497190.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497191.rbf 472 bytes
C:\RECYCLER\NPROTECT\00497192.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497193.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497194.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497195.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497196.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497197.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497198.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497199.rbf 264 bytes
C:\RECYCLER\NPROTECT\00497200.rbf 168 bytes
C:\RECYCLER\NPROTECT\00497201.rbf 208 bytes
C:\RECYCLER\NPROTECT\00497202.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497203.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497204.rbf 264 bytes
C:\RECYCLER\NPROTECT\00497205.rbf 472 bytes
C:\RECYCLER\NPROTECT\00497206.rbf 392 bytes
C:\RECYCLER\NPROTECT\00497207.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497208.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497209.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497210.rbf 184 bytes
C:\RECYCLER\NPROTECT\00497211.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497212.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497213.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497214.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497215.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497216.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497217.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497218.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497219.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497220.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497221.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497222.rbf 584 bytes
C:\RECYCLER\NPROTECT\00497223.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497224.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497225.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497226.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497227.rbf 192 bytes
C:\RECYCLER\NPROTECT\00497228.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497229.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497230.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497231.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497232.rbf 224 bytes
C:\RECYCLER\NPROTECT\00497233.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497234.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497235.rbf 160 bytes
C:\RECYCLER\NPROTECT\00497236.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497237.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497238.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497239.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497240.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497241.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497242.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497243.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497244.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497245.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497246.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497247.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497248.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497249.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497250.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497251.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497252.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497253.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497254.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497255.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497256.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497257.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497258.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497259.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497260.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497261.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497262.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497263.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497264.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497265.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497266.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497267.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497268.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497269.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497270.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497271.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497272.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497273.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497274.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497275.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497276.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497277.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497278.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497279.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497280.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497281.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497282.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497283.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497284.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497285.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497286.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497287.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497288.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497289.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497290.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497291.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497292.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497293.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497294.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497295.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497296.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497297.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497298.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497299.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497300.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497301.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497302.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497303.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497304.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497305.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497306.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497307.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497308.rbf 288 bytes
C:\RECYCLER\NPROTECT\00497309.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497310.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497311.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497312.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00497313.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00497314.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497315.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497316.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497317.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497318.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497319.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497320.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497321.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497322.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497323.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497324.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497325.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497326.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497327.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497328.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497329.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497330.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497331.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497332.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497333.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497334.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497335.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497336.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497337.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497338.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497339.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497340.rbf 240 bytes
C:\RECYCLER\NPROTECT\00497341.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497342.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497343.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497344.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497345.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497346.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497347.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497348.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497349.rbf 120 bytes
C:\RECYCLER\NPROTECT\00497350.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497351.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497352.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497353.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497354.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497355.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497356.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497357.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497358.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497359.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497360.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497361.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497362.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497363.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497364.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497365.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497366.rbf 288 bytes
C:\RECYCLER\NPROTECT\00497367.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497368.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497369.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497370.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497371.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497372.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497373.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497374.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497375.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497376.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497377.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497378.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497379.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497380.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497381.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497382.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497383.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497384.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497385.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497386.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497387.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00497388.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497389.rbf 2039808 bytes
C:\RECYCLER\NPROTECT\00497390.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497391.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497392.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497393.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497394.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497395.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497396.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497397.rbf 770048 bytes
C:\RECYCLER\NPROTECT\00497398.rbf 86016 bytes
C:\RECYCLER\NPROTECT\00497399.rbf 487424 bytes
C:\RECYCLER\NPROTECT\00497400.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497401.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497402.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497403.rbf 1003520 bytes
C:\RECYCLER\NPROTECT\00497404.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497405.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497406.rbf 33914880 bytes
C:\RECYCLER\NPROTECT\00497407.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497408.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497409.rbf 1343488 bytes
C:\RECYCLER\NPROTECT\00497410.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00497411.rbf 196608 bytes
C:\RECYCLER\NPROTECT\00497412.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00497413.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00497414.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00497415.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00497416.rbf 262144 bytes
C:\RECYCLER\NPROTECT\00497417.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00497418.rbf 126976 bytes
C:\RECYCLER\NPROTECT\00497419.rbf 61440 bytes
C:\RECYCLER\NPROTECT\00497420.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00497421.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497422.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00497423.rbf 122880 bytes
C:\RECYCLER\NPROTECT\00497424.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00497425.rbf 49152 bytes
C:\RECYCLER\NPROTECT\00497426.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497427.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00497428.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00497429.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00497430.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00497431.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497432.rbf 204800 bytes
C:\RECYCLER\NPROTECT\00497433.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00497434.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00497435.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00497436.rbf 102400 bytes
C:\RECYCLER\NPROTECT\00497437.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00497438.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00497439.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00497440.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00497441.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00497442.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00497443.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00497444.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497445.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497446.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497447.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497448.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00497449.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00497450.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00497451.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497452.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497453.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497454.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497455.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497456.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497457.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00497458.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497459.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497460.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497461.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00497462.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497463.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497464.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497465.rbf 438272 bytes
C:\RECYCLER\NPROTECT\00497466.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00497467.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00497468.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00497469.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00497470.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00497471.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00497472.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00497473.rbf 12255232 bytes
C:\RECYCLER\NPROTECT\00497474.rbf 1617920 bytes
C:\RECYCLER\NPROTECT\00497475.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497476.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00497477.rbf 632 bytes
C:\RECYCLER\NPROTECT\00497478.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497479.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00497480.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497481.rbf 160 bytes
C:\RECYCLER\NPROTECT\00497482.rbf 168 bytes
C:\RECYCLER\NPROTECT\00497483.rbf 160 bytes
C:\RECYCLER\NPROTECT\00497484.rbf 168 bytes
C:\RECYCLER\NPROTECT\00497485.rbf 160 bytes
C:\RECYCLER\NPROTECT\00497486.rbf 152 bytes
C:\RECYCLER\NPROTECT\00497487.rbf 160 bytes
C:\RECYCLER\NPROTECT\00497488.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497489.rbf 159744 bytes
C:\RECYCLER\NPROTECT\00497490.rbf 176128 bytes
C:\RECYCLER\NPROTECT\00497491.rbf 700416 bytes
C:\RECYCLER\NPROTECT\00497492.rbf 672 bytes
C:\RECYCLER\NPROTECT\00497493.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497494.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497495.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497496.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497497.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497498.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497499.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00497500.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497501.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497502.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497503.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497504.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497505.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00497506.rbf 4485120 bytes
C:\RECYCLER\NPROTECT\00497507.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00497508.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497509.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00497510.rbs 122880 bytes
C:\RECYCLER\NPROTECT\00497511.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00497512.msi 188416 bytes
C:\RECYCLER\NPROTECT\00497513.MST 135168 bytes
C:\RECYCLER\NPROTECT\00497514.mst 135168 bytes
C:\RECYCLER\NPROTECT\00497515.lo_ 69632 bytes
C:\RECYCLER\NPROTECT\00497517.cpl 53248 bytes
C:\RECYCLER\NPROTECT\00497518.exe 53248 bytes
C:\RECYCLER\NPROTECT\00497519.exe 57344 bytes
C:\RECYCLER\NPROTECT\00497520.exe 131072 bytes
C:\RECYCLER\NPROTECT\00497521.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00497522.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497523.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497524.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497525.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497526.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497527.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497528.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497529.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497530.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497531.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497532.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497533.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497534.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497535.rbf 184 bytes
C:\RECYCLER\NPROTECT\00497536.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497537.rbf 336 bytes
C:\RECYCLER\NPROTECT\00497538.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497539.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497540.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497541.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497542.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497543.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497544.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497545.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497546.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497547.rbf 216 bytes
C:\RECYCLER\NPROTECT\00497548.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497549.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497550.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497551.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497552.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497553.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497554.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497555.rbf 320 bytes
C:\RECYCLER\NPROTECT\00497556.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497557.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497558.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497559.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497560.rbf 344 bytes
C:\RECYCLER\NPROTECT\00497561.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497562.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497563.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497564.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497565.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497566.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497567.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497568.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497569.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497570.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497571.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497572.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497573.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497574.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497575.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497576.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497577.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497578.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497579.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497580.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497581.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497582.rbf 296 bytes
C:\RECYCLER\NPROTECT\00497583.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497584.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497585.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497586.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497587.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497588.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497589.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497590.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497591.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497592.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497593.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497594.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497595.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497596.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497597.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00497598.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497599.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497600.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497601.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497602.rbf 464 bytes
C:\RECYCLER\NPROTECT\00497603.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497604.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497605.rbf 544 bytes
C:\RECYCLER\NPROTECT\00497606.rbf 144 bytes
C:\RECYCLER\NPROTECT\00497607.rbf 304 bytes
C:\RECYCLER\NPROTECT\00497608.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497609.rbf 336 bytes
C:\RECYCLER\NPROTECT\00497610.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497611.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497612.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497613.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497614.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497615.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497616.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497617.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497618.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497619.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497620.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497621.rbf 144 bytes
C:\RECYCLER\NPROTECT\00497622.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497623.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497624.rbf 344 bytes
C:\RECYCLER\NPROTECT\00497625.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497626.rbf 512 bytes
C:\RECYCLER\NPROTECT\00497627.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497628.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497629.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497630.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497631.rbf 320 bytes
C:\RECYCLER\NPROTECT\00497632.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497633.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497634.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497635.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497636.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497637.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497638.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497639.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497640.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497641.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497642.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497643.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497644.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497645.rbf 192 bytes
C:\RECYCLER\NPROTECT\00497646.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497647.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497648.rbf 240 bytes
C:\RECYCLER\NPROTECT\00497649.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497650.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497651.rbf 192 bytes
C:\RECYCLER\NPROTECT\00497652.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497653.rbf 400 bytes
C:\RECYCLER\NPROTECT\00497654.rbf 176 bytes
C:\RECYCLER\NPROTECT\00497655.rbf 320 bytes
C:\RECYCLER\NPROTECT\00497656.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497657.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497658.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497659.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497660.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497661.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497662.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497663.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497664.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497665.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497666.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497667.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497668.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497669.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497670.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497671.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497672.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497673.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497674.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497675.rbf 144 bytes
C:\RECYCLER\NPROTECT\00497676.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497677.rbf 304 bytes
C:\RECYCLER\NPROTECT\00497678.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497679.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497680.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497681.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497682.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497683.rbf 488 bytes
C:\RECYCLER\NPROTECT\00497684.rbf 304 bytes
C:\RECYCLER\NPROTECT\00497685.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497686.rbf 208 bytes
C:\RECYCLER\NPROTECT\00497687.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497688.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497689.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497690.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497691.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497692.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497693.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497694.rbf 248 bytes
C:\RECYCLER\NPROTECT\00497695.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497696.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497697.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497698.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497699.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497700.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497701.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497702.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497703.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497704.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497705.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497706.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497707.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497708.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497709.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497710.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497711.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497712.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497713.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497714.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497715.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497716.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497717.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497718.rbf 520 bytes
C:\RECYCLER\NPROTECT\00497719.rbf 544 bytes
C:\RECYCLER\NPROTECT\00497720.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497721.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497722.rbf 544 bytes
C:\RECYCLER\NPROTECT\00497723.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497724.rbf 536 bytes
C:\RECYCLER\NPROTECT\00497725.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497726.rbf 456 bytes
C:\RECYCLER\NPROTECT\00497727.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497728.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497729.rbf 456 bytes
C:\RECYCLER\NPROTECT\00497730.rbf 456 bytes
C:\RECYCLER\NPROTECT\00497731.rbf 272 bytes
C:\RECYCLER\NPROTECT\00497732.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497733.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497734.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497735.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497736.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497737.rbf 488 bytes
C:\RECYCLER\NPROTECT\00497738.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497739.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497740.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497741.rbf 184 bytes
C:\RECYCLER\NPROTECT\00497742.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497743.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497744.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497745.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497746.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497747.rbf 264 bytes
C:\RECYCLER\NPROTECT\00497748.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497749.rbf 208 bytes
C:\RECYCLER\NPROTECT\00497750.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497751.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497752.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497753.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497754.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497755.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497756.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497757.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497758.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497759.rbf 200 bytes
C:\RECYCLER\NPROTECT\00497760.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497761.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497762.rbf 152 bytes
C:\RECYCLER\NPROTECT\00497763.rbf 224 bytes
C:\RECYCLER\NPROTECT\00497764.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497765.rbf 400 bytes
C:\RECYCLER\NPROTECT\00497766.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497767.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497768.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497769.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497770.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497771.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497772.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497773.rbf 464 bytes
C:\RECYCLER\NPROTECT\00497774.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497775.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497776.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497777.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497778.rbf 472 bytes
C:\RECYCLER\NPROTECT\00497779.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497780.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497781.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497782.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497783.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497784.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497785.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497786.rbf 264 bytes
C:\RECYCLER\NPROTECT\00497787.rbf 168 bytes
C:\RECYCLER\NPROTECT\00497788.rbf 208 bytes
C:\RECYCLER\NPROTECT\00497789.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497790.rbf 384 bytes
C:\RECYCLER\NPROTECT\00497791.rbf 264 bytes
C:\RECYCLER\NPROTECT\00497792.rbf 472 bytes
C:\RECYCLER\NPROTECT\00497793.rbf 392 bytes
C:\RECYCLER\NPROTECT\00497794.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497795.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497796.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497797.rbf 184 bytes
C:\RECYCLER\NPROTECT\00497798.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497799.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497800.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497801.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497802.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497803.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497804.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497805.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497806.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497807.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497808.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497809.rbf 584 bytes
C:\RECYCLER\NPROTECT\00497810.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497811.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497812.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497813.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497814.rbf 192 bytes
C:\RECYCLER\NPROTECT\00497815.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497816.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497817.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497818.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497819.rbf 224 bytes
C:\RECYCLER\NPROTECT\00497820.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497821.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497822.rbf 160 bytes
C:\RECYCLER\NPROTECT\00497823.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497824.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497825.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497826.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497827.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497828.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497829.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497830.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497831.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497832.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497833.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497834.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497835.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497836.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497837.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497838.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497839.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497840.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497841.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497842.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497843.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497844.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497845.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497846.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497847.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497848.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497849.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497850.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497851.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497852.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497853.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497854.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497855.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497856.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497857.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497858.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497859.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497860.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497861.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497862.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497863.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497864.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497865.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497866.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497867.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497868.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497869.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497870.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497871.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497872.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497873.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497874.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497875.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497876.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497877.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497878.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497879.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497880.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497881.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497882.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497883.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497884.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497885.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497886.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497887.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497888.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497889.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497890.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497891.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497892.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497893.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497894.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497895.rbf 288 bytes
C:\RECYCLER\NPROTECT\00497896.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497897.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497898.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00497899.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00497900.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00497901.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497902.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497903.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497904.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497905.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497906.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497907.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497908.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497909.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497910.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497911.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497912.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497913.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497914.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497915.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497916.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497917.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497918.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497919.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497920.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497921.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497922.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497923.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497924.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497925.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497926.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497927.rbf 240 bytes
C:\RECYCLER\NPROTECT\00497928.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497929.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497930.rbf 112 bytes
C:\RECYCLER\NPROTECT\00497931.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497932.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497933.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497934.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497935.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497936.rbf 120 bytes
C:\RECYCLER\NPROTECT\00497937.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497938.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497939.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497940.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497941.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497942.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497943.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497944.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497945.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497946.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497947.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497948.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497949.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497950.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497951.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497952.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497953.rbf 288 bytes
C:\RECYCLER\NPROTECT\00497954.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497955.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497956.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497957.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497958.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497959.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497960.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497961.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497962.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497963.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497964.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497965.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497966.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497967.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497968.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497969.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497970.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497971.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497972.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497973.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497974.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00497975.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497976.rbf 2039808 bytes
C:\RECYCLER\NPROTECT\00497977.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497978.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497979.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497980.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497981.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497982.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497983.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497984.rbf 770048 bytes
C:\RECYCLER\NPROTECT\00497985.rbf 86016 bytes
C:\RECYCLER\NPROTECT\00497986.rbf 487424 bytes
C:\RECYCLER\NPROTECT\00497987.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497988.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497989.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497990.rbf 1003520 bytes
C:\RECYCLER\NPROTECT\00497991.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497992.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497993.rbf 33914880 bytes
C:\RECYCLER\NPROTECT\00497994.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497995.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497996.rbf 1343488 bytes
C:\RECYCLER\NPROTECT\00497997.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00497998.rbf 196608 bytes
C:\RECYCLER\NPROTECT\00497999.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498000.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00498001.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498002.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00498003.rbf 262144 bytes
C:\RECYCLER\NPROTECT\00498004.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498005.rbf 126976 bytes
C:\RECYCLER\NPROTECT\00498006.rbf 61440 bytes
C:\RECYCLER\NPROTECT\00498007.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00498008.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498009.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498010.rbf 122880 bytes
C:\RECYCLER\NPROTECT\00498011.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498012.rbf 49152 bytes
C:\RECYCLER\NPROTECT\00498013.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498014.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498015.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498016.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498017.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498018.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498019.rbf 204800 bytes
C:\RECYCLER\NPROTECT\00498020.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498021.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00498022.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498023.rbf 102400 bytes
C:\RECYCLER\NPROTECT\00498024.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00498025.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498026.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00498027.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00498028.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498029.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00498030.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498031.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498032.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498033.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498034.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498035.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498036.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00498037.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00498038.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498039.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498040.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498041.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498042.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498043.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498044.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498045.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498046.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498047.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498048.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498049.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498050.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498051.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498052.rbf 438272 bytes
C:\RECYCLER\NPROTECT\00498053.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498054.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00498055.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00498056.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498057.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498058.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498059.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00498060.rbf 12255232 bytes
C:\RECYCLER\NPROTECT\00498061.rbf 1617920 bytes
C:\RECYCLER\NPROTECT\00498062.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498063.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498064.rbf 632 bytes
C:\RECYCLER\NPROTECT\00498065.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498066.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00498067.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498068.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498069.rbf 168 bytes
C:\RECYCLER\NPROTECT\00498070.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498071.rbf 168 bytes
C:\RECYCLER\NPROTECT\00498072.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498073.rbf 152 bytes
C:\RECYCLER\NPROTECT\00498074.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498075.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498076.rbf 159744 bytes
C:\RECYCLER\NPROTECT\00498077.rbf 176128 bytes
C:\RECYCLER\NPROTECT\00498078.rbf 700416 bytes
C:\RECYCLER\NPROTECT\00498079.rbf 672 bytes
C:\RECYCLER\NPROTECT\00498080.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498081.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498082.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498083.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498084.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498085.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498086.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00498087.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498088.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498089.rbf 136 bytes
C:\RECYCLER\NPROTECT\00498090.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498091.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498092.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498093.rbf 4493312 bytes
C:\RECYCLER\NPROTECT\00498094.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498095.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498096.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498097.rbs 122880 bytes
C:\RECYCLER\NPROTECT\00498098.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00498099.msi 188416 bytes
C:\RECYCLER\NPROTECT\00498100.MST 147456 bytes
C:\RECYCLER\NPROTECT\00498101.mst 147456 bytes
C:\RECYCLER\NPROTECT\00498106 224 bytes
C:\RECYCLER\NPROTECT\00498109 216 bytes
C:\RECYCLER\NPROTECT\00498132.SYS 8192 bytes
C:\RECYCLER\NPROTECT\00498144 696 bytes
C:\RECYCLER\NPROTECT\00498145.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498160 64 bytes
C:\RECYCLER\NPROTECT\00498165.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498166.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498167.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498168.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498173.exe 1232896 bytes
C:\RECYCLER\NPROTECT\00498174.EXE 4096 bytes
C:\RECYCLER\NPROTECT\00498175.LZM 4096 bytes
C:\RECYCLER\NPROTECT\00498176.LOG 4096 bytes
C:\RECYCLER\NPROTECT\00498177.exe 61440 bytes
C:\RECYCLER\NPROTECT\00498178 232 bytes
C:\RECYCLER\NPROTECT\00498179 80 bytes
C:\RECYCLER\NPROTECT\00498180.txt 57344 bytes
C:\RECYCLER\NPROTECT\00498181.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498182 16 bytes
C:\RECYCLER\NPROTECT\00498183.txt 296 bytes
C:\RECYCLER\NPROTECT\00498184.txt 152 bytes
C:\RECYCLER\NPROTECT\00498186.txt 104 bytes
C:\RECYCLER\NPROTECT\00498188.txt 104 bytes
C:\RECYCLER\NPROTECT\00498191.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498197.job 440 bytes
C:\RECYCLER\NPROTECT\00498198.txt 40 bytes
C:\RECYCLER\NPROTECT\00498210.exe 36864 bytes
C:\RECYCLER\NPROTECT\00498211 40 bytes
C:\RECYCLER\NPROTECT\00498214.reg 8192 bytes
C:\RECYCLER\NPROTECT\00498215 256 bytes
C:\RECYCLER\NPROTECT\00498216 122880 bytes
C:\RECYCLER\NPROTECT\00498304 4096 bytes
C:\RECYCLER\NPROTECT\00498321.txt 464 bytes
C:\RECYCLER\NPROTECT\00498323.txt 88 bytes
C:\RECYCLER\NPROTECT\00498324.txt 88 bytes
C:\RECYCLER\NPROTECT\00498325.txt 96 bytes
C:\RECYCLER\NPROTECT\00498332.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498340.txt 88 bytes
C:\RECYCLER\NPROTECT\00498347.txt 88 bytes
C:\RECYCLER\NPROTECT\00498348.txt 96 bytes
C:\RECYCLER\NPROTECT\00498349.txt 88 bytes
C:\RECYCLER\NPROTECT\00498350.txt 88 bytes
C:\RECYCLER\NPROTECT\00498351.txt 96 bytes
C:\RECYCLER\NPROTECT\00498352.txt 96 bytes
C:\RECYCLER\NPROTECT\00498353.txt 88 bytes
C:\RECYCLER\NPROTECT\00498354.txt 96 bytes
C:\RECYCLER\NPROTECT\00498355.txt 96 bytes
C:\RECYCLER\NPROTECT\00498356.txt 80 bytes
C:\RECYCLER\NPROTECT\00498357.txt 88 bytes
C:\RECYCLER\NPROTECT\00498358.txt 88 bytes
C:\RECYCLER\NPROTECT\00498359.txt 96 bytes
C:\RECYCLER\NPROTECT\00498360.txt 104 bytes
C:\RECYCLER\NPROTECT\00498361.txt 96 bytes
C:\RECYCLER\NPROTECT\00498362.txt 96 bytes
C:\RECYCLER\NPROTECT\00498363.txt 96 bytes
C:\RECYCLER\NPROTECT\00498364.txt 96 bytes
C:\RECYCLER\NPROTECT\00498365.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498366.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498367.txt 88 bytes
C:\RECYCLER\NPROTECT\00498368.txt 96 bytes
C:\RECYCLER\NPROTECT\00498369.txt 248 bytes
C:\RECYCLER\NPROTECT\00498370.txt 96 bytes
C:\RECYCLER\NPROTECT\00498371.txt 296 bytes
C:\RECYCLER\NPROTECT\00498372.txt 248 bytes
C:\RECYCLER\NPROTECT\00498373.txt 384 bytes
C:\RECYCLER\NPROTECT\00498374.txt 160 bytes
C:\RECYCLER\NPROTECT\00498375.txt 136 bytes
C:\RECYCLER\NPROTECT\00498376.txt 72 bytes
C:\RECYCLER\NPROTECT\00498377.txt 136 bytes
C:\RECYCLER\NPROTECT\00498378.txt 72 bytes
C:\RECYCLER\NPROTECT\00498379.txt 336 bytes
C:\RECYCLER\NPROTECT\00498380.txt 160 bytes
C:\RECYCLER\NPROTECT\00498381.txt 272 bytes
C:\RECYCLER\NPROTECT\00498382.txt 264 bytes
C:\RECYCLER\NPROTECT\00498383.txt 96 bytes
C:\RECYCLER\NPROTECT\00498384.txt 88 bytes
C:\RECYCLER\NPROTECT\00498385.txt 96 bytes
C:\RECYCLER\NPROTECT\00498386.txt 88 bytes
C:\RECYCLER\NPROTECT\00498387.txt 184 bytes
C:\RECYCLER\NPROTECT\00498388.txt 176 bytes
C:\RECYCLER\NPROTECT\00498389.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498390.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498391.txt 224 bytes
C:\RECYCLER\NPROTECT\00498392.txt 176 bytes
C:\RECYCLER\NPROTECT\00498393.txt 224 bytes
C:\RECYCLER\NPROTECT\00498394.txt 176 bytes
C:\RECYCLER\NPROTECT\00498395.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498396 456 bytes
C:\RECYCLER\NPROTECT\00498397.log 232 bytes
C:\RECYCLER\NPROTECT\AlbumArtSmall.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{1B84FE9B-E830-4A0B-AF3F-C91D7BBA58EE}_Large.jpg 8192 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{1B84FE9B-E830-4A0B-AF3F-C91D7BBA58EE}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{551D8A92-EB1B-43AD-90E2-5547C3E78184}_Large.jpg 8192 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{551D8A92-EB1B-43AD-90E2-5547C3E78184}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{6FC7CBD6-2BBE-4056-B343-3EDDB2733BC7}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{6FC7CBD6-2BBE-4056-B343-3EDDB2733BC7}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{80DA5C02-8C10-445C-BB6B-CCE21CF00358}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{80DA5C02-8C10-445C-BB6B-CCE21CF00358}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D0AC7971-7B7D-4978-AE90-24116142D80C}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D0AC7971-7B7D-4978-AE90-24116142D80C}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D80A1D23-8651-401F-9CBD-B7836DEBE896}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D80A1D23-8651-401F-9CBD-B7836DEBE896}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\desktop.ini 344 bytes
C:\RECYCLER\NPROTECT\Folder.jpg 12288 bytes
C:\RECYCLER\NPROTECT\NPROTECT.LOG 647168 bytes

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1517

******************************************

Completion time: 07-02-12 9:10:02
---------------------------------------------------------
greyrocker is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-12-2007, 05:58 AM   #6 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:03:43 12/02/2007

+ Scan result:



C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP462\A0049286.dll -> Adware.Comet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0050060.EXE -> Adware.Comet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046951.exe/RemoveWebDP.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046951.exe/nfo.ocx -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046951.exe/nfom.dll -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046951.exe/nfomon.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046953.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP442\A0047711.ocx -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP442\A0047712.dll -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP442\A0047713.exe -> Adware.DelphinMediaViewer : Cleaned with backup (quarantined).
C:\Program Files\Aquatica Waterworlds\AQ3Helper.exe -> Adware.Gator : Cleaned with backup (quarantined).
C:\Program Files\Aquatica Waterworlds\AQ3Uninstaller.exe -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP422\A0046918.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP434\A0047405.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP442\A0047710.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP461\A0049271.dll -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP461\A0049272.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
HKLM\SOFTWARE\navexcel -> Adware.NavExcel : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP422\A0046906.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP446\A0047953.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP478\A0049632.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP478\A0049633.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046931.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046933.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00498173.exe -> Backdoor.Bifrose.qo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP446\A0047959.exe -> Backdoor.Bifrose.ztb : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00498210.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP422\A0046910.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP422\A0046911.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\Documents and Settings\Lee\Desktop\Programs\TvInternetSetup.exe -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP419\A0046358.exe -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP422\A0046905.exe -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP461\A0049268.EXE -> Downloader.PurityScan.dy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046952.EXE -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP461\A0049265.dll -> Downloader.Small.ece : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP461\A0049264.exe -> Dropper.DollarR.b : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP446\A0047952.dll -> Logger.Delf.mk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP457\A0048611.exe -> Not-A-Virus.PSWTool.Win32.Dialupass.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP457\A0048610.exe -> Not-A-Virus.PSWTool.Win32.MailPassView.130 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP457\A0048609.exe -> Not-A-Virus.PSWTool.Win32.Messen.106 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP441\A0047606.exe -> Trojan.Delf.wd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP457\A0048612.exe -> Trojan.IcqSmiley.e : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP430\A0047287.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00498215 -> Trojan.Qhosts : Cleaned with backup (quarantined).


::Report end

Panda Activescan

Incident Status Location

Potentially unwanted tool:application/myway Not disinfected c:\program files\MySearch
Adware:adware/navhelper Not disinfected c:\program files\NavExcel
Potentially unwanted tool:application/mywebsearch Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10}
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Lee\Cookies\lee@bs.serving-sys[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Lee\Cookies\lee@serving-sys[2].txt
Adware:Adware/SaveNow Not disinfected C:\MyEmoticons\My.Emo
Adware:Adware/SaveNow Not disinfected C:\MyEmoticons\uninstall.exe
Adware:Adware/IST.ISTBar Not disinfected C:\Program Files\Common Files\Totem Shared\Update\WindowsEx.dll.041
Adware:Adware/IST.ISTBar Not disinfected C:\Program Files\Common Files\Totem Shared\Update\WindowsEx.dll.043
Potentially unwanted tool:Application/MyWay Not disinfected C:\Program Files\MySearch\SrchAstt\1.bin\MYSRCHAS.DLL
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\RECYCLER\NPROTECT\00498437.exe
Logfile of HijackThis v1.99.1
Scan saved at 12:58:35, on 12/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\Program Files\ScrubXP\scrubxp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fantastic Flame Screensaver\FantasticFlameAgent.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
C:\Program Files\PikaOne Software\FlyCASE\PikaBackup.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [sc] C:\Program Files\ScrubXP\scrubxp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ServiceHost] "C:\Program Files\Java\jre1.5.0_06\bin\svchost.exe" ""
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Norton System Doctor.LNK = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
O4 - Startup: Pika Backup.lnk = C:\Program Files\PikaOne Software\FlyCASE\PikaBackup.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Fantastic Flame Agent.lnk = C:\Program Files\Fantastic Flame Screensaver\FantasticFlameAgent.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/tech...a/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1134934287140
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/amp...1.11_en_dl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
greyrocker is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-12-2007, 09:10 PM   #7 (permalink)
Mentor, Analyst - Security Team
 
Deckard's Avatar
 
Join Date: May 2006
Location: Oregon
Posts: 2,503
OS: MacOS X, Debian, OpenBSD, Windows


You're welcome! I like flattery -- it'll get you everywhere.

You've got a persistant bugger, so let's try fixing it again and if it still stays around, we'll bring out the big guns.

Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions. If there is anything you don't understand, please ask BEFORE proceeding with the fixes. Please do these steps in order and do not skip any.

Clean Quarantine
Please follow Symantec's guide to clean out your Norton quarantine directory.


Submit for Analysis
Please download the Suspicious File Packer from Safer-Networking.Org and unzip it to your Desktop. Double-click on SFP.exe to run it. Next, please copy the following red lines and paste them into the Step 1: Paste Text window:

C:\Program Files\Java\jre1.5.0_06\bin\svchost.exe

then click "Continue". This will create a .cab file on your Desktop named requested-files[Date/Time].cab.

Please submit it to this Malware Submission page. Please include your login so I know which submission is yours.


Reboot
Reboot your system to Safe Mode by repeatedly tapping the F8 key until the menu appears and choosing Safe Mode from the list. On some systems, this may be the F5 key so try that if F8 doesn't work. Login on with your usual account. Make sure to close any open windows.


HijackThis Fixes
Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they still exist (make sure you do not miss any):
O4 - HKLM\..\Run: [ServiceHost] "C:\Program Files\Java\jre1.5.0_06\bin\svchost.exe" ""
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
Please remember to close all other windows, including browsers then click Fix checked. Close HijackThis.


Deletions
Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.
C:\MyEmoticons
C:\Program Files\Common Files\Totem Shared
C:\Program Files\Java\jre1.5.0_06\bin\svchost.exe
C:\Program Files\MySearch
C:\Program Files\NavExcel

Reboot
Reboot your system to Normal Mode.


Online Scan
Perform an online scan using Internet Explorer with Kaspersky WebScanner. Click on Launch Kaspersky Anti-Virus Web Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded, click on NEXT.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database: extended
    • Scan Options: Scan Archives and Scan Mail Bases
  • Click OK
  • Turn off the real time scanner of any existing antivirus program before performing the online scan. You can turn it back on after the scan is done.
  • Now under select a target to scan, select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run all the way.
  • Once the scan is complete it will display if your system has been infected.
  • Click on the Save as Text button and save the file to your desktop.
  • Copy and paste that information in your next post.
Take note the names and locations of any file it detects but fails to clean.


Re-run ComboFix
Double click combofix.exe & follow the prompts. When the tool has finished, it will move the old log to C:\ComboFix2.txt and produce a new log in C:\ComboFix.txt. Please post only the new log.


With Your Next Post...
Please paste the following with your next reply (in this order please):
  1. Kaspersky scan report,
  2. The contents of C:\ComboFix.txt, and
  3. a new HiJackThis log taken after ComboFix finishes.
__________________
The chance to begin again in a golden land of opportunity and adventure.

Need HijackThis help? Please read MicroBell's Five Step Process before posting.
Please donate and help keep this site free to all.


UNITE/ASAP: Proud member since 2006
Deckard is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-13-2007, 03:01 PM   #8 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


(Part 1) -------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, February 13, 2007 10:20:30 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 13/02/2007
Kaspersky Anti-Virus database records: 267483
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 111416
Number of viruses found: 21
Number of infected objects: 335 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:20:17

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-11112006-125219.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-02-13_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\Lee\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Lee\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Temp\Perflib_Perfdata_450.dat Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Temp\Perflib_Perfdata_910.dat Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Temp\~DF4482.tmp Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Temp\~DF4511.tmp Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Lee\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lee\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Lee\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\294F2611.exe Infected: Trojan.Win32.Agent.qg skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP419\A0046359.exe/stream/data0009 Infected: Trojan-Downloader.Win32.Agent.bca skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP419\A0046359.exe/stream/data0010 Infected: Trojan-Downloader.Win32.Agent.bca skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP419\A0046359.exe/stream/data0011 Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP419\A0046359.exe/stream Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP419\A0046359.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046949.EXE/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP423\A0046949.EXE NSIS: infected - 1 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049672.exe Infected: Backdoor.Win32.Fuetel.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049673.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049673.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049673.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049673.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049673.exe CryptFF: infected - 3 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049674.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049674.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049674.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049674.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049674.exe CryptFF: infected - 3 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049675.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049675.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049675.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049675.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049675.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049675.exe CryptFF: infected - 4 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049676.exe/stream/data0002/stream/data0002 Infected: not-a-virus:AdWare.Win32.Maxifiles.ab skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049676.exe/stream/data0002/stream Infected: not-a-virus:AdWare.Win32.Maxifiles.ab skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049676.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Maxifiles.ab skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049676.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049676.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049676.exe NSIS: infected - 5 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049676.exe CryptFF: infected - 5 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049677.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049678.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049679.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049680.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049681.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049682.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049683.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049684.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049685.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049686.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049687.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049688.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049689.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049690.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049691.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049692.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049693.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049694.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049695.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049696.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049697.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049698.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049699.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049700.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049701.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049702.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049703.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049704.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049705.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049706.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049707.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049708.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049709.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049710.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049711.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049712.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049713.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049714.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049715.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049716.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049717.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049718.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049719.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049720.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049721.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049722.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049723.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049724.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049725.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049726.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049727.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049728.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049729.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049730.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049731.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049732.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049733.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049734.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049735.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049736.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049737.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049738.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049739.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049740.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049741.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049742.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049743.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049744.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049745.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049746.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049747.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049748.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049749.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049750.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049751.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049752.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049753.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049754.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049755.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049756.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049757.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049758.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049759.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049760.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049761.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049762.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049763.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049764.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049765.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049766.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049767.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049768.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049769.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049770.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049772.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.aa skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049773.exe Infected: not-a-virus:AdTool.Win32.WinAD.bv skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049774.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049775.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049776.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049777.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049778.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049779.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049780.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049781.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049782.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049783.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049784.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049785.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049786.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049787.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049788.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049789.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049790.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049791.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049792.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049793.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049794.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049795.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049796.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049797.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049798.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049799.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049800.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049801.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049802.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049803.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049804.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049805.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049806.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049807.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049808.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049809.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049810.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049811.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049812.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049813.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049814.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049815.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049816.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049817.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049818.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049819.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049820.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049821.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049822.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049823.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049824.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049825.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049826.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049827.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049828.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049829.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049830.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049831.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049832.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049833.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049834.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049835.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049836.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049837.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049838.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049839.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049840.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049841.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049842.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049843.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049844.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049845.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049846.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049847.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049848.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049849.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049850.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049851.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049852.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049853.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049854.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049855.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049856.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049857.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049858.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049859.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049860.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049861.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049862.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049863.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049864.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049865.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049866.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049867.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049868.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049869.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049870.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049871.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049872.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049873.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049874.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049875.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049876.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049877.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049878.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049879.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049880.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049881.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049882.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049883.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049884.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049885.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049886.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049887.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049888.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049889.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049890.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049891.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049892.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049893.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049894.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049895.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049896.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049897.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049898.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049899.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049900.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049901.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049902.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049903.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049904.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049905.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049906.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049907.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049908.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049909.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049910.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049911.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049912.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049913.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049914.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049915.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049916.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049917.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049918.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049919.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049920.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049921.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049922.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049923.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049924.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049925.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049926.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049927.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049928.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049929.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049930.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049931.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049932.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049933.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049934.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049935.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049936.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049937.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049938.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049939.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049940.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049941.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049942.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049943.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049944.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049945.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049946.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049947.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049948.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049949.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049950.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049951.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049952.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049953.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049954.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049955.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049956.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049957.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049958.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049959.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049960.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049961.exe Infected: Backdoor.Win32.Ciadoor.13 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049962.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.ad skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049963.ocx Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.c skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049964.dll Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.f skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049965.exe Infected: not-a-virus:AdWare.Win32.DelphinMediaViewer.f skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049966.exe Infected: Backdoor.Win32.Bifrose.adz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049967.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049969.exe Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP479\A0049970.exe Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP483\A0050134.DLL Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP483\A0050135.EXE Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050458.DLL Infected: not-a-virus:AdWare.Win32.MySearch.f skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050626.exe/stream/data0009 Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050626.exe/stream/data0010 Infected: Trojan-Downloader.Win32.Agent.bdr skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050626.exe/stream/data0011 Infected: Trojan-Downloader.Win32.Agent.bdr skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050626.exe/stream Infected: Trojan-Downloader.Win32.Agent.bdr skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050626.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050628.exe Infected: Trojan-Downloader.Win32.Agent.bca skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP485\A0050629.exe Infected: not-a-virus:AdWare.Win32.Gator.1008 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP488\A0051792.DLL Infected: not-a-virus:AdWare.Win32.MyWay.p skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP488\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{6864FA66-717E-48EA-A890-24BF59535546}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd9053.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
greyrocker is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-13-2007, 03:06 PM   #9 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


(Part2) "Lee" - 07-02-13 22:38:26 Service Pack 2
ComboFix 07-02-11 - Running from: "C:\Documents and Settings\Lee\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2007-01-13 to 2007-02-13 ))))))))))))))))))))))))))))))))))


2007-02-13 20:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-02-13 20:43 <DIR> d-------- C:\WINDOWS\LastGood
2007-02-12 11:12 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-02-12 09:18 <DIR> d-------- C:\bintheredunthat
2007-02-12 08:14 <DIR> d-------- C:\BFU
2007-02-11 21:56 <DIR> d-------- C:\ComboScan
2007-02-09 13:49 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-09 13:49 <DIR> d-------- C:\Program Files\Grisoft
2007-02-09 12:10 <DIR> d-------- C:\Program Files\HijackThis
2007-02-08 13:37 <DIR> d-------- C:\Program Files\FLVPlayer
2007-02-08 13:36 <DIR> d-------- C:\Downloads
2007-02-08 13:36 <DIR> d-------- C:\DOCUME~1\Lee\Application Data\GetRightToGo
2007-02-03 08:05 <DIR> d-------- C:\Program Files\ToniArts
2007-01-30 09:24 630,784 --a------ C:\WINDOWS\system32\vp7vfw.dll
2007-01-30 09:24 <DIR> d-------- C:\Program Files\On2 Technologies
2007-01-14 10:59 162,304 --a------ C:\UNWISE.EXE


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-13 19:32 -------- d-------- C:\DOCUME~1\Lee\Application Data\utorrent
2007-02-13 02:54 -------- d-------- C:\Program Files\norton internet security
2007-02-12 14:05 -------- d-------- C:\Program Files\java
2007-02-12 14:03 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-12 12:07 -------- d-------- C:\Program Files\windows defender
2007-02-12 12:06 -------- d-------- C:\Program Files\scrubxp
2007-02-12 12:06 -------- d-------- C:\Program Files\quicktime
2007-02-12 12:04 -------- d-------- C:\Program Files\messenger
2007-02-12 12:03 -------- d-------- C:\Program Files\itunes
2007-02-12 12:01 -------- d-------- C:\Program Files\google
2007-02-12 12:01 -------- d-------- C:\Program Files\fantastic flame screensaver
2007-02-12 12:01 -------- d-------- C:\Program Files\dell support
2007-02-12 09:10 51733 --a------ C:\WINDOWS\system32\plugin1.dat
2007-02-09 16:47 -------- d-------- C:\DOCUME~1\Lee\Application Data\dvdcss
2007-02-03 11:38 -------- d-------- C:\Program Files\guild wars
2007-02-03 08:05 -------- d--h----- C:\Program Files\installshield installation information
2007-01-24 20:54 -------- d-------- C:\Program Files\lexmarkx73
2007-01-15 12:36 -------- d-------- C:\DOCUME~1\Lee\Application Data\adobeum
2007-01-14 12:23 -------- d--h----- C:\Program Files\Common Files\uninstall information
2007-01-14 11:05 51733 --a------ C:\WINDOWS\system32\scarddlg.dat
2007-01-03 08:10 -------- d-------- C:\DOCUME~1\Lee\Application Data\adobe
2006-12-30 17:42 -------- d---s---- C:\DOCUME~1\Lee\Application Data\microsoft
2006-12-30 16:32 -------- d-------- C:\Program Files\bethesda softworks
2006-12-28 08:58 -------- d-------- C:\Program Files\aft software
2006-12-28 08:55 796672 --a------ C:\WINDOWS\gpinstall.exe
2006-12-27 14:45 -------- d-------- C:\Program Files\ricochet lost worlds recharged
2006-12-27 14:37 -------- d-------- C:\Program Files\galaxian
2006-12-26 22:33 -------- d-------- C:\Program Files\tvinternet
2006-12-26 09:45 -------- d-------- C:\Program Files\windows media connect 2
2006-12-26 09:24 -------- d-------- C:\Program Files\ipod
2006-12-26 09:22 -------- d-------- C:\Program Files\apple software update


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"P17Helper"="Rundll32 P17.dll,P17Helper"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"PC Booster"="C:\\Program Files\\inKline Global\\PC Booster\\pcbooster.exe"
"PrinTray"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\printray.exe"
"sc"="C:\\Program Files\\ScrubXP\\scrubxp.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"TrueImageMonitor.exe"="C:\\Program Files\\Acronis\\TrueImage\\TrueImageMonitor.exe"
"AcronisTimounterMonitor"="C:\\Program Files\\Acronis\\TrueImage\\TimounterMonitor.exe"
"Acronis Scheduler2 Service"="\"C:\\Program Files\\Common Files\\Acronis\\Schedule2\\schedhlp.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~3.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk"
"backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray"
"item"="ATI CATALYST System Tray"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Digital Line Detect.lnk"
"backup"="C:\\WINDOWS\\pss\\Digital Line Detect.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\DIGITA~1\\DLG.exe "
"item"="Digital Line Detect"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
"backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
"command"="C:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE "
"item"="InterVideo WinCinema Manager"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler V3.exeStartup"
"item"="PowerReg Scheduler V3"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"item"="PowerReg Scheduler"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^blueyonder Instant Support Tool.lnk]
"backup"="C:\\WINDOWS\\pss\\blueyonder Instant Support Tool.lnkCommon Startup"
"command"="C:\\PROGRA~1\\BLUEYO~1\\bin\\matcli.exe -boot"
"item"="blueyonder Instant Support Tool"
"location"="Common Startup"
"path"="C:\\DOCUME~1\\ALLUSE~1\\Start Menu\\Programs\\Startup\\blueyonder Instant Support Tool.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AQ3HelperStartUp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AQ3HEL~1"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\AQUATI~1\\AQ3HEL~1.EXE /partner AQ3"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTSysVol"
"hkey"="HKLM"
"command"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
"command"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="InCD"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"hkey"="HKLM"
"inimapping"="0"
"item"="iTunesHelper"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Manager]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACBTNM~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACBTNM~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Monitor]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACMONI~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACMONI~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBLKsk]
"hkey"="HKLM"
"inimapping"="0"
"item"="LXBLKsk"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAGIXautostart]
"command"="G:\\Content\\Software\\Full_Programs\\Music Maker Silver 2005\\mm2005_silver_upgrade_UK.EXE"
"hkey"="HKLM"
"inimapping"="0"
"item"="mm2005_silver_upgrade_UK"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McafWelcome]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcwelcom"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcagent"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcupdate"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
"command"="C:\\Program Files\\Lexmark\\Lexmark Photo Center\\MemoryCardManager.exe -startup"
"hkey"="HKLM"
"inimapping"="0"
"item"="MemoryCardManager"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSKDetct"
"hkey"="HKLM"
"command"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hkey"="HKCU"
"inimapping"="0"
"item"="msmsgs"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"hkey"="HKLM"
"inimapping"="0"
"item"="qttask"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"command"="soundman.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="soundman"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcvsshld"
"hkey"="HKLM"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearRecentDocsOnExit"=dword:00000000
"HideClock"=dword:00000000
"NoCDBurning"=dword:00000000
"NoClose"=dword:00000000
"NoCommonGroups"=dword:00000000
"NoFileAssociate"=dword:00000000
"NoFileMenu"=dword:00000000
"NoFind"=dword:00000000
"NoFolderOptions"=dword:00000000
"NoLowDiskSpaceChecks"=dword:00000001
"NoRecentDocsHistory"=dword:00000001
"NoRun"=dword:00000000
"NoShellSearchButton"=dword:00000000
"NoSimpleStartMenu"=dword:00000000
"NoSMHelp"=dword:00000000
"NoToolbarsOnTaskbar"=dword:00000000
"NoTrayContextMenu"=dword:00000000
"NoTrayItemsDisplay"=dword:00000000
"NoViewContextMenu"=dword:00000000
"NoWinKeys"=dword:00000000
"StartMenuLogoff"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
bthsvcs REG_MULTI_SZ BthServ\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\RECYCLER\NPROTECT
C:\RECYCLER\NPROTECT\00497939.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497940.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497941.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497942.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497943.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497944.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497945.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497946.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497947.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497948.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497949.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497950.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497951.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497952.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497953.rbf 288 bytes
C:\RECYCLER\NPROTECT\00497954.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497955.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497956.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497957.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497958.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497959.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497960.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497961.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497962.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497963.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497964.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497965.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497966.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497967.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497968.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497969.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497970.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497971.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497972.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497973.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497974.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00497975.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497976.rbf 2039808 bytes
C:\RECYCLER\NPROTECT\00497977.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497978.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497979.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497980.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497981.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497982.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497983.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497984.rbf 770048 bytes
C:\RECYCLER\NPROTECT\00497985.rbf 86016 bytes
C:\RECYCLER\NPROTECT\00497986.rbf 487424 bytes
C:\RECYCLER\NPROTECT\00497987.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497988.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497989.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497990.rbf 1003520 bytes
C:\RECYCLER\NPROTECT\00497991.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497992.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497993.rbf 33914880 bytes
C:\RECYCLER\NPROTECT\00497994.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497995.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497996.rbf 1343488 bytes
C:\RECYCLER\NPROTECT\00497997.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00497998.rbf 196608 bytes
C:\RECYCLER\NPROTECT\00497999.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498000.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00498001.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498002.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00498003.rbf 262144 bytes
C:\RECYCLER\NPROTECT\00498004.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498005.rbf 126976 bytes
C:\RECYCLER\NPROTECT\00498006.rbf 61440 bytes
C:\RECYCLER\NPROTECT\00498007.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00498008.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498009.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498010.rbf 122880 bytes
C:\RECYCLER\NPROTECT\00498011.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498012.rbf 49152 bytes
C:\RECYCLER\NPROTECT\00498013.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498014.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498015.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498016.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498017.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498018.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498019.rbf 204800 bytes
C:\RECYCLER\NPROTECT\00498020.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498021.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00498022.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498023.rbf 102400 bytes
C:\RECYCLER\NPROTECT\00498024.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00498025.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498026.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00498027.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00498028.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498029.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00498030.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498031.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498032.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498033.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498034.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498035.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498036.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00498037.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00498038.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498039.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498040.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498041.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498042.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498043.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498044.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498045.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498046.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498047.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498048.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498049.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498050.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498051.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498052.rbf 438272 bytes
C:\RECYCLER\NPROTECT\00498053.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498054.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00498055.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00498056.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498057.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498058.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498059.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00498060.rbf 12255232 bytes
C:\RECYCLER\NPROTECT\00498061.rbf 1617920 bytes
C:\RECYCLER\NPROTECT\00498062.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498063.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498064.rbf 632 bytes
C:\RECYCLER\NPROTECT\00498065.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498066.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00498067.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498068.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498069.rbf 168 bytes
C:\RECYCLER\NPROTECT\00498070.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498071.rbf 168 bytes
C:\RECYCLER\NPROTECT\00498072.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498073.rbf 152 bytes
C:\RECYCLER\NPROTECT\00498074.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498075.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498076.rbf 159744 bytes
C:\RECYCLER\NPROTECT\00498077.rbf 176128 bytes
C:\RECYCLER\NPROTECT\00498078.rbf 700416 bytes
C:\RECYCLER\NPROTECT\00498079.rbf 672 bytes
C:\RECYCLER\NPROTECT\00498080.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498081.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498082.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498083.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498084.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498085.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498086.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00498087.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498088.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498089.rbf 136 bytes
C:\RECYCLER\NPROTECT\00498090.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498091.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498092.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498093.rbf 4493312 bytes
C:\RECYCLER\NPROTECT\00498094.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498095.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498096.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498097.rbs 122880 bytes
C:\RECYCLER\NPROTECT\00498098.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00498099.msi 188416 bytes
C:\RECYCLER\NPROTECT\00498100.MST 147456 bytes
C:\RECYCLER\NPROTECT\00498101.mst 147456 bytes
C:\RECYCLER\NPROTECT\00498106 224 bytes
C:\RECYCLER\NPROTECT\00498109 216 bytes
C:\RECYCLER\NPROTECT\00498132.SYS 8192 bytes
C:\RECYCLER\NPROTECT\00498144 696 bytes
C:\RECYCLER\NPROTECT\00498145.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498160 64 bytes
C:\RECYCLER\NPROTECT\00498165.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498166.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498167.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498168.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498174.EXE 4096 bytes
C:\RECYCLER\NPROTECT\00498175.LZM 4096 bytes
C:\RECYCLER\NPROTECT\00498176.LOG 4096 bytes
C:\RECYCLER\NPROTECT\00498177.exe 61440 bytes
C:\RECYCLER\NPROTECT\00498178 232 bytes
C:\RECYCLER\NPROTECT\00498179 80 bytes
C:\RECYCLER\NPROTECT\00498180.txt 57344 bytes
C:\RECYCLER\NPROTECT\00498181.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498182 16 bytes
C:\RECYCLER\NPROTECT\00498183.txt 296 bytes
C:\RECYCLER\NPROTECT\00498184.txt 152 bytes
C:\RECYCLER\NPROTECT\00498186.txt 104 bytes
C:\RECYCLER\NPROTECT\00498188.txt 104 bytes
C:\RECYCLER\NPROTECT\00498191.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498197.job 440 bytes
C:\RECYCLER\NPROTECT\00498198.txt 40 bytes
C:\RECYCLER\NPROTECT\00498211 40 bytes
C:\RECYCLER\NPROTECT\00498214.reg 8192 bytes
C:\RECYCLER\NPROTECT\00498216 122880 bytes
C:\RECYCLER\NPROTECT\00498304 4096 bytes
C:\RECYCLER\NPROTECT\00498321.txt 464 bytes
C:\RECYCLER\NPROTECT\00498323.txt 88 bytes
C:\RECYCLER\NPROTECT\00498324.txt 88 bytes
C:\RECYCLER\NPROTECT\00498325.txt 96 bytes
C:\RECYCLER\NPROTECT\00498332.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498340.txt 88 bytes
C:\RECYCLER\NPROTECT\00498347.txt 88 bytes
C:\RECYCLER\NPROTECT\00498348.txt 96 bytes
C:\RECYCLER\NPROTECT\00498349.txt 88 bytes
C:\RECYCLER\NPROTECT\00498350.txt 88 bytes
C:\RECYCLER\NPROTECT\00498351.txt 96 bytes
C:\RECYCLER\NPROTECT\00498352.txt 96 bytes
C:\RECYCLER\NPROTECT\00498353.txt 88 bytes
C:\RECYCLER\NPROTECT\00498354.txt 96 bytes
C:\RECYCLER\NPROTECT\00498355.txt 96 bytes
C:\RECYCLER\NPROTECT\00498356.txt 80 bytes
C:\RECYCLER\NPROTECT\00498357.txt 88 bytes
C:\RECYCLER\NPROTECT\00498358.txt 88 bytes
C:\RECYCLER\NPROTECT\00498359.txt 96 bytes
C:\RECYCLER\NPROTECT\00498360.txt 104 bytes
C:\RECYCLER\NPROTECT\00498361.txt 96 bytes
C:\RECYCLER\NPROTECT\00498362.txt 96 bytes
C:\RECYCLER\NPROTECT\00498363.txt 96 bytes
C:\RECYCLER\NPROTECT\00498364.txt 96 bytes
C:\RECYCLER\NPROTECT\00498365.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498366.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498367.txt 88 bytes
C:\RECYCLER\NPROTECT\00498368.txt 96 bytes
C:\RECYCLER\NPROTECT\00498369.txt 248 bytes
C:\RECYCLER\NPROTECT\00498370.txt 96 bytes
C:\RECYCLER\NPROTECT\00498371.txt 296 bytes
C:\RECYCLER\NPROTECT\00498372.txt 248 bytes
C:\RECYCLER\NPROTECT\00498373.txt 384 bytes
C:\RECYCLER\NPROTECT\00498374.txt 160 bytes
C:\RECYCLER\NPROTECT\00498375.txt 136 bytes
C:\RECYCLER\NPROTECT\00498376.txt 72 bytes
C:\RECYCLER\NPROTECT\00498377.txt 136 bytes
C:\RECYCLER\NPROTECT\00498378.txt 72 bytes
C:\RECYCLER\NPROTECT\00498379.txt 336 bytes
C:\RECYCLER\NPROTECT\00498380.txt 160 bytes
C:\RECYCLER\NPROTECT\00498381.txt 272 bytes
C:\RECYCLER\NPROTECT\00498382.txt 264 bytes
C:\RECYCLER\NPROTECT\00498383.txt 96 bytes
C:\RECYCLER\NPROTECT\00498384.txt 88 bytes
C:\RECYCLER\NPROTECT\00498385.txt 96 bytes
C:\RECYCLER\NPROTECT\00498386.txt 88 bytes
C:\RECYCLER\NPROTECT\00498387.txt 184 bytes
C:\RECYCLER\NPROTECT\00498388.txt 176 bytes
C:\RECYCLER\NPROTECT\00498389.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498390.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498391.txt 224 bytes
C:\RECYCLER\NPROTECT\00498392.txt 176 bytes
C:\RECYCLER\NPROTECT\00498393.txt 224 bytes
C:\RECYCLER\NPROTECT\00498394.txt 176 bytes
C:\RECYCLER\NPROTECT\00498395.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498396 456 bytes
C:\RECYCLER\NPROTECT\00498397.log 232 bytes
C:\RECYCLER\NPROTECT\00498398.log 73728 bytes
C:\RECYCLER\NPROTECT\00498399.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498401.JOB 336 bytes
C:\RECYCLER\NPROTECT\00498402.ini 72 bytes
C:\RECYCLER\NPROTECT\00498403.ini 72 bytes
C:\RECYCLER\NPROTECT\00498404.dat 32768 bytes
C:\RECYCLER\NPROTECT\00498405.ini 72 bytes
C:\RECYCLER\NPROTECT\00498406.ini 72 bytes
C:\RECYCLER\NPROTECT\00498407.ini 72 bytes
C:\RECYCLER\NPROTECT\00498408.ini 72 bytes
C:\RECYCLER\NPROTECT\00498409 4096 bytes
C:\RECYCLER\NPROTECT\00498410 4096 bytes
C:\RECYCLER\NPROTECT\00498411.TXT 352 bytes
C:\RECYCLER\NPROTECT\00498412 4096 bytes
C:\RECYCLER\NPROTECT\00498413.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00498414.TXT 224 bytes
C:\RECYCLER\NPROTECT\00498415.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498416.BAT 69632 bytes
C:\RECYCLER\NPROTECT\00498417 4096 bytes
C:\RECYCLER\NPROTECT\00498418 4096 bytes
C:\RECYCLER\NPROTECT\00498419.log 416 bytes
C:\RECYCLER\NPROTECT\00498420 312 bytes
C:\RECYCLER\NPROTECT\00498421.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498422 104 bytes
C:\RECYCLER\NPROTECT\00498423.VBS 352 bytes
C:\RECYCLER\NPROTECT\00498424.txt 104 bytes
C:\RECYCLER\NPROTECT\00498425.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498426.txt 512 bytes
C:\RECYCLER\NPROTECT\00498427 48 bytes
C:\RECYCLER\NPROTECT\00498428.com 147456 bytes
C:\RECYCLER\NPROTECT\00498429.reg 4096 bytes
C:\RECYCLER\NPROTECT\00498430.exe 28672 bytes
C:\RECYCLER\NPROTECT\00498431.reg 212992 bytes
C:\RECYCLER\NPROTECT\00498432.E_E 163840 bytes
C:\RECYCLER\NPROTECT\00498433.exe 184320 bytes
C:\RECYCLER\NPROTECT\00498434.bat 102400 bytes
C:\RECYCLER\NPROTECT\00498435.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498436.exe 40960 bytes
C:\RECYCLER\NPROTECT\00498437.exe 28672 bytes
C:\RECYCLER\NPROTECT\00498438.exe 45056 bytes
C:\RECYCLER\NPROTECT\00498439.exe 40960 bytes
C:\RECYCLER\NPROTECT\00498440.bat 8192 bytes
C:\RECYCLER\NPROTECT\00498441.EXE 8192 bytes
C:\RECYCLER\NPROTECT\00498442.exe 143360 bytes
C:\RECYCLER\NPROTECT\00498443.exe 126976 bytes
C:\RECYCLER\NPROTECT\00498444.exe 81920 bytes
C:\RECYCLER\NPROTECT\00498445.exe 49152 bytes
C:\RECYCLER\NPROTECT\00498446 8192 bytes
C:\RECYCLER\NPROTECT\00498447 312 bytes
C:\RECYCLER\NPROTECT\00498448.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00498449.REG 4096 bytes
C:\RECYCLER\NPROTECT\00498450.bat 664 bytes
C:\RECYCLER\NPROTECT\00498453.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498454.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498455.dat 196608 bytes
C:\RECYCLER\NPROTECT\00498456.dat 49152 bytes
C:\RECYCLER\NPROTECT\00498476.dat 16384 bytes
C:\RECYCLER\NPROTECT\00498477.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498478.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498479.dat 16384 bytes
C:\RECYCLER\NPROTECT\00498488.cab 16384 bytes
C:\RECYCLER\NPROTECT\00498496.cab 16384 bytes
C:\RECYCLER\NPROTECT\00498507.JOB 336 bytes
C:\RECYCLER\NPROTECT\00498515.edb 1056768 bytes
C:\RECYCLER\NPROTECT\00498519.edb 65536 bytes
C:\RECYCLER\NPROTECT\00498631.XML 56 bytes
C:\RECYCLER\NPROTECT\00498640.PAC 9031680 bytes
C:\RECYCLER\NPROTECT\00498641.PAC 122880 bytes
C:\RECYCLER\NPROTECT\00498644.PAC 294912 bytes
C:\RECYCLER\NPROTECT\00498647.PAC 176128 bytes
C:\RECYCLER\NPROTECT\00498650.PAC 688128 bytes
C:\RECYCLER\NPROTECT\00498653.dll 1331200 bytes
C:\RECYCLER\NPROTECT\00498654.dll 98304 bytes
C:\RECYCLER\NPROTECT\00498655.dll 196608 bytes
C:\RECYCLER\NPROTECT\00498656.dll 147456 bytes
C:\RECYCLER\NPROTECT\00498657.dll 69632 bytes
C:\RECYCLER\NPROTECT\00498658.jar 1896448 bytes
C:\RECYCLER\NPROTECT\00498659.jar 8192 bytes
C:\RECYCLER\NPROTECT\00498660.dll 36864 bytes
C:\RECYCLER\NPROTECT\00498661.DLL 32768 bytes
C:\RECYCLER\NPROTECT\00498662.DLL 253952 bytes
C:\RECYCLER\NPROTECT\00498663.dll 36864 bytes
C:\RECYCLER\NPROTECT\00498664.dll 122880 bytes
C:\RECYCLER\NPROTECT\00498665.jar 12288 bytes
C:\RECYCLER\NPROTECT\00498666.DLL 61440 bytes
C:\RECYCLER\NPROTECT\00498667.dll 32768 bytes
C:\RECYCLER\NPROTECT\00498668.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498669.dll 28672 bytes
C:\RECYCLER\NPROTECT\00498670.dll 122880 bytes
C:\RECYCLER\NPROTECT\00498671.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498672.DLL 32768 bytes
C:\RECYCLER\NPROTECT\00498673.exe 49152 bytes
C:\RECYCLER\NPROTECT\00498674.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498675.DLL 139264 bytes
C:\RECYCLER\NPROTECT\00498676.exe 131072 bytes
C:\RECYCLER\NPROTECT\00498677.jar 757760 bytes
C:\RECYCLER\NPROTECT\00498678.dll 28672 bytes
C:\RECYCLER\NPROTECT\00498679.jar 81920 bytes
C:\RECYCLER\NPROTECT\00498680.dll 57344 bytes
C:\RECYCLER\NPROTECT\00498681.dll 204800 bytes
C:\RECYCLER\NPROTECT\00498682.dll 131072 bytes
C:\RECYCLER\NPROTECT\00498683.dll 86016 bytes
C:\RECYCLER\NPROTECT\00498684.cpl 53248 bytes
C:\RECYCLER\NPROTECT\00498685.dll 98304 bytes
C:\RECYCLER\NPROTECT\00498686.dll 90112 bytes
C:\RECYCLER\NPROTECT\00498687.dll 53248 bytes
C:\RECYCLER\NPROTECT\00498688.dll 81920 bytes
C:\RECYCLER\NPROTECT\00498689.dll 151552 bytes
C:\RECYCLER\NPROTECT\00498690.dll 32768 bytes
C:\RECYCLER\NPROTECT\00498691.jar 495616 bytes
C:\RECYCLER\NPROTECT\00498692.exe 245760 bytes
C:\RECYCLER\NPROTECT\00498693.exe 40960 bytes
C:\RECYCLER\NPROTECT\00498694.dll 1527808 bytes
C:\RECYCLER\NPROTECT\00498695.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498696.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498697.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498698.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498699.JAR 4096 bytes
C:\RECYCLER\NPROTECT\00498700.DLL 36864 bytes
C:\RECYCLER\NPROTECT\00498701.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498702.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498703.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498704.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498705.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498706.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498707.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498708.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498709.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498710.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498711.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498712.dll 81920 bytes
C:\RECYCLER\NPROTECT\00498713.dll 40960 bytes
C:\RECYCLER\NPROTECT\00498714.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498715.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498716.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498717.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498718.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498719.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498720.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498721.exe 57344 bytes
C:\RECYCLER\NPROTECT\00498722.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498723.jar 999424 bytes
C:\RECYCLER\NPROTECT\00498724.EXE 53248 bytes
C:\RECYCLER\NPROTECT\00498725.txt 12288 bytes
C:\RECYCLER\NPROTECT\00498726.dll 28672 bytes
C:\RECYCLER\NPROTECT\00498727.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498728.EXE 53248 bytes
C:\RECYCLER\NPROTECT\00498729.jar 33566720 bytes
C:\RECYCLER\NPROTECT\00498730.EXE 53248 bytes
C:\RECYCLER\NPROTECT\00498731.JAR 155648 bytes
C:\RECYCLER\NPROTECT\00498732.JAR 176128 bytes
C:\RECYCLER\NPROTECT\00498733.jar 8192 bytes
C:\RECYCLER\NPROTECT\00498734.TXT 53248 bytes
C:\RECYCLER\NPROTECT\00498735.EXE 57344 bytes
C:\RECYCLER\NPROTECT\00498736.dll 65536 bytes
C:\RECYCLER\NPROTECT\00498737.EXE 131072 bytes
C:\RECYCLER\NPROTECT\00498738.JAR 4096 bytes
C:\RECYCLER\NPROTECT\00498739.dll 53248 bytes
C:\RECYCLER\NPROTECT\00498740.DLL 28672 bytes
C:\RECYCLER\NPROTECT\00498741.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00498742.dll 65536 bytes
C:\RECYCLER\NPROTECT\00498743 4096 bytes
C:\RECYCLER\NPROTECT\00498744 4096 bytes
C:\RECYCLER\NPROTECT\00498745 4096 bytes
C:\RECYCLER\NPROTECT\00498746 4096 bytes
C:\RECYCLER\NPROTECT\00498747 4096 bytes
C:\RECYCLER\NPROTECT\00498748 4096 bytes
C:\RECYCLER\NPROTECT\00498749 4096 bytes
C:\RECYCLER\NPROTECT\00498750 4096 bytes
C:\RECYCLER\NPROTECT\00498751 4096 bytes
C:\RECYCLER\NPROTECT\00498752 4096 bytes
C:\RECYCLER\NPROTECT\00498753 4096 bytes
C:\RECYCLER\NPROTECT\00498754 4096 bytes
C:\RECYCLER\NPROTECT\00498755 96 bytes
C:\RECYCLER\NPROTECT\00498756 4096 bytes
C:\RECYCLER\NPROTECT\00498757 4096 bytes
C:\RECYCLER\NPROTECT\00498758 520 bytes
C:\RECYCLER\NPROTECT\00498759 28672 bytes
C:\RECYCLER\NPROTECT\00498760 4096 bytes
C:\RECYCLER\NPROTECT\00498761 4096 bytes
C:\RECYCLER\NPROTECT\00498762 4096 bytes
C:\RECYCLER\NPROTECT\00498763 520 bytes
C:\RECYCLER\NPROTECT\00498764 4096 bytes
C:\RECYCLER\NPROTECT\00498765 72 bytes
C:\RECYCLER\NPROTECT\00498766 4096 bytes
C:\RECYCLER\NPROTECT\00498767 4096 bytes
C:\RECYCLER\NPROTECT\00498768 368 bytes
C:\RECYCLER\NPROTECT\00498769 128 bytes
C:\RECYCLER\NPROTECT\00498770 520 bytes
C:\RECYCLER\NPROTECT\00498771 544 bytes
C:\RECYCLER\NPROTECT\00498772 4096 bytes
C:\RECYCLER\NPROTECT\00498773 4096 bytes
C:\RECYCLER\NPROTECT\00498774 4096 bytes
C:\RECYCLER\NPROTECT\00498775 4096 bytes
C:\RECYCLER\NPROTECT\00498776 4096 bytes
C:\RECYCLER\NPROTECT\00498777 4096 bytes
C:\RECYCLER\NPROTECT\00498778 4096 bytes
C:\RECYCLER\NPROTECT\00498779 4096 bytes
C:\RECYCLER\NPROTECT\00498780 4096 bytes
C:\RECYCLER\NPROTECT\00498781 128 bytes
C:\RECYCLER\NPROTECT\00498782 4096 bytes
C:\RECYCLER\NPROTECT\00498783 4096 bytes
C:\RECYCLER\NPROTECT\00498784 4096 bytes
C:\RECYCLER\NPROTECT\00498785 360 bytes
C:\RECYCLER\NPROTECT\00498786 336 bytes
C:\RECYCLER\NPROTECT\00498787 4096 bytes
C:\RECYCLER\NPROTECT\00498788 4096 bytes
C:\RECYCLER\NPROTECT\00498789 4096 bytes
C:\RECYCLER\NPROTECT\00498790 520 bytes
C:\RECYCLER\NPROTECT\00498791 4096 bytes
C:\RECYCLER\NPROTECT\00498792 4096 bytes
C:\RECYCLER\NPROTECT\00498793 128 bytes
C:\RECYCLER\NPROTECT\00498794 224 bytes
C:\RECYCLER\NPROTECT\00498795 12288 bytes
C:\RECYCLER\NPROTECT\00498796 176 bytes
C:\RECYCLER\NPROTECT\00498797 4096 bytes
C:\RECYCLER\NPROTECT\00498798 4096 bytes
C:\RECYCLER\NPROTECT\00498799 4096 bytes
C:\RECYCLER\NPROTECT\00498800 160 bytes
C:\RECYCLER\NPROTECT\00498801 368 bytes
C:\RECYCLER\NPROTECT\00498802 4096 bytes
C:\RECYCLER\NPROTECT\00498803 520 bytes
C:\RECYCLER\NPROTECT\00498804 4096 bytes
C:\RECYCLER\NPROTECT\00498805 4096 bytes
C:\RECYCLER\NPROTECT\00498806 584 bytes
C:\RECYCLER\NPROTECT\00498807 4096 bytes
C:\RECYCLER\NPROTECT\00498808 4096 bytes
C:\RECYCLER\NPROTECT\00498809 4096 bytes
C:\RECYCLER\NPROTECT\00498810 4096 bytes
C:\RECYCLER\NPROTECT\00498811 4096 bytes
C:\RECYCLER\NPROTECT\00498812 336 bytes
C:\RECYCLER\NPROTECT\00498813 4096 bytes
C:\RECYCLER\NPROTECT\00498814 4096 bytes
C:\RECYCLER\NPROTECT\00498815 4096 bytes
C:\RECYCLER\NPROTECT\00498816 160 bytes
C:\RECYCLER\NPROTECT\00498817 320 bytes
C:\RECYCLER\NPROTECT\00498818 4096 bytes
C:\RECYCLER\NPROTECT\00498819 4096 bytes
C:\RECYCLER\NPROTECT\00498820 4096 bytes
C:\RECYCLER\NPROTECT\00498821 8192 bytes
C:\RECYCLER\NPROTECT\00498822 8192 bytes
C:\RECYCLER\NPROTECT\00498823 8192 bytes
C:\RECYCLER\NPROTECT\00498824 288 bytes
C:\RECYCLER\NPROTECT\00498825 4096 bytes
C:\RECYCLER\NPROTECT\00498826 4096 bytes
C:\RECYCLER\NPROTECT\00498827 4096 bytes
C:\RECYCLER\NPROTECT\00498828 128 bytes
C:\RECYCLER\NPROTECT\00498829 4096 bytes
C:\RECYCLER\NPROTECT\00498830 4096 bytes
C:\RECYCLER\NPROTECT\00498831 280 bytes
C:\RECYCLER\NPROTECT\00498832 4096 bytes
C:\RECYCLER\NPROTECT\00498833 112 bytes
C:\RECYCLER\NPROTECT\00498834 4096 bytes
C:\RECYCLER\NPROTECT\00498835 4096 bytes
C:\RECYCLER\NPROTECT\00498836 4096 bytes
C:\RECYCLER\NPROTECT\00498837 72 bytes
C:\RECYCLER\NPROTECT\00498838 32 bytes
C:\RECYCLER\NPROTECT\00498839 4096 bytes
C:\RECYCLER\NPROTECT\00498840 272 bytes
C:\RECYCLER\NPROTECT\00498841 8192 bytes
C:\RECYCLER\NPROTECT\00498842 360 bytes
C:\RECYCLER\NPROTECT\00498843 4096 bytes
C:\RECYCLER\NPROTECT\00498844 192 bytes
C:\RECYCLER\NPROTECT\00498845 4096 bytes
C:\RECYCLER\NPROTECT\00498846 4096 bytes
C:\RECYCLER\NPROTECT\00498847 4096 bytes
C:\RECYCLER\NPROTECT\00498848 4096 bytes
C:\RECYCLER\NPROTECT\00498849 80 bytes
C:\RECYCLER\NPROTECT\00498850 4096 bytes
C:\RECYCLER\NPROTECT\00498851 16384 bytes
C:\RECYCLER\NPROTECT\00498852.RTP 4640768 bytes
C:\RECYCLER\NPROTECT\00498853.DLL 208896 bytes
C:\RECYCLER\NPROTECT\00498855.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498856.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498857.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498858.rbs 16384 bytes
C:\RECYCLER\NPROTECT\00498859.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00498862.cpl 53248 bytes
C:\RECYCLER\NPROTECT\00498863.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498864.exe 57344 bytes
C:\RECYCLER\NPROTECT\00498865.exe 131072 bytes
C:\RECYCLER\NPROTECT\00498866.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498867.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498868.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498869.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498870.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498871.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498872.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498873.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498874.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498875.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498876.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498877.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498878.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498879.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498880.rbf 184 bytes
C:\RECYCLER\NPROTECT\00498881.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498882.rbf 336 bytes
C:\RECYCLER\NPROTECT\00498883.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498884.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498885.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498886.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498887.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498888.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498889.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498890.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498891.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498892.rbf 216 bytes
C:\RECYCLER\NPROTECT\00498893.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498894.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498895.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498896.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498897.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498898.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498899.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498900.rbf 320 bytes
C:\RECYCLER\NPROTECT\00498901.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498902.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498903.rbf 112 bytes
C:\RECYCLER\NPROTECT\00498904.rbf 104 bytes
C:\RECYCLER\NPROTECT\00498905.rbf 344 bytes
C:\RECYCLER\NPROTECT\00498906.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498907.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498908.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498909.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498910.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498911.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498912.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498913.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498914.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498915.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498916.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498917.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498918.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498919.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498920.rbf 104 bytes
C:\RECYCLER\NPROTECT\00498921.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498922.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498923.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498924.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498925.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498926.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498927.rbf 296 bytes
C:\RECYCLER\NPROTECT\00498928.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498929.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498930.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498931.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498932.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498933.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498934.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498935.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498936.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498937.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498938.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498939.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498940.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498941.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498942.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498943.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498944.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498945.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498946.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498947.rbf 464 bytes
C:\RECYCLER\NPROTECT\00498948.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498949.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498950.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498951.rbf 544 bytes
C:\RECYCLER\NPROTECT\00498952.rbf 144 bytes
C:\RECYCLER\NPROTECT\00498953.rbf 304 bytes
C:\RECYCLER\NPROTECT\00498954.rbf 520 bytes
C:\RECYCLER\NPROTECT\00498955.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498956.rbf 336 bytes
C:\RECYCLER\NPROTECT\00498957.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498958.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498959.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498960.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498961.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498962.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498963.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498964.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498965.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498966.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498967.rbf 144 bytes
C:\RECYCLER\NPROTECT\00498968.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498969.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498970.rbf 344 bytes
C:\RECYCLER\NPROTECT\00498971.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498972.rbf 512 bytes
C:\RECYCLER\NPROTECT\00498973.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498974.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498975.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498976.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498977.rbf 320 bytes
C:\RECYCLER\NPROTECT\00498978.rbf 112 bytes
C:\RECYCLER\NPROTECT\00498979.rbf 384 bytes
C:\RECYCLER\NPROTECT\00498980.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498981.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498982.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498983.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498984.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498985.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498986.rbf 144 bytes
C:\RECYCLER\NPROTECT\00498987.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498988.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498989.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498990.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498991.rbf 192 bytes
C:\RECYCLER\NPROTECT\00498992.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498993.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498994.rbf 240 bytes
C:\RECYCLER\NPROTECT\00498995.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498996.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498997.rbf 192 bytes
C:\RECYCLER\NPROTECT\00498998.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498999.rbf 400 bytes
C:\RECYCLER\NPROTECT\00499000.rbf 192 bytes
C:\RECYCLER\NPROTECT\00499001.rbf 320 bytes
C:\RECYCLER\NPROTECT\00499002.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499003.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499004.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499005.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499006.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499007.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499008.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499009.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499010.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499011.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499012.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499013.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499014.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499015.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499016.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499017.rbf 384 bytes
C:\RECYCLER\NPROTECT\00499018.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499019.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499020.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499021.rbf 144 bytes
C:\RECYCLER\NPROTECT\00499022.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499023.rbf 304 bytes
C:\RECYCLER\NPROTECT\00499024.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499025.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499026.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499027.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499028.rbf 384 bytes
C:\RECYCLER\NPROTECT\00499029.rbf 488 bytes
C:\RECYCLER\NPROTECT\00499030.rbf 304 bytes
C:\RECYCLER\NPROTECT\00499031.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499032.rbf 208 bytes
C:\RECYCLER\NPROTECT\00499033.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499034.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499035.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499036.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499037.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499038.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499039.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499040.rbf 248 bytes
C:\RECYCLER\NPROTECT\00499041.rbf 176 bytes
C:\RECYCLER\NPROTECT\00499042.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499043.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499044.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499045.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499046.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499047.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499048.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499049.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499050.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499051.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499052.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499053.rbf 88 bytes
C:\RECYCLER\NPROTECT\00499054.rbf 88 bytes
C:\RECYCLER\NPROTECT\00499055.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499056.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499057.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499058.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499059.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499060.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499061.rbf 520 bytes
C:\RECYCLER\NPROTECT\00499062.rbf 536 bytes
C:\RECYCLER\NPROTECT\00499063.rbf 520 bytes
C:\RECYCLER\NPROTECT\00499064.rbf 520 bytes
C:\RECYCLER\NPROTECT\00499065.rbf 544 bytes
C:\RECYCLER\NPROTECT\00499066.rbf 536 bytes
C:\RECYCLER\NPROTECT\00499067.rbf 536 bytes
C:\RECYCLER\NPROTECT\00499068.rbf 544 bytes
C:\RECYCLER\NPROTECT\00499069.rbf 536 bytes
C:\RECYCLER\NPROTECT\00499070.rbf 536 bytes
C:\RECYCLER\NPROTECT\00499071.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499072.rbf 456 bytes
C:\RECYCLER\NPROTECT\00499073.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499074.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499075.rbf 456 bytes
C:\RECYCLER\NPROTECT\00499076.rbf 456 bytes
C:\RECYCLER\NPROTECT\00499077.rbf 272 bytes
C:\RECYCLER\NPROTECT\00499078.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499079.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499080.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499081.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499082.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499083.rbf 488 bytes
C:\RECYCLER\NPROTECT\00499084.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499085.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499086.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499087.rbf 184 bytes
C:\RECYCLER\NPROTECT\00499088.rbf 136 bytes
C:\RECYCLER\NPROTECT\00499089.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499090.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499091.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499092.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499093.rbf 264 bytes
C:\RECYCLER\NPROTECT\00499094.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499095.rbf 208 bytes
C:\RECYCLER\NPROTECT\00499096.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499097.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499098.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499099.rbf 136 bytes
C:\RECYCLER\NPROTECT\00499100.rbf 88 bytes
C:\RECYCLER\NPROTECT\00499101.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499102.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499103.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499104.rbf 128 bytes
C:\RECYCLER\NPROTECT\00499105.rbf 200 bytes
C:\RECYCLER\NPROTECT\00499106.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499107.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499108.rbf 152 bytes
C:\RECYCLER\NPROTECT\00499109.rbf 224 bytes
C:\RECYCLER\NPROTECT\00499110.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499111.rbf 400 bytes
C:\RECYCLER\NPROTECT\00499112.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499113.rbf 88 bytes
C:\RECYCLER\NPROTECT\00499114.rbf 128 bytes
C:\RECYCLER\NPROTECT\00499115.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499116.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499117.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499118.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499119.rbf 464 bytes
C:\RECYCLER\NPROTECT\00499120.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499121.rbf 128 bytes
C:\RECYCLER\NPROTECT\00499122.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499123.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499124.rbf 472 bytes
C:\RECYCLER\NPROTECT\00499125.rbf 88 bytes
C:\RECYCLER\NPROTECT\00499126.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499127.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499128.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499129.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499130.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499131.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499132.rbf 264 bytes
C:\RECYCLER\NPROTECT\00499133.rbf 168 bytes
C:\RECYCLER\NPROTECT\00499134.rbf 208 bytes
C:\RECYCLER\NPROTECT\00499135.rbf 136 bytes
C:\RECYCLER\NPROTECT\00499136.rbf 384 bytes
C:\RECYCLER\NPROTECT\00499137.rbf 264 bytes
C:\RECYCLER\NPROTECT\00499138.rbf 472 bytes
C:\RECYCLER\NPROTECT\00499139.rbf 392 bytes
C:\RECYCLER\NPROTECT\00499140.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499141.rbf 128 bytes
C:\RECYCLER\NPROTECT\00499142.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499143.rbf 184 bytes
C:\RECYCLER\NPROTECT\00499144.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499145.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499146.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499147.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499148.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499149.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499150.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499151.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499152.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499153.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499154.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499155.rbf 584 bytes
C:\RECYCLER\NPROTECT\00499156.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499157.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499158.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499159.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499160.rbf 192 bytes
C:\RECYCLER\NPROTECT\00499161.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499162.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499163.rbf 128 bytes
C:\RECYCLER\NPROTECT\00499164.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499165.rbf 224 bytes
C:\RECYCLER\NPROTECT\00499166.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499167.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499168.rbf 160 bytes
C:\RECYCLER\NPROTECT\00499169.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499170.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499171.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499172.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499173.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499174.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499175.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499176.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499177.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499178.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499179.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499180.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499181.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499182.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499183.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499184.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499185.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499186.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499187.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499188.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499189.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499190.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499191.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499192.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499193.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499194.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499195.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499196.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499197.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499198.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499199.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499200.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499201.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499202.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499203.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499204.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499205.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499206.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499207.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499208.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499209.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499210.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499211.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499212.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499213.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499214.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499215.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499216.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499217.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499218.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499219.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499220.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499221.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499222.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499223.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499224.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499225.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499226.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499227.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499228.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499229.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499230.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499231.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499232.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499233.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499234.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499235.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499236.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499237.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499238.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499239.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499240.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499241.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499242.rbf 288 bytes
C:\RECYCLER\NPROTECT\00499243.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499244.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499245.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00499246.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00499247.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00499248.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499249.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499250.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499251.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499252.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499253.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499254.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499255.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499256.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499257.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499258.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499259.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499260.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499261.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499262.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499263.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499264.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499265.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499266.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499267.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499268.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499269.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499270.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499271.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499272.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499273.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499274.rbf 240 bytes
C:\RECYCLER\NPROTECT\00499275.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499276.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499277.rbf 112 bytes
C:\RECYCLER\NPROTECT\00499278.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499279.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499280.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499281.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499282.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499283.rbf 120 bytes
C:\RECYCLER\NPROTECT\00499284.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499285.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499286.rbf 88 bytes
C:\RECYCLER\NPROTECT\00499287.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499288.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499289.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499290.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499291.rbf 104 bytes
C:\RECYCLER\NPROTECT\00499292.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499293.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499294.rbf 128 bytes
C:\RECYCLER\NPROTECT\00499295.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499296.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499297.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499298.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499299.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499300.rbf 288 bytes
C:\RECYCLER\NPROTECT\00499301.rbf 80 bytes
C:\RECYCLER\NPROTECT\00499302.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499303.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499304.rbf 136 bytes
C:\RECYCLER\NPROTECT\00499305.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499306.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499307.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499308.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499309.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499310.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499311.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499312.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499313.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499314.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499315.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499316.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499317.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499318.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499319.rbf 32 bytes
C:\RECYCLER\NPROTECT\00499320.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499321.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00499322.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00499323.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499324.rbf 2043904 bytes
C:\RECYCLER\NPROTECT\00499325.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499326.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499327.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499328.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499329.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499330.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499331.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499332.rbf 770048 bytes
C:\RECYCLER\NPROTECT\00499333.rbf 86016 bytes
C:\RECYCLER\NPROTECT\00499334.rbf 487424 bytes
C:\RECYCLER\NPROTECT\00499335.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499336.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499337.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499338.rbf 1003520 bytes
C:\RECYCLER\NPROTECT\00499339.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499340.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00499341.rbf 33935360 bytes
C:\RECYCLER\NPROTECT\00499342.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499343.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499344.rbf 1343488 bytes
C:\RECYCLER\NPROTECT\00499345.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00499346.rbf 196608 bytes
C:\RECYCLER\NPROTECT\00499347.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00499348.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00499349.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00499350.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00499351.rbf 266240 bytes
C:\RECYCLER\NPROTECT\00499352.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00499353.rbf 126976 bytes
C:\RECYCLER\NPROTECT\00499354.rbf 61440 bytes
C:\RECYCLER\NPROTECT\00499355.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00499356.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00499357.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00499358.rbf 122880 bytes
C:\RECYCLER\NPROTECT\00499359.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00499360.rbf 49152 bytes
C:\RECYCLER\NPROTECT\00499361.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499362.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00499363.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00499364.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00499365.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00499366.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499367.rbf 204800 bytes
C:\RECYCLER\NPROTECT\00499368.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00499369.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00499370.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00499371.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00499372.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00499373.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00499374.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00499375.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00499376.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00499377.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00499378.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00499379.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499380.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499381.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499382.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499383.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00499384.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00499385.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00499386.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00499387.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00499388.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00499389.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00499390.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00499391.rbf 77824 bytes
C:\RECYCLER\NPROTECT\00499392.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00499393.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499394.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499395.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499396.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00499397.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499398.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499399.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499400.rbf 442368 bytes
C:\RECYCLER\NPROTECT\00499401.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00499402.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00499403.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00499404.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00499405.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00499406.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00499407.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00499408.rbf 12255232 bytes
C:\RECYCLER\NPROTECT\00499409.rbf 1622016 bytes
C:\RECYCLER\NPROTECT\00499410.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499411.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00499412.rbf 632 bytes
C:\RECYCLER\NPROTECT\00499413.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499414.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00499415.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499416.rbf 160 bytes
C:\RECYCLER\NPROTECT\00499417.rbf 168 bytes
C:\RECYCLER\NPROTECT\00499418.rbf 160 bytes
C:\RECYCLER\NPROTECT\00499419.rbf 168 bytes
C:\RECYCLER\NPROTECT\00499420.rbf 160 bytes
C:\RECYCLER\NPROTECT\00499421.rbf 152 bytes
C:\RECYCLER\NPROTECT\00499422.rbf 160 bytes
C:\RECYCLER\NPROTECT\00499423.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499424.rbf 159744 bytes
C:\RECYCLER\NPROTECT\00499425.rbf 176128 bytes
C:\RECYCLER\NPROTECT\00499426.rbf 700416 bytes
C:\RECYCLER\NPROTECT\00499427.rbf 672 bytes
C:\RECYCLER\NPROTECT\00499428.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00499429.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499430.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499431.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499432.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00499433.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499434.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00499435.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499436.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00499437.rbf 136 bytes
C:\RECYCLER\NPROTECT\00499438.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499439.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499440.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00499441.rbf 4653056 bytes
C:\RECYCLER\NPROTECT\00499442.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00499443.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00499444.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00499445.rbs 118784 bytes
C:\RECYCLER\NPROTECT\00499446.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00499447.msi 192512 bytes
C:\RECYCLER\NPROTECT\00499448.MST 135168 bytes
C:\RECYCLER\NPROTECT\00499449.mst 135168 bytes
C:\RECYCLER\NPROTECT\00499450.lo_ 69632 bytes
C:\RECYCLER\NPROTECT\00499475.DIC 168 bytes
C:\RECYCLER\NPROTECT\00499478.C$$ 280 bytes
C:\RECYCLER\NPROTECT\00499479.cfg 176 bytes
C:\RECYCLER\NPROTECT\00499502 72 bytes
C:\RECYCLER\NPROTECT\00499503.C$$ 272 bytes
C:\RECYCLER\NPROTECT\00499504.cfg 176 bytes
C:\RECYCLER\NPROTECT\00499516 72 bytes
C:\RECYCLER\NPROTECT\00499517.C$$ 280 bytes
C:\RECYCLER\NPROTECT\00499518.cfg 176 bytes
C:\RECYCLER\NPROTECT\00499554 72 bytes
C:\RECYCLER\NPROTECT\00499614.doc 168 bytes
C:\RECYCLER\NPROTECT\00499615.ASD 36864 bytes
C:\RECYCLER\NPROTECT\00499616.doc 168 bytes
C:\RECYCLER\NPROTECT\00499617.dot 168 bytes
C:\RECYCLER\NPROTECT\00499618.doc 168 bytes
C:\RECYCLER\NPROTECT\00499620.TOR 20480 bytes
C:\RECYCLER\NPROTECT\00499621.TOR 8192 bytes
C:\RECYCLER\NPROTECT\00499622.TOR 20480 bytes
C:\RECYCLER\NPROTECT\00499630.dat 16384 bytes
C:\RECYCLER\NPROTECT\00499632.ini 152 bytes
C:\RECYCLER\NPROTECT\00499675.WMD 73728 bytes
C:\RECYCLER\NPROTECT\00499676.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499677.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499678.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499679.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499680.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499691.edb 65536 bytes
C:\RECYCLER\NPROTECT\00499698.WMD 73728 bytes
C:\RECYCLER\NPROTECT\00499699.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499700.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499701.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499702.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499703.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499704.WMD 163840 bytes
C:\RECYCLER\NPROTECT\00499707.WMD 73728 bytes
C:\RECYCLER\NPROTECT\00499708.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499709.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499710.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499711.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499712.WMD 4096 bytes
C:\RECYCLER\NPROTECT\00499713.dat 16384 bytes
C:\RECYCLER\NPROTECT\00499714.TXT 152 bytes
C:\RECYCLER\NPROTECT\00499715.ini 152 bytes
C:\RECYCLER\NPROTECT\00499723.XML 56 bytes
C:\RECYCLER\NPROTECT\00499726.XML 56 bytes
C:\RECYCLER\NPROTECT\00499730.XML 56 bytes
C:\RECYCLER\NPROTECT\00499743.edb 65536 bytes
C:\RECYCLER\NPROTECT\00499745.XML 56 bytes
C:\RECYCLER\NPROTECT\00499752.XML 56 bytes
C:\RECYCLER\NPROTECT\00499755.XML 56 bytes
C:\RECYCLER\NPROTECT\00499758.XML 56 bytes
C:\RECYCLER\NPROTECT\00499763.JPG 40960 bytes
C:\RECYCLER\NPROTECT\00499765.XML 56 bytes
C:\RECYCLER\NPROTECT\00499771.XML 56 bytes
C:\RECYCLER\NPROTECT\00499784.XML 56 bytes
C:\RECYCLER\NPROTECT\00499788.XML 56 bytes
C:\RECYCLER\NPROTECT\00499792.XML 56 bytes
C:\RECYCLER\NPROTECT\00499805.sol 4096 bytes
C:\RECYCLER\NPROTECT\00499806.edb 65536 bytes
C:\RECYCLER\NPROTECT\00499816.TOR 20480 bytes
C:\RECYCLER\NPROTECT\00499817.TOR 16384 bytes
C:\RECYCLER\NPROTECT\00499834.edb 65536 bytes
C:\RECYCLER\NPROTECT\00499846.xml 999424 bytes
C:\RECYCLER\NPROTECT\00499849.TOR 16384 bytes
C:\RECYCLER\NPROTECT\00499850.TOR 53248 bytes
C:\RECYCLER\NPROTECT\00499855.TOR 28672 bytes
C:\RECYCLER\NPROTECT\00499863.cab 16384 bytes
C:\RECYCLER\NPROTECT\00499871.cab 16384 bytes
C:\RECYCLER\NPROTECT\00499884.edb 65536 bytes
C:\RECYCLER\NPROTECT\00499919.edb 65536 bytes
C:\RECYCLER\NPROTECT\00499921 8192 bytes
C:\RECYCLER\NPROTECT\00499922 8192 bytes
C:\RECYCLER\NPROTECT\00499947.dat 16384 bytes
C:\RECYCLER\NPROTECT\00499949.ini 152 bytes
C:\RECYCLER\NPROTECT\00499979.TXT 112 bytes
C:\RECYCLER\NPROTECT\00499983.TXT 72 bytes
C:\RECYCLER\NPROTECT\00499984.TXT 144 bytes
C:\RECYCLER\NPROTECT\00499985.TXT 208 bytes
C:\RECYCLER\NPROTECT\00499986.TXT 280 bytes
C:\RECYCLER\NPROTECT\00499987.TXT 352 bytes
C:\RECYCLER\NPROTECT\00499988.TXT 416 bytes
C:\RECYCLER\NPROTECT\00499989.TXT 552 bytes
C:\RECYCLER\NPROTECT\00499990.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00499992.TXT 192 bytes
C:\RECYCLER\NPROTECT\00499995.TXT 136 bytes
C:\RECYCLER\NPROTECT\00499996.TXT 232 bytes
C:\RECYCLER\NPROTECT\00499997.TXT 232 bytes
C:\RECYCLER\NPROTECT\00499998.TXT 568 bytes
C:\RECYCLER\NPROTECT\00499999.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500000.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500001.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500002.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500003.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500004.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500005.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500006.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500007.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500008.TXT 216 bytes
C:\RECYCLER\NPROTECT\00500012.TXT 216 bytes
C:\RECYCLER\NPROTECT\00500013.TXT 304 bytes
C:\RECYCLER\NPROTECT\00500017.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500019.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500020.TXT 88 bytes
C:\RECYCLER\NPROTECT\00500021.SOL 104 bytes
C:\RECYCLER\NPROTECT\00500022.TXT 432 bytes
C:\RECYCLER\NPROTECT\00500026.TXT 208 bytes
C:\RECYCLER\NPROTECT\00500027.TXT 320 bytes
C:\RECYCLER\NPROTECT\00500030.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500031.TXT 96 bytes
C:\RECYCLER\NPROTECT\00500032.TXT 448 bytes
C:\RECYCLER\NPROTECT\00500035.TXT 88 bytes
C:\RECYCLER\NPROTECT\00500039.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500040.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500041.TXT 96 bytes
C:\RECYCLER\NPROTECT\00500042.TXT 88 bytes
C:\RECYCLER\NPROTECT\00500043.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500044.TXT 96 bytes
C:\RECYCLER\NPROTECT\00500047.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500048.TXT 472 bytes
C:\RECYCLER\NPROTECT\00500051.TXT 88 bytes
C:\RECYCLER\NPROTECT\00500054.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500055.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500056.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500057.TXT 88 bytes
C:\RECYCLER\NPROTECT\00500058.TXT 304 bytes
C:\RECYCLER\NPROTECT\00500060.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500062.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500063.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500064.TXT 488 bytes
C:\RECYCLER\NPROTECT\00500067.TXT 88 bytes
C:\RECYCLER\NPROTECT\00500068.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500072.TXT 192 bytes
C:\RECYCLER\NPROTECT\00500073.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500074.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500075.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500076.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500077.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500078.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500079.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500080.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500081.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500082.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500083.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500084.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500085.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500086.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500087.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500088.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500089.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500090.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500091.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500092.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500093.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500094.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500095.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500096.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500097.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500098.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500099.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500100.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500101.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500102.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500103.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500104.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500105.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500106.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500107.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500108.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500109.TXT 88 bytes
C:\RECYCLER\NPROTECT\00500110.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500111.TXT 488 bytes
C:\RECYCLER\NPROTECT\00500112.TXT 488 bytes
C:\RECYCLER\NPROTECT\00500115.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500116.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500117.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500118.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500119.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500120.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500121.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500122.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500123.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500125.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500126.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500127.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500128.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500129.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500132.TXT 504 bytes
C:\RECYCLER\NPROTECT\00500133.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500135.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500137.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500139.TXT 520 bytes
C:\RECYCLER\NPROTECT\00500140.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500141.SOL 104 bytes
C:\RECYCLER\NPROTECT\00500142.SOL 104 bytes
C:\RECYCLER\NPROTECT\00500143.TXT 96 bytes
C:\RECYCLER\NPROTECT\00500144.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500145.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500150.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500151.TXT 120 bytes
C:\RECYCLER\NPROTECT\00500152.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500155.TXT 96 bytes
C:\RECYCLER\NPROTECT\00500156.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500157.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500158.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500159.TXT 120 bytes
C:\RECYCLER\NPROTECT\00500160.TXT 96 bytes
C:\RECYCLER\NPROTECT\00500161.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500164.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500165.TXT 120 bytes
C:\RECYCLER\NPROTECT\00500166.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500168.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500170.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500171.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500172.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500173.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500174.TXT 120 bytes
C:\RECYCLER\NPROTECT\00500175.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500176.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500178.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500180.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500181.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500182.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500183.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500184.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500185.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500186.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500187.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500188.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500189.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500190.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500191.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500192.TXT 216 bytes
C:\RECYCLER\NPROTECT\00500193.TXT 216 bytes
C:\RECYCLER\NPROTECT\00500194.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500195.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500196.TXT 120 bytes
C:\RECYCLER\NPROTECT\00500197.TXT 208 bytes
C:\RECYCLER\NPROTECT\00500200.TXT 400 bytes
C:\RECYCLER\NPROTECT\00500203.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500204.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500205.SOL 104 bytes
C:\RECYCLER\NPROTECT\00500206.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500207.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500210.TXT 416 bytes
C:\RECYCLER\NPROTECT\00500213.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500214.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500216.TXT 432 bytes
C:\RECYCLER\NPROTECT\00500217.TXT 432 bytes
C:\RECYCLER\NPROTECT\00500218.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500221.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500222.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500223.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500224.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500225.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500226.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500227.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500228.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500229.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500231.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500232.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500233.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500234.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500235.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500236.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500237.SOL 208 bytes
C:\RECYCLER\NPROTECT\00500238.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500239.SOL 112 bytes
C:\RECYCLER\NPROTECT\00500242.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500243.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500244.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500245.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500246.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500247.TXT 200 bytes
C:\RECYCLER\NPROTECT\00500248.TXT 448 bytes
C:\RECYCLER\NPROTECT\00500251.TXT 544 bytes
C:\RECYCLER\NPROTECT\00500252.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500256.TXT 192 bytes
C:\RECYCLER\NPROTECT\00500257.TXT 136 bytes
C:\RECYCLER\NPROTECT\00500264.dat 32768 bytes
C:\RECYCLER\NPROTECT\00500265.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500266.TXT 336 bytes
C:\RECYCLER\NPROTECT\00500267.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500268.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500269.TXT 96 bytes
C:\RECYCLER\NPROTECT\00500270.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00500271.TXT 192 bytes
C:\RECYCLER\NPROTECT\00500272.TXT 240 bytes
C:\RECYCLER\NPROTECT\00500273.TXT 288 bytes
C:\RECYCLER\NPROTECT\00500274.TXT 104 bytes
C:\RECYCLER\NPROTECT\00500275.TXT 280 bytes
C:\RECYCLER\NPROTECT\00500276.TXT 136 bytes
C:\RECYCLER\NPROTECT\00500277.TXT 112 bytes
C:\RECYCLER\NPROTECT\00500278.TXT 80 bytes
C:\RECYCLER\NPROTECT\00500279.TXT 224 bytes
C:\RECYCLER\NPROTECT\00500280.TXT 176 bytes
C:\RECYCLER\NPROTECT\00500281.TXT 144 bytes
C:\RECYCLER\NPROTECT\00500282.ini 152 bytes
C:\RECYCLER\NPROTECT\00500299.TOR 45056 bytes
C:\RECYCLER\NPROTECT\00500312.SHD 4096 bytes
C:\RECYCLER\NPROTECT\00500313.SPL 1961984 bytes
C:\RECYCLER\NPROTECT\00500316.TXT 240 bytes
C:\RECYCLER\NPROTECT\00500318.dat 98304 bytes
C:\RECYCLER\NPROTECT\00500319.dat 49152 bytes
C:\RECYCLER\NPROTECT\00500320.dat 16384 bytes
C:\RECYCLER\NPROTECT\00500325.DAT 16 bytes
C:\RECYCLER\NPROTECT\00500327.DAT 16 bytes
C:\RECYCLER\NPROTECT\00500372.JOB 336 bytes
C:\RECYCLER\NPROTECT\00500394.edb 65536 bytes
C:\RECYCLER\NPROTECT\00500414.xml 12288 bytes
C:\RECYCLER\NPROTECT\00500484 224 bytes
C:\RECYCLER\NPROTECT\00500487 216 bytes
C:\RECYCLER\NPROTECT\00500530.SYS 8192 bytes
C:\RECYCLER\NPROTECT\00500541 696 bytes
C:\RECYCLER\NPROTECT\00500542.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500554 64 bytes
C:\RECYCLER\NPROTECT\00500559.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500560.txt 8192 bytes
C:\RECYCLER\NPROTECT\00500561.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500562.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500563.txt 57344 bytes
C:\RECYCLER\NPROTECT\00500564.txt 8192 bytes
C:\RECYCLER\NPROTECT\00500566 16 bytes
C:\RECYCLER\NPROTECT\00500568.txt 104 bytes
C:\RECYCLER\NPROTECT\00500570.txt 104 bytes
C:\RECYCLER\NPROTECT\00500572.txt 104 bytes
C:\RECYCLER\NPROTECT\00500575.bat 4096 bytes
C:\RECYCLER\NPROTECT\00500578 4096 bytes
C:\RECYCLER\NPROTECT\00500580.txt 368 bytes
C:\RECYCLER\NPROTECT\00500581.txt 88 bytes
C:\RECYCLER\NPROTECT\00500582.txt 88 bytes
C:\RECYCLER\NPROTECT\00500583.txt 96 bytes
C:\RECYCLER\NPROTECT\00500584.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500585.txt 88 bytes
C:\RECYCLER\NPROTECT\00500586.txt 88 bytes
C:\RECYCLER\NPROTECT\00500587.txt 96 bytes
C:\RECYCLER\NPROTECT\00500588.txt 88 bytes
C:\RECYCLER\NPROTECT\00500589.txt 88 bytes
C:\RECYCLER\NPROTECT\00500590.txt 96 bytes
C:\RECYCLER\NPROTECT\00500591.txt 96 bytes
C:\RECYCLER\NPROTECT\00500592.txt 88 bytes
C:\RECYCLER\NPROTECT\00500593.txt 96 bytes
C:\RECYCLER\NPROTECT\00500594.txt 96 bytes
C:\RECYCLER\NPROTECT\00500595.txt 80 bytes
C:\RECYCLER\NPROTECT\00500596.txt 88 bytes
C:\RECYCLER\NPROTECT\00500597.txt 88 bytes
C:\RECYCLER\NPROTECT\00500598.txt 96 bytes
C:\RECYCLER\NPROTECT\00500599.txt 104 bytes
C:\RECYCLER\NPROTECT\00500600.txt 96 bytes
C:\RECYCLER\NPROTECT\00500601.txt 96 bytes
C:\RECYCLER\NPROTECT\00500602.txt 96 bytes
C:\RECYCLER\NPROTECT\00500603.txt 96 bytes
C:\RECYCLER\NPROTECT\00500604.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500605.txt 8192 bytes
C:\RECYCLER\NPROTECT\00500606.txt 88 bytes
C:\RECYCLER\NPROTECT\00500607.txt 96 bytes
C:\RECYCLER\NPROTECT\00500608.txt 248 bytes
C:\RECYCLER\NPROTECT\00500609.txt 96 bytes
C:\RECYCLER\NPROTECT\00500610.txt 296 bytes
C:\RECYCLER\NPROTECT\00500611.txt 248 bytes
C:\RECYCLER\NPROTECT\00500612.txt 384 bytes
C:\RECYCLER\NPROTECT\00500613.txt 160 bytes
C:\RECYCLER\NPROTECT\00500614.txt 136 bytes
C:\RECYCLER\NPROTECT\00500615.txt 72 bytes
C:\RECYCLER\NPROTECT\00500616.txt 136 bytes
C:\RECYCLER\NPROTECT\00500617.txt 72 bytes
C:\RECYCLER\NPROTECT\00500618.txt 296 bytes
C:\RECYCLER\NPROTECT\00500619.txt 120 bytes
C:\RECYCLER\NPROTECT\00500620.txt 272 bytes
C:\RECYCLER\NPROTECT\00500621.txt 264 bytes
C:\RECYCLER\NPROTECT\00500622.txt 96 bytes
C:\RECYCLER\NPROTECT\00500623.txt 88 bytes
C:\RECYCLER\NPROTECT\00500624.txt 96 bytes
C:\RECYCLER\NPROTECT\00500625.txt 88 bytes
C:\RECYCLER\NPROTECT\00500626.txt 184 bytes
C:\RECYCLER\NPROTECT\00500627.txt 176 bytes
C:\RECYCLER\NPROTECT\00500628.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500629.txt 4096 bytes
C:\RECYCLER\NPROTECT\00500630.txt 224 bytes
C:\RECYCLER\NPROTECT\00500631.txt 176 bytes
C:\RECYCLER\NPROTECT\00500632.txt 224 bytes
C:\RECYCLER\NPROTECT\00500633.txt 176 bytes
C:\RECYCLER\NPROTECT\00500634.txt 8192 bytes
C:\RECYCLER\NPROTECT\00500635 456 bytes
C:\RECYCLER\NPROTECT\00500636.log 69632 bytes
C:\RECYCLER\NPROTECT\AlbumArtSmall.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{1B84FE9B-E830-4A0B-AF3F-C91D7BBA58EE}_Large.jpg 8192 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{1B84FE9B-E830-4A0B-AF3F-C91D7BBA58EE}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{551D8A92-EB1B-43AD-90E2-5547C3E78184}_Large.jpg 8192 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{551D8A92-EB1B-43AD-90E2-5547C3E78184}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{6FC7CBD6-2BBE-4056-B343-3EDDB2733BC7}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{6FC7CBD6-2BBE-4056-B343-3EDDB2733BC7}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{80DA5C02-8C10-445C-BB6B-CCE21CF00358}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{80DA5C02-8C10-445C-BB6B-CCE21CF00358}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D0AC7971-7B7D-4978-AE90-24116142D80C}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D0AC7971-7B7D-4978-AE90-24116142D80C}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D80A1D23-8651-401F-9CBD-B7836DEBE896}_Large.jpg 12288 bytes
C:\RECYCLER\NPROTECT\AlbumArt_{D80A1D23-8651-401F-9CBD-B7836DEBE896}_Small.jpg 4096 bytes
C:\RECYCLER\NPROTECT\desktop.ini 344 bytes
C:\RECYCLER\NPROTECT\Folder.jpg 12288 bytes
C:\RECYCLER\NPROTECT\NPROTECT.LOG 647168 bytes

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1517

********************************************************************

Completion time: 07-02-13 22:40:09
C:\ComboFix2.txt ... 07-02-12 09:10
greyrocker is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-13-2007, 03:12 PM   #10 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


(Part 3) More stuff! I'm tired! I am truly humbled by your expertise!

Last edited by greyrocker; 02-13-2007 at 03:26 PM.
greyrocker is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 02-13-2007, 03:16 PM   #11 (permalink)
Registered User
 
Join Date: Feb 2007
Posts: 26
OS: xp


(Part 3) More stuff to look over I am not worthy! "Lee" - 07-02-13 22:38:26 Service Pack 2
ComboFix 07-02-11 - Running from: "C:\Documents and Settings\Lee\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2007-01-13 to 2007-02-13 ))))))))))))))))))))))))))))))))))


2007-02-13 20:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-02-13 20:43 <DIR> d-------- C:\WINDOWS\LastGood
2007-02-12 11:12 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-02-12 09:18 <DIR> d-------- C:\bintheredunthat
2007-02-12 08:14 <DIR> d-------- C:\BFU
2007-02-11 21:56 <DIR> d-------- C:\ComboScan
2007-02-09 13:49 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-09 13:49 <DIR> d-------- C:\Program Files\Grisoft
2007-02-09 12:10 <DIR> d-------- C:\Program Files\HijackThis
2007-02-08 13:37 <DIR> d-------- C:\Program Files\FLVPlayer
2007-02-08 13:36 <DIR> d-------- C:\Downloads
2007-02-08 13:36 <DIR> d-------- C:\DOCUME~1\Lee\Application Data\GetRightToGo
2007-02-03 08:05 <DIR> d-------- C:\Program Files\ToniArts
2007-01-30 09:24 630,784 --a------ C:\WINDOWS\system32\vp7vfw.dll
2007-01-30 09:24 <DIR> d-------- C:\Program Files\On2 Technologies
2007-01-14 10:59 162,304 --a------ C:\UNWISE.EXE


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-13 19:32 -------- d-------- C:\DOCUME~1\Lee\Application Data\utorrent
2007-02-13 02:54 -------- d-------- C:\Program Files\norton internet security
2007-02-12 14:05 -------- d-------- C:\Program Files\java
2007-02-12 14:03 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-12 12:07 -------- d-------- C:\Program Files\windows defender
2007-02-12 12:06 -------- d-------- C:\Program Files\scrubxp
2007-02-12 12:06 -------- d-------- C:\Program Files\quicktime
2007-02-12 12:04 -------- d-------- C:\Program Files\messenger
2007-02-12 12:03 -------- d-------- C:\Program Files\itunes
2007-02-12 12:01 -------- d-------- C:\Program Files\google
2007-02-12 12:01 -------- d-------- C:\Program Files\fantastic flame screensaver
2007-02-12 12:01 -------- d-------- C:\Program Files\dell support
2007-02-12 09:10 51733 --a------ C:\WINDOWS\system32\plugin1.dat
2007-02-09 16:47 -------- d-------- C:\DOCUME~1\Lee\Application Data\dvdcss
2007-02-03 11:38 -------- d-------- C:\Program Files\guild wars
2007-02-03 08:05 -------- d--h----- C:\Program Files\installshield installation information
2007-01-24 20:54 -------- d-------- C:\Program Files\lexmarkx73
2007-01-15 12:36 -------- d-------- C:\DOCUME~1\Lee\Application Data\adobeum
2007-01-14 12:23 -------- d--h----- C:\Program Files\Common Files\uninstall information
2007-01-14 11:05 51733 --a------ C:\WINDOWS\system32\scarddlg.dat
2007-01-03 08:10 -------- d-------- C:\DOCUME~1\Lee\Application Data\adobe
2006-12-30 17:42 -------- d---s---- C:\DOCUME~1\Lee\Application Data\microsoft
2006-12-30 16:32 -------- d-------- C:\Program Files\bethesda softworks
2006-12-28 08:58 -------- d-------- C:\Program Files\aft software
2006-12-28 08:55 796672 --a------ C:\WINDOWS\gpinstall.exe
2006-12-27 14:45 -------- d-------- C:\Program Files\ricochet lost worlds recharged
2006-12-27 14:37 -------- d-------- C:\Program Files\galaxian
2006-12-26 22:33 -------- d-------- C:\Program Files\tvinternet
2006-12-26 09:45 -------- d-------- C:\Program Files\windows media connect 2
2006-12-26 09:24 -------- d-------- C:\Program Files\ipod
2006-12-26 09:22 -------- d-------- C:\Program Files\apple software update


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"P17Helper"="Rundll32 P17.dll,P17Helper"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"PC Booster"="C:\\Program Files\\inKline Global\\PC Booster\\pcbooster.exe"
"PrinTray"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\printray.exe"
"sc"="C:\\Program Files\\ScrubXP\\scrubxp.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"TrueImageMonitor.exe"="C:\\Program Files\\Acronis\\TrueImage\\TrueImageMonitor.exe"
"AcronisTimounterMonitor"="C:\\Program Files\\Acronis\\TrueImage\\TimounterMonitor.exe"
"Acronis Scheduler2 Service"="\"C:\\Program Files\\Common Files\\Acronis\\Schedule2\\schedhlp.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~3.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk"
"backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray"
"item"="ATI CATALYST System Tray"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Digital Line Detect.lnk"
"backup"="C:\\WINDOWS\\pss\\Digital Line Detect.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\DIGITA~1\\DLG.exe "
"item"="Digital Line Detect"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
"backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
"command"="C:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE "
"item"="InterVideo WinCinema Manager"
"location"="Common Startup"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler V3.exeStartup"
"item"="PowerReg Scheduler V3"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lee^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"item"="PowerReg Scheduler"
"location"="Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^blueyonder Instant Support Tool.lnk]
"backup"="C:\\WINDOWS\\pss\\blueyonder Instant Support Tool.lnkCommon Startup"
"command"="C:\\PROGRA~1\\BLUEYO~1\\bin\\matcli.exe -boot"
"item"="blueyonder Instant Support Tool"
"location"="Common Startup"
"path"="C:\\DOCUME~1\\ALLUSE~1\\Start Menu\\Programs\\Startup\\blueyonder Instant Support Tool.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AQ3HelperStartUp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AQ3HEL~1"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\AQUATI~1\\AQ3HEL~1.EXE /partner AQ3"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTSysVol"
"hkey"="HKLM"
"command"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
"command"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="InCD"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"hkey"="HKLM"
"inimapping"="0"
"item"="iTunesHelper"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Manager]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACBTNM~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACBTNM~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Monitor]
"hkey"="HKLM"
"inimapping"="0"
"item"="ACMONI~1"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"command"="C:\\PROGRA~1\\LEXMAR~2\\ACMONI~1.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBLKsk]
"hkey"="HKLM"
"inimapping"="0"
"item"="LXBLKsk"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAGIXautostart]
"command"="G:\\Content\\Software\\Full_Programs\\Music Maker Silver 2005\\mm2005_silver_upgrade_UK.EXE"
"hkey"="HKLM"
"inimapping"="0"
"item"="mm2005_silver_upgrade_UK"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McafWelcome]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcwelcom"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcagent"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcupdate"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
"command"="C:\\Program Files\\Lexmark\\Lexmark Photo Center\\MemoryCardManager.exe -startup"
"hkey"="HKLM"
"inimapping"="0"
"item"="MemoryCardManager"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSKDetct"
"hkey"="HKLM"
"command"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hkey"="HKCU"
"inimapping"="0"
"item"="msmsgs"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"hkey"="HKLM"
"inimapping"="0"
"item"="qttask"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"command"="soundman.exe"
"hkey"="HKLM"
"inimapping"="0"
"item"="soundman"
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mcvsshld"
"hkey"="HKLM"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearRecentDocsOnExit"=dword:00000000
"HideClock"=dword:00000000
"NoCDBurning"=dword:00000000
"NoClose"=dword:00000000
"NoCommonGroups"=dword:00000000
"NoFileAssociate"=dword:00000000
"NoFileMenu"=dword:00000000
"NoFind"=dword:00000000
"NoFolderOptions"=dword:00000000
"NoLowDiskSpaceChecks"=dword:00000001
"NoRecentDocsHistory"=dword:00000001
"NoRun"=dword:00000000
"NoShellSearchButton"=dword:00000000
"NoSimpleStartMenu"=dword:00000000
"NoSMHelp"=dword:00000000
"NoToolbarsOnTaskbar"=dword:00000000
"NoTrayContextMenu"=dword:00000000
"NoTrayItemsDisplay"=dword:00000000
"NoViewContextMenu"=dword:00000000
"NoWinKeys"=dword:00000000
"StartMenuLogoff"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
bthsvcs REG_MULTI_SZ BthServ\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\RECYCLER\NPROTECT
C:\RECYCLER\NPROTECT\00497939.rbf 88 bytes
C:\RECYCLER\NPROTECT\00497940.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497941.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497942.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497943.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497944.rbf 104 bytes
C:\RECYCLER\NPROTECT\00497945.rbf 96 bytes
C:\RECYCLER\NPROTECT\00497946.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497947.rbf 128 bytes
C:\RECYCLER\NPROTECT\00497948.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497949.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497950.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497951.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497952.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497953.rbf 288 bytes
C:\RECYCLER\NPROTECT\00497954.rbf 80 bytes
C:\RECYCLER\NPROTECT\00497955.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497956.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497957.rbf 136 bytes
C:\RECYCLER\NPROTECT\00497958.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497959.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497960.rbf 72 bytes
C:\RECYCLER\NPROTECT\00497961.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497962.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497963.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497964.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497965.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497966.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497967.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497968.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497969.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497970.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497971.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497972.rbf 32 bytes
C:\RECYCLER\NPROTECT\00497973.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497974.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00497975.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497976.rbf 2039808 bytes
C:\RECYCLER\NPROTECT\00497977.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497978.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497979.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497980.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497981.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497982.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497983.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497984.rbf 770048 bytes
C:\RECYCLER\NPROTECT\00497985.rbf 86016 bytes
C:\RECYCLER\NPROTECT\00497986.rbf 487424 bytes
C:\RECYCLER\NPROTECT\00497987.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497988.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497989.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497990.rbf 1003520 bytes
C:\RECYCLER\NPROTECT\00497991.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497992.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00497993.rbf 33914880 bytes
C:\RECYCLER\NPROTECT\00497994.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00497995.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00497996.rbf 1343488 bytes
C:\RECYCLER\NPROTECT\00497997.rbf 98304 bytes
C:\RECYCLER\NPROTECT\00497998.rbf 196608 bytes
C:\RECYCLER\NPROTECT\00497999.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498000.rbf 69632 bytes
C:\RECYCLER\NPROTECT\00498001.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498002.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00498003.rbf 262144 bytes
C:\RECYCLER\NPROTECT\00498004.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498005.rbf 126976 bytes
C:\RECYCLER\NPROTECT\00498006.rbf 61440 bytes
C:\RECYCLER\NPROTECT\00498007.rbf 32768 bytes
C:\RECYCLER\NPROTECT\00498008.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498009.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498010.rbf 122880 bytes
C:\RECYCLER\NPROTECT\00498011.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498012.rbf 49152 bytes
C:\RECYCLER\NPROTECT\00498013.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498014.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498015.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498016.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498017.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498018.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498019.rbf 204800 bytes
C:\RECYCLER\NPROTECT\00498020.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498021.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00498022.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498023.rbf 102400 bytes
C:\RECYCLER\NPROTECT\00498024.rbf 90112 bytes
C:\RECYCLER\NPROTECT\00498025.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498026.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00498027.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00498028.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498029.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00498030.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498031.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498032.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498033.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498034.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498035.rbf 36864 bytes
C:\RECYCLER\NPROTECT\00498036.rbf 81920 bytes
C:\RECYCLER\NPROTECT\00498037.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00498038.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498039.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498040.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498041.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498042.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498043.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498044.rbf 73728 bytes
C:\RECYCLER\NPROTECT\00498045.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498046.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498047.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498048.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498049.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498050.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498051.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498052.rbf 438272 bytes
C:\RECYCLER\NPROTECT\00498053.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498054.rbf 245760 bytes
C:\RECYCLER\NPROTECT\00498055.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00498056.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498057.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498058.rbf 28672 bytes
C:\RECYCLER\NPROTECT\00498059.rbf 65536 bytes
C:\RECYCLER\NPROTECT\00498060.rbf 12255232 bytes
C:\RECYCLER\NPROTECT\00498061.rbf 1617920 bytes
C:\RECYCLER\NPROTECT\00498062.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498063.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498064.rbf 632 bytes
C:\RECYCLER\NPROTECT\00498065.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498066.rbf 151552 bytes
C:\RECYCLER\NPROTECT\00498067.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498068.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498069.rbf 168 bytes
C:\RECYCLER\NPROTECT\00498070.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498071.rbf 168 bytes
C:\RECYCLER\NPROTECT\00498072.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498073.rbf 152 bytes
C:\RECYCLER\NPROTECT\00498074.rbf 160 bytes
C:\RECYCLER\NPROTECT\00498075.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498076.rbf 159744 bytes
C:\RECYCLER\NPROTECT\00498077.rbf 176128 bytes
C:\RECYCLER\NPROTECT\00498078.rbf 700416 bytes
C:\RECYCLER\NPROTECT\00498079.rbf 672 bytes
C:\RECYCLER\NPROTECT\00498080.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498081.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498082.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498083.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498084.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498085.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498086.rbf 40960 bytes
C:\RECYCLER\NPROTECT\00498087.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498088.rbf 12288 bytes
C:\RECYCLER\NPROTECT\00498089.rbf 136 bytes
C:\RECYCLER\NPROTECT\00498090.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498091.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498092.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498093.rbf 4493312 bytes
C:\RECYCLER\NPROTECT\00498094.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498095.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498096.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498097.rbs 122880 bytes
C:\RECYCLER\NPROTECT\00498098.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00498099.msi 188416 bytes
C:\RECYCLER\NPROTECT\00498100.MST 147456 bytes
C:\RECYCLER\NPROTECT\00498101.mst 147456 bytes
C:\RECYCLER\NPROTECT\00498106 224 bytes
C:\RECYCLER\NPROTECT\00498109 216 bytes
C:\RECYCLER\NPROTECT\00498132.SYS 8192 bytes
C:\RECYCLER\NPROTECT\00498144 696 bytes
C:\RECYCLER\NPROTECT\00498145.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498160 64 bytes
C:\RECYCLER\NPROTECT\00498165.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498166.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498167.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498168.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498174.EXE 4096 bytes
C:\RECYCLER\NPROTECT\00498175.LZM 4096 bytes
C:\RECYCLER\NPROTECT\00498176.LOG 4096 bytes
C:\RECYCLER\NPROTECT\00498177.exe 61440 bytes
C:\RECYCLER\NPROTECT\00498178 232 bytes
C:\RECYCLER\NPROTECT\00498179 80 bytes
C:\RECYCLER\NPROTECT\00498180.txt 57344 bytes
C:\RECYCLER\NPROTECT\00498181.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498182 16 bytes
C:\RECYCLER\NPROTECT\00498183.txt 296 bytes
C:\RECYCLER\NPROTECT\00498184.txt 152 bytes
C:\RECYCLER\NPROTECT\00498186.txt 104 bytes
C:\RECYCLER\NPROTECT\00498188.txt 104 bytes
C:\RECYCLER\NPROTECT\00498191.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498197.job 440 bytes
C:\RECYCLER\NPROTECT\00498198.txt 40 bytes
C:\RECYCLER\NPROTECT\00498211 40 bytes
C:\RECYCLER\NPROTECT\00498214.reg 8192 bytes
C:\RECYCLER\NPROTECT\00498216 122880 bytes
C:\RECYCLER\NPROTECT\00498304 4096 bytes
C:\RECYCLER\NPROTECT\00498321.txt 464 bytes
C:\RECYCLER\NPROTECT\00498323.txt 88 bytes
C:\RECYCLER\NPROTECT\00498324.txt 88 bytes
C:\RECYCLER\NPROTECT\00498325.txt 96 bytes
C:\RECYCLER\NPROTECT\00498332.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498340.txt 88 bytes
C:\RECYCLER\NPROTECT\00498347.txt 88 bytes
C:\RECYCLER\NPROTECT\00498348.txt 96 bytes
C:\RECYCLER\NPROTECT\00498349.txt 88 bytes
C:\RECYCLER\NPROTECT\00498350.txt 88 bytes
C:\RECYCLER\NPROTECT\00498351.txt 96 bytes
C:\RECYCLER\NPROTECT\00498352.txt 96 bytes
C:\RECYCLER\NPROTECT\00498353.txt 88 bytes
C:\RECYCLER\NPROTECT\00498354.txt 96 bytes
C:\RECYCLER\NPROTECT\00498355.txt 96 bytes
C:\RECYCLER\NPROTECT\00498356.txt 80 bytes
C:\RECYCLER\NPROTECT\00498357.txt 88 bytes
C:\RECYCLER\NPROTECT\00498358.txt 88 bytes
C:\RECYCLER\NPROTECT\00498359.txt 96 bytes
C:\RECYCLER\NPROTECT\00498360.txt 104 bytes
C:\RECYCLER\NPROTECT\00498361.txt 96 bytes
C:\RECYCLER\NPROTECT\00498362.txt 96 bytes
C:\RECYCLER\NPROTECT\00498363.txt 96 bytes
C:\RECYCLER\NPROTECT\00498364.txt 96 bytes
C:\RECYCLER\NPROTECT\00498365.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498366.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498367.txt 88 bytes
C:\RECYCLER\NPROTECT\00498368.txt 96 bytes
C:\RECYCLER\NPROTECT\00498369.txt 248 bytes
C:\RECYCLER\NPROTECT\00498370.txt 96 bytes
C:\RECYCLER\NPROTECT\00498371.txt 296 bytes
C:\RECYCLER\NPROTECT\00498372.txt 248 bytes
C:\RECYCLER\NPROTECT\00498373.txt 384 bytes
C:\RECYCLER\NPROTECT\00498374.txt 160 bytes
C:\RECYCLER\NPROTECT\00498375.txt 136 bytes
C:\RECYCLER\NPROTECT\00498376.txt 72 bytes
C:\RECYCLER\NPROTECT\00498377.txt 136 bytes
C:\RECYCLER\NPROTECT\00498378.txt 72 bytes
C:\RECYCLER\NPROTECT\00498379.txt 336 bytes
C:\RECYCLER\NPROTECT\00498380.txt 160 bytes
C:\RECYCLER\NPROTECT\00498381.txt 272 bytes
C:\RECYCLER\NPROTECT\00498382.txt 264 bytes
C:\RECYCLER\NPROTECT\00498383.txt 96 bytes
C:\RECYCLER\NPROTECT\00498384.txt 88 bytes
C:\RECYCLER\NPROTECT\00498385.txt 96 bytes
C:\RECYCLER\NPROTECT\00498386.txt 88 bytes
C:\RECYCLER\NPROTECT\00498387.txt 184 bytes
C:\RECYCLER\NPROTECT\00498388.txt 176 bytes
C:\RECYCLER\NPROTECT\00498389.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498390.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498391.txt 224 bytes
C:\RECYCLER\NPROTECT\00498392.txt 176 bytes
C:\RECYCLER\NPROTECT\00498393.txt 224 bytes
C:\RECYCLER\NPROTECT\00498394.txt 176 bytes
C:\RECYCLER\NPROTECT\00498395.txt 8192 bytes
C:\RECYCLER\NPROTECT\00498396 456 bytes
C:\RECYCLER\NPROTECT\00498397.log 232 bytes
C:\RECYCLER\NPROTECT\00498398.log 73728 bytes
C:\RECYCLER\NPROTECT\00498399.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498401.JOB 336 bytes
C:\RECYCLER\NPROTECT\00498402.ini 72 bytes
C:\RECYCLER\NPROTECT\00498403.ini 72 bytes
C:\RECYCLER\NPROTECT\00498404.dat 32768 bytes
C:\RECYCLER\NPROTECT\00498405.ini 72 bytes
C:\RECYCLER\NPROTECT\00498406.ini 72 bytes
C:\RECYCLER\NPROTECT\00498407.ini 72 bytes
C:\RECYCLER\NPROTECT\00498408.ini 72 bytes
C:\RECYCLER\NPROTECT\00498409 4096 bytes
C:\RECYCLER\NPROTECT\00498410 4096 bytes
C:\RECYCLER\NPROTECT\00498411.TXT 352 bytes
C:\RECYCLER\NPROTECT\00498412 4096 bytes
C:\RECYCLER\NPROTECT\00498413.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00498414.TXT 224 bytes
C:\RECYCLER\NPROTECT\00498415.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498416.BAT 69632 bytes
C:\RECYCLER\NPROTECT\00498417 4096 bytes
C:\RECYCLER\NPROTECT\00498418 4096 bytes
C:\RECYCLER\NPROTECT\00498419.log 416 bytes
C:\RECYCLER\NPROTECT\00498420 312 bytes
C:\RECYCLER\NPROTECT\00498421.txt 4096 bytes
C:\RECYCLER\NPROTECT\00498422 104 bytes
C:\RECYCLER\NPROTECT\00498423.VBS 352 bytes
C:\RECYCLER\NPROTECT\00498424.txt 104 bytes
C:\RECYCLER\NPROTECT\00498425.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498426.txt 512 bytes
C:\RECYCLER\NPROTECT\00498427 48 bytes
C:\RECYCLER\NPROTECT\00498428.com 147456 bytes
C:\RECYCLER\NPROTECT\00498429.reg 4096 bytes
C:\RECYCLER\NPROTECT\00498430.exe 28672 bytes
C:\RECYCLER\NPROTECT\00498431.reg 212992 bytes
C:\RECYCLER\NPROTECT\00498432.E_E 163840 bytes
C:\RECYCLER\NPROTECT\00498433.exe 184320 bytes
C:\RECYCLER\NPROTECT\00498434.bat 102400 bytes
C:\RECYCLER\NPROTECT\00498435.bat 4096 bytes
C:\RECYCLER\NPROTECT\00498436.exe 40960 bytes
C:\RECYCLER\NPROTECT\00498437.exe 28672 bytes
C:\RECYCLER\NPROTECT\00498438.exe 45056 bytes
C:\RECYCLER\NPROTECT\00498439.exe 40960 bytes
C:\RECYCLER\NPROTECT\00498440.bat 8192 bytes
C:\RECYCLER\NPROTECT\00498441.EXE 8192 bytes
C:\RECYCLER\NPROTECT\00498442.exe 143360 bytes
C:\RECYCLER\NPROTECT\00498443.exe 126976 bytes
C:\RECYCLER\NPROTECT\00498444.exe 81920 bytes
C:\RECYCLER\NPROTECT\00498445.exe 49152 bytes
C:\RECYCLER\NPROTECT\00498446 8192 bytes
C:\RECYCLER\NPROTECT\00498447 312 bytes
C:\RECYCLER\NPROTECT\00498448.TXT 4096 bytes
C:\RECYCLER\NPROTECT\00498449.REG 4096 bytes
C:\RECYCLER\NPROTECT\00498450.bat 664 bytes
C:\RECYCLER\NPROTECT\00498453.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498454.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498455.dat 196608 bytes
C:\RECYCLER\NPROTECT\00498456.dat 49152 bytes
C:\RECYCLER\NPROTECT\00498476.dat 16384 bytes
C:\RECYCLER\NPROTECT\00498477.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498478.DAT 16 bytes
C:\RECYCLER\NPROTECT\00498479.dat 16384 bytes
C:\RECYCLER\NPROTECT\00498488.cab 16384 bytes
C:\RECYCLER\NPROTECT\00498496.cab 16384 bytes
C:\RECYCLER\NPROTECT\00498507.JOB 336 bytes
C:\RECYCLER\NPROTECT\00498515.edb 1056768 bytes
C:\RECYCLER\NPROTECT\00498519.edb 65536 bytes
C:\RECYCLER\NPROTECT\00498631.XML 56 bytes
C:\RECYCLER\NPROTECT\00498640.PAC 9031680 bytes
C:\RECYCLER\NPROTECT\00498641.PAC 122880 bytes
C:\RECYCLER\NPROTECT\00498644.PAC 294912 bytes
C:\RECYCLER\NPROTECT\00498647.PAC 176128 bytes
C:\RECYCLER\NPROTECT\00498650.PAC 688128 bytes
C:\RECYCLER\NPROTECT\00498653.dll 1331200 bytes
C:\RECYCLER\NPROTECT\00498654.dll 98304 bytes
C:\RECYCLER\NPROTECT\00498655.dll 196608 bytes
C:\RECYCLER\NPROTECT\00498656.dll 147456 bytes
C:\RECYCLER\NPROTECT\00498657.dll 69632 bytes
C:\RECYCLER\NPROTECT\00498658.jar 1896448 bytes
C:\RECYCLER\NPROTECT\00498659.jar 8192 bytes
C:\RECYCLER\NPROTECT\00498660.dll 36864 bytes
C:\RECYCLER\NPROTECT\00498661.DLL 32768 bytes
C:\RECYCLER\NPROTECT\00498662.DLL 253952 bytes
C:\RECYCLER\NPROTECT\00498663.dll 36864 bytes
C:\RECYCLER\NPROTECT\00498664.dll 122880 bytes
C:\RECYCLER\NPROTECT\00498665.jar 12288 bytes
C:\RECYCLER\NPROTECT\00498666.DLL 61440 bytes
C:\RECYCLER\NPROTECT\00498667.dll 32768 bytes
C:\RECYCLER\NPROTECT\00498668.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498669.dll 28672 bytes
C:\RECYCLER\NPROTECT\00498670.dll 122880 bytes
C:\RECYCLER\NPROTECT\00498671.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498672.DLL 32768 bytes
C:\RECYCLER\NPROTECT\00498673.exe 49152 bytes
C:\RECYCLER\NPROTECT\00498674.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498675.DLL 139264 bytes
C:\RECYCLER\NPROTECT\00498676.exe 131072 bytes
C:\RECYCLER\NPROTECT\00498677.jar 757760 bytes
C:\RECYCLER\NPROTECT\00498678.dll 28672 bytes
C:\RECYCLER\NPROTECT\00498679.jar 81920 bytes
C:\RECYCLER\NPROTECT\00498680.dll 57344 bytes
C:\RECYCLER\NPROTECT\00498681.dll 204800 bytes
C:\RECYCLER\NPROTECT\00498682.dll 131072 bytes
C:\RECYCLER\NPROTECT\00498683.dll 86016 bytes
C:\RECYCLER\NPROTECT\00498684.cpl 53248 bytes
C:\RECYCLER\NPROTECT\00498685.dll 98304 bytes
C:\RECYCLER\NPROTECT\00498686.dll 90112 bytes
C:\RECYCLER\NPROTECT\00498687.dll 53248 bytes
C:\RECYCLER\NPROTECT\00498688.dll 81920 bytes
C:\RECYCLER\NPROTECT\00498689.dll 151552 bytes
C:\RECYCLER\NPROTECT\00498690.dll 32768 bytes
C:\RECYCLER\NPROTECT\00498691.jar 495616 bytes
C:\RECYCLER\NPROTECT\00498692.exe 245760 bytes
C:\RECYCLER\NPROTECT\00498693.exe 40960 bytes
C:\RECYCLER\NPROTECT\00498694.dll 1527808 bytes
C:\RECYCLER\NPROTECT\00498695.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498696.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498697.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498698.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498699.JAR 4096 bytes
C:\RECYCLER\NPROTECT\00498700.DLL 36864 bytes
C:\RECYCLER\NPROTECT\00498701.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498702.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498703.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498704.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498705.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498706.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498707.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498708.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498709.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498710.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498711.PRO 4096 bytes
C:\RECYCLER\NPROTECT\00498712.dll 81920 bytes
C:\RECYCLER\NPROTECT\00498713.dll 40960 bytes
C:\RECYCLER\NPROTECT\00498714.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498715.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498716.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498717.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498718.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498719.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498720.dll 73728 bytes
C:\RECYCLER\NPROTECT\00498721.exe 57344 bytes
C:\RECYCLER\NPROTECT\00498722.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498723.jar 999424 bytes
C:\RECYCLER\NPROTECT\00498724.EXE 53248 bytes
C:\RECYCLER\NPROTECT\00498725.txt 12288 bytes
C:\RECYCLER\NPROTECT\00498726.dll 28672 bytes
C:\RECYCLER\NPROTECT\00498727.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498728.EXE 53248 bytes
C:\RECYCLER\NPROTECT\00498729.jar 33566720 bytes
C:\RECYCLER\NPROTECT\00498730.EXE 53248 bytes
C:\RECYCLER\NPROTECT\00498731.JAR 155648 bytes
C:\RECYCLER\NPROTECT\00498732.JAR 176128 bytes
C:\RECYCLER\NPROTECT\00498733.jar 8192 bytes
C:\RECYCLER\NPROTECT\00498734.TXT 53248 bytes
C:\RECYCLER\NPROTECT\00498735.EXE 57344 bytes
C:\RECYCLER\NPROTECT\00498736.dll 65536 bytes
C:\RECYCLER\NPROTECT\00498737.EXE 131072 bytes
C:\RECYCLER\NPROTECT\00498738.JAR 4096 bytes
C:\RECYCLER\NPROTECT\00498739.dll 53248 bytes
C:\RECYCLER\NPROTECT\00498740.DLL 28672 bytes
C:\RECYCLER\NPROTECT\00498741.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00498742.dll 65536 bytes
C:\RECYCLER\NPROTECT\00498743 4096 bytes
C:\RECYCLER\NPROTECT\00498744 4096 bytes
C:\RECYCLER\NPROTECT\00498745 4096 bytes
C:\RECYCLER\NPROTECT\00498746 4096 bytes
C:\RECYCLER\NPROTECT\00498747 4096 bytes
C:\RECYCLER\NPROTECT\00498748 4096 bytes
C:\RECYCLER\NPROTECT\00498749 4096 bytes
C:\RECYCLER\NPROTECT\00498750 4096 bytes
C:\RECYCLER\NPROTECT\00498751 4096 bytes
C:\RECYCLER\NPROTECT\00498752 4096 bytes
C:\RECYCLER\NPROTECT\00498753 4096 bytes
C:\RECYCLER\NPROTECT\00498754 4096 bytes
C:\RECYCLER\NPROTECT\00498755 96 bytes
C:\RECYCLER\NPROTECT\00498756 4096 bytes
C:\RECYCLER\NPROTECT\00498757 4096 bytes
C:\RECYCLER\NPROTECT\00498758 520 bytes
C:\RECYCLER\NPROTECT\00498759 28672 bytes
C:\RECYCLER\NPROTECT\00498760 4096 bytes
C:\RECYCLER\NPROTECT\00498761 4096 bytes
C:\RECYCLER\NPROTECT\00498762 4096 bytes
C:\RECYCLER\NPROTECT\00498763 520 bytes
C:\RECYCLER\NPROTECT\00498764 4096 bytes
C:\RECYCLER\NPROTECT\00498765 72 bytes
C:\RECYCLER\NPROTECT\00498766 4096 bytes
C:\RECYCLER\NPROTECT\00498767 4096 bytes
C:\RECYCLER\NPROTECT\00498768 368 bytes
C:\RECYCLER\NPROTECT\00498769 128 bytes
C:\RECYCLER\NPROTECT\00498770 520 bytes
C:\RECYCLER\NPROTECT\00498771 544 bytes
C:\RECYCLER\NPROTECT\00498772 4096 bytes
C:\RECYCLER\NPROTECT\00498773 4096 bytes
C:\RECYCLER\NPROTECT\00498774 4096 bytes
C:\RECYCLER\NPROTECT\00498775 4096 bytes
C:\RECYCLER\NPROTECT\00498776 4096 bytes
C:\RECYCLER\NPROTECT\00498777 4096 bytes
C:\RECYCLER\NPROTECT\00498778 4096 bytes
C:\RECYCLER\NPROTECT\00498779 4096 bytes
C:\RECYCLER\NPROTECT\00498780 4096 bytes
C:\RECYCLER\NPROTECT\00498781 128 bytes
C:\RECYCLER\NPROTECT\00498782 4096 bytes
C:\RECYCLER\NPROTECT\00498783 4096 bytes
C:\RECYCLER\NPROTECT\00498784 4096 bytes
C:\RECYCLER\NPROTECT\00498785 360 bytes
C:\RECYCLER\NPROTECT\00498786 336 bytes
C:\RECYCLER\NPROTECT\00498787 4096 bytes
C:\RECYCLER\NPROTECT\00498788 4096 bytes
C:\RECYCLER\NPROTECT\00498789 4096 bytes
C:\RECYCLER\NPROTECT\00498790 520 bytes
C:\RECYCLER\NPROTECT\00498791 4096 bytes
C:\RECYCLER\NPROTECT\00498792 4096 bytes
C:\RECYCLER\NPROTECT\00498793 128 bytes
C:\RECYCLER\NPROTECT\00498794 224 bytes
C:\RECYCLER\NPROTECT\00498795 12288 bytes
C:\RECYCLER\NPROTECT\00498796 176 bytes
C:\RECYCLER\NPROTECT\00498797 4096 bytes
C:\RECYCLER\NPROTECT\00498798 4096 bytes
C:\RECYCLER\NPROTECT\00498799 4096 bytes
C:\RECYCLER\NPROTECT\00498800 160 bytes
C:\RECYCLER\NPROTECT\00498801 368 bytes
C:\RECYCLER\NPROTECT\00498802 4096 bytes
C:\RECYCLER\NPROTECT\00498803 520 bytes
C:\RECYCLER\NPROTECT\00498804 4096 bytes
C:\RECYCLER\NPROTECT\00498805 4096 bytes
C:\RECYCLER\NPROTECT\00498806 584 bytes
C:\RECYCLER\NPROTECT\00498807 4096 bytes
C:\RECYCLER\NPROTECT\00498808 4096 bytes
C:\RECYCLER\NPROTECT\00498809 4096 bytes
C:\RECYCLER\NPROTECT\00498810 4096 bytes
C:\RECYCLER\NPROTECT\00498811 4096 bytes
C:\RECYCLER\NPROTECT\00498812 336 bytes
C:\RECYCLER\NPROTECT\00498813 4096 bytes
C:\RECYCLER\NPROTECT\00498814 4096 bytes
C:\RECYCLER\NPROTECT\00498815 4096 bytes
C:\RECYCLER\NPROTECT\00498816 160 bytes
C:\RECYCLER\NPROTECT\00498817 320 bytes
C:\RECYCLER\NPROTECT\00498818 4096 bytes
C:\RECYCLER\NPROTECT\00498819 4096 bytes
C:\RECYCLER\NPROTECT\00498820 4096 bytes
C:\RECYCLER\NPROTECT\00498821 8192 bytes
C:\RECYCLER\NPROTECT\00498822 8192 bytes
C:\RECYCLER\NPROTECT\00498823 8192 bytes
C:\RECYCLER\NPROTECT\00498824 288 bytes
C:\RECYCLER\NPROTECT\00498825 4096 bytes
C:\RECYCLER\NPROTECT\00498826 4096 bytes
C:\RECYCLER\NPROTECT\00498827 4096 bytes
C:\RECYCLER\NPROTECT\00498828 128 bytes
C:\RECYCLER\NPROTECT\00498829 4096 bytes
C:\RECYCLER\NPROTECT\00498830 4096 bytes
C:\RECYCLER\NPROTECT\00498831 280 bytes
C:\RECYCLER\NPROTECT\00498832 4096 bytes
C:\RECYCLER\NPROTECT\00498833 112 bytes
C:\RECYCLER\NPROTECT\00498834 4096 bytes
C:\RECYCLER\NPROTECT\00498835 4096 bytes
C:\RECYCLER\NPROTECT\00498836 4096 bytes
C:\RECYCLER\NPROTECT\00498837 72 bytes
C:\RECYCLER\NPROTECT\00498838 32 bytes
C:\RECYCLER\NPROTECT\00498839 4096 bytes
C:\RECYCLER\NPROTECT\00498840 272 bytes
C:\RECYCLER\NPROTECT\00498841 8192 bytes
C:\RECYCLER\NPROTECT\00498842 360 bytes
C:\RECYCLER\NPROTECT\00498843 4096 bytes
C:\RECYCLER\NPROTECT\00498844 192 bytes
C:\RECYCLER\NPROTECT\00498845 4096 bytes
C:\RECYCLER\NPROTECT\00498846 4096 bytes
C:\RECYCLER\NPROTECT\00498847 4096 bytes
C:\RECYCLER\NPROTECT\00498848 4096 bytes
C:\RECYCLER\NPROTECT\00498849 80 bytes
C:\RECYCLER\NPROTECT\00498850 4096 bytes
C:\RECYCLER\NPROTECT\00498851 16384 bytes
C:\RECYCLER\NPROTECT\00498852.RTP 4640768 bytes
C:\RECYCLER\NPROTECT\00498853.DLL 208896 bytes
C:\RECYCLER\NPROTECT\00498855.rbf 53248 bytes
C:\RECYCLER\NPROTECT\00498856.rbf 57344 bytes
C:\RECYCLER\NPROTECT\00498857.rbf 131072 bytes
C:\RECYCLER\NPROTECT\00498858.rbs 16384 bytes
C:\RECYCLER\NPROTECT\00498859.ipi 8192 bytes
C:\RECYCLER\NPROTECT\00498862.cpl 53248 bytes
C:\RECYCLER\NPROTECT\00498863.exe 53248 bytes
C:\RECYCLER\NPROTECT\00498864.exe 57344 bytes
C:\RECYCLER\NPROTECT\00498865.exe 131072 bytes
C:\RECYCLER\NPROTECT\00498866.rbf 147456 bytes
C:\RECYCLER\NPROTECT\00498867.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498868.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498869.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498870.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498871.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498872.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498873.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498874.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498875.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498876.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498877.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498878.rbf 8192 bytes
C:\RECYCLER\NPROTECT\00498879.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498880.rbf 184 bytes
C:\RECYCLER\NPROTECT\00498881.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498882.rbf 336 bytes
C:\RECYCLER\NPROTECT\00498883.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498884.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498885.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498886.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498887.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498888.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498889.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498890.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498891.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498892.rbf 216 bytes
C:\RECYCLER\NPROTECT\00498893.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498894.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498895.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498896.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498897.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498898.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498899.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498900.rbf 320 bytes
C:\RECYCLER\NPROTECT\00498901.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498902.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498903.rbf 112 bytes
C:\RECYCLER\NPROTECT\00498904.rbf 104 bytes
C:\RECYCLER\NPROTECT\00498905.rbf 344 bytes
C:\RECYCLER\NPROTECT\00498906.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498907.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498908.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498909.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498910.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498911.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498912.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498913.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498914.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498915.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498916.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498917.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498918.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498919.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498920.rbf 104 bytes
C:\RECYCLER\NPROTECT\00498921.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498922.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498923.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498924.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498925.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498926.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498927.rbf 296 bytes
C:\RECYCLER\NPROTECT\00498928.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498929.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498930.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498931.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498932.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498933.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498934.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498935.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498936.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498937.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498938.rbf 32 bytes
C:\RECYCLER\NPROTECT\00498939.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498940.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498941.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498942.rbf 16384 bytes
C:\RECYCLER\NPROTECT\00498943.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498944.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498945.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498946.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498947.rbf 464 bytes
C:\RECYCLER\NPROTECT\00498948.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498949.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498950.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498951.rbf 544 bytes
C:\RECYCLER\NPROTECT\00498952.rbf 144 bytes
C:\RECYCLER\NPROTECT\00498953.rbf 304 bytes
C:\RECYCLER\NPROTECT\00498954.rbf 520 bytes
C:\RECYCLER\NPROTECT\00498955.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498956.rbf 336 bytes
C:\RECYCLER\NPROTECT\00498957.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498958.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498959.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498960.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498961.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498962.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498963.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498964.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498965.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498966.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498967.rbf 144 bytes
C:\RECYCLER\NPROTECT\00498968.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498969.rbf 80 bytes
C:\RECYCLER\NPROTECT\00498970.rbf 344 bytes
C:\RECYCLER\NPROTECT\00498971.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498972.rbf 512 bytes
C:\RECYCLER\NPROTECT\00498973.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498974.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498975.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498976.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498977.rbf 320 bytes
C:\RECYCLER\NPROTECT\00498978.rbf 112 bytes
C:\RECYCLER\NPROTECT\00498979.rbf 384 bytes
C:\RECYCLER\NPROTECT\00498980.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498981.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498982.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498983.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498984.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498985.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498986.rbf 144 bytes
C:\RECYCLER\NPROTECT\00498987.rbf 72 bytes
C:\RECYCLER\NPROTECT\00498988.rbf 96 bytes
C:\RECYCLER\NPROTECT\00498989.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498990.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498991.rbf 192 bytes
C:\RECYCLER\NPROTECT\00498992.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498993.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498994.rbf 240 bytes
C:\RECYCLER\NPROTECT\00498995.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498996.rbf 88 bytes
C:\RECYCLER\NPROTECT\00498997.rbf 192 bytes
C:\RECYCLER\NPROTECT\00498998.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00498999.rbf 400 bytes
C:\RECYCLER\NPROTECT\00499000.rbf 192 bytes
C:\RECYCLER\NPROTECT\00499001.rbf 320 bytes
C:\RECYCLER\NPROTECT\00499002.rbf 96 bytes
C:\RECYCLER\NPROTECT\00499003.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499004.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499005.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499006.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499007.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499008.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499009.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499010.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499011.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499012.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499013.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499014.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499015.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499016.rbf 4096 bytes
C:\RECYCLER\NPROTECT\00499017.rbf 384 bytes
C:\RECYCLER\NPROTECT\00499018.rbf 72 bytes
C:\RECYCLER\NPROTECT\00499019.rbf 4096 bytes