Hello Dave
Here are the log files:
Security Check:
Results of screen317's Security Check version 0.99.31
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check: Windows Firewall Enabled!
avast! Free Antivirus
Online Armor 5.5
```````````````````````````````
Anti-malware/Other Utilities Check: SUPERAntiSpyware
CCleaner
Java(TM) 6 Update 31
Java 2 Runtime Environment, SE v1.4.2
````````````````````````````````
Process Check:
objlist.exe by Laurent Tall Emu Online Armor OAcat.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
``````````End of Log```````````` SysProt AntiRootkit v1.0.1.0:
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\smss.exe
PID: 392
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\csrss.exe
PID: 440
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\winlogon.exe
PID: 464
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\services.exe
PID: 508
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\lsass.exe
PID: 520
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 700
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 744
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 824
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 920
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 996
Hidden: No
Window Visible: No
Name: C:\Program Files\Online Armor\oacat.exe
PID: 1072
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 1236
Hidden: No
Window Visible: No
Name: C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PID: 1428
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\spoolsv.exe
PID: 1800
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PID: 1840
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 844
Hidden: No
Window Visible: No
Name: C:\Program Files\SUPERAntiSpyware\SASCore.exe
PID: 1040
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PID: 564
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 1144
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 1204
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre6\bin\jqs.exe
PID: 1624
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 1928
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 416
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 656
Hidden: No
Window Visible: No
Name: C:\Program Files\UPHClean\uphclean.exe
PID: 892
Hidden: No
Window Visible: No
Name: C:\WINDOWS\wanmpsvc.exe
PID: 1200
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\alg.exe
PID: 2852
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\hkcmd.exe
PID: 3112
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
PID: 3152
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\DSentry.exe
PID: 3168
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
PID: 3212
Hidden: No
Window Visible: No
Name: C:\Program Files\Dell\Media Experience\PCMService.exe
PID: 3248
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe
PID: 3260
Hidden: No
Window Visible: No
Name: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PID: 3288
Hidden: No
Window Visible: No
Name: C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
PID: 3300
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\hphmon05.exe
PID: 3312
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PID: 3324
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PID: 3388
Hidden: No
Window Visible: No
Name: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe
PID: 3400
Hidden: No
Window Visible: No
Name: C:\Program Files\AVAST Software\Avast\AvastUI.exe
PID: 3412
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Akamai\netsession_win.exe
PID: 3576
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PID: 3592
Hidden: No
Window Visible: No
Name: C:\WINDOWS\SYSTEM32\ctfmon.exe
PID: 3608
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Akamai\netsession_win.exe
PID: 3752
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
PID: 3780
Hidden: No
Window Visible: No
Name: C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
PID: 3788
Hidden: No
Window Visible: No
Name: C:\Program Files\Internet Explorer\iexplore.exe
PID: 408
Hidden: No
Window Visible: No
Name: C:\Program Files\Internet Explorer\iexplore.exe
PID: 2224
Hidden: No
Window Visible: No
Name: C:\Program Files\Internet Explorer\iexplore.exe
PID: 2960
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\Don Higham\Desktop\ysrot\SysProt\SysProt\SysProt.exe
PID: 1988
Hidden: No
Window Visible: Yes
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\Don Higham\Desktop\ysrot\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: EBD74000
Module End: EBD7F000
Hidden: No
Module Name: \WINDOWS\system32\ntoskrnl.exe
Service Name: ---
Module Base: 804D7000
Module End: 806EE580
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806EF000
Module End: 8070F300
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F7D65000
Module End: F7D67000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F7C75000
Module End: F7C78000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F7816000
Module End: F7844000
Hidden: No
Module Name: \WINDOWS\System32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F7D67000
Module End: F7D69000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F7805000
Module End: F7816000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F7865000
Module End: F786F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F7E2D000
Module End: F7E2E000
Hidden: No
Module Name: \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F7AE5000
Module End: F7AEC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F7875000
Module End: F7880000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F77E6000
Module End: F7805000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F7AED000
Module End: F7AF2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F7885000
Module End: F7892000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F77CE000
Module End: F77E6000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F7895000
Module End: F789E000
Hidden: No
Module Name: \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F78A5000
Module End: F78B2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: F77AE000
Module End: F77CE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F779C000
Module End: F77AE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F78B5000
Module End: F78BF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drvmcdb.sys
Service Name: drvmcdb
Module Base: F7787000
Module End: F779C000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F7770000
Module End: F7787000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F76E3000
Module End: F7770000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F76B6000
Module End: F76E3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F769C000
Module End: F76B6000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F7AA5000
Module End: F7AAE000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ialmnt5.sys
Service Name: ialm
Module Base: F7535000
Module End: F754C000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F7521000
Module End: F7535000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F7B25000
Module End: F7B2B000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F74FD000
Module End: F7521000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F7B2D000
Module End: F7B35000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys
Service Name: HSFHWBS2
Module Base: F74D6000
Module End: F74FD000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HSF_DP.sys
Service Name: HSF_DP
Module Base: F73CB000
Module End: F74D6000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys
Service Name: winachsf
Module Base: F733F000
Module End: F73CB000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F7B35000
Module End: F7B3D000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys
Service Name: bcm4sbxp
Module Base: F7AB5000
Module End: F7AC0000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F7AC5000
Module End: F7AD2000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F7B45000
Module End: F7B4B000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\serial.sys
Service Name: Serial
Module Base: F7AD5000
Module End: F7AE5000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\serenum.sys
Service Name: serenum
Module Base: F7D59000
Module End: F7D5D000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\parport.sys
Service Name: Parport
Module Base: F732B000
Module End: F733F000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F78D5000
Module End: F78E0000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Afc.sys
Service Name: Afc
Module Base: F7B4D000
Module End: F7B55000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\AFS2K.SYS
Service Name: AFS2K
Module Base: F78E5000
Module End: F78EF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pfc.sys
Service Name: pfc
Module Base: F7D5D000
Module End: F7D60000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sscdbhk5.sys
Service Name: sscdbhk5
Module Base: F7D99000
Module End: F7D9B000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F78F5000
Module End: F7905000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F7905000
Module End: F7914000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ks.sys
Service Name: ---
Module Base: F7308000
Module End: F732B000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys
Service Name: GEARAspiWDM
Module Base: F7B55000
Module End: F7B5B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\smwdm.sys
Service Name: smwdm
Module Base: F7282000
Module End: F7308000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: F725E000
Module End: F7282000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: F7925000
Module End: F7934000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\aeaudio.sys
Service Name: aeaudio
Module Base: F7D9D000
Module End: F7D9F000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\serscan.sys
Service Name: StillCam
Module Base: F7DA3000
Module End: F7DA5000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7ECE000
Module End: F7ECF000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F79B5000
Module End: F79C2000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F7570000
Module End: F7573000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F721C000
Module End: F7233000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F79C5000
Module End: F79D0000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F79D5000
Module End: F79E1000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F7B65000
Module End: F7B6A000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F7B6D000
Module End: F7B72000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F7B75000
Module End: F7B7A000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F79E5000
Module End: F79EF000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F7B7D000
Module End: F7B83000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F7DC1000
Module End: F7DC3000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\update.sys
Service Name: Update
Module Base: F711E000
Module End: F717C000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\omci.sys
Service Name: omci
Module Base: F7B85000
Module End: F7B8A000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F7568000
Module End: F756C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F79F5000
Module End: F79FF000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ialmkchw.sys
Service Name: {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}
Module Base: EF08A000
Module End: EF09E000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ialmsbw.sys
Service Name: {6080A529-897E-4629-A488-ABA0C29B635E}
Module Base: EF06E000
Module End: EF08A000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F7A25000
Module End: F7A34000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F7DC9000
Module End: F7DCB000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Service Name: Flpydisk
Module Base: F7B8D000
Module End: F7B92000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\i2omgmt.SYS
Service Name: i2omgmt
Module Base: F7CFD000
Module End: F7D00000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F7DD7000
Module End: F7DD9000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F7FB3000
Module End: F7FB4000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F7DD9000
Module End: F7DDB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ssrtln.sys
Service Name: ssrtln
Module Base: F7B9D000
Module End: F7BA3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: F7BA5000
Module End: F7BAC000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F7BAD000
Module End: F7BB3000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F7DDB000
Module End: F7DDD000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F7DDD000
Module End: F7DDF000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F7BB5000
Module End: F7BBA000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F7BBD000
Module End: F7BC5000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: F7D05000
Module End: F7D08000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\OAnet.sys
Service Name: OAnet
Module Base: F7BC5000
Module End: F7BCB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: EED43000
Module End: EED56000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F7A55000
Module End: F7A5E000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: EECEA000
Module End: EED43000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\MpFirewall.sys
Service Name: MPFIREWL
Module Base: EECD6000
Module End: EECEA000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\OAmon.sys
Service Name: OAmon
Module Base: F7A65000
Module End: F7A6E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswTdi.SYS
Service Name: aswTdi
Module Base: F7A75000
Module End: F7A80000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: EECAE000
Module End: EECD6000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswRdr.SYS
Service Name: aswRdr
Module Base: F7BCD000
Module End: F7BD4000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\ws2ifsl.sys
Service Name: WS2IFSL
Module Base: F7D11000
Module End: F7D14000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: EEC8C000
Module End: EECAE000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: F7A85000
Module End: F7A8E000
Hidden: No
Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
Service Name: SASKUTIL
Module Base: EEBCA000
Module End: EEBEC000
Hidden: No
Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Service Name: SASDIFSV
Module Base: F7BD5000
Module End: F7BDB000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: EEB9F000
Module End: EEBCA000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\oahlp32.sys
Service Name: oahlpXX
Module Base: F7935000
Module End: F793E000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Service Name: OADevice
Module Base: EEB46000
Module End: EEB77000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: EEAD6000
Module End: EEB46000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: F7945000
Module End: F7950000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: EEAB0000
Module End: EEAD6000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F7955000
Module End: F795E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Service Name: aswSP
Module Base: EE9F8000
Module End: EEA43000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswSnx.SYS
Service Name: aswSnx
Module Base: EE98B000
Module End: EE9F8000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbccgp.sys
Service Name: usbccgp
Module Base: F7BE5000
Module End: F7BED000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Aavmker4.SYS
Service Name: Aavmker4
Module Base: F7BF5000
Module End: F7BFB000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbprint.sys
Service Name: usbprint
Module Base: F7BFD000
Module End: F7C04000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HPZius12.sys
Service Name: HPZius12
Module Base: F7C05000
Module End: F7C0B000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
Service Name: USBSTOR
Module Base: F7C0D000
Module End: F7C14000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\LVUSBSta.sys
Service Name: LVUSBSta
Module Base: F7965000
Module End: F796E000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\usbscan.sys
Service Name: BulkUsb
Module Base: F7D49000
Module End: F7D4D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Service Name: HidUsb
Module Base: F7D4D000
Module End: F7D50000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: F7975000
Module End: F797E000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HPZid412.sys
Service Name: HPZid412
Module Base: F7995000
Module End: F79A2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: F7D55000
Module End: F7D59000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\HPZipr12.sys
Service Name: HPZipr12
Module Base: F7CE9000
Module End: F7CED000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: ED801000
Module End: ED811000
Hidden: No
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: ED03C000
Module End: ED054000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7DFF000
Module End: F7E01000
Hidden: Yes
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: EE97F000
Module End: EE982000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: EE93B000
Module End: EE940000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: F7F98000
Module End: F7F99000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswFsBlk.SYS
Service Name: aswFsBlk
Module Base: F7C85000
Module End: F7C88000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drvnddm.sys
Service Name: drvnddm
Module Base: ED61A000
Module End: ED624000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsndres.sys
Service Name: tfsndres
Module Base: F7EF5000
Module End: F7EF6000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsnifs.sys
Service Name: tfsnifs
Module Base: ECF87000
Module End: ECF9C000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsnopio.sys
Service Name: tfsnopio
Module Base: ED034000
Module End: ED038000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsnpool.sys
Service Name: tfsnpool
Module Base: F7D7D000
Module End: F7D7F000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsnboio.sys
Service Name: tfsnboio
Module Base: EE92B000
Module End: EE932000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsncofs.sys
Service Name: tfsncofs
Module Base: ED5F6000
Module End: ED5FF000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsndrct.sys
Service Name: tfsndrct
Module Base: F7EF9000
Module End: F7EFA000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsnudf.sys
Service Name: tfsnudf
Module Base: ECF6F000
Module End: ECF87000
Hidden: No
Module Name: C:\WINDOWS\system32\dla\tfsnudfa.sys
Service Name: tfsnudfa
Module Base: ECF56000
Module End: ECF6F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
Service Name: fssfltr
Module Base: F71FC000
Module End: F7208000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: ECFCC000
Module End: ECFD0000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: ECE42000
Module End: ECE66000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\aswMon2.SYS
Service Name: aswMon2
Module Base: ECDD8000
Module End: ECDF2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: ECB43000
Module End: ECB58000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: ECD90000
Module End: ECD9F000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: EC930000
Module End: EC95D000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Service Name: ParVdm
Module Base: F7DAB000
Module End: F7DAD000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\ASCTRM.SYS
Service Name: ASCTRM
Module Base: F7DCB000
Module End: F7DCD000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys
Service Name: mdmxsdk
Module Base: ECC90000
Module End: ECC93000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\srv.sys
Service Name: Srv
Module Base: EC7E8000
Module End: EC840000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys
Service Name: ---
Module Base: EC798000
Module End: EC79B000
Hidden: Yes
Module Name: C:\WINDOWS\system32\Drivers\LVPr2Mon.sys
Service Name: LVPr2Mon
Module Base: F7C1D000
Module End: F7C22000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: EC2CF000
Module End: EC310000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
Service Name: IpFilterDriver
Module Base: EC247000
Module End: EC250000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: EBEE4000
Module End: EBF0F000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\fdc.sys
Service Name: Fdc
Module Base: F7B3D000
Module End: F7B44000
Hidden: No
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwAddBootEntry
Address: EE99DFC4
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwAllocateVirtualMemory
Address: EEA02510
Driver Base: EE9F8000
Driver End: EEA43000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwAssignProcessToJobObject
Address: EEB49928
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwClose
Address: EE9C16A9
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwConnectPort
Address: EEB4864C
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateEvent
Address: EE9A0456
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwCreateEventPair
Address: EE9A04AE
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwCreateFile
Address: EEB4F316
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateIoCompletion
Address: EE9A05C4
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwCreateKey
Address: EE9C105D
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwCreateMutant
Address: EE9A03AC
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwCreatePort
Address: EEB4846A
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateProcess
Address: EEB49EE8
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateProcessEx
Address: EEB46978
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateSection
Address: EE9A04FE
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwCreateSemaphore
Address: EE9A0400
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwCreateThread
Address: EEB47634
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwCreateTimer
Address: EE9A0572
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwDebugActiveProcess
Address: EEB47D22
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwDeleteBootEntry
Address: EE99DFE8
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwDeleteKey
Address: EE9C1D6F
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwDeleteValueKey
Address: EE9C2025
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwDuplicateObject
Address: EE9A0848
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwEnumerateKey
Address: EE9C1BDA
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwEnumerateValueKey
Address: EE9C1A45
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwFreeVirtualMemory
Address: EEA025C0
Driver Base: EE9F8000
Driver End: EEA43000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwLoadDriver
Address: EE99DDB2
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwModifyBootEntry
Address: EE99E00C
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwNotifyChangeKey
Address: EE9A09BC
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwNotifyChangeMultipleKeys
Address: EE99EAA4
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenEvent
Address: EE9A0486
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenEventPair
Address: EE9A04D6
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenFile
Address: EEB4F694
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwOpenIoCompletion
Address: EE9A05EE
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenKey
Address: EE9C13B9
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenMutant
Address: EE9A03D8
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenProcess
Address: EE9A0680
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenSection
Address: EE9A053E
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenSemaphore
Address: EE9A042E
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenThread
Address: EE9A0764
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwOpenTimer
Address: EE9A059C
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwProtectVirtualMemory
Address: EEA02658
Driver Base: EE9F8000
Driver End: EEA43000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwQueryKey
Address: EE9C18C0
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwQueryObject
Address: EE99E96A
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwQueryValueKey
Address: EE9C1712
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwQueueApcThread
Address: EEB49A44
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwRenameKey
Address: EEA0A9E6
Driver Base: EE9F8000
Driver End: EEA43000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS
Function Name: ZwRequestPort
Address: EEB48CB0
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwRequestWaitReplyPort
Address: EEB49018
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwRestoreKey
Address: EE9C06D0
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwResumeThread
Address: EEB480CE
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSecureConnectPort
Address: EEB4886E
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSetBootEntryOrder
Address: EE99E030
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwSetBootOptions
Address: EE99E054
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwSetContextThread
Address: EEB47BCC
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSetSystemInformation
Address: EE99DE0C
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwSetSystemPowerState
Address: EE99DF48
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwSetValueKey
Address: EE9C1E76
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwShutdownSystem
Address: EE99DF24
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwSuspendProcess
Address: EEB481FE
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSuspendThread
Address: EEB47F7A
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwSystemDebugControl
Address: EE99DF6C
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwTerminateProcess
Address: EEB47472
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwTerminateThread
Address: EEB47A66
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwUnloadDriver
Address: EEB49518
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
Function Name: ZwUnloadKey
Address: EC7986D0
Driver Base: EC798000
Driver End: EC79B000
Driver Name: \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys
Function Name: ZwVdmControl
Address: EE99E078
Driver Base: EE98B000
Driver End: EE9F8000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS
Function Name: ZwWriteVirtualMemory
Address: EEB49804
Driver Base: EEB46000
Driver End: EEB77000
Driver Name: \??\C:\WINDOWS\system32\drivers\OADriver.sys
******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: ObMakeTemporaryObject
At Address: 805A038B
Jump To: EEA1369C
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
Hooked Function: ObInsertObject
At Address: 805650BA
Jump To: EEA1515C
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0635.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0636.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0637.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0638.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0639.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0640.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0641.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0642.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0643.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0644.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0645.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0646.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0647.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0648.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0649.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0650.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0651.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0652.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0653.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0654.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0655.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0656.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0657.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0658.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0659.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0660.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0661.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0662.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0663.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0664.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0665.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0666.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0667.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0668.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0669.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0670.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0671.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0672.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0673.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0674.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0675.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0676.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0677.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0678.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0679.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0680.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0681.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0689.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0690.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0691.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0692.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0693.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0694.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0695.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0696.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0697.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0698.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0699.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0700.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0701.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0702.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0703.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0704.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0705.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0706.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0707.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0708.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0709.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0710.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0711.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0712.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0713.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0714.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0715.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0716.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0717.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0718.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0719.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0720.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0721.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0722.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0723.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0724.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0725.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0726.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0727.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0728.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0729.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0730.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0731.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0732.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0733.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0734.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0735.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0736.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0737.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0738.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0739.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0740.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0741.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0742.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0743.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0744.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0745.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0746.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0747.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0748.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0749.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0750.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\IMG_0751.JPG
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 061.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 062.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 063.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 064.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 065.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 066.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 067.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 068.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 069.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 070.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 071.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 072.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 073.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 074.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\LPool R.O.Pics - October 08 075.jpg
Status: Access denied
Object: C:\0ebf499d58908eb22937c3c82992ec\1 - LV RO Pictures\Thumbs.db
Status: Access denied
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{9A02A81E-BD94-AABE-DCF5-538661AB6A58}\01\10-{9A02A81E-BD94-AABE-DCF5-538661AB6A58}-v1-{B2A7
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\00\427-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\01\11-{D97343BA-678F-F720-2F4D-86BD4A8269B5}-v1
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\01\471-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\02\418-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\03\426-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\04\470-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\05\420-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\06\430-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\07\425-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\08\431-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\09\428-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\10\429-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\12\434-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\13\433-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\14\435-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\15\438-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{D97343BA-678F-F720-2F4D-86BD4A8269B5}\16\447-{B2A7C221-3E8D-43D6-99FB-62FB66B7DC43}-v
Status: Hidden
Object: C:\Documents and Settings\Don Higham\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\romaburdett@hotma