Announcement

Collapse
No announcement yet.

A wonderful birthday present...

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    A wonderful birthday present...

    I was doing a school project today and it required me to record some sound, so I opened up sound recorder but it wouldn't find my mic. So I did google.com search on sound recorder, and I got this: http://www.roemersoftware.com/free-sound-recorder.html

    Never use that, by the way.

    It didn't work either anyways, and it was one of those things where you were supposed to restart your computer when you install it but I didn't. When it didn't work, I went to uninstall it, but there wasn't an option to do that in the program menu (of course!). So I uninstalled it with the add/remove programs.

    It uninstalled, and to my knowledge it was off my computer... that was where I was wrong.

    I restarted my computer later that day to find when I first started up, right after I clicked the user I wanted to sign on with, before I could even see the desktop, a windows box saying that the program above couldn't find some .dll..... It was strange because that was before I could even see my desktop, it was just that window and a black screen.

    So its not off my computer, its not in my program files, so it must be in my registry right?

    Hijack this log:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:11:27 PM, on 1/29/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16575)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Grisoft\AVG7\avgcc.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Logitech\SetPoint II\SetpointII.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Grisoft\AVG7\avgw.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\Steam\Steam.exe
    C:\Program Files\Steam\GameOverlayUI.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://xtranet.aetna.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: SetPointII.lnk = ?
    O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
    O13 - Gopher Prefix:
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

    --
    End of file - 6501 bytes

    Can you guys see anything ?

    The big problem is that for some reason everything is running a LOT slower. Which is bad.

    Tried loading up cod4, took FOREVER to load, so long it disconnected and I had to do it again to play. The frame rate was OK, but I was getting bad frequent freezes. I did a quick superpi, on the 1m my time increased 5 seconds (from 21 to 26). I wasn't running anything that would change the time that anything near that much.

    What do you guys suggest? System restore? I don't like doing those, and they never seem to work anyways. Going to start spyware/virus checking, but it seems funny this would only happen after the restart and the box if it were that.

    Please halp me O computer wizards, give me a good birthday present and fix this.
    [img]http://img149.imageshack.us/img149/120/latinsigsj0.jpg[/img] [img]http://sigs.2142-stats.com/BenKenobi_player_7511.png[/img] [img]http://www.ronpaul2008.com/img/public_banners/hope-banner1.gif[/img] [url=http://www.cainslair.com/paypal2Cain.htm/]
    You will donate to Cain's. Now.[/url]

    #2
    download spybot-search and destroy, run it


    also, what anti-virus do you have?

    Comment


      #3
      I already have ad-ware.. and my virus scanner is AVG anti-virus free
      [img]http://img149.imageshack.us/img149/120/latinsigsj0.jpg[/img] [img]http://sigs.2142-stats.com/BenKenobi_player_7511.png[/img] [img]http://www.ronpaul2008.com/img/public_banners/hope-banner1.gif[/img] [url=http://www.cainslair.com/paypal2Cain.htm/]
      You will donate to Cain's. Now.[/url]

      Comment


        #4
        Your best bet for getting rid of a Trojan, I'm talking from years of experience here.

        Spybot Search-and-destroy + Safemode = Problem Free.

        Give it a go, and get back to me/us. You'll be surprised at what you find.

        Comment


          #5
          I don't think I've got a trojan, tho

          Did AVG and Ad-aware, nothing other than a few trackers....

          I'll try the search and destroy tmrw
          [img]http://img149.imageshack.us/img149/120/latinsigsj0.jpg[/img] [img]http://sigs.2142-stats.com/BenKenobi_player_7511.png[/img] [img]http://www.ronpaul2008.com/img/public_banners/hope-banner1.gif[/img] [url=http://www.cainslair.com/paypal2Cain.htm/]
          You will donate to Cain's. Now.[/url]

          Comment


            #6
            Originally posted by BenKenobi
            I don't think I've got a trojan, tho

            Did AVG and Ad-aware, nothing other than a few trackers....

            I'll try the search and destroy tmrw
            Trust me, I thought I only had 1, ended up I had 7... :P And make sure you run it in Safemode. It's the only way you can be sure that you've gotten rid of it. Because if you do it while windows is running, it has a tendency to come back. Whatever it finds.

            And not only Trojans, but it finds virsus's and other bugs your other two might've missed.

            I would tell you to do this if I didnt have the best intentions in mind. Trust me, it works wonders

            Comment


              #7
              Make sure you disable the system restore too.

              Comment


                #8
                Hey man, I do this for a living, and first thing you always want to do is to exhaust ALL possibilities of trying to remove it through add/remove programs.

                When I get home I will give you a tool that will surely remove everything harmful on your computer.

                For the time being, There is also a trial version of a program that I use which is called "RegRun Gold" Here: http://www.greatis.com/security/download.htm

                It is one of the best tools I've used as a last resort, but I will give you some of my tech tools that actually work, instead of some of these freebie programs that you can get anywhere. I will also give you some other tools as well.

                A good FREE program that is another one of my best PC tuneup tools is called Crap Cleaner. http://www.ccleaner.com I have tested THOUSANDS of software tools and this is one of the most handy tools to use and should be followed by a "Disk Cleanup" and then a "Defrag" but don't do any of this until you have removed everything that is infecting your computer. I could go into more detail and provide the downloads if I werent at work.

                Meanwhile you might want to check out one of the Stickies in the "Computer Lab" section. I believe there is one that has a list of tools that are all semi good for taking care of problems like this.
                http://dark4se.com/cainslairforums/viewtopic.php?t=6354

                ~~mike~~

                Comment


                  #9
                  Wow, thanks Mike... I anxiously wait your arrival home
                  [img]http://img149.imageshack.us/img149/120/latinsigsj0.jpg[/img] [img]http://sigs.2142-stats.com/BenKenobi_player_7511.png[/img] [img]http://www.ronpaul2008.com/img/public_banners/hope-banner1.gif[/img] [url=http://www.cainslair.com/paypal2Cain.htm/]
                  You will donate to Cain's. Now.[/url]

                  Comment


                    #10
                    Originally posted by Cold Catalyst
                    Originally posted by BenKenobi
                    I don't think I've got a trojan, tho

                    Did AVG and Ad-aware, nothing other than a few trackers....

                    I'll try the search and destroy tmrw
                    Trust me, I thought I only had 1, ended up I had 7... :P And make sure you run it in Safemode. It's the only way you can be sure that you've gotten rid of it. Because if you do it while windows is running, it has a tendency to come back. Whatever it finds.

                    And not only Trojans, but it finds virsus's and other bugs your other two might've missed.

                    I would tell you to do this if I didnt have the best intentions in mind. Trust me, it works wonders
                    By the way, spybot in safe mode picked up 3 tracking cookies
                    [img]http://img149.imageshack.us/img149/120/latinsigsj0.jpg[/img] [img]http://sigs.2142-stats.com/BenKenobi_player_7511.png[/img] [img]http://www.ronpaul2008.com/img/public_banners/hope-banner1.gif[/img] [url=http://www.cainslair.com/paypal2Cain.htm/]
                    You will donate to Cain's. Now.[/url]

                    Comment


                      #11
                      Originally posted by BenKenobi
                      Originally posted by Cold Catalyst
                      Originally posted by BenKenobi
                      I don't think I've got a trojan, tho

                      Did AVG and Ad-aware, nothing other than a few trackers....

                      I'll try the search and destroy tmrw
                      Trust me, I thought I only had 1, ended up I had 7... :P And make sure you run it in Safemode. It's the only way you can be sure that you've gotten rid of it. Because if you do it while windows is running, it has a tendency to come back. Whatever it finds.

                      And not only Trojans, but it finds virsus's and other bugs your other two might've missed.

                      I would tell you to do this if I didnt have the best intentions in mind. Trust me, it works wonders
                      By the way, spybot in safe mode picked up 3 tracking cookies
                      That's all? Well.. I'm stumped

                      Comment


                        #12
                        You can always try a windows repair. Theres 2 ways to do it. One where it wipes everything out and another that leaves everything alone and just restores the windows files that were changed. So after the process is over all your programs are still there, your Icons and desktop are just the way you left it ect.

                        It really wouldn't hurt to do a system restore, you always have the option of undoing it if it doesn't make a difference.
                        Old school or the new, doesn't mean a thing if your heart's not true...

                        Comment


                          #13
                          Sorry man, I forgot my wife was taking my little girl to see "Hannah Montana" in concert last night, so I had to babysit my two boys and didn't get much of a chance to get out to my shop last night. I'll be going home for lunch today where I will just upload a lot of tools to a server for you. I'll then PM you with some downloads.

                          Comment


                            #14
                            First thing, download THIS TOOL

                            I use this instead of windows default TaskManager, and if you unzip this somewhere safe on your C drive where it won't get deleted ... you can choose the option to have it actually replace windows Task Manager ... the option can be unchecked later, but when you hit CTRL-ALT-DEL, this will popup instead.

                            First off get this thing downloaded and when you run it, see if there are anything out of the ordinary. You will normally see things highlighted in different colors.. red being bad or unknown stuff.. but just because it is red doesn't mean it is bad. If you are not sure what a process is... right click it and then click "Google" and it will do a google search for that process and you can find out what it is...

                            Lets see if there is anything weird going on in the processes first.

                            Comment


                              #15
                              This is what I got Process PID CPU Description Company Name
                              System Idle Process 0 98.49
                              Interrupts n/a Hardware Interrupts
                              DPCs n/a Deferred Procedure Calls
                              System 4
                              smss.exe 356 Windows Session Manager Microsoft Corporation
                              csrss.exe 484 Client Server Runtime Process Microsoft Corporation
                              wininit.exe 532 Windows Start-Up Application Microsoft Corporation
                              services.exe 576 Services and Controller app Microsoft Corporation
                              svchost.exe 776 Host Process for Windows Services Microsoft Corporation
                              ehmsas.exe 1696 Media Center Media Status Aggregator Service Microsoft Corporation
                              svchost.exe 832 Host Process for Windows Services Microsoft Corporation
                              svchost.exe 888 Host Process for Windows Services Microsoft Corporation
                              svchost.exe 960 Host Process for Windows Services Microsoft Corporation
                              audiodg.exe 1080
                              svchost.exe 984 Host Process for Windows Services Microsoft Corporation
                              dwm.exe 1940 Desktop Window Manager Microsoft Corporation
                              WUDFHost.exe 2540 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation
                              svchost.exe 1004 Host Process for Windows Services Microsoft Corporation
                              taskeng.exe 1820 Task Scheduler Engine Microsoft Corporation
                              taskeng.exe 2944 Task Scheduler Engine Microsoft Corporation
                              taskeng.exe 7836 Task Scheduler Engine Microsoft Corporation
                              SLsvc.exe 1112 Microsoft Software Licensing Service Microsoft Corporation
                              svchost.exe 1160 Host Process for Windows Services Microsoft Corporation
                              svchost.exe 1284 Host Process for Windows Services Microsoft Corporation
                              spoolsv.exe 1524 Spooler SubSystem App Microsoft Corporation
                              svchost.exe 1548 Host Process for Windows Services Microsoft Corporation
                              avgamsvr.exe 340 AVG Alert Manager GRISOFT, s.r.o.
                              avgupsvc.exe 784 AVG Update Service GRISOFT, s.r.o.
                              avgrssvc.exe 1152 AVG Resident Shield Service GRISOFT, s.r.o.
                              avgrssvc.exe 1228 AVG Resident Shield Service GRISOFT, s.r.o.
                              avgemc.exe 1416 AVG E-Mail Scanner GRISOFT, s.r.o.
                              PnkBstrA.exe 296
                              svchost.exe 1276 Host Process for Windows Services Microsoft Corporation
                              svchost.exe 1900 Host Process for Windows Services Microsoft Corporation
                              svchost.exe 1240 Host Process for Windows Services Microsoft Corporation
                              SearchIndexer.exe 1252 Microsoft Windows Search Indexer Microsoft Corporation
                              iPodService.exe 2708 iPodService Module Apple Inc.
                              wmpnetwk.exe 3592 Windows Media Player Network Sharing Service Microsoft Corporation
                              lsass.exe 592 Local Security Authority Process Microsoft Corporation
                              lsm.exe 600 Local Session Manager Service Microsoft Corporation
                              csrss.exe 544 Client Server Runtime Process Microsoft Corporation
                              winlogon.exe 692 Windows Logon Application Microsoft Corporation
                              explorer.exe 1980 Windows Explorer Microsoft Corporation
                              MSASCui.exe 1000 Windows Defender User Interface Microsoft Corporation
                              qttask.exe 1580 QuickTime Task Apple Inc.
                              iTunesHelper.exe 1612 iTunesHelper Module Apple Inc.
                              rundll32.exe 1876 Windows host process (Rundll32) Microsoft Corporation
                              ehtray.exe 828 Media Center Tray Applet Microsoft Corporation
                              SetPointII.exe 1808 Logitech SetPoint EventManager Logitech Inc.
                              KHALMNPR.exe 2724 Logitech KHAL Main Process Logitech, Inc.
                              wmpnscfg.exe 3548 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
                              firefox.exe 5960 Firefox Mozilla Corporation
                              procexp.exe 5208 1.52 Sysinternals Process Explorer Sysinternals
                              rundll32.exe 2132 Windows host process (Rundll32) Microsoft Corporation
                              aolsoftware.exe 2896 AOL America Online, Inc.

                              Process: System Pid: 4

                              Type Name
                              \KernelObjects\Session1
                              \KernelObjects\Session0
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              \KernelObjects\Session1
                              <Unknown type> \SeRmCommandPort
                              <Unknown type> \UMDFCommunicationPorts\Loopback-5fd89c65-cf82-11dc-bd83-00044b01d495
                              Desktop \Disconnect
                              Desktop \Disconnect
                              Directory \Device\Harddisk1
                              Directory \Windows\WindowStations
                              Directory \Sessions\1\Windows\WindowStations
                              Directory \Device\Http
                              Directory \Device\Harddisk0
                              Event \BaseNamedObjects\NVFlushUnattachEvent
                              Event \UniqueSessionIdEvent
                              Event \UniqueInteractiveSessionIdEvent
                              Event \Sessions\1\BaseNamedObjects\EventShutDownCSRSS
                              Event \KernelObjects\LowMemoryCondition
                              Event \LanmanServerAnnounceEvent
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File C:\System Volume Information\{61aa9356-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File C:\Windows\System32\config\RegBack\SOFTWARE
                              File C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\RawIp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\en-US\win32k.sys.mui
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\System Volume Information\{61aa91eb-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\Windows\bootstat.dat
                              File C:\Windows\System32\config\SOFTWARE
                              File C:\System Volume Information\{61aa93a0-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\Windows\System32\config\SYSTEM.LOG1
                              File C:\Windows\System32\config\SAM.LOG1
                              File C:\Windows\System32\config\COMPONENTS
                              File C:\Windows\System32\config\SECURITY.LOG1
                              File C:\Windows\System32\config\DEFAULT.LOG1
                              File C:\Windows\System32\config\COMPONENTS.LOG2
                              File C:\Windows\System32\config\SOFTWARE.LOG1
                              File C:\Windows\System32\config\SAM.LOG2
                              File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsM pPsSession.etl
                              File C:\System Volume Information\{61aa9452-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\System Volume Information\{61aa9472-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf
                              File C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regt rans-ms
                              File C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regt rans-ms
                              File \clfs
                              File \clfs
                              File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEve ntLog-System.etl
                              File C:\System Volume Information\{0317ac34-cec6-11dc-a37a-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\System Volume Information\{61aa961a-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEve ntlog-Security.etl
                              File C:\System Volume Information\{61aa9705-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\System Volume Information\{61aa967f-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\System Volume Information\{5fd89cf5-cf82-11dc-bd83-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File \Device\Tcp
                              File C:\System Volume Information\{61aa94ec-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEve ntLog-Application.etl
                              File C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl .002
                              File C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDia gLog.etl
                              File C:\System Volume Information\{6f75c817-cf25-11dc-bcde-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\config\SECURITY
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Udp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File C:\Windows\System32\LogFiles\Scm\SCM.EVM
                              File C:
                              File C:\Windows\ServiceProfiles\NetworkService\NTUSER.D AT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf
                              File C:\Windows\ServiceProfiles\NetworkService\NTUSER.D AT
                              File C:\Windows\ServiceProfiles\NetworkService\ntuser.d at.LOG1
                              File C:\Windows\ServiceProfiles\NetworkService\ntuser.d at.LOG2
                              File C:\Windows\ServiceProfiles\NetworkService\NTUSER.D AT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regt rans-ms
                              File C:\Windows\ServiceProfiles\NetworkService\NTUSER.D AT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regt rans-ms
                              File \clfs
                              File \clfs
                              File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT {3a539869-6a70-11db-887c-d362bd253390}.TM.blf
                              File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
                              File C:\Windows\ServiceProfiles\LocalService\ntuser.dat .LOG1
                              File C:\Windows\ServiceProfiles\LocalService\ntuser.dat .LOG2
                              File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT {3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regt rans-ms
                              File C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT {3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regt rans-ms
                              File \clfs
                              File \clfs
                              File C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl
                              File \Device\Tcp
                              File C:\Windows\System32\config\SOFTWARE.LOG2
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\config\SAM
                              File \Device\Mup
                              File \Device\Mup
                              File \Device\Mup
                              File \clfs
                              File C:\Users\Ben\ntuser.dat.LOG1
                              File \Device\NetbiosSmb
                              File C:\Users\Ben\ntuser.dat
                              File C:\Users\Ben\ntuser.dat.LOG2
                              File C:\Users\Ben\ntuser.dat{0dbd00cb-ba19-11db-8691-00044b01bf09}.TM.blf
                              File \Device\NetbiosSmb
                              File \Device\Tcp
                              File C:\Users\Ben\ntuser.dat{0dbd00cb-ba19-11db-8691-00044b01bf09}.TMContainer00000000000000000001.regt rans-ms
                              File C:\Users\Ben\ntuser.dat{0dbd00cb-ba19-11db-8691-00044b01bf09}.TMContainer00000000000000000002.regt rans-ms
                              File \clfs
                              File \Device\NamedPipe\
                              File C:\Users\Ben\AppData\Local\Microsoft\Windows\UsrCl ass.dat
                              File C:\Users\Ben\AppData\Local\Microsoft\Windows\UsrCl ass.dat.LOG1
                              File C:\Users\Ben\AppData\Local\Microsoft\Windows\UsrCl ass.dat.LOG2
                              File \Device\NamedPipe\
                              File C:\Users\Ben\AppData\Local\Microsoft\Windows\UsrCl ass.dat{2917e5ee-b82e-11db-b9b6-00044b01bf09}.TM.blf
                              File \clfs
                              File C:\Users\Ben\AppData\Local\Microsoft\Windows\UsrCl ass.dat{2917e5ee-b82e-11db-b9b6-00044b01bf09}.TMContainer00000000000000000001.regt rans-ms
                              File C:\Users\Ben\AppData\Local\Microsoft\Windows\UsrCl ass.dat{2917e5ee-b82e-11db-b9b6-00044b01bf09}.TMContainer00000000000000000002.regt rans-ms
                              File \clfs
                              File C:\Windows\System32\spool\SpoolerETW.etl
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\SLsvc.exe
                              File C:\Windows\System32\ntdll.dll
                              File C:\Windows\System32\kernel32.dll
                              File C:\Windows\System32\advapi32.dll
                              File C:\Windows\System32\rpcrt4.dll
                              File C:\Windows\System32\msvcrt.dll
                              File C:\Windows\System32\SLC.dll
                              File C:\Windows\System32\user32.dll
                              File C:\Windows\System32\gdi32.dll
                              File C:\Windows\System32\dnsapi.dll
                              File C:\Windows\System32\ws2_32.dll
                              File C:\Windows\System32\nsi.dll
                              File C:\Windows\System32\imm32.dll
                              File C:\Windows\System32\msctf.dll
                              File C:\Windows\System32\lpk.dll
                              File C:\Windows\System32\usp10.dll
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \clfs
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \clfs
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\$Extend\$RmMetadata\$Txf
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \Device\Tcp
                              File \Device\Tcp
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File \clfs
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\wbem\Logs\WMITracing.log
                              File \clfs
                              File C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer000 00000000000000002
                              File C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer000 00000000000000001
                              File \Device\Tcp
                              File C:\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf
                              File \clfs
                              File \Device\Udp
                              File C:\Windows\System32\config\TxR\{26ba2207-669a-11dc-8b31-f261637aad0d}.TxR.blf
                              File \clfs
                              File \Device\Tcp
                              File C:\Windows\System32\config\DEFAULT
                              File C:\Windows\System32\config\SYSTEM.LOG2
                              File \Device\Tcp
                              File C:\Windows\System32\config\SYSTEM
                              File C:\System Volume Information\{61aa928b-c736-11dc-9b45-00044b01d495}{3808876b-c176-4e48-b7ae-04046e6cc752}
                              File C:\Windows\System32\config\RegBack\SECURITY
                              File C:\Windows\System32\rsaenh.dll
                              File C:\Windows\System32\config\TxR\{26ba2207-669a-11dc-8b31-f261637aad0d}.TxR.2.regtrans-ms
                              File \clfs
                              File C:\Windows\System32\setupapi.dll
                              File C:\Windows\System32\config\COMPONENTS.LOG1
                              File \clfs
                              File \Device\NetBT_Tcpip_{41400971-B406-453C-9693-1D8986F75EF1}
                              File C:\Windows\System32\ole32.dll
                              File C:\Windows\System32\wfp\wfpdiag.etl
                              File C:\Windows\System32\config\RegBack\DEFAULT
                              File C:\Windows\System32\oleaut32.dll
                              File C:\Windows\System32\config\DEFAULT.LOG2
                              File C:\Windows\System32\wintrust.dll
                              File C:\Windows\System32\crypt32.dll
                              File C:\Windows\System32\msasn1.dll
                              File C:\Windows\System32\userenv.dll
                              File C:\Windows\System32\secur32.dll
                              File C:\pagefile.sys
                              File C:\Windows\System32\config\RegBack\COMPONENTS
                              File \Device\Tcp
                              File \Device\Tcp
                              File C:\Windows\System32\imagehlp.dll
                              File C:\Windows\System32\config\TxR\{26ba2207-669a-11dc-8b31-f261637aad0d}.TxR.1.regtrans-ms
                              File C:\Windows\System32\config\RegBack\SAM
                              File \Device\Tcp
                              File C:\Windows\System32\config\SECURITY.LOG2
                              File C:\Windows\System32\config\TxR\{26ba2207-669a-11dc-8b31-f261637aad0d}.TxR.0.regtrans-ms
                              File C:\Windows\System32\Msdtc\KtmRmTmContainer00000000 000000000001
                              File C:\Windows\System32\Msdtc\KtmRmTmContainer00000000 000000000002
                              File C:\Windows\System32\Msdtc\KtmRmTm.blf
                              File C:\Windows\System32\config\RegBack\SYSTEM
                              Key HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdap ter
                              Key HKLM\SYSTEM\ControlSet001\Services\AvgMfx86\Parame ters
                              Key HKLM\SYSTEM\ControlSet001\Control\Session Manager\Memory Management\PrefetchParameters
                              Key HKLM\SYSTEM\ControlSet001\Control\ProductOptions
                              Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
                              Key HKLM\SYSTEM\ControlSet001\Control\WMI\Security
                              Key HKLM\SYSTEM\ControlSet001\Control\DeviceClasses\{2 8d78fad-5a12-11d1-ae5b-0000f803a8c2}\##?#USB#VID_03F0&PID_3B11&MI_01#6&1e 478a30&0&0001#{28d78fad-5a12-11d1-ae5b-0000f803a8c2}\#\Device Parameters
                              Key HKLM\SYSTEM\Setup
                              Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 1
                              Key HKLM\SOFTWARE\Microsoft\Cryptography\RNG
                              Key HKLM\SYSTEM\ControlSet001\Control\Session Manager\Quota System
                              Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 5\Scsi Bus 0
                              Key HKLM\SOFTWARE\Microsoft\Cryptography\RNG
                              Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Gro up Policy\State\Machine
                              Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Gro up Policy\State\Machine
                              Key HKLM\SYSTEM\ControlSet001\Services\HTTP\Parameters \UrlAclInfo
                              Key HKLM\SYSTEM\ControlSet001\Services\disk
                              Key HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-2P-B4
                              Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameter s\PersistentRoutes
                              Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameter s
                              Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameter s\Interfaces\{41400971-B406-453C-9693-1D8986F75EF1}
                              Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameter s\Interfaces\{0ADF0BE0-4F9A-4E55-A394-A026F202DC9F}
                              Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameter s\Interfaces\{3a539854-6a70-11db-887c-806e6f6e6963}
                              Key HKLM\SYSTEM\ControlSet001\Control\hivelist
                              Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 3\Scsi Bus 1
                              Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 4\Scsi Bus 1
                              Key HKLM\SYSTEM\ControlSet001
                              Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 3\Scsi Bus 0
                              Key HKLM\SYSTEM\ControlSet001\Services\disk
                              Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\ Order
                              Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0
                              Key HKLM\SYSTEM\ControlSet001\Services\disk
                              Key HKLM\SYSTEM\ControlSet001\Services\disk
                              Key \REGISTRY
                              Key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 4\Scsi Bus 0
                              Key HKLM\SYSTEM\ControlSet001\Control\Lsa
                              Key HKLM\SYSTEM\ControlSet001\Services\Mup
                              Key HKLM\SYSTEM\ControlSet001\Services\Smb\Parameters
                              Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameter s
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Process <Error Opening Process>
                              Section \Device\PhysicalMemory
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              Thread <Error Opening Thread>
                              [img]http://img149.imageshack.us/img149/120/latinsigsj0.jpg[/img] [img]http://sigs.2142-stats.com/BenKenobi_player_7511.png[/img] [img]http://www.ronpaul2008.com/img/public_banners/hope-banner1.gif[/img] [url=http://www.cainslair.com/paypal2Cain.htm/]
                              You will donate to Cain's. Now.[/url]

                              Comment

                              Cain's Lair Forums Statistics

                              Collapse

                              Topics: 26,182   Posts: 269,814   Members: 6,177   Active Members: 4
                              Welcome to our newest member, EzraGilchr.

                              Today's Birthdays

                              Collapse

                              There are no members with birthdays today.

                              Top Active Users

                              Collapse

                              There are no top active users.
                              widgetinstance 184 (More Posts) skipped due to lack of content & hide_module_if_empty option.
                              Working...
                              X