OTListIt logfile created on: 5/18/2009 7:15:32 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Sarah\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.53 Mb Total Physical Memory | 635.17 Mb Available Physical Memory | 62.06% Memory free
1.66 Gb Paging File | 1.38 Gb Available in Paging File | 83.03% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 114.49 Gb Total Space | 77.60 Gb Free Space | 67.78% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SARAH-COFWCBSLF
Current User Name: Sarah
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
PRC - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Documents and Settings\Sarah\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AOL ACS [Auto | Stopped]) -- File not found
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
SRV - (N360 [Auto | Running]) -- C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe (Symantec Corporation)
SRV - (Nero BackItUp Scheduler 4.0 [Auto | Stopped]) -- File not found
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (PavPrSrv [Auto | Stopped]) -- File not found
SRV - (Pml Driver HPZ12 [Unknown | Running]) -- C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
SRV - (rpcapd [On_Demand | Stopped]) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (EraserSvc10910 [Auto | Stopped]) -- C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV - (ASPI32 [System | Running]) -- C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (BHDrvx86 [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\BHDrvx86.sys (Symantec Corporation)
DRV - (ccHP [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\ccHPx86.sys (Symantec Corporation)
DRV - (cmpci [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc)
DRV - (Edspport [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\es56tpi.sys (Creative Labs,Inc.)
DRV - (eeCtrl [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (IDSxpx86 [System | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090508.002\IDSxpx86.sys (Symantec Corporation)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MODEMCSA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (NAVENG [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090518.038\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090518.038\NAVEX15.SYS (Symantec Corporation)
DRV - (nm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\NMnt.sys (Microsoft Corporation)
DRV - (NPF [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (prodrv06 [System | Running]) -- C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prohlp02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prosync1 [Boot | Running]) -- C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (rtl8139 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfhlp01 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (sisagp [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SRTSP [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA [Boot | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMEFA.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) -- C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMIDS.SYS (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) -- C:\WINDOWS\system32\drivers\N360\0300000.087\SYMTDI.SYS (Symantec Corporation)
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (wanatw [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://windiwsfsearch.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://windiwsfsearc...q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com
IE - HKLM\Software\Microsoft\Internet Explorer\SearchURL\w, = http://windiwsfsearch.com/search?q=%s
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://windiwsfsearch.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\w, = http://windiwsfsearch.com/search?q=%s
IE - URLSearchHook: <default> - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = cdn
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/16 22:33:30 | 00,000,000 | ---D | M]
O1 HOSTS File: (116 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 antivirprotection.com
O1 - Hosts: 94.232.248.66 www.antivirprotection.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [stezinit] C:\WINDOWS\sprscore.exe (Systems Integration 2)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [AvirTr] "C:\Program Files\AvirTrsoftware\AvirTr.exe" File not found
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SearchAndDestroyT] C:\Program Files\Search And Destroy\SearchAndDestroy.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [system tool] C:\WINDOWS\sysguard.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZJxdm025YYUS File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: //@[email protected]/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 3 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} http://codecs.micros...86/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.micros...386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1242526973656 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.su...ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupd...7999.8188310185 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (huwv5r8msm5y7.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\SYSTEM32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\SYSTEM32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\SYSTEM32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\SYSTEM32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\SYSTEM32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\System32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\SYSTEM32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\SYSTEM32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\SYSTEM32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\SYSTEM32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\SYSTEM32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\SYSTEM32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\SYSTEM32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\SYSTEM32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\SYSTEM32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\SYSTEM32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\SYSTEM32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/19 01:56:07 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2005/01/19 01:02:39 | 00,000,055 | ---- | M] () - C:\AUTOEXEC.SOL -- [ NTFS ]
O33 - MountPoints2\{5b0f4bed-d11d-11dd-b099-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{5b0f4bed-d11d-11dd-b099-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5b0f4bed-d11d-11dd-b099-00038a000015}\Shell\AutoRun\command - "" = C:\WINDOWS\SYSTEM32\setup.exe -- [2008/04/13 17:12:34 | 00,023,040 | ---- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/18 07:12:34 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
File not found -- C:\WINDOWS\System32\UACumyirijxoovelvk.dll
File not found -- C:\WINDOWS\System32\UACkijyudlovmvwysa.dll
[2009/05/18 07:12:26 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTListIt2.exe
[2009/05/17 07:56:06 | 00,001,831 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Liong The Lost Amulets.lnk
[2009/05/16 22:39:46 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/16 22:39:46 | 00,000,706 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/16 22:39:44 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/16 22:39:42 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/16 22:39:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/16 22:39:16 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Sarah\Desktop\mbs.exe
[2009/05/16 22:36:57 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Sarah\Desktop\mbam-setup.exe
[2009/05/16 21:46:12 | 00,000,790 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/05/16 21:45:42 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/05/16 21:43:47 | 06,367,264 | ---- | C] () -- C:\Documents and Settings\Sarah\My Documents\s.exe
[2009/05/16 19:57:48 | 00,000,000 | ---D | C] -- C:\Program Files\Norton Support
[2009/05/16 19:39:56 | 00,762,348 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\Cat.DB
[2009/05/16 19:31:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2009/05/16 19:30:36 | 00,036,400 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SymIM.sys
[2009/05/16 19:30:31 | 00,124,464 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/05/16 19:30:31 | 00,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009/05/16 19:30:31 | 00,007,386 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/05/16 19:30:31 | 00,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/05/16 19:30:31 | 00,000,000 | ---D | C] -- C:\Program Files\Symantec
[2009/05/16 19:30:18 | 00,001,919 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2009/05/16 19:30:16 | 00,310,320 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.sys
[2009/05/16 19:30:16 | 00,307,760 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.sys
[2009/05/16 19:30:16 | 00,217,392 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symtdi.sys
[2009/05/16 19:30:16 | 00,089,776 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symfw.sys
[2009/05/16 19:30:16 | 00,043,696 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.sys
[2009/05/16 19:30:16 | 00,039,984 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndisv.sys
[2009/05/16 19:30:16 | 00,037,296 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndis.sys
[2009/05/16 19:30:16 | 00,034,736 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symids.sys
[2009/05/16 19:30:15 | 00,482,352 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\cchpx86.sys
[2009/05/16 19:30:15 | 00,258,608 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.sys
[2009/05/16 19:29:57 | 00,003,373 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.inf
[2009/05/16 19:29:57 | 00,001,753 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.inf
[2009/05/16 19:29:57 | 00,001,528 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.inf
[2009/05/16 19:29:57 | 00,001,389 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.inf
[2009/05/16 19:29:57 | 00,001,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.inf
[2009/05/16 19:29:57 | 00,000,640 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.inf
[2009/05/16 19:29:57 | 00,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\isolate.ini
[2009/05/16 19:29:42 | 00,009,423 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.cat
[2009/05/16 19:29:41 | 00,007,410 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.cat
[2009/05/16 19:29:41 | 00,007,372 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.cat
[2009/05/16 19:29:41 | 00,007,364 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.CAT
[2009/05/16 19:29:41 | 00,007,355 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.cat
[2009/05/16 19:29:41 | 00,007,347 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.cat
[2009/05/16 19:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360\0300000.087
[2009/05/16 19:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
[2009/05/16 19:29:38 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2009/05/16 19:29:38 | 00,000,000 | ---D | C] -- C:\Program Files\Norton 360
[2009/05/16 19:29:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2009/05/16 19:29:25 | 00,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2009/05/16 19:29:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/05/16 19:27:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Desktop\Downloads
[2009/05/16 19:27:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\GetRightToGo
[2009/05/16 19:27:03 | 00,355,974 | ---- | C] (Digital River, Inc.) -- C:\Documents and Settings\Sarah\Desktop\Download_N360S300EN1_now.exe
[2009/05/16 09:31:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2009/05/16 09:31:20 | 01,222,128 | ---- | C] (McAfee, Inc.) -- C:\Documents and Settings\Sarah\My Documents\DMSetup.exe
[2009/05/16 07:56:27 | 06,367,264 | ---- | C] () -- C:\Documents and Settings\Sarah\My Documents\SUPERAntiSpyware.exe
[2009/05/15 07:04:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avanquest
[2009/05/15 06:59:46 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\AntiVirus
[2009/05/14 20:53:16 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\MSVolume.dll
[2009/05/13 20:31:23 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Doc3.doc
[2009/05/13 19:23:06 | 00,055,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/05/13 19:14:14 | 00,000,000 | -H-- | C] () -- C:\Documents and Settings\Sarah\My Documents\Default.rdp
[2009/05/13 03:06:30 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/12 08:07:13 | 00,213,024 | ---- | C] () -- C:\WINDOWS\System32\drivers\str.sys
[2009/05/12 07:43:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\TikGames
[2009/05/12 07:43:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TikGames
[2009/05/11 07:35:42 | 00,005,592 | ---- | C] () -- C:\WINDOWS\System32\uacinit.dll
[2009/05/11 07:35:33 | 00,000,224 | ---- | C] () -- C:\WINDOWS\System32\UACgiwailvinuuyxmf.dat
[2009/05/11 06:20:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Enchanted Katya
[2009/05/11 06:18:48 | 00,001,766 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Enchanted Katya and the Mystery of the Lost Wizard.lnk
[2009/05/11 06:14:58 | 00,001,760 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Laura Jones 2.lnk
[2009/05/11 03:00:24 | 00,000,260 | ---- | C] () -- C:\WINDOWS\tasks\WGASetup.job
[2009/05/11 03:00:23 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\KB905474
[2009/05/10 06:56:33 | 00,001,802 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Wild West Quest 2.lnk
[2009/05/09 18:48:21 | 00,427,460 | ---- | C] () -- C:\Documents and Settings\Sarah\My Documents\sm_5[2].jpg
[2009/05/08 06:49:10 | 00,001,912 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Adventures of Robinson Crusoe.lnk
[2009/05/07 16:19:22 | 00,001,729 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Wild Tribe.lnk
[2009/05/04 18:34:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Nero
[2009/05/04 09:21:58 | 00,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2009/05/04 08:55:05 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2009/05/04 08:55:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nero
[2009/05/04 08:25:13 | 00,000,000 | ---D | C] -- C:\SONY_DVD_RECORDER_VOLUME
[2009/05/04 08:23:32 | 00,045,056 | ---- | C] (Adaptec) -- C:\WINDOWS\System32\WNASPI32.DLL
[2009/05/04 08:23:32 | 00,025,244 | ---- | C] (Adaptec) -- C:\WINDOWS\System32\drivers\ASPI32.SYS
[2009/05/04 08:23:32 | 00,005,600 | ---- | C] (Adaptec) -- C:\WINDOWS\System\WINASPI.DLL
[2009/05/04 08:23:32 | 00,004,672 | ---- | C] (Adaptec) -- C:\WINDOWS\System\WOWPOST.EXE
[2009/05/04 08:23:15 | 00,641,021 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2009/05/04 08:23:15 | 00,200,192 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\LameACM.acm
[2009/05/04 08:23:15 | 00,187,904 | ---- | C] () -- C:\WINDOWS\System32\Lame.exe
[2009/05/04 08:23:15 | 00,166,912 | ---- | C] () -- C:\WINDOWS\System32\Lame_enc.dll
[2009/05/04 08:23:15 | 00,001,676 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2009/05/04 08:23:15 | 00,000,414 | ---- | C] () -- C:\WINDOWS\System32\Lame_acm.xml
[2009/05/04 08:22:30 | 00,000,000 | ---D | C] -- C:\Program Files\EasyDVDRip
[2009/05/04 08:13:39 | 00,101,605 | ---- | C] () -- C:\WINDOWS\hpqins13.dat.temp
[2009/05/04 08:12:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\DriverCure
[2009/05/04 08:12:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/05/04 08:12:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DriverCure
[2009/05/04 06:26:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Playrix Entertainment
[2009/05/01 09:48:43 | 00,000,000 | ---D | C] -- C:\Bipo.MysteryoftheRedPanda
[2009/04/28 19:44:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Move Networks
[2009/04/27 07:09:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\BrandX Games
[2009/04/27 06:21:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Absolutist
[2009/04/24 06:54:09 | 00,157,696 | ---- | C] () -- C:\Documents and Settings\Sarah\My Documents\Contact Order.doc
[2007/05/04 06:18:20 | 00,000,000 | ---- | C] () -- C:\WINDOWS\spr32snl.dll
[2007/05/04 06:18:20 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iopb32ul.dll
[2007/05/04 06:18:20 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iopa32ul.dll
[2007/04/17 13:14:33 | 00,000,076 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2007/03/05 13:34:28 | 00,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/02/27 19:55:14 | 00,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2006/06/01 17:22:00 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/04/11 12:13:33 | 00,000,023 | ---- | C] () -- C:\WINDOWS\DownloadStudio.INI
[2005/10/03 16:34:57 | 00,000,725 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/09/22 21:12:27 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[2005/08/02 14:24:02 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2005/05/26 15:54:10 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2005/02/16 13:02:46 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2005/02/16 13:02:46 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2004/11/07 11:11:42 | 00,000,045 | ---- | C] () -- C:\WINDOWS\CELHFOGK.ini
[2004/11/07 11:11:37 | 00,000,099 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/10/30 16:01:15 | 00,000,024 | ---- | C] () -- C:\WINDOWS\INJ.INI
[2004/09/14 19:20:08 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/08/16 13:03:03 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/07/15 11:42:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2004/07/15 11:42:00 | 01,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2004/07/15 11:42:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2004/07/15 11:42:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2004/07/15 11:42:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004/05/18 23:10:49 | 00,002,274 | ---- | C] () -- C:\WINDOWS\eqlsUIConfig.ini
[2004/04/04 22:57:58 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2004/03/03 18:24:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\slingox.INI
[2004/02/27 17:11:52 | 00,000,166 | ---- | C] () -- C:\WINDOWS\SMRTGAMS.INI
[2004/02/19 18:17:08 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2004/02/19 16:31:54 | 00,000,070 | ---- | C] () -- C:\WINDOWS\Morphexe.INI
[2004/02/16 15:56:17 | 00,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2004/01/13 21:16:50 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/01/13 21:00:04 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2004/01/13 21:00:00 | 00,003,698 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2004/01/13 20:59:30 | 00,000,312 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2004/01/13 20:59:26 | 00,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2004/01/13 20:59:06 | 00,002,814 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2004/01/13 20:59:05 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2003/12/09 13:16:52 | 00,442,368 | ---- | C] ( ) -- C:\WINDOWS\System32\comintfs.dll
[2001/08/23 05:00:00 | 00,000,975 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[1998/08/16 05:00:00 | 00,004,096 | ---- | C] () -- C:\WINDOWS\System32\sysres.dll
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/05/18 07:12:34 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTListIt2.exe
[2009/05/18 06:55:37 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/18 06:54:27 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009/05/18 06:54:22 | 00,088,002 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/05/18 06:54:16 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/18 06:54:10 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Sarah\Local Settings\desktop.ini
[2009/05/18 06:54:00 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/17 07:56:06 | 00,001,831 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Liong The Lost Amulets.lnk
[2009/05/17 07:56:06 | 00,001,420 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Pogo Games.lnk
[2009/05/17 06:55:13 | 00,000,975 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/17 06:55:13 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/17 06:55:13 | 00,000,211 | RHS- | M] () -- C:\boot.ini
[2009/05/16 22:39:46 | 00,000,706 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/16 22:39:21 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Sarah\Desktop\mbs.exe
[2009/05/16 22:37:00 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Sarah\Desktop\mbam-setup.exe
[2009/05/16 21:46:12 | 00,000,790 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/05/16 21:43:47 | 06,367,264 | ---- | M] () -- C:\Documents and Settings\Sarah\My Documents\s.exe
[2009/05/16 19:40:13 | 00,762,348 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\Cat.DB
[2009/05/16 19:30:31 | 00,124,464 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/05/16 19:30:31 | 00,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009/05/16 19:30:31 | 00,007,386 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/05/16 19:30:31 | 00,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/05/16 19:30:19 | 00,001,919 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2009/05/16 19:30:16 | 00,310,320 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.sys
[2009/05/16 19:30:16 | 00,307,760 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.sys
[2009/05/16 19:30:16 | 00,217,392 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symtdi.sys
[2009/05/16 19:30:16 | 00,089,776 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symfw.sys
[2009/05/16 19:30:16 | 00,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.sys
[2009/05/16 19:30:16 | 00,039,984 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndisv.sys
[2009/05/16 19:30:16 | 00,037,296 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symndis.sys
[2009/05/16 19:30:16 | 00,036,400 | R--- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SymIM.sys
[2009/05/16 19:30:16 | 00,034,736 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\symids.sys
[2009/05/16 19:30:15 | 00,482,352 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\cchpx86.sys
[2009/05/16 19:30:15 | 00,258,608 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.sys
[2009/05/16 19:29:57 | 00,003,373 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.inf
[2009/05/16 19:29:57 | 00,001,753 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.inf
[2009/05/16 19:29:57 | 00,001,528 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.inf
[2009/05/16 19:29:57 | 00,001,389 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.inf
[2009/05/16 19:29:57 | 00,001,383 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.inf
[2009/05/16 19:29:57 | 00,000,640 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.inf
[2009/05/16 19:29:57 | 00,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\isolate.ini
[2009/05/16 19:29:42 | 00,009,423 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymNet.cat
[2009/05/16 19:29:41 | 00,007,410 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.cat
[2009/05/16 19:29:41 | 00,007,372 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtspx.cat
[2009/05/16 19:29:41 | 00,007,364 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.CAT
[2009/05/16 19:29:41 | 00,007,355 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\srtsp.cat
[2009/05/16 19:29:41 | 00,007,347 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0300000.087\ccHPx86.cat
[2009/05/16 19:27:04 | 00,355,974 | ---- | M] (Digital River, Inc.) -- C:\Documents and Settings\Sarah\Desktop\Download_N360S300EN1_now.exe
[2009/05/16 09:34:22 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/05/16 09:31:22 | 01,222,128 | ---- | M] (McAfee, Inc.) -- C:\Documents and Settings\Sarah\My Documents\DMSetup.exe
[2009/05/16 07:56:38 | 06,367,264 | ---- | M] () -- C:\Documents and Settings\Sarah\My Documents\SUPERAntiSpyware.exe
[2009/05/16 07:31:42 | 00,005,592 | ---- | M] () -- C:\WINDOWS\System32\uacinit.dll
[2009/05/14 20:53:16 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\MSVolume.dll
[2009/05/14 03:00:00 | 00,000,496 | ---- | M] () -- C:\WINDOWS\tasks\AdwareAlert Scheduled Scan.job
[2009/05/13 20:31:24 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Doc3.doc
[2009/05/13 19:14:14 | 00,000,000 | -H-- | M] () -- C:\Documents and Settings\Sarah\My Documents\Default.rdp
[2009/05/13 08:11:06 | 00,000,039 | ---- | M] () -- C:\WINDOWS\Irremote.ini
[2009/05/13 03:06:30 | 00,000,118 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2009/05/12 08:07:35 | 00,213,024 | ---- | M] () -- C:\WINDOWS\System32\drivers\str.sys
[2009/05/12 07:35:46 | 00,000,224 | ---- | M] () -- C:\WINDOWS\System32\UACgiwailvinuuyxmf.dat
[2009/05/11 06:18:48 | 00,001,766 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Enchanted Katya and the Mystery of the Lost Wizard.lnk
[2009/05/11 06:14:58 | 00,001,760 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Laura Jones 2.lnk
[2009/05/10 06:56:33 | 00,001,802 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Wild West Quest 2.lnk
[2009/05/09 18:52:52 | 00,427,460 | ---- | M] () -- C:\Documents and Settings\Sarah\My Documents\sm_5[2].jpg
[2009/05/08 16:34:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/05/08 06:49:10 | 00,001,912 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Adventures of Robinson Crusoe.lnk
[2009/05/07 16:19:22 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Wild Tribe.lnk
[2009/05/07 00:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/04 08:23:19 | 00,001,676 | ---- | M] () -- C:\WINDOWS\unins000.dat
[2009/05/04 08:23:14 | 00,641,021 | ---- | M] () -- C:\WINDOWS\unins000.exe
[2009/05/04 08:13:43 | 00,101,252 | ---- | M] () -- C:\WINDOWS\hpqins13.dat
[2009/04/24 06:54:09 | 00,157,696 | ---- | M] () -- C:\Documents and Settings\Sarah\My Documents\Contact Order.doc
[2009/04/20 09:34:28 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/04/20 09:34:23 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
========== LOP Check ==========
[2009/05/16 19:31:06 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/05/16 19:31:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2009/01/31 10:34:18 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/27 18:38:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2009/04/27 06:21:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Absolutist
[2008/04/13 08:32:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/02/09 07:40:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AdventureChronicles1
[2008/09/02 09:16:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2005/02/16 11:17:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL
[2005/02/16 11:17:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/10/06 13:14:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2006/11/20 20:30:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/08/13 17:14:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Astar Games
[2009/05/15 07:06:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avanquest
[2006/03/31 19:53:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avery
[2009/05/13 19:08:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg8
[2009/01/31 11:16:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Beanbag Studios
[2008/12/25 08:46:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BigFish
[2008/10/06 05:48:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2009/03/22 18:54:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\blg
[2008/10/15 03:42:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Blizzard
[2009/05/15 11:18:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/05/04 08:17:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverCure
[2008/01/12 13:58:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA
[2008/06/08 10:55:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2008/08/30 09:23:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2009/02/23 08:19:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy-PizzaParty
[2008/05/01 10:38:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/10 13:06:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2007/05/30 19:15:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FloodLightGames
[2008/11/06 07:52:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FlyWheelGames
[2008/07/07 09:34:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreshGames
[2009/02/16 07:15:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2008/06/29 10:26:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Go Go Gourmet
[2009/03/16 06:37:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii
[2009/01/31 08:53:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii Games
[2009/03/07 14:31:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gold Casual Games
[2006/09/15 00:15:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2008/04/16 08:59:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HiddenSecretsNightmare
[2009/03/14 07:32:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
[2009/03/03 13:53:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HoverBee Studios
[2007/02/27 19:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP
[2005/09/17 23:29:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/04/03 08:08:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intenium
[2005/07/27 18:01:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2008/12/25 10:25:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin
[2008/06/17 12:13:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
[2008/04/06 10:25:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/10/28 00:39:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kodak
[2008/05/31 13:16:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/07/02 12:51:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2009/05/16 22:39:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/16 09:31:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2008/04/08 09:25:44 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/03/10 07:47:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MiniIT Games
[2008/05/18 11:41:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MonteCristo
[2005/12/08 10:16:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2009/05/10 08:22:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/10/05 09:09:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2009/02/12 07:24:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NeptunesAdve
[2009/05/13 08:23:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nero
[2009/05/16 19:31:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Norton
[2009/05/16 19:29:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2006/08/01 13:04:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NVIDIA
[2005/02/16 11:17:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2007/12/07 17:30:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon
[2009/04/10 10:16:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Games
[2007/04/15 10:25:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/05/04 08:12:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2008/08/21 10:16:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PBGsavesDirectory
[2009/05/14 20:36:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/05/08 06:49:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/02/28 20:33:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayPond
[2009/03/30 07:19:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playtonium Games
[2005/04/30 09:12:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2005/02/16 11:17:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuickTime
[2005/06/07 15:59:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/02/01 15:16:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2008/06/07 11:02:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2006/02/04 14:56:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/09/14 12:11:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/04/03 11:17:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/05/17 07:31:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2009/05/17 08:49:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/08/30 10:26:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TheRace_dev
[2009/05/12 07:43:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TikGames
[2005/10/04 17:09:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/12/18 08:12:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Valusoft
[2007/02/07 22:25:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/06/27 15:32:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VirtualFarm
[2008/07/01 10:41:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VisualShape
[2006/03/10 08:25:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/17 10:38:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WotT
[2007/11/11 12:14:44 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data\yahoo!
[2009/05/16 19:27:23 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Sarah\Application Data
[2008/05/03 11:25:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Adobe
[2008/04/11 16:14:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\AdobeUM
[2008/02/16 09:51:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\AdwareAlert
[2006/04/15 11:32:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Ahead
[2005/04/14 19:50:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Aim
[2009/03/31 13:55:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Alawar
[2008/10/07 05:56:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\AlterLab
[2009/03/29 08:02:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Anabel
[2008/03/22 15:53:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Apple Computer
[2009/05/15 07:24:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Avanquest
[2008/09/20 08:53:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\BeachPartyCraze
[2008/09/02 12:38:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Beanbag Studios
[2006/04/30 15:31:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Beep
[2007/08/05 08:24:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Big Fish Games
[2008/12/25 08:45:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\BigFish
[2009/03/22 18:54:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\blg
[2008/03/08 09:05:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\BloodTies
[2009/03/16 12:39:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Boolat Games
[2009/03/06 19:34:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Boomzap
[2008/10/30 17:14:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\BottleBuster
[2009/04/27 07:09:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\BrandX Games
[2009/01/31 12:25:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\cerasus.media
[2008/09/18 16:04:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Chicken Chase
[2009/04/01 08:56:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Coyotes Tale
[2006/05/04 09:38:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\CR680TWN
[2006/04/02 16:00:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Creative
[2009/05/04 08:12:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\DriverCure
[2005/10/04 21:21:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\EA
[2009/03/13 06:16:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\EleFun Games
[2009/05/11 06:20:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Enchanted Katya
[2009/01/19 14:00:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Fabulous Finds
[2009/03/10 13:06:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Flood Light Games
[2007/05/30 19:15:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\FloodLightGames
[2007/11/07 07:21:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\ForgottenRiddles
[2009/01/24 09:23:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\ForgottenRiddles2
[2007/10/27 08:24:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\FotoFinish
[2009/01/26 08:20:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Friday's games
[2008/10/02 17:04:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\funkitron
[2009/03/28 08:04:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Fuzzy Games
[2008/06/20 11:01:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Gaijin Ent
[2008/11/23 08:47:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Gamelab
[2009/05/16 19:38:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\GetRightToGo
[2009/01/31 08:53:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Gogii Games
[2008/08/19 14:19:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Go-Go Gourmet Chef of the Year
[2009/03/07 14:31:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Gold Casual Games
[2006/09/16 00:35:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Google
[2005/04/13 23:55:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Help
[2007/03/03 10:43:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\HP
[2005/02/16 11:17:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Identities
[2005/07/27 18:01:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Intuit
[2008/07/08 11:37:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\IOMediaSupport6SZZ001s
[2008/09/18 17:54:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\ITTNord
[2008/12/25 10:25:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\iWin
[2008/06/17 11:03:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\iWinArcade
[2008/02/17 11:30:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Jane s Hotel
[2009/03/15 10:56:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Jetsetter
[2008/01/20 11:26:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Lavasoft
[2005/02/16 11:17:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Leadertech
[2008/06/17 11:14:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Legends of pirates
[2008/07/02 12:51:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Ludia
[2008/05/03 11:25:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Macromedia
[2008/09/19 10:25:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Magic Academy
[2006/01/10 21:13:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Magic Match
[2009/03/28 09:10:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Meridian93
[2009/05/13 19:08:22 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Sarah\Application Data\Microsoft
[2009/03/10 07:47:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\MiniIT Games
[2009/05/09 20:17:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Move Networks
[2008/03/17 19:33:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\MSN6
[2008/11/11 09:17:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Mushroom Age
[2008/06/19 12:58:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\My Games
[2006/11/19 17:59:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\MySpace
[2009/01/22 07:37:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\MysteryStudio
[2009/05/04 18:35:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Nero
[2009/04/07 06:24:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Oberon Games
[2009/01/22 07:47:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Oberonv1001
[2009/04/15 06:38:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Oberonv1002
[2008/10/02 19:58:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Oberonv1005
[2008/10/03 18:49:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\panoramik
[2008/10/31 06:24:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\PetShowCraze
[2008/06/24 15:38:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\PlanetPlayMore
[2009/05/08 06:49:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\PlayFirst
[2009/05/04 06:26:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Playrix Entertainment
[2009/01/24 10:27:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Pogo Games
[2006/09/12 13:04:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Real
[2009/01/23 06:53:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Restorer
[2008/09/10 10:02:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Righteous Kill
[2009/04/13 07:04:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Sahmon Games
[2009/03/30 06:58:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\SecretIslandEng
[2008/04/08 13:51:48 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Sarah\Application Data\SecuROM
[2009/04/05 06:47:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Shape games
[2007/10/27 08:08:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\SmartDraw
[2007/10/23 18:51:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Sony Corporation
[2008/07/08 11:37:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Spinapse
[2008/10/24 06:06:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\SulusGames
[2006/04/17 22:56:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Sun
[2008/02/16 09:56:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Sunbelt Software
[2009/04/17 09:58:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com
[2008/07/08 12:05:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Suspects and Clues Players
[2008/07/08 11:37:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Suspects and Clues Prefs
[2008/03/23 19:45:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Symantec
[2005/02/16 11:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\teamspeak2
[2008/08/05 07:37:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\TheScruffs
[2009/05/12 07:43:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\TikGames
[2009/02/04 09:26:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\TMInc
[2008/03/02 13:04:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Ubisoft
[2007/01/27 11:50:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\uTorrent
[2008/12/18 08:12:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Valusoft
[2007/02/07 22:25:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Viewpoint
[2008/07/01 10:41:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\VisualShape
[2005/10/05 22:18:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Wildfire
[2005/02/16 11:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\WinWay
[2007/11/11 12:13:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Yahoo!
[2005/02/16 11:17:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Yahoo! Messenger
[2009/01/31 07:46:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\YoudaGames
[2009/05/16 09:34:22 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/05/14 03:00:00 | 00,000,496 | ---- | M] () -- C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
[2009/05/08 16:34:05 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/05/18 06:54:16 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/05/18 06:54:27 | 00,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AD171C9E
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:82E1D3A4
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:27EEEB5C
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B61DB9F
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D226F1A4
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B652B720
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AD27A66
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:442CBC07
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3222DF9E
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05816AFA
@Alternate Data Stream - 182 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:78DBBDCD
@Alternate Data Stream - 182 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54997B77
@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5EC637CB
@Alternate Data Stream - 154 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B212553
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:41C283B2
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07348C09
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BAD46F6
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BFAA502
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FDD78BE5
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BD47E4EB
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EAD6852
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A08FFD4D
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60D735B2
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2D0C22DC
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6CE0638C
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E951D483
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:766CD192
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:01442FD8
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:00C31200
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:72E546C1
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:26C2E4B1
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:18AE7C5A
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA42DF8E
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CC174F28
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6FCD73D7
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5D458568
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5B85C37B
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF2C26D2
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C3B04546
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:481DAC2B
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BCE9E9B
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9B7E8561
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:273A8657
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FDAF118C
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D61069DE
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D31BE97C
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D091E13E
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:981349EA
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AB6C1D7
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6A7B7A50
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:27AD48A5
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1C5692E6
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05113FB9
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A39CF033
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8FBE0E9C
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C8950EF
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71F96743
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5F15D632
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4F636E25
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20FFCF0B
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E7700065
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BC428E9F
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B894C266
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90E3641D
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E60033F
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6CEB2458
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:560D46AC
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:478FEFC3
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:38849DE5
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E6E9EB6C
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E6427C0F
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9B0F9E15
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:765C6A14
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6CBAF5F3
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5615A588
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73EAFFB
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A644A4BC
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8D02044C
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:79F970BE
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5635DE41
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5216CD26
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48372097
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:42228396
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:34FC1C45
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:327FAF99
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2FAFBD6A
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C47D2D17
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:389D51A1
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:104EF12D
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E7E2CF32
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D6146633
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C17FCA88
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B4FDEF97
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:68DA8CC0
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4CD2D817
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CB8D545
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1291B7F6
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F0A6D4E5
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD160B0D
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1361E51
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5A1A3CC5
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3C75E5BE
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:30376ACC
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B8B2AF8
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:11F7EB8A
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8A0BC27
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:912389B7
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:895798AD
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2B2EF65C
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:226A6E31
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E55CE2D1
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CBCE0A92
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BAC9506D
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:981884E7
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:95B7F1EC
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80A452DD
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:550179F5
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52B439AA
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:37CE0F2E
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2D61FFEE
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:158CC5FF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F65733F1
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EBC3E09A
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D197DC80
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C5A35877
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A724744F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9AD927A6
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7091055F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62197B73
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59BDDCD5
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:580E04D8
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BD6F4E7
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B3A35EC
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2FC9D9C0
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1C9565AC
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:08E9A813
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C40E212B
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:933FD10F
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:37F44C44
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:03B3646C
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F00E008B
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED45A20F
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E90251A2
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E62BE020
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9F36615A
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:940EEA60
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:88D7DDBC
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8135A716
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:76986D86
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24AB14E7
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2250B408
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FE4E15B1
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E1F04E8D
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D417F0D5
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C6FB18EA
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C202A457
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:864A52B8
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5A27D490
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D1D6B2D
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BBB1871
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E8F2B426
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E1031541
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A689D757
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:618BF152
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B49E3BC
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:45A334DD
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:275EB145
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:128A6DC9
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F4133568
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:997E6AF4
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:51A22C60
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3C9CF9A7
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E54FA796
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C213B3C4
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8DB5ACDD
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:82C50600
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8160BC44
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:567AC0A6
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:403D77D3
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90FE524C
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:89123481
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:861A898F
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4F58D818
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F01E7F17
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA2FBCA1
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A4E5024A
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4FFA5B5C
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4E158DDD
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3FC4A10A
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FD931C5F
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E98C5DD9
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E89EDC52
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E36991C0
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D644D3DF
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BFD53918
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B156F3F2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:85630A39
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F22DA14
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3064D21D
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1D6686D8
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1941675B
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:03392111
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A18FC5E4
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96BE5F33
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8D4852A2
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8C458D50
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6EAE3ABC
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:17DA7CD5
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ECF5194F
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA592591
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CEB4672B
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A696643D
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9AB56A06
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7F66BF58
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5466F106
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4CF61E54
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:494C4968
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:38317199
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1DF79F4B
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B79AEF3
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA8B212D
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61E5F0F7
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54F1BE9B
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:77846FFE
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6BD1DCDD
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:687D1056
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52DBE86F
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3447AB86
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2FF4577A
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:26946BE8
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:18E45954
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:699C6EB5
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57BF34C6
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:561B1D2B
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:077CC761
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48B90E7
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1F4198F
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:730BC923
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D7FCCD3
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D066AD2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:46545F5C
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E2DEF21B
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8B440CF5
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:25005EFA
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:86FA1A34
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54F7A151
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1DECED1B
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0DA384B0
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D09AEE3D
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BB48E5A3
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91EA783C
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:53C0A7FF
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20451762
< End of report >
OTListIt Extras logfile created on: 5/18/2009 7:15:32 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Sarah\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.53 Mb Total Physical Memory | 635.17 Mb Available Physical Memory | 62.06% Memory free
1.66 Gb Paging File | 1.38 Gb Available in Paging File | 83.03% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 114.49 Gb Total Space | 77.60 Gb Free Space | 67.78% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SARAH-COFWCBSLF
Current User Name: Sarah
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
.scr [@ = scrfile] -- "%1" /s
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"EnableFirewall" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger File not found
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC File not found
C:\WINDOWS\system32\msnmgr.exe:*:Enabled:msnmgr File not found
C:\Program Files\StreamCast\Morpheus\MorphEXE.exe:*:Enabled:Morpheus File not found
C:\Program Files\Sony\Station\Launchpad\LaunchPad.exe:*:Enabled:LaunchPad ()
C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player Application (Apple Inc.)
C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger File not found
C:\Program Files\WinMX\WinMX.exe:*:Enabled:WinMX Application File not found
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 File not found
c:\windows\system32\rk.exe:*:Enabled:rk.exe File not found
C:\Documents and Settings\Sarah\Local Settings\Temp\~osA0.tmp\ossproxy.exe:*:Enabled:ossproxy.exe File not found
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare File not found
C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent File not found
C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader (Blizzard Entertainment)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\WINDOWS\ie7\iexplore.exe:*:Enabled:Internet Explorer File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{0AFC9710-5DD6-4C6A-BA52-91AE992B2C9D}" = Safari
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 13
"{2EA45803-BEB7-46C4-9ADC-46A5F9E7BB77}" = GEAR driver installer for x86 and x64
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36DC3E2F-CD8C-4953-9E8F-9A1916D10AA1}" = hph_software
"{44734179-8A79-4DEE-BB08-73037F065543}" = Apple Mobile Device Support
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{639858DD-4966-40F3-A706-7C838BCF3A2B}" = MaxBlast 3
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11109097}" = Luxor - Amun Rising
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111271497}" = Mystery Case Files - Prime Suspects
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11170417}" = Luxor 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112179547}" = Mystery Case Files Ravenhearst
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112614887}" = Big City Adventure San Francisco
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114079860}" = Tri Peaks 2 Quest For The Ruby Ring
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11657090}" = Wild West Quest 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116878750}" = Adventures of Robinson Crusoe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116956447}" = Wild Tribe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116959157}" = Enchanted Katya and the Mystery of the Lost Wizard
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11698160}" = Laura Jones 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117026820}" = Liong The Lost Amulets
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A5BD3FD3-FEEE-4CB6-9FB5-5B5796B239D0}" = HP Photosmart A530 Series
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ACCCEE83-B49B-4964-8A4F-378B8FBC9F75}" = hph_ProductContext
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BC8032F1-0D5E-43C6-B14A-77AC8F9690B5}" = DesignPro 5.0 Media Edition
"{BE365801-FB4B-49D7-87D2-9477EE371F1C}" = D1300_Help
"{C13F11D1-00BA-44DF-B626-35E1C03F85E5}" = D1300
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D1AE6D4D-C37A-487d-83D8-C333125B2459}" = HP Photosmart and Deskjet 7.0 Software
"{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}" = HP Photosmart and Deskjet 7.0 Software
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"Ad-Aware" = Ad-Aware
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"BFGC" = Big Fish Games Client
"BFG-Mystery Case Files - Madame Fate" = Mystery Case Files: Madame Fate (remove only)
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"CurseClient" = Curse Client
"DXTXTRA" = Microsoft DirectX Transform optional components
"ESSMDM" = Uninstall Broadxent DSI Modem
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Indeo® software" = Indeo® software
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{BC8032F1-0D5E-43C6-B14A-77AC8F9690B5}" = DesignPro 5.0 Media Edition
"Luxor" = Luxor (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mortimer Beckett and the Secrets of Spooky Manor" = Mortimer Beckett and the Secrets of Spooky Manor
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"N360" = Norton 360
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PCI Audio Applications" = PCI Audio Applications
"PCI Audio Driver" = PCI Audio Driver
"PCPitstop Panda AntiVirus Scan" = PCPitstop Panda AntiVirus Scan (remove only)
"Picasa2" = Picasa 2
"Shockwave" = Shockwave
"Slingo Quest" = Slingo Quest (remove only)
"SystemRequirementsLab" = System Requirements Lab
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 3.1
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD & MP3 Codec Pack_is1" = XviD & MP3 Codec Pack (remove only)
"Yahoo! Messenger" = Yahoo! Messenger
"YInstHelper" = Yahoo! Install Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Sprint Digital Lounge" = Sprint Digital Lounge
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/11/2009 11:19:37 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/11/2009 11:19:40 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/11/2009 11:19:40 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/11/2009 11:19:43 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/11/2009 11:19:43 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/12/2009 10:05:41 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/12/2009 10:05:41 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/12/2009 10:05:44 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/14/2009 10:51:50 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
Error - 5/14/2009 10:52:02 AM | Computer Name = SARAH-COFWCBSLF | Source = nview_info | ID = 11141121
Description =
[ System Events ]
Error - 5/17/2009 9:56:56 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ShldDrv
Error - 5/17/2009 9:57:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7000
Description = The HTTP service failed to start due to the following error: %%2
Error - 5/17/2009 9:57:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7001
Description = The SSDP Discovery Service service depends on the HTTP service which
failed to start because of the following error: %%2
Error - 5/18/2009 9:55:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7000
Description = The AOL Connectivity Service service failed to start due to the following
error: %%3
Error - 5/18/2009 9:55:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7000
Description = The Nero BackItUp Scheduler 4.0 service failed to start due to the
following error: %%2
Error - 5/18/2009 9:55:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Driver service failed to start due to
the following error: %%2
Error - 5/18/2009 9:55:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Service service failed to start due to
the following error: %%3
Error - 5/18/2009 9:55:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
ShldDrv
Error - 5/18/2009 9:55:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7000
Description = The HTTP service failed to start due to the following error: %%2
Error - 5/18/2009 9:55:22 AM | Computer Name = SARAH-COFWCBSLF | Source = Service Control Manager | ID = 7001
Description = The SSDP Discovery Service service depends on the HTTP service which
failed to start because of the following error: %%2
< End of report >