Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Virus Name Unkown


  • Please log in to reply

#1
orssi

orssi

    New Member

  • Member
  • Pip
  • 9 posts
:) I had AVG free anti virus and Spybot S&D freeware as a part of my security set up.
My PC suddenly, started shutting down on its own initiative couldn’t figure it out; as I would have received a notification to flash on my screen from AVG indicating to me of a virus threat.
So, didn’t think a virus was the cause; checked my system couldn’t find any changes to my set up. Checked AVG Free to find the last seven auto scans hadn’t run their full scan. So run AVG on full scan and my computer shutdown after 10 minutes, ran it again, did the same thing. So ran spybot to check and see what would happen, and that to shutdown my PC after 20 minutes, finally logged on to your site. Went to the Virus, Spyware and Trojan Removal topics, section post# 1, and just followed your guidelines. I downloaded and ran TFC (Temp File Cleaner) and Malwarebytes' Anti-Malware, ran Avast! Antivirus, after uninstalling AVG anti free –virus as suggested first. I think they removed all the viruses so, to check for any leftover parts and my registry is ok I have included all three reports up to that point.

Then ran OTL and am waiting for your suggestions, or not. Thanks a bunch guys.

OTL Extras logfile created on: 29/10/2009 14:40:16 - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\t5550\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18828)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 48.38% Memory free
4.00 Gb Paging File | 2.89 Gb Available in Paging File | 72.23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.74 Gb Total Space | 67.57 Gb Free Space | 60.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 19.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: T5550-PC
Current User Name: t5550
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-93040632-1514837124-2520170126-1000]
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1355FB03-703B-4637-8DDC-B99D16B99A2A}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{1EF39A3B-6F6C-46F8-B0BC-9A9F2CEE9B8D}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{31ABA6AD-19DC-4093-93E9-B8CE0E4DE96A}" = rport=137 | protocol=17 | dir=out | app=system |
"{4C1D3559-9A7B-43CF-82A6-4F1B672009B7}" = lport=137 | protocol=17 | dir=in | app=system |
"{4D4CD2BF-74DD-4C50-8135-FF52343814EF}" = lport=445 | protocol=6 | dir=in | app=system |
"{5DFF05D9-DE0F-4772-852C-6F3C18E04559}" = rport=138 | protocol=17 | dir=out | app=system |
"{64545C6D-D489-482E-9506-DA106C308564}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7389E54A-CDB9-4BC5-8ACD-B544E012B788}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{7DCAB507-096E-4394-95CB-987395F3CD40}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{829F0403-E86D-4A58-9D4A-639DF1524D26}" = lport=138 | protocol=17 | dir=in | app=system |
"{94FBC5DC-051F-41C7-94F8-DD660C52FCCE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{96476B6B-ED45-46E2-B251-CD7D405AD59A}" = lport=139 | protocol=6 | dir=in | app=system |
"{9AB7061C-F285-4ED9-87BF-A4601412D339}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A01506D3-76CC-4090-B52E-F9D525430257}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B6B8BF3F-1FED-4E89-9BF3-525FC3E1B96C}" = rport=139 | protocol=6 | dir=out | app=system |
"{D7904459-F1B3-43E7-8F9D-138BB310F3EB}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{E8A12BE5-4298-47CB-917B-0F04FDFB4CAD}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{E9526950-A3D8-4FE5-BECD-2998CE6DAFC9}" = rport=445 | protocol=6 | dir=out | app=system |
"{F27907D4-5798-498D-9BBC-8B062052176F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{052A33E7-7C8C-498B-B608-7257DBB5933E}" = protocol=1 | dir=in | [email protected],-28543 |
"{08110528-FE93-4E3B-A33D-32351DF7FE27}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0A6532F1-13F2-4827-9A39-58A29A4884B8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{22F6BF2F-C9CE-4742-9166-A6968AE4D29E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{24995590-A1B8-4F32-93C1-81A8E544A539}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{2807C454-40AA-4C2D-9708-E3D3CC383C2B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{29BCDBB8-6CFD-4B2F-BA19-D9A0CBA6DE1E}" = protocol=1 | dir=out | [email protected],-28544 |
"{3AF1F6E4-E280-437E-86AA-A0F2CEABDDA9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{3BB9715D-7F1F-43E3-8200-FAA1275CA813}" = protocol=58 | dir=out | [email protected],-28546 |
"{5B989760-A3F1-4A84-BB4C-BC8E89713122}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{63307A6C-8458-45A4-9969-E750338F37E6}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{7D9C6D19-786E-4267-88C5-EEC795E04A10}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8480D360-07CE-47D8-B09C-36C58D3E7F43}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{8D580E8F-C664-42A0-B314-07868CEF59A2}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{9A170CBC-5162-4064-9F7E-9F1E2014080B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{9D277A84-5D9F-44DE-90AE-F1A12EE07F1C}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DA54EC85-A679-4359-A104-62B6A0CEAE23}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{DDDCE594-AE7E-4EBC-A582-DEDEFD078CD3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{EC806D4F-D7BB-47DA-A6D7-03BF96DBC556}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F78F9F3E-37AD-409B-B362-3DBD8222340B}" = protocol=58 | dir=in | [email protected],-28545 |
"{FD58C2A4-8D6C-4376-BEB9-1F8BA110BA34}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0915B10F-8597-4FE7-BC4D-EA3E2FDA646A}" = PS_AIO_03_C4400_Software_Min
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar v1.0
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{25771101-7948-4591-ABF3-B1ECE7A7F45F}" = HP Update
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 16
"{27197499-7680-4208-8FD8-5439CDB0FDC1}" = HPProductAssistant
"{276E3ECB-E9E9-494E-A3F9-173BAD7D9643}" = C4400
"{2AFEAA03-2DFE-4519-A629-EDAB6541ABE9}" = HPSSupply
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{40727DD3-9679-4D09-81D0-25F0017DF61C}" = ArcSoft VideoImpression 2
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{42C7A1F1-6986-41E6-B0C7-94657FE89301}" = Mavis Beacon Teaches Typing Deluxe 15
"{4A3D0CF8-60FF-4CEF-91A4-A1F001424602}" = DocProc
"{4B6AD248-D3BF-426A-8D64-847288154F13}" = QuickSet
"{4CC59DA1-469B-49A5-9F6B-C4D26990294A}" = PS_AIO_03_C4400_ProductContext
"{4E5386F5-C0F6-4532-A54A-374865AEAB71}" = Cisco PEAP Module
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{593A6CAF-E114-4e31-884F-74FF349E8E36}" = SolutionCenter
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5A3FEF2D-0E14-412E-869C-421AB373EE43}" = C4400_Help
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C71FEFE-6582-4B09-808E-E347892BFE00}" = BTOffer
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70E1E357-E57C-4284-B04E-58196DC27BC1}" = PanoStandAlone
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76F9CF97-FC4B-4E20-B363-D127C888448F}" = Cisco LEAP Module
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{83d96ed0-98aa-4515-8ddc-816f3efdd104}" = MyDSC2
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86732AE7-CB91-4f15-B091-FBA3D3926CD6}" = HP Photosmart C4400 All-In-One Driver Software 11.0 Rel .3
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACECB7C-5EB2-42B3-A2E1-B91878B6C5D7}" = PS_AIO_03_C4400_Software
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARD_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARD_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARD_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9F4EE72A-C5C9-42ad-ABEF-427690843577}" = MarketResearch
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A899DA1F-D626-401C-8651-F2921E3B4CB3}" = 3Connect
"{AA2E8A46-B45E-4aea-8A23-88AB57D04523}" = WebReg
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BBF71276-E8DF-4D5E-8869-3397BF04CF1C}" = ArcSoft PhotoImpression 5
"{BE9880CD-73A9-4EFD-83E5-4BB38D48E2BD}" = HP Smart Web Printing
"{BF08AB1C-3357-4f20-A200-8EBB8EF27C59}" = BufferChm
"{BF53252E-4AB2-4C7F-A0FD-6100755745E3}" = Cisco EAP-FAST Module
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D16B4BE6-8B10-422f-8034-96D1CA9483B5}" = GPBaseService
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{E133E97F-5186-4503-BEC8-752EB9E8EBD7}" = Copy
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"avast!" = avast! Antivirus
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"cayahooantispy" = CA Yahoo! Anti-Spy (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Dell Webcam Center" = Dell Webcam Center
"Dell Webcam Manager" = Dell Webcam Manager
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Free Download Manager_is1" = Free Download Manager 3.0
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 11.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 11.0
"HPExtendedCapabilities" = HP Customer Participation Program 11.0
"HPOCR" = OCR Software by I.R.I.S. 11.0
"Huawei Modems" = Huawei modem
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"ProInst" = Intel® PROSet/Wireless Software
"Shop for HP Supplies" = Shop for HP Supplies
"Software Informer_is1" = Software Informer 1.0 BETA
"SpywareBlaster_is1" = SpywareBlaster 4.2
"STANDARD" = Microsoft Office Standard 2007
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Mail Advisor" = Yahoo! Mail Advisor
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 27/10/2009 14:28:07 | Computer Name = t5550-PC | Source = EventSystem | ID = 4609
Description =

Error - 27/10/2009 20:13:37 | Computer Name = t5550-PC | Source = RasClient | ID = 20227
Description =

Error - 28/10/2009 06:33:30 | Computer Name = t5550-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 28/10/2009 06:33:30 | Computer Name = t5550-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 28/10/2009 12:06:37 | Computer Name = t5550-PC | Source = SDWinSec.exe | ID = 0
Description =

Error - 28/10/2009 15:56:40 | Computer Name = t5550-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 28/10/2009 18:40:22 | Computer Name = t5550-PC | Source = Application Hang | ID = 1002
Description = The program SpybotSD.exe version 1.6.2.46 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1568 Start Time: 01ca581186fb9933 Termination Time: 357

Error - 29/10/2009 04:08:49 | Computer Name = t5550-PC | Source = RasClient | ID = 20227
Description =

Error - 29/10/2009 08:51:04 | Computer Name = t5550-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 29/10/2009 08:51:04 | Computer Name = t5550-PC | Source = Windows Search Service | ID = 3013
Description =

[ Broadcom Wireless LAN Events ]
Error - 01/10/2009 16:00:43 | Computer Name = t5550-PC | Source = WLAN-Tray | ID = 0
Description = 21:00:43, Thu, Oct 01, 09 Error - Unable to gain access to user store


[ Media Center Events ]
Error - 27/10/2009 13:14:03 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 28/10/2009 05:39:46 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 28/10/2009 06:21:20 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 28/10/2009 06:30:47 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 28/10/2009 06:47:34 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 28/10/2009 16:20:13 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 28/10/2009 19:00:48 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 28/10/2009 19:36:23 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 29/10/2009 03:10:20 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 29/10/2009 04:08:11 | Computer Name = t5550-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

[ OSession Events ]
Error - 14/08/2009 15:18:59 | Computer Name = t5550-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 4320 seconds of active time. This session ended with a crash.

Error - 14/08/2009 17:32:11 | Computer Name = t5550-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 29/10/2009 10:05:56 | Computer Name = t5550-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 14:03:06 on 29/10/2009 was unexpected.

Error - 29/10/2009 10:06:40 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2009 10:08:15 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 29/10/2009 10:08:15 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2009 10:08:22 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2009 10:08:26 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2009 10:08:27 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2009 10:08:28 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2009 10:08:31 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 29/10/2009 10:08:33 | Computer Name = t5550-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >

OTL logfile created on: 29/10/2009 14:40:16 - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\t5550\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18828)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 48.38% Memory free
4.00 Gb Paging File | 2.89 Gb Available in Paging File | 72.23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.74 Gb Total Space | 67.57 Gb Free Space | 60.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 19.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: T5550-PC
Current User Name: t5550
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2009/10/29 13:52:12 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\t5550\Desktop\OTL.exe
PRC - [2009/09/21 15:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/09/21 15:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/09/17 02:30:12 | 01,933,381 | ---- | M] (Informer Technologies, Inc.) -- C:\Program Files\Software Informer\softinfo.exe
PRC - [2009/09/15 11:56:48 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/09/15 11:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/09/15 11:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/09/15 11:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/09/15 11:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/08/28 18:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/07/31 14:23:21 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/07/23 13:41:50 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/07/23 13:41:45 | 00,122,368 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2009/04/11 06:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2009/04/11 06:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009/04/11 06:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2009/03/05 15:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/02/23 18:45:16 | 03,934,744 | ---- | M] (Birdstep Technology) -- C:\Program Files\3\3Connect\WilogApp.exe
PRC - [2009/02/23 18:45:16 | 00,670,256 | ---- | M] (Birdstep Technology) -- C:\Program Files\3\3Connect\AutoUpdateSrv.exe
PRC - [2009/01/31 02:45:14 | 03,399,727 | ---- | M] (FreeDownloadManager.ORG) -- C:\Program Files\Free Download Manager\fdm.exe
PRC - [2009/01/26 14:31:10 | 01,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/12/12 10:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/08/26 14:58:12 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/08/26 14:58:10 | 00,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/06/05 22:06:32 | 00,125,208 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
PRC - [2008/03/26 01:25:18 | 00,286,720 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
PRC - [2008/03/25 20:27:58 | 00,049,152 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2008/03/25 19:49:02 | 00,184,320 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
PRC - [2008/03/25 19:49:00 | 00,569,344 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
PRC - [2008/03/25 19:40:42 | 00,214,360 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2008/02/22 16:01:38 | 01,193,240 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2008/02/15 17:25:34 | 00,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
PRC - [2008/02/15 17:23:20 | 00,405,504 | ---- | M] (IDT, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
PRC - [2008/02/15 08:41:46 | 00,256,536 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe
PRC - [2008/02/15 08:41:44 | 00,133,656 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpers.exe
PRC - [2008/02/15 08:41:34 | 00,166,424 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hkcmd.exe
PRC - [2008/01/19 07:38:38 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 07:33:40 | 00,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2008/01/19 07:33:09 | 00,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehtray.exe
PRC - [2008/01/19 07:33:09 | 00,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehmsas.exe
PRC - [2007/12/08 13:34:40 | 03,444,736 | ---- | M] (Dell Inc.) -- C:\Windows\System32\WLTRAY.EXE
PRC - [2007/12/08 13:34:40 | 00,024,064 | ---- | M] () -- C:\Windows\System32\WLTRYSVC.EXE
PRC - [2007/12/08 13:34:10 | 02,506,752 | ---- | M] (Dell Inc.) -- C:\Windows\System32\bcmwltry.exe
PRC - [2007/10/25 12:31:20 | 00,167,936 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2007/09/20 14:31:10 | 00,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\aestsrv.exe
PRC - [2007/07/27 15:43:34 | 00,118,784 | ---- | M] (Creative Technology Ltd.) -- C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
PRC - [2007/07/25 15:41:42 | 00,647,168 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2007/07/25 15:22:44 | 00,327,680 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2007/06/06 15:44:44 | 00,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apntex.exe
PRC - [2007/05/22 13:18:56 | 00,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2006/11/05 10:22:16 | 00,221,184 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
PRC - [2006/11/05 10:15:12 | 00,880,640 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
PRC - [2006/11/05 10:13:00 | 00,159,744 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
PRC - [2006/11/05 09:55:48 | 00,010,752 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
PRC - [2006/11/02 12:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe
PRC - [2006/09/08 14:10:22 | 00,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\HidFind.exe
PRC - [2006/08/04 15:39:20 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe
PRC - [2005/06/10 09:44:02 | 00,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2002/08/30 11:11:32 | 02,392,064 | ---- | M] (TLC Education Properties LLC) -- C:\Program Files\Broderbund\Mavis Beacon Teaches Typing Deluxe 15\minimavis.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/09/25 01:27:04 | 00,793,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll -- (FontCache [On_Demand | Stopped])
SRV - [2009/09/21 15:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/09/15 11:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/09/15 11:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/09/15 11:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2009/09/15 11:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009/08/28 18:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/07/23 13:41:38 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2009/04/11 06:28:25 | 01,017,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2009/04/11 06:28:20 | 00,373,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (WAS [On_Demand | Running])
SRV - [2009/04/11 06:28:20 | 00,373,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (W3SVC [Auto | Running])
SRV - [2009/04/11 06:28:17 | 00,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetsrv\apphostsvc.dll -- (AppHostSvc [Auto | Running])
SRV - [2009/03/30 04:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/02/18 18:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/02/18 18:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2009/02/18 18:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/01/26 14:31:10 | 01,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService [Auto | Running])
SRV - [2008/12/12 10:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/11/04 00:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2008/08/26 14:58:12 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter [Auto | Running])
SRV - [2008/07/18 12:13:20 | 00,053,760 | ---- | M] (Hewlett-Packard) -- C:\Windows\System32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2008/07/18 12:13:20 | 00,044,032 | ---- | M] (Hewlett-Packard) -- C:\Windows\System32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running])
SRV - [2008/03/25 20:27:36 | 00,135,168 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc [Auto | Running])
SRV - [2008/03/25 19:38:24 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08 [On_Demand | Running])
SRV - [2008/02/15 17:25:34 | 00,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe -- (STacSV [Auto | Running])
SRV - [2008/01/19 07:38:24 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2008/01/19 07:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2008/01/19 07:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2007/12/08 13:34:40 | 00,024,064 | ---- | M] () -- C:\Windows\System32\WLTRYSVC.EXE -- (wltrysvc [Auto | Running])
SRV - [2007/09/20 14:31:10 | 00,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\aestsrv.exe -- (AESTFilters [Auto | Running])
SRV - [2007/07/25 15:41:42 | 00,647,168 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running])
SRV - [2007/07/25 15:22:44 | 00,327,680 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2006/11/05 10:15:12 | 00,880,640 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -- (RoxMediaDB9 [On_Demand | Running])
SRV - [2006/11/05 10:13:00 | 00,159,744 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -- (RoxWatch9 [Auto | Running])
SRV - [2006/11/02 12:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Running])
SRV - [2006/11/02 12:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/09/14 13:54:34 | 00,073,728 | ---- | M] (MicroVision Development, Inc.) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe -- (stllssvr [On_Demand | Stopped])
SRV - [2006/08/04 15:39:20 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe -- (XAudioService [Auto | Running])
SRV - [2004/10/22 02:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])

========== Modules (SafeList) ==========

MOD - [2009/10/29 13:52:12 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\t5550\Desktop\OTL.exe
MOD - [2009/04/11 06:21:38 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2002/08/14 10:08:40 | 00,118,784 | ---- | M] (Broderbund) -- C:\Program Files\Broderbund\Mavis Beacon Teaches Typing Deluxe 15\KeyHook.dll

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8E D1 5E 87 B5 37 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.theprized...www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}:2.3.50
FF - prefs.js..extensions.enabledItems: [email protected]:0.3.1
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.29
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.4
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2
FF - prefs.js..extensions.enabledItems: {99B98C2C-7274-45a3-A640-D9DF1A1C8460}:1.3.1
FF - prefs.js..extensions.enabledItems: {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}:2.1.072
FF - prefs.js..extensions.enabledItems: {cc5cc7f7-8645-49b2-862f-f6e8116dfc44}:0.6.76
FF - prefs.js..extensions.enabledItems: {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:3.5.4
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.6
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:3.3.17
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.0.7
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.2.1
FF - prefs.js..extensions.enabledItems: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374}:3.5.9
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.4
FF - prefs.js..extensions.enabledItems: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.5.8
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.4
FF - prefs.js..extensions.enabledItems: {A4732521-77D9-447E-A557-B279AC923F06}:0.6.6
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.3.1
FF - prefs.js..extensions.enabledItems: {c33c5b47-69c8-45a4-a5e0-af85bbe628dd}:1.6.1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: {f13b157f-b174-47e7-a34d-4815ddfdfeb8}:0.9.87.4
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {398e77b8-2304-11dc-8314-0800200c9a66}:0.3.13
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:4.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.11
FF - prefs.js..extensions.enabledItems: {aba3f5c2-35d5-4960-bdfc-de9c162e39ce}:2.0.1.1
FF - prefs.js..extensions.enabledItems: {a6ca9b3b-5e52-4f47-85d8-cca35bb57596}:1.4.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.4.3
FF - prefs.js..extensions.enabledItems: {4fa0d965-cd01-4d08-9bdb-0d8c47cfd5d8}:3.13
FF - prefs.js..extensions.enabledItems: ststusscicalc@sunny:4.6.2
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.38
FF - prefs.js..extensions.enabledItems: {75623d5d-4683-402a-b610-ac4bab767c86}:3.0.1
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2b}:1.1.11
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.69
FF - prefs.js..extensions.enabledItems: {36C13C8F-54F1-412e-8177-2E411719162D}:4.0.1
FF - prefs.js..keyword.URL: "http://uk.yhs.search...2-tb-web_uk&p="

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/27 21:56:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/07/08 21:24:11 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/27 15:00:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/27 15:00:40 | 00,000,000 | ---D | M]

[2009/04/09 19:59:55 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Extensions
[2009/04/09 19:59:55 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/28 23:02:24 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions
[2009/10/21 16:03:05 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009/10/21 16:03:03 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009/04/10 12:18:29 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2009/06/30 07:42:19 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/22 12:39:54 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2009/04/10 12:18:29 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2b}
[2009/08/11 13:21:49 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2009/07/22 18:30:13 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{398e77b8-2304-11dc-8314-0800200c9a66}
[2009/07/01 14:08:29 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
[2009/04/10 13:05:12 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{43520B8F-4107-4351-AC64-9BCC5EEA24B9}
[2009/08/16 20:00:39 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2009/04/10 12:18:29 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{4fa0d965-cd01-4d08-9bdb-0d8c47cfd5d8}
[2009/04/10 13:05:12 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2009/04/10 11:52:34 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{6b6601f1-361e-4b9f-bb6d-f8305000e4f6}
[2009/09/21 23:52:22 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2009/10/21 16:03:01 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/09/01 20:06:30 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
[2009/04/10 11:52:34 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2009/09/15 18:50:35 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2009/09/28 17:25:38 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2009/07/01 14:08:05 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{A4732521-77D9-447E-A557-B279AC923F06}
[2009/07/22 18:30:02 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}
[2009/04/10 11:52:35 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{aba3f5c2-35d5-4960-bdfc-de9c162e39ce}
[2009/07/25 13:08:21 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/10/21 16:02:59 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/07/01 14:17:15 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2009/10/21 16:02:53 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
[2009/09/09 11:26:19 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{cc5cc7f7-8645-49b2-862f-f6e8116dfc44}
[2009/04/21 12:46:31 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2009/09/21 23:52:22 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/04/10 11:52:34 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{ec268e28-22c6-4a6c-ac22-635cabee283c}
[2009/09/09 11:26:40 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2009/04/10 12:18:28 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}
[2009/09/17 12:54:47 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2009/10/24 22:18:56 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\[email protected]
[2009/10/07 21:54:34 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\[email protected]
[2009/04/12 16:58:52 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\[email protected]
[2009/10/24 22:18:56 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\mozilla\Firefox\Profiles\1a2rtg9g.default\extensions\ststusscicalc@sunny
[2009/08/01 14:21:40 | 00,002,271 | ---- | M] () -- C:\Users\t5550\AppData\Roaming\Mozilla\FireFox\Profiles\1a2rtg9g.default\searchplugins\surf-canyon.xml
[2009/10/28 22:00:34 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/13 19:17:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/06/19 12:31:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/08 12:38:05 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/10/20 21:30:55 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009/09/13 19:17:16 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/13 19:17:16 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2006/06/15 19:33:58 | 00,233,472 | ---- | M] (C3D) -- C:\Program Files\mozilla firefox\plugins\CrazyTalk4Native.dll
[2006/05/25 17:43:32 | 00,204,895 | ---- | M] (Reallusion Inc.) -- C:\Program Files\mozilla firefox\plugins\ctdomemhelper.dll
[2005/09/29 13:41:38 | 00,077,824 | ---- | M] (Reallusion Inc.) -- C:\Program Files\mozilla firefox\plugins\ctframeplayerobject.dll
[2006/06/19 12:10:42 | 00,426,081 | ---- | M] (Reallusion Inc.) -- C:\Program Files\mozilla firefox\plugins\ctplayerobject.dll
[2005/02/02 11:19:12 | 00,458,752 | ---- | M] (BEXTech) -- C:\Program Files\mozilla firefox\plugins\imagickrt.dll
[2007/04/10 16:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2009/07/31 14:23:11 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/09/13 19:17:17 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 19:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009/08/03 14:07:42 | 00,373,104 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll
[2009/02/27 11:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/01/03 15:00:40 | 00,069,632 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npRLCT4Player.dll
[2006/04/10 17:35:38 | 00,139,264 | ---- | M] (Reallusion Inc.) -- C:\Program Files\mozilla firefox\plugins\rlcontentclass.dll
[2005/11/09 10:10:06 | 00,204,800 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\RLMusicPacker.dll
[2005/11/09 10:42:52 | 00,106,496 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\RLMusicUnpacker.dll
[2006/01/04 10:22:00 | 00,212,992 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\RLVoicePacker.dll
[2006/01/04 10:21:44 | 00,167,936 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\RLVoiceUnpacker.dll
[2009/08/11 13:20:46 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/11 13:20:46 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/23 11:21:20 | 00,001,489 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml
[2009/08/11 13:20:46 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/11 13:20:46 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/11 13:20:46 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/11 13:20:46 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

O1 HOSTS File: (348880 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 11963 more lines...
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\System32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe File not found
O4 - HKCU..\Run: [Windows Media Center] C:\Windows\ehome\ehuihlp.DLL (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 64 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.euro....r/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.micro...gWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.) - E:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008/02/18 15:48:26 | 00,027,750 | R--- | M] () - E:\Autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2007/10/29 17:25:38 | 00,000,047 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{194eb2ea-28de-11de-8a9d-001d094fba8a}\Shell - "" = AutoRun
O33 - MountPoints2\{194eb2ea-28de-11de-8a9d-001d094fba8a}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{194eb2eb-28de-11de-8a9d-001d094fba8a}\Shell - "" = AutoRun
O33 - MountPoints2\{194eb2eb-28de-11de-8a9d-001d094fba8a}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{194ecf2a-28de-11de-8a9d-001d094fba8a}\Shell - "" = AutoRun
O33 - MountPoints2\{194ecf2a-28de-11de-8a9d-001d094fba8a}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{194ecfa7-28de-11de-8a9d-001d094fba8a}\Shell - "" = AutoRun
O33 - MountPoints2\{194ecfa7-28de-11de-8a9d-001d094fba8a}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{194ecfb2-28de-11de-8a9d-001d094fba8a}\Shell - "" = AutoRun
O33 - MountPoints2\{194ecfb2-28de-11de-8a9d-001d094fba8a}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{548e3d35-4ece-11dd-94c6-001fe11b8b92}\Shell - "" = AutoRun
O33 - MountPoints2\{548e3d35-4ece-11dd-94c6-001fe11b8b92}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{548e3d76-4ece-11dd-94c6-001fe11b8b92}\Shell - "" = AutoRun
O33 - MountPoints2\{548e3d76-4ece-11dd-94c6-001fe11b8b92}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{6e0969d7-257c-11de-8223-001fe11b8b92}\Shell - "" = AutoRun
O33 - MountPoints2\{6e0969d7-257c-11de-8223-001fe11b8b92}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{6e0969d9-257c-11de-8223-001fe11b8b92}\Shell - "" = AutoRun
O33 - MountPoints2\{6e0969d9-257c-11de-8223-001fe11b8b92}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{9f0989b6-263d-11de-9650-001d094fba8a}\Shell - "" = AutoRun
O33 - MountPoints2\{9f0989b6-263d-11de-9650-001d094fba8a}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{a480c7cf-2557-11de-93ef-001fe11b8b92}\Shell - "" = AutoRun
O33 - MountPoints2\{a480c7cf-2557-11de-93ef-001fe11b8b92}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{a480c7d1-2557-11de-93ef-001fe11b8b92}\Shell - "" = AutoRun
O33 - MountPoints2\{a480c7d1-2557-11de-93ef-001fe11b8b92}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{a480c7f8-2557-11de-93ef-001d094fba8a}\Shell - "" = AutoRun
O33 - MountPoints2\{a480c7f8-2557-11de-93ef-001d094fba8a}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{c09d18d0-43d3-11dd-a1d2-001d094fba8a}\Shell\AutoRun\command - "" = C:\Windows\EXPLORER.EXE -- [2009/04/11 06:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{c09d18d0-43d3-11dd-a1d2-001d094fba8a}\Shell\explore\Command - "" = C:\Windows\EXPLORER.EXE -- [2009/04/11 06:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{c09d18d0-43d3-11dd-a1d2-001d094fba8a}\Shell\open\Command - "" = C:\Windows\EXPLORER.EXE -- [2009/04/11 06:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/04/24 05:44:40 | 00,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

NetSvcs: FastUserSwitchingCompatibility - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: Nla - Service key not found. File not found
NetSvcs: Ntmssvc - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: SRService - Service key not found. File not found
NetSvcs: Wmi - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: LogonHours - Service key not found. File not found
NetSvcs: PCAudit - Service key not found. File not found
NetSvcs: helpsvc - Service key not found. File not found
NetSvcs: uploadmgr - Service key not found. File not found

========== Files/Folders - Created Within 14 Days ==========

[2009/10/28 23:14:38 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/10/24 15:11:54 | 00,000,000 | ---D | C] -- C:\ProgramData\SupportSoft
[2009/10/23 20:22:27 | 00,000,000 | ---D | C] -- C:\Users\t5550\AppData\Roaming\Dell
[2009/10/28 23:14:44 | 00,000,000 | ---D | C] -- C:\Users\t5550\AppData\Roaming\Malwarebytes
[2009/10/28 11:12:49 | 00,000,000 | ---D | C] -- C:\Users\t5550\AppData\Roaming\PeerNetworking
[2009/10/23 10:50:51 | 00,000,000 | ---D | C] -- C:\Users\t5550\AppData\Local\Deployment
[2009/10/24 15:10:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\supportsoft
[2009/10/29 07:28:09 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/10/28 23:14:38 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/29 09:05:31 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009/10/29 09:14:05 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2009/10/29 13:52:09 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Users\t5550\Desktop\OTL.exe
[2009/10/29 13:07:22 | 00,472,064 | ---- | C] ( ) -- C:\Users\t5550\Desktop\RootRepeal.exe
[2009/10/29 09:47:45 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Users\t5550\Desktop\spybotsd162.exe
[2009/10/29 07:28:48 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/10/29 07:28:47 | 00,052,368 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/10/29 07:28:43 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/10/29 07:28:42 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/10/29 07:28:42 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/10/29 07:28:11 | 01,279,968 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/10/29 07:28:11 | 00,053,328 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/10/29 07:24:38 | 00,308,160 | ---- | C] (ALWIL Software) -- C:\Users\t5550\Desktop\avast_home_setup.exe
[2009/10/28 23:14:39 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/10/28 23:14:38 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/10/28 22:51:55 | 00,271,872 | ---- | C] (OldTimer Tools) -- C:\Users\t5550\Desktop\TFC.exe
[2009/10/26 18:05:49 | 00,000,000 | ---D | C] -- C:\Users\t5550\Documents\Hiking Gear Info
[2009/10/23 11:30:26 | 00,000,000 | ---D | C] -- C:\Windows\System32\Lang

========== Files - Modified Within 14 Days ==========

[2009/10/29 14:41:59 | 00,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{BA94A9C5-6D60-48CF-9956-B21F79D4DD27}.job
[2009/10/29 14:39:03 | 00,026,258 | ---- | M] () -- C:\Users\t5550\Documents\letter to geeks 29 10 09.docx
[2009/10/29 14:06:16 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/29 14:06:09 | 00,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/29 14:06:09 | 00,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/29 14:05:55 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/10/29 13:56:10 | 00,000,503 | ---- | M] () -- C:\Windows\win.ini
[2009/10/29 13:52:12 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\t5550\Desktop\OTL.exe
[2009/10/29 13:30:13 | 00,631,342 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/10/29 13:30:12 | 00,731,074 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/10/29 13:30:12 | 00,114,058 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/10/29 13:17:02 | 00,001,838 | ---- | M] () -- C:\Users\t5550\Documents\RootRepeal.exe
[2009/10/29 13:08:20 | 00,000,000 | ---- | M] () -- C:\Windows\System32\settings.dat
[2009/10/29 13:07:26 | 00,472,064 | ---- | M] ( ) -- C:\Users\t5550\Desktop\RootRepeal.exe
[2009/10/29 11:24:01 | 00,002,633 | ---- | M] () -- C:\Users\t5550\Desktop\Microsoft Office Outlook 2007.lnk
[2009/10/29 09:53:18 | 00,001,055 | ---- | M] () -- C:\Users\t5550\Desktop\Spybot - Search & Destroy.lnk
[2009/10/29 09:48:39 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Users\t5550\Desktop\spybotsd162.exe
[2009/10/29 09:13:19 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009/10/29 09:13:04 | 02,237,085 | -H-- | M] () -- C:\Users\t5550\AppData\Local\IconCache.db
[2009/10/29 08:19:50 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/10/29 07:28:50 | 00,001,849 | ---- | M] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/10/29 01:13:43 | 00,308,160 | ---- | M] (ALWIL Software) -- C:\Users\t5550\Desktop\avast_home_setup.exe
[2009/10/28 23:14:42 | 00,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/28 22:52:20 | 00,271,872 | ---- | M] (OldTimer Tools) -- C:\Users\t5550\Desktop\TFC.exe
[2009/10/28 19:02:40 | 00,348,880 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2009/10/28 11:12:49 | 00,027,043 | ---- | M] () -- C:\Users\t5550\AppData\Roaming\UserTile.png
[2009/10/28 10:56:29 | 00,007,442 | ---- | M] () -- C:\Windows\System32\DModem_Trace.trc
[2009/10/28 10:16:20 | 22,406,5758 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2009/10/27 18:12:08 | 00,104,448 | ---- | M] () -- C:\Users\t5550\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/27 16:57:07 | 00,049,152 | ---- | M] () -- C:\Windows\System32\umstartup.etl
[2009/10/27 16:51:45 | 00,039,936 | ---- | M] () -- C:\Windows\System32\umstartup000.etl
[2009/10/26 12:25:00 | 00,000,472 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/10/25 14:12:50 | 00,001,142 | ---- | M] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2009/10/25 09:59:07 | 00,000,422 | ---- | M] () -- C:\Windows\tasks\Driver Robot.job
[2009/10/24 15:50:56 | 00,002,545 | ---- | M] () -- C:\Users\t5550\Documents\Dell Support Center.lnk
[2009/10/24 15:50:56 | 00,002,545 | ---- | M] () -- C:\Users\Public\Desktop\Dell Support Center.lnk
[2009/10/24 15:17:22 | 00,001,927 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
[2009/10/24 14:27:25 | 00,016,070 | ---- | M] () -- C:\Windows\System32\results.xml
[2009/10/24 13:59:31 | 00,022,729 | ---- | M] () -- C:\newkey
[2009/10/24 13:59:31 | 00,022,729 | ---- | M] () -- C:\newfile.enc
[2009/10/23 11:24:56 | 00,000,680 | ---- | M] () -- C:\Users\t5550\AppData\Local\d3d9caps.dat
[2009/10/21 13:40:33 | 00,347,178 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20091028-190240.backup

========== Files - No Company Name ==========
[2009/10/29 13:17:02 | 00,001,838 | ---- | C] () -- C:\Users\t5550\Documents\RootRepeal.exe
[2009/10/29 13:08:20 | 00,000,000 | ---- | C] () -- C:\Windows\System32\settings.dat
[2009/10/29 11:50:02 | 00,026,258 | ---- | C] () -- C:\Users\t5550\Documents\letter to geeks 29 10 09.docx
[2009/10/29 09:53:18 | 00,001,055 | ---- | C] () -- C:\Users\t5550\Desktop\Spybot - Search & Destroy.lnk
[2009/10/29 09:13:19 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009/10/29 07:28:50 | 00,001,849 | ---- | C] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/10/29 07:28:11 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/10/28 23:14:42 | 00,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/28 11:12:49 | 00,027,043 | ---- | C] () -- C:\Users\t5550\AppData\Roaming\UserTile.png
[2009/10/28 10:54:29 | 00,007,442 | ---- | C] () -- C:\Windows\System32\DModem_Trace.trc
[2009/10/28 10:16:20 | 22,406,5758 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2009/10/28 04:15:40 | 02,237,085 | -H-- | C] () -- C:\Users\t5550\AppData\Local\IconCache.db
[2009/10/24 15:57:32 | 00,002,545 | ---- | C] () -- C:\Users\t5550\Documents\Dell Support Center.lnk
[2009/10/24 15:11:27 | 00,002,545 | ---- | C] () -- C:\Users\Public\Desktop\Dell Support Center.lnk
[2009/09/04 20:45:06 | 00,000,088 | RHS- | C] () -- C:\Windows\System32\2AD5172CF1.sys
[2009/09/04 20:30:08 | 00,003,766 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2009/08/03 14:07:42 | 00,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/06/20 21:28:40 | 00,054,784 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2009/06/17 21:52:27 | 01,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll
[2009/06/17 21:52:27 | 01,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll
[2009/06/17 21:52:27 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
[2009/06/17 18:13:53 | 00,074,703 | ---- | C] () -- C:\Windows\System32\mfc45.dll
[2009/06/01 19:14:43 | 00,000,000 | ---- | C] () -- C:\Windows\Mavis Beacon Teaches Typing.INI
[2009/05/30 22:25:17 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/04/19 11:05:38 | 00,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/04/18 22:59:05 | 00,000,000 | ---- | C] () -- C:\Windows\hpqEmlSz.INI
[2009/04/12 21:48:13 | 00,000,000 | ---- | C] () -- C:\Users\t5550\AppData\Roaming\wklnhst.dat
[2009/04/09 17:36:22 | 00,025,412 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2009/04/09 15:40:38 | 00,104,448 | ---- | C] () -- C:\Users\t5550\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/27 01:09:45 | 00,056,056 | ---- | C] () -- C:\Windows\System32\DLAAPI_W.DLL
[2008/06/27 01:09:44 | 00,000,120 | ---- | C] () -- C:\Windows\wininit.ini
[2008/06/27 00:53:56 | 00,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2008/06/27 00:53:55 | 01,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008/06/27 00:53:55 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2008/06/27 00:53:55 | 00,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2008/06/27 00:43:48 | 00,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/06/27 00:29:52 | 00,086,544 | ---- | C] () -- C:\Users\t5550\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/06/27 00:29:14 | 00,000,680 | ---- | C] () -- C:\Users\t5550\AppData\Local\d3d9caps.dat
[2007/08/06 23:22:15 | 00,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2007/07/25 15:40:02 | 00,999,424 | ---- | C] () -- C:\Windows\System32\WLIHVUI.dll
[2006/11/02 12:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 12:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 10:23:31 | 00,000,503 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 10:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 07:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/09/16 22:36:50 | 00,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 00,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll

========== LOP Check ==========

[2009/10/28 23:14:44 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming
[2009/04/14 15:58:18 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\4Team
[2009/08/23 13:16:29 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\ArcSoft
[2008/07/10 23:21:17 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Birdstep Technology
[2009/06/01 19:17:27 | 00,000,000 | -H-D | M] -- C:\Users\t5550\AppData\Roaming\Broderbund
[2009/09/04 20:43:08 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Corel
[2009/10/23 20:22:28 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Dell
[2009/10/29 14:43:01 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Free Download Manager
[2008/06/27 00:51:33 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Intel
[2009/06/17 18:13:39 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\iolo
[2009/06/03 19:51:58 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\licenses
[2006/11/02 12:37:34 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Media Center Programs
[2009/06/03 19:54:00 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\PCMM2009
[2009/10/28 11:12:49 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\PeerNetworking
[2009/04/09 18:54:05 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Roxio
[2009/10/29 14:07:23 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Software Informer
[2008/06/27 00:52:23 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\TMP
[2009/05/23 17:41:59 | 00,000,000 | ---D | M] -- C:\Users\t5550\AppData\Roaming\Uniblue
[2009/10/26 12:25:00 | 00,000,472 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/10/25 09:59:07 | 00,000,422 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job
[2009/10/29 14:06:16 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/10/29 09:14:45 | 00,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009/10/29 14:41:59 | 00,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{BA94A9C5-6D60-48CF-9956-B21F79D4DD27}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %SYSTEMDRIVE%\eventlog.dll /s /md5 >

< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[scecli.dll : MD5=8FC182167381E9915651267044105EE1] -> [2009/04/11 06:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\scecli.dll
[scecli.dll : MD5=80E2839D05CA5970A86D7BE2A08BFF61] -> [2006/11/02 09:46:12 | 00,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[scecli.dll : MD5=28B84EB538F7E8A0FE8B9299D591E0B9] -> [2008/01/19 07:36:19 | 00,177,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[scecli.dll : MD5=8FC182167381E9915651267044105EE1] -> [2009/04/11 06:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[netlogon.dll : MD5=95DAECF0FB120A7B5DA679CC54E37DDE] -> [2009/04/11 06:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netlogon.dll
[netlogon.dll : MD5=889A2C9F2AACCD8F64EF50AC0B3D553B] -> [2006/11/02 09:46:11 | 00,559,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[netlogon.dll : MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F] -> [2008/01/19 07:35:36 | 00,592,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[netlogon.dll : MD5=95DAECF0FB120A7B5DA679CC54E37DDE] -> [2009/04/11 06:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll

< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
[cngaudit.dll : MD5=7F15B4953378C8B5161D65C26D5FED4D] -> [2006/11/02 09:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cngaudit.dll
[cngaudit.dll : MD5=7F15B4953378C8B5161D65C26D5FED4D] -> [2006/11/02 09:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< %SYSTEMDRIVE%\sceclt.dll /s /md5 >

< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >

< %SYSTEMDRIVE%\logevent.dll /s /md5 >

< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
[iastor.sys : MD5=997E8F5939F2D12CD9F2E6B395724C16] -> [2007/03/21 11:58:56 | 00,304,920 | ---- | M] (Intel Corporation) -- C:\dell\drivers\R166200\iastor.sys

< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
[nvstor.sys : MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9] -> [2007/01/06 05:59:42 | 00,035,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor.sys
[nvstor.sys : MD5=ABED0C09758D1D97DB0042DBB2688177] -> [2008/01/19 07:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[nvstor.sys : MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9] -> [2007/01/06 05:59:42 | 00,035,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_45f67928\nvstor.sys
[nvstor.sys : MD5=9E0BA19A28C498A6D323D065DB76DFFC] -> [2006/11/02 09:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[nvstor.sys : MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9] -> [2007/01/06 05:59:42 | 00,035,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\DriverStore\FileRepository\nvstor.inf_f48b8337\nvstor.sys
[nvstor.sys : MD5=ABED0C09758D1D97DB0042DBB2688177] -> [2008/01/19 07:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[atapi.sys : MD5=1F05B78AB91C9075565A9D8A4B880BC4] -> [2009/04/11 06:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\atapi.sys
[atapi.sys : MD5=B35CFCEF838382AB6490B321C87EDF17] -> [2009/04/10 02:28:32 | 00,021,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[atapi.sys : MD5=A779CA2C76DA4FCB595E692C05E8E4EB] -> [2007/02/21 19:49:48 | 00,019,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[atapi.sys : MD5=1F05B78AB91C9075565A9D8A4B880BC4] -> [2009/04/11 06:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[atapi.sys : MD5=4F4FCB8B6EA06784FB6D475B7EC7300F] -> [2006/11/02 09:49:36 | 00,019,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[atapi.sys : MD5=2D9C903DC76A66813D350A562DE40ED9] -> [2008/01/19 07:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[atapi.sys : MD5=A779CA2C76DA4FCB595E692C05E8E4EB] -> [2007/02/21 19:49:48 | 00,019,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[atapi.sys : MD5=B35CFCEF838382AB6490B321C87EDF17] -> [2009/04/10 02:28:32 | 00,021,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[atapi.sys : MD5=5653737BAD8C6C10136451C195C19881] -> [2007/02/21 19:49:48 | 00,019,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[atapi.sys : MD5=E03E8C99D15D0381E02743C36AFC7C6F] -> [2009/04/10 02:28:31 | 00,021,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
[atapi.sys : MD5=2D9C903DC76A66813D350A562DE40ED9] -> [2008/01/19 07:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[atapi.sys : MD5=1F05B78AB91C9075565A9D8A4B880BC4] -> [2009/04/11 06:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >

< %SYSTEMDRIVE%\viasraid.sys /s /md5 >

< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[AGP440.sys : MD5=EF23439CDD587F64C2C1B8825CEAD7D8] -> [2006/11/02 09:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\AGP440.sys
[AGP440.sys : MD5=13F9E33747E6B41A3FF305C37DB0D360] -> [2008/01/19 07:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[AGP440.sys : MD5=EF23439CDD587F64C2C1B8825CEAD7D8] -> [2006/11/02 09:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[AGP440.sys : MD5=13F9E33747E6B41A3FF305C37DB0D360] -> [2008/01/19 07:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[AGP440.sys : MD5=13F9E33747E6B41A3FF305C37DB0D360] -> [2008/01/19 07:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[AGP440.sys : MD5=13F9E33747E6B41A3FF305C37DB0D360] -> [2008/01/19 07:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys

< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Websites from Geoge Noory Radio Show\Iluminati:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Websites from Geoge Noory Radio Show:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Voice over work:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Things to do places to go\Things to do in California:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Things to do places to go:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Setting up Email Accts in Outlook:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Passwords\Corel Account Paintshop Pro_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Passwords\Account CreatedRegistration Confirmation_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Passwords:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\NetGear WAG511 Driver:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\My new hard drive:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\MY COMPUTER REPAIR Pat Oconnel:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\How to for Lap Top Links:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Geeks to Go:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\DVD MP3 XPack:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Support:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Inspiron 1525 service tag etc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\WinAce 2.5 Installer:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Win Zip\hosts:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Win Zip:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Registry back up from CC cleaner Oct 07:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Quark Install:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\New TouchPad Driver 10 27 07\Latest Driver for touch pad Oct 07:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\New TouchPad Driver 10 27 07:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Nero 6.3 Ultra:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Diskeeper 8.0.478.0:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\ESS Maestro 3i:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Dont know what these Drivers are for:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Dont know what DELL Drivers:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Dell Suspend Utilities:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Dell OS Updates:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Dell Latitude C600 System BIOS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Dell Help and Support Customizations:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Dell Access Direct:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Canon S450 Driver:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\ATI Mobility 3 Mobility 4:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\Actiontec MiniPCI V.90 DataFax Modem:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers\3Com 10100 & V.90 LAN Mini-PCI:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\Dell Help Drivers:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers\ATI Video Driver:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell Help Drivers Keys & Installers:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell & Other informatonal Manuals\Microsoft Office 2003 eBooks:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell & Other informatonal Manuals\Epson Stylus C4OUX Manuals:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell & Other informatonal Manuals\Dell Latitude C600 Manuals\Dell most helpful:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell & Other informatonal Manuals\Dell Latitude C600 Manuals\c600pins:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell & Other informatonal Manuals\Dell Latitude C600 Manuals:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Dell & Other informatonal Manuals:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\Computer Glasses:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\All Downloads upto 12 27 05\CPanel:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\All Downloads upto 12 27 05\BIN:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer\All Downloads upto 12 27 05:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Technical Info for my computer:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Recovery emails from the crossing 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Rays Photos 2009-06-13\100428:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Rays Photos 2009-06-13:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Purely Ccreative\2009-09 (Sep):Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Purely Ccreative:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Political Lyrics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Pictures 2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Pictures 1:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photos at Glogs 23 09 09:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photo002008.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photo002007.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photo002006.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photo002005.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photo002004.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photo002003.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Photo001.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Outlooks Files 14 4 09:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Our Deepest Fear:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\One Show Sales of goods act Dom Littlewood:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Notes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Video\50666-Nina-Hartley-Shorty-Iz-[bleep]in-Yo-Mama_files\a_data:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Video\50666-Nina-Hartley-Shorty-Iz-[bleep]in-Yo-Mama_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Video:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Video 2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Workspaces:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Textures:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Swatches:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Styled Lines:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Selections:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Scripts-Trusted:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Scripts-Restricted:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Print Templates:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Presets:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Preset Shapes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Picture Tubes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Picture Frames:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Patterns:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Palettes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Monitor Profiles:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Mixer Pages:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Masks:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Gradients:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Environment Maps:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Displacement Maps:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Deformation Maps:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\CMYK Profiles:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Bump Maps:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files\Brushes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My PSP Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Photos 10 6 09\photos 29 9 09:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Photos 10 6 09:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Book 2\Missing Peace Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Book 2\have been working missing piece:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Book 2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\My Albums:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Metapyhisical Business Documents:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Marketing for Phillip:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\LimeWire\Store Purchased:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\LimeWire:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Letters out\Fred 23 9 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Letters out:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Letters in:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\JOKES to send to friends\fun tests of the mind:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\JOKES to send to friends\Fun Lyrics and Photos to send by Email:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\JOKES to send to friends\Christmas Stuff\0840720726_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\JOKES to send to friends\Christmas Stuff:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\JOKES to send to friends:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\Sales Info\Work related Scripts sales help docs:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\Sales Info:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\personal references:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\Old Resumes you wont want to send 5 23 06:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\Jobs and Search Engines etc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\CURRENT RESUMES updated 11 07\More descriptive Cover Notes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\CURRENT RESUMES updated 11 07:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales\Apartments:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Jobs Apartments Resumes References & Sales:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Intense orgasms:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\In the Media Things of interest\Sand Fantasy Link_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\In the Media Things of interest\Links:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\In the Media Things of interest:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Hiking Gear Info:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Tinctures:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Tea Green for Healing & Losing Weight:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Supplements:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Stop Smoking:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Herbs and Health\PH Testing Explained:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Herbs and Health\Computer Glasses:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Herbs and Health:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Hand Foot & Ear Charts:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Dangers of Hydrogenated Oils:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Channelling:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Book for Eye exercises:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical\Allergic Reactions:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Health Healing and Metaphysical:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Zeana Grafton Holt Gods teaching 3 10 08\PRINT OUTS Today:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Zeana Grafton Holt Gods teaching 3 10 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Writings for the Radio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\What God wants us to do:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\The Crossing:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Putting on and maintaining the Armour of God_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Political Lyrics\Thomas Jefferson:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Political Lyrics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08\Philips exam of Hope 2 2 108:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08\Folder moved from USB 12 9 08\PRINT OUTS Today:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08\Folder moved from USB 12 9 08\HOPE Project 2 12 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08\Folder moved from USB 12 9 08\Daily Study:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08\Folder moved from USB 12 9 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08\Daily Study:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08\Baptism Info 3 6 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Phiips Ministry set up 3 10 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Mark Van Druff Unmerited Favour:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Letter signing of Prayers:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Words of Good will:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\When your down:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Tests for smart people:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Stories:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Shocking Pics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Remiders of what Love is:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Puts a Smile on:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Praying 4 others:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Non Religious\When Graphic artists get bored:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Non Religious:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Learning Gods Word:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Interesting Stuff\A Fire Rainbow:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Interesting Stuff:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Funny Stuff:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\For Women who want to lose weight:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Christmas Stuff:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email\Beatuful:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fun Lyrics & Photos to send by Email:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry\Fear of God and Compassion for Others:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Gods Word & Ministry:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\George Galloway:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Friends & Work Ph #s:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Find a partner:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr Richard Boylan shielding101_files\Sheilding\shielding101_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr Richard Boylan shielding101_files\Sheilding:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr Richard Boylan shielding101_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr R Boylan\Dr Boylan Radio recor Starseed April 6 2006:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr R Boylan:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr R Boylan on the radio april 08\[DrRichBoylanReports] The webpage address for the Dr_Boylan Coast to Coast Interview has changed - Yahoo! Mail_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr R Boylan on the radio april 08\[DrRichBoylanReports] message from the Whale Nation, relayed by Ihantowan Dakota Star Altar-Keeper Chief Golden Eagle - Yahoo! Mail_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr R Boylan on the radio april 08\[DrRichBoylanReports] for thoseof you with dial-up connection sto the Internet - Yahoo! Mail_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr R Boylan on the radio april 08\[DrRichBoylanReports] audio of Dr_ Boylan's interview on CoastTo CoastAM March 31 about the Altimarians arriving, etc_ - Yahoo! Mail_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dr R Boylan on the radio april 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Downloads logged into firefox from 09:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Water:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Underwater:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Temples Pagodars:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\sunsets:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Snow:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Relcs:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Posers:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Planetscapes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Ocean:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Night Scenery:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\mountains:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\More XP Wallpapers:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\moonscapes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Lightnng:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Lakes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Islands:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\heads & Faces:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Hauntng:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\green:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Graphcs:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Girls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Forests:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\focus:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Flags:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Deserts:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Cars:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Bizzare graphics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Anmals:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy\Abstracts:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Digital Blasphemy:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Dentist:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\David Icke:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Date I:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Crossing more emails 06:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Cropcircles.bmp:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Cooking and Recipes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Cannot Open\Symbols + Business Card will not open:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Cannot Open:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Brian Pendarvis:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Blackwood Productions\Marketing On Line:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Blackwood Productions:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Resume Info:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Print OUTS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Passwords:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Norah Jones Come Away with Me:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\The Crossing:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Print OUTS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Political Lyrics\Thomas Jefferson:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Political Lyrics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Phiips Ministry set up 3 10 08\PRINT OUTS Today:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Phiips Ministry set up 3 10 08\HOPE Project 2 12 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Phiips Ministry set up 3 10 08\Gods teaching from Zeana Grafton Holt 3 10 08\PRINT OUTS Today:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Phiips Ministry set up 3 10 08\Gods teaching from Zeana Grafton Holt 3 10 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Phiips Ministry set up 3 10 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Mark Van Druff Unmerited Favour:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Fun Lyrics to send by Email:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info\Currently Learning 3 31 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08\Gods Word & useful info:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\Back up from Memory Stick 3 31 08:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\A poem for recovery:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\9 28 07 I NEED TO DO THESE THINGS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\12 Step Program\Andyaddict Info from Narcotics Annonymous:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\12 Step Program\A A Meetings in Sy & Sx:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\12 Step Program\9 28 07 I NEED TO DO THESE THINGS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Documents\12 Step Program:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\t5550\Desktop\CNV00010.jpg:Roxio EMC Stream
@Alternate Data Stream - 130 bytes -> C:\Users\All Users\TEMP:5D432CE3
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:5D432CE3
@Alternate Data Stream - 125 bytes -> C:\Users\All Users\TEMP:5C321E34
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP