Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Explorer Slow/Computer infected?


  • Please log in to reply

#1
DakTrudel

DakTrudel

    New Member

  • Member
  • Pip
  • 2 posts
Hi,
Thanks in advance for any help you can give me. Internet explorer is extremely slow and stalls. I installed Firefox but am still worried about why Internet Explorer is messed up. I have taken all the toolbars off and reset it to original settings. I have muddled around and scanned with different products, like housecall, Kapersky, super anti spyware, etc. Tried scanning with Ad-aware and it wouldn't let me. I have also had problems with my wife's new Panisonic camera uploading pictures since all this began. Then I got smart and came to this site and followed the malware and spyware cleaning guide. Info is below and attached. Thanks again, I am out of my league here.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-06 06:33:30
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Family\AppData\Local\Temp\pxryapod.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys ZwTerminateProcess [0x928670B0]

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

---- Files - GMER 1.0.15 ----

File C:\Users\Family\Downloads\OTL.exe 513536 bytes

---- EOF - GMER 1.0.15 ----

OTL logfile created on: 1/6/2010 6:35:50 AM - Run 1
OTL by OldTimer - Version 3.1.21.0 Folder = C:\Users\Family\Desktop\Spyware Cleaners
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.93 Gb Total Space | 120.64 Gb Free Space | 41.75% Space Free | Partition Type: NTFS
Drive D: | 9.16 Gb Total Space | 1.25 Gb Free Space | 13.63% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE-PC
Current User Name: Family
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/01/05 20:42:19 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Users\Family\Desktop\Spyware Cleaners\OTL.exe
PRC - [2009/12/18 19:49:26 | 00,186,760 | ---- | M] () -- C:\Program Files\Photodex\ProShowGold\scsiaccess.exe
PRC - [2009/12/16 16:26:56 | 02,002,160 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2009/11/29 09:33:22 | 00,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/11/19 22:29:16 | 00,623,960 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
PRC - [2009/11/01 08:46:40 | 00,160,592 | ---- | M] (Siber Systems) -- C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2009/10/28 20:21:26 | 00,141,600 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/10/28 20:21:14 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/10/11 04:17:36 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/09/13 18:52:50 | 01,048,392 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/05/29 12:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/04/10 22:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/03 23:47:05 | 00,079,872 | ---- | M] (SanDisk Corporation) -- C:\Users\Family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2009/03/30 16:28:36 | 01,533,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/03/30 16:28:36 | 00,183,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009/02/27 22:35:03 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/02/26 18:57:18 | 00,252,952 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe
PRC - [2009/02/26 18:57:16 | 00,150,552 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpers.exe
PRC - [2009/02/26 18:57:12 | 00,173,592 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hkcmd.exe
PRC - [2009/01/26 14:31:10 | 01,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/11/06 11:33:56 | 00,288,088 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
PRC - [2008/11/06 11:33:54 | 00,582,992 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
PRC - [2008/10/25 10:44:34 | 00,031,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2008/10/25 07:18:50 | 00,098,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008/10/24 08:14:36 | 00,206,112 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2008/07/03 11:27:12 | 06,266,880 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/01/20 18:25:33 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2007/11/19 13:54:04 | 00,079,136 | ---- | M] (Hewlett-Packard Company) -- c:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/09/19 16:30:52 | 00,065,536 | ---- | M] (Hewlett-Packard) -- c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
PRC - [2007/08/07 06:26:28 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\drivers\XAudio.exe
PRC - [2007/05/31 08:21:28 | 00,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdcBase.exe
PRC - [2007/05/08 16:24:20 | 00,054,840 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2007/04/18 07:01:34 | 00,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
PRC - [2007/02/28 03:38:16 | 00,061,440 | ---- | M] (Sigmatel) -- C:\Windows\system\w98eject.exe
PRC - [2007/02/15 03:59:00 | 00,118,784 | ---- | M] (OsdMaestro) -- C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
PRC - [2006/12/19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\Windows\System32\IoctlSvc.exe
PRC - [2004/09/25 01:37:42 | 01,691,648 | ---- | M] (Roxio) -- C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
PRC - [2004/01/29 11:23:36 | 00,040,960 | ---- | M] (Timex Corporation) -- C:\Program Files\Timex\Data Link USB\DataLinkLauncher.exe


========== Modules (SafeList) ==========

MOD - [2010/01/05 20:42:19 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Users\Family\Desktop\Spyware Cleaners\OTL.exe
MOD - [2009/04/10 22:21:38 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/11/11 19:00:02 | 00,011,016 | ---- | M] (Kaspersky Lab) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll
MOD - [2008/11/11 18:59:38 | 00,083,208 | ---- | M] (Kaspersky Lab) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/12/18 19:49:26 | 00,186,760 | ---- | M] () [Auto | Running] -- C:\Program Files\Photodex\ProShowGold\scsiaccess.exe -- (ScsiAccess)
SRV - [2009/10/28 20:21:14 | 00,545,568 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/09/28 09:42:50 | 00,109,056 | ---- | M] (ArcSoft Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/09/24 17:27:04 | 00,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/07/26 12:32:18 | 00,208,616 | ---- | M] (Kaspersky Lab) [Auto | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe -- (AVP)
SRV - [2009/07/08 12:31:36 | 00,313,840 | ---- | M] (Sonic Solutions) [Disabled | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe -- (RoxLiveShare9)
SRV - [2009/07/08 12:31:32 | 00,170,480 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -- (RoxWatch9)
SRV - [2009/07/08 12:31:12 | 01,108,464 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -- (RoxMediaDB9)
SRV - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/05/29 12:41:26 | 00,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/04/22 16:07:05 | 00,182,768 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2009/03/30 16:28:36 | 01,533,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009/01/26 14:31:10 | 01,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/11/06 11:33:54 | 00,582,992 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe -- (RUBotted)
SRV - [2008/11/04 00:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 10:44:08 | 00,065,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2008/04/08 08:56:30 | 00,800,040 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService)
SRV - [2008/01/22 10:13:26 | 00,275,752 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2008/01/20 18:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/06 23:20:56 | 00,088,560 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe -- (Roxio UPnP Renderer 9)
SRV - [2007/12/06 23:20:52 | 00,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe -- (Roxio Upnp Server 9)
SRV - [2007/11/19 13:54:04 | 00,079,136 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- c:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2007/09/19 16:30:52 | 00,065,536 | ---- | M] (Hewlett-Packard) [Auto | Running] -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service)
SRV - [2007/08/07 06:26:28 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\System32\drivers\XAudio.exe -- (XAudioService)
SRV - [2007/05/31 08:21:24 | 00,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 08:21:18 | 00,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006/12/19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\Windows\System32\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
SRV - [2006/11/02 04:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\ehome\ehstart.dll -- (ehstart)
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2004/10/22 02:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...a...&pf=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...=en&source=iglk
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/05 21:17:27 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/05 21:17:27 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\THBExt [2009/04/01 21:24:23 | 00,000,000 | ---D | M]

[2010/01/01 18:26:09 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

Hosts file not found
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TMRUBottedTray] C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Family\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll (Kaspersky Lab)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo1.walgre...eensActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.4.3.cab (DLM Control)
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} http://coupons.smart...oad/cscmv5X.cab (CMV5 Class)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.evite.com...geUploader5.cab (Image Uploader Control)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.on...e/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} http://samsclubus.pn...veX_Control.cab (Photo Upload Plugin Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/17 10:25:37 | 00,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{2706e11a-f790-11dd-9062-001d92b1eda5}\Shell\AutoRun\command - "" = G:\setupSNK.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/20 18:34:27 | 00,000,000 | ---D | M]
NetSvcs: Irmon - C:\Windows\System32\irmon.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/01/05 20:52:31 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/05 20:52:29 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/01/05 20:52:28 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/01/05 20:52:27 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/05 20:50:29 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/01/05 20:49:37 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/01/05 20:27:10 | 05,061,512 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Family\Desktop\mbam-setup.exe
[2010/01/05 20:25:29 | 00,000,000 | ---D | C] -- C:\Users\Family\Desktop\Spyware Cleaners
[2010/01/01 22:14:05 | 00,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2010/01/01 21:11:45 | 00,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/01/01 21:11:23 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/01/01 21:09:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/01/01 18:55:00 | 00,000,000 | ---D | C] -- C:\Users\Family\.housecall6.6
[2010/01/01 15:13:59 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2010/01/01 14:37:12 | 00,000,000 | ---D | C] -- C:\Program Files\TrendMicro
[2010/01/01 14:25:52 | 00,206,608 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\TMPassthru.sys
[2010/01/01 14:25:49 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/01/01 13:36:54 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/01/01 01:06:58 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/12/30 19:59:34 | 00,000,000 | ---D | C] -- C:\ProgramData\ArcSoft
[2009/12/29 22:13:27 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2009/12/29 22:06:47 | 00,000,000 | ---D | C] -- C:\Users\Family\AppData\Local\ArcSoft
[2009/12/29 20:10:23 | 00,011,776 | ---- | C] (Arcsoft, Inc.) -- C:\Windows\System32\drivers\afc.sys
[2009/12/29 20:10:22 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ArcSoft
[2009/12/29 20:10:19 | 00,126,976 | ---- | C] (ArcSoft Inc.) -- C:\Windows\System32\MediaImpression Slideshow.scr
[2009/12/29 20:10:01 | 00,000,000 | ---D | C] -- C:\Windows\System32\MediaImpression Slideshow
[2009/12/29 20:09:57 | 00,000,000 | ---D | C] -- C:\Program Files\ArcSoft
[2009/12/29 20:08:32 | 00,501,912 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\PICSDK2.dll
[2009/12/29 20:08:32 | 00,120,992 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\EpPicPrt.dll
[2009/12/29 20:08:32 | 00,108,704 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\PICEntry.dll
[2009/12/29 20:08:32 | 00,080,024 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\PICSDK.dll
[2009/12/29 20:08:31 | 00,071,840 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\EPPicMgr.dll
[2009/12/29 20:07:36 | 00,045,056 | ---- | C] (Matsushita Electric Industrial Co., Ltd.) -- C:\Windows\System32\PhDi2.sys
[2009/12/29 20:07:33 | 00,000,000 | ---D | C] -- C:\Program Files\Panasonic

========== Files - Modified Within 14 Days ==========

[2010/01/06 06:36:10 | 08,650,752 | -HS- | M] () -- C:\Users\Family\NTUSER.DAT
[2010/01/06 04:45:42 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/01/06 04:45:42 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/01/06 04:18:59 | 00,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 2).job
[2010/01/05 22:18:59 | 00,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 1).job
[2010/01/05 20:49:59 | 00,000,919 | ---- | M] () -- C:\Users\Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/01/05 20:47:55 | 00,000,419 | ---- | M] () -- C:\Users\Family\Documents - Shortcut.lnk
[2010/01/05 20:45:44 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/01/05 20:45:41 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/01/05 20:45:40 | 34,783,15008 | -HS- | M] () -- C:\hiberfil.sys
[2010/01/05 20:44:55 | 08,107,040 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.dat
[2010/01/05 20:44:55 | 01,556,512 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox2.dat
[2010/01/05 20:44:55 | 00,066,512 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.idx
[2010/01/05 20:44:55 | 00,008,496 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox2.idx
[2010/01/05 20:44:31 | 00,524,288 | -HS- | M] () -- C:\Users\Family\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/01/05 20:44:31 | 00,065,536 | -HS- | M] () -- C:\Users\Family\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/01/05 20:27:52 | 05,061,512 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Family\Desktop\mbam-setup.exe
[2010/01/03 15:32:50 | 00,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/01/03 15:32:50 | 00,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 4).job
[2010/01/03 15:32:49 | 00,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 3).job
[2010/01/03 14:11:08 | 02,870,193 | -H-- | M] () -- C:\Users\Family\AppData\Local\IconCache.db
[2010/01/02 11:00:51 | 00,694,964 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/01/02 11:00:51 | 00,598,350 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/01/02 11:00:51 | 00,101,988 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/01/01 21:11:26 | 00,000,908 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/01/01 18:26:12 | 00,001,730 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/01/01 17:14:58 | 00,486,552 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/01/01 15:17:32 | 00,524,288 | ---- | M] () -- C:\Users\Family\Desktop\dds.scr
[2010/01/01 14:22:19 | 00,143,856 | ---- | M] () -- C:\Users\Family\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/01/01 13:47:56 | 00,355,028 | ---- | M] () -- C:\Users\Family\Documents\cc_20100101_134727.reg
[2010/01/01 13:36:55 | 00,001,676 | ---- | M] () -- C:\Users\Family\Desktop\CCleaner.lnk
[2009/12/31 10:40:49 | 00,000,036 | ---- | M] () -- C:\Users\Family\AppData\Local\housecall.guid.cache
[2009/12/30 19:59:41 | 00,000,026 | ---- | M] () -- C:\UpdaterforApp.ini
[2009/12/30 14:55:24 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/12/30 14:54:58 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/12/29 20:10:58 | 00,001,926 | ---- | M] () -- C:\Users\Public\Desktop\Panorama Maker 4.lnk
[2009/12/29 20:10:22 | 00,002,121 | ---- | M] () -- C:\Users\Public\Desktop\Media Impression.lnk
[2009/12/29 20:07:38 | 00,001,791 | ---- | M] () -- C:\Users\Public\Desktop\PHOTOfunSTUDIO.lnk
[2009/12/24 09:25:22 | 00,000,680 | ---- | M] () -- C:\Users\Family\AppData\Local\d3d9caps.dat

========== Files Created - No Company Name ==========

[2010/01/05 20:49:59 | 00,000,919 | ---- | C] () -- C:\Users\Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/01/05 20:47:55 | 00,000,419 | ---- | C] () -- C:\Users\Family\Documents - Shortcut.lnk
[2010/01/03 14:15:38 | 00,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/01/03 14:15:38 | 00,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 4).job
[2010/01/03 14:15:38 | 00,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 3).job
[2010/01/03 14:15:38 | 00,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 2).job
[2010/01/03 14:15:37 | 00,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 1).job
[2010/01/01 21:11:26 | 00,000,908 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/01/01 18:26:12 | 00,001,730 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/01/01 15:17:26 | 00,524,288 | ---- | C] () -- C:\Users\Family\Desktop\dds.scr
[2010/01/01 13:47:32 | 00,355,028 | ---- | C] () -- C:\Users\Family\Documents\cc_20100101_134727.reg
[2010/01/01 13:36:55 | 00,001,676 | ---- | C] () -- C:\Users\Family\Desktop\CCleaner.lnk
[2009/12/31 10:40:49 | 00,000,036 | ---- | C] () -- C:\Users\Family\AppData\Local\housecall.guid.cache
[2009/12/30 19:59:41 | 00,000,026 | ---- | C] () -- C:\UpdaterforApp.ini
[2009/12/29 20:10:58 | 00,001,926 | ---- | C] () -- C:\Users\Public\Desktop\Panorama Maker 4.lnk
[2009/12/29 20:10:22 | 00,002,121 | ---- | C] () -- C:\Users\Public\Desktop\Media Impression.lnk
[2009/12/29 20:08:32 | 00,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2009/12/29 20:08:32 | 00,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2009/12/29 20:08:32 | 00,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2009/12/29 20:08:32 | 00,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2009/12/29 20:08:32 | 00,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2009/12/29 20:08:32 | 00,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2009/12/29 20:08:32 | 00,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2009/12/29 20:08:32 | 00,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2009/12/29 20:08:32 | 00,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2009/12/29 20:08:32 | 00,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2009/12/29 20:08:32 | 00,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2009/12/29 20:08:32 | 00,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2009/12/29 20:08:32 | 00,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2009/12/29 20:08:32 | 00,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2009/12/29 20:08:32 | 00,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2009/12/29 20:08:32 | 00,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2009/12/29 20:08:32 | 00,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2009/12/29 20:08:32 | 00,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2009/12/29 20:08:31 | 00,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2009/12/29 20:08:31 | 00,013,732 | ---- | C] () -- C:\Windows\System32\EPPICLocal_EN.cfg
[2009/12/29 20:08:31 | 00,006,442 | ---- | C] () -- C:\Windows\System32\EPPICLocal_IT.cfg
[2009/12/29 20:08:31 | 00,006,347 | ---- | C] () -- C:\Windows\System32\EPPICLocal_PT.cfg
[2009/12/29 20:08:31 | 00,006,347 | ---- | C] () -- C:\Windows\System32\EPPICLocal_BP.cfg
[2009/12/29 20:08:31 | 00,006,335 | ---- | C] () -- C:\Windows\System32\EPPICLocal_GE.cfg
[2009/12/29 20:08:31 | 00,006,195 | ---- | C] () -- C:\Windows\System32\EPPICLocal_FR.cfg
[2009/12/29 20:08:31 | 00,006,195 | ---- | C] () -- C:\Windows\System32\EPPICLocal_CF.cfg
[2009/12/29 20:08:31 | 00,006,122 | ---- | C] () -- C:\Windows\System32\EPPICLocal_DU.cfg
[2009/12/29 20:08:31 | 00,006,103 | ---- | C] () -- C:\Windows\System32\EPPICLocal_ES.cfg
[2009/12/29 20:08:31 | 00,005,817 | ---- | C] () -- C:\Windows\System32\EPPICLocal_KO.cfg
[2009/12/29 20:08:31 | 00,005,436 | ---- | C] () -- C:\Windows\System32\EPPICLocal_SC.cfg
[2009/12/29 20:08:31 | 00,002,889 | ---- | C] () -- C:\Windows\System32\EPPICLocal_RU.cfg
[2009/12/29 20:08:31 | 00,002,426 | ---- | C] () -- C:\Windows\System32\EPPICLocal_TC.cfg
[2009/12/29 20:07:38 | 00,001,791 | ---- | C] () -- C:\Users\Public\Desktop\PHOTOfunSTUDIO.lnk
[2009/09/16 16:02:08 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/12 23:42:07 | 00,339,388 | ---- | C] () -- C:\Users\Family\AppData\Local\imageCache7.db
[2009/08/10 20:28:28 | 00,000,000 | ---- | C] () -- C:\Windows\QuickInstall.INI
[2009/08/03 14:07:42 | 00,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/05 14:59:43 | 00,000,049 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009/06/07 23:40:40 | 00,610,304 | ---- | C] () -- C:\Users\Family\AppData\Local\filesync.metadata
[2009/05/06 21:31:29 | 00,000,024 | ---- | C] () -- C:\Windows\cdplayer.ini
[2009/05/02 14:48:31 | 00,000,288 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/02/28 12:47:31 | 00,000,142 | ---- | C] () -- C:\Windows\wpd99.drv
[2009/02/28 12:47:30 | 00,051,716 | ---- | C] () -- C:\Windows\System32\pdf995mon.dll
[2009/01/20 19:31:51 | 00,000,680 | ---- | C] () -- C:\Users\Family\AppData\Local\d3d9caps.dat
[2009/01/04 01:32:50 | 00,062,976 | ---- | C] () -- C:\Users\Family\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/04 00:37:05 | 00,000,165 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2008/04/17 11:01:05 | 01,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll
[2008/04/17 11:01:05 | 01,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll
[2008/04/17 11:01:05 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
[2008/04/17 11:01:05 | 00,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2008/04/17 10:25:56 | 00,000,068 | ---- | C] () -- C:\Windows\System32\Compaq_Demo.ini
[2008/04/17 10:09:02 | 00,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
[2008/04/17 10:09:02 | 00,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
[2008/03/25 16:56:08 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1461.dll
[2007/02/03 08:59:04 | 00,050,127 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2006/11/02 04:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/01 23:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010/01/05 22:18:59 | 00,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 1).job
[2010/01/06 04:18:59 | 00,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 2).job
[2010/01/03 15:32:49 | 00,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 3).job
[2010/01/03 15:32:50 | 00,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 4).job
[2010/01/03 15:32:50 | 00,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/01/05 20:44:35 | 00,032,646 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007/11/07 08:03:18 | 00,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe


< MD5 for: AGP440.SYS >
[2008/01/20 18:23:01 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008/01/20 18:23:01 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/20 18:23:01 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/20 18:23:01 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/20 18:23:01 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 01:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/10 22:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/10 22:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/10 22:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/20 18:23:00 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/20 18:23:00 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 01:49:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 01:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 01:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/01/12 21:30:08 | 00,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/20 18:23:23 | 00,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008/01/20 18:23:23 | 00,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/20 18:23:23 | 00,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 01:51:25 | 00,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/10 22:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/10 22:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/20 18:24:05 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 01:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/20 18:23:21 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008/01/20 18:23:21 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/20 18:23:21 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 18:24:50 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/10 22:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009/04/10 22:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 03:31:42 | 00,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtmsft.dll
[2009/03/08 03:31:37 | 00,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtrans.dll
[2009/04/10 22:27:47 | 00,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2009/04/10 22:28:23 | 00,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\yardsale arrow.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Writing prompts.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Writing prompts 2.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Writers Workshop Mini-Lessons.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Wolf Scout Contacts.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Wife of a teacher.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Whats in a name..txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\What having a second has taught me.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Weekly Calendar Student Teaching.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Wamu Payoff Amount.TIF:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\W.W.J.D.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Vivian's REP stuff.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Verizon Letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Utilities.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Upper to Lower Case Matching (snowman).doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Turkey Bake.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Tupperware info.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\TS info for Mary Jo.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\TS info for Mary Jo #2.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Trudel Update.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Trudel Update 2006.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Trudel Update 2005.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Trudel Update 2004.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Trudel Pet information.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Trudel Boys Important Info.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Trimester At a Glance.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Toy Labels.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\touch math.tif:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\To Be.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Timex letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Themes and Just for Fun.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\The Trudel Family Update 2002.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\The State of Our Unions 2001.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\The Prudential Fitnessgram.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\The Monitor.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Test sheet for albert.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\tbn.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\T.S. Blastoff invitation.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Symbol.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Super Star Behavior Slips.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\summer03.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\star homework cover sheet1.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Staff Meeting 1_18_06.DOC:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\St. Declan.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Spanish goal sheet.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Sleeping arrangements.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Silkworm Experiments.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Should We Live Together.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\shapes.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Shape book.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Sewing machine manual.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\seedsguide_March12.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\secretsister.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Secret Shopper infor.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\seatfiller info.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Schoolwide SST 2005_1.DOC:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Scholastic Parent Letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Schedule.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\sauce.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\San Jose Facility.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\ROSTER-central current.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\ROSTER central.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Room Parent Meeting Agenda.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Roles & Resp.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Riverside District Attorney.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Request for funds.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Relaxation exercises.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Reading Strategies Pamphlet.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\rainbow fish questions.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\rainbow fish dynamic charater lesson.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Quinlan info.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\QDATA_20070903_20080330OFXOLD.DAT:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\QDATA_20070903_20080330OFXLOG.DAT:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\PTA Roster06.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\PTA motion.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Program At A Glance.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\PROBLEM - SOLVING MODELS.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Priest Plea.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Power Writing.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\PoppyBcertificate.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Plan Book.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Pampered Chef Invite List.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Palm Zire Warranty order.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\P.T.A. board interest.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Orange Crunch Bake.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Oral Presentation Rubric.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Operation Interdependence.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Open PTA Position 0607.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Open House.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\ONE OF US.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\NOvember05 184.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Nomination committee.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Newlywed Survival Kit.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\New 2008OFXLOG.DAT:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Natural Pesticides.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Names FL.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\myfilefoldergames2001.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Murrieta Hosting & Domain Information.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Move It.rcl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Mothers and Others Bunko List.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Morning Prayer.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Monthly Calendar for Student Teaching.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Money request letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Moms clubSecretSisform.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\model_thermometer.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Microsoft Word - Little Church Regi.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\mepoems.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Menifee Letter Intent.DOC:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Medical Release form.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Medical Release form Declan.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Medical Release form Brennan.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Medical Release Cats.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Marriage Preparation & Cohabiting.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Letter_From_Sprint.rtf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Letter to Martha.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Letter of Recommendation Mark.DOC:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Letter Intent Template.DOC:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Letter for Serina.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Lessons 111802.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Krazy (kids edit) - Dionne.m4a:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Kenny and Lela.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Kenny and Lela.dmsm:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Kclt0404_FINAL.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\jv299.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Job Letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Jeff's Obit.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Itinerary for trip to Ireland.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Invite List for Kieran Trudel.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\I.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\I Want You To Know.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\How to make rice cereal.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\How I am wasting my degree.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\House payment spreadsheets.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Hours Sheet Student Teaching.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Hours Data Sheet.rtf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\History Day Paper Format.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\HIGHLANDER.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Hi Shana.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Hey Terra.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Hey Pete.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Graphing MM Scores.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Goodbye announcement.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Frosty the Snowman Lyrics.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Friday Review Games.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Friday August 29 2008.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Fax for church.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Fax coversheet Dr. Laura.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Family (Cohab and Divorce).pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Exer-Char_06-09-responsibility-activitysheets.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Exer-Char_06-09-responsibility.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\EOY Trudel.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\EOY Rivera.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\EOY Photo Disc.dmsm:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\EOY Lundy.dmsm:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\EE2002 Wknd Schedule.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\dynamic character lesson.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Dynamic Character Lesson.1.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\DVD Repair letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\dsp19.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Dr. Laura.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\dot to dot grid.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Dlink info.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Divider Labels.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Discovery Toys invite list.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Discernment.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\development journal.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Den2BearAdvancementRecords.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan's sticker chart.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan's Star Wars Game.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan update April 2001.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan Update 2 years.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan Update 1 year.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan Info for Grandpa Joe (June 2001).doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Declan Info for Grammy and Pappy.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\DeCamera Management Closing Documents.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Dear Dr.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Dear Declan2.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Dear Declan.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Dave Matthews Band.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Daily Journal Ratings.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\CuttingFreePrayer.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Cumulative Project.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Cross Cultural adoption questionnaire-AL.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Credit Inquiry Letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Cranberry Chip CookiesCranberry Chip CookiesCranberry Chip Cookies.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\CPR CLASS Invoice 071401.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\CPR CLASS 3 Invoice.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\CPR CLASS 2 Invoice.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Coupon.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\coordinator letter Feb 04.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Coordinator Goodbye letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Cookie Recipies.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Contact List.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Comprehensive Project Check List.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Como.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Cohabiting and children.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Cohabitation.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\coffee table for sale.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\cloudwords 2perpage.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Christmas letter2000.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Christmas Letter 2003.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Chocolate Spoons.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Child Cancelization letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Character Counts Tickets.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Change of address fax to Blue Cross.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\chancecards.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\certfappHemet.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\catalog2002.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Car accident.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Cannon Customer Care.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\canningsalsa.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Canned Heat.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Calender Etc 2008.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Bylaaws2.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Brennan's sticker chart.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Brennan's congrats.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Brennan's Bcertificate.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Brennan.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Brennan Update.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Brennan and Declan Info..doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Braveheartscript.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Boxtop Bingo.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\BlueCross Fax regarding Unillab bill.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Blue Cross Letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Bill of Sale.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\bfast.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Bathroom flow chart.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Back to School 2006.dmsm:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Baby Shower List.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\arroz con pollo.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\April 20 Declan Letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Appreciative Inquiry.ppt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Ambrosia Salad.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\Acer and Lexmark UPC Rebate.bmp:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\About Me.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\A Tru Handyman invoice1.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\A PRAYER FOR THE CHILDREN.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\5thgradesciandsoc.jwl:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\30th Anniversary Letter.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\3 days roots schedule.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\2 by 2 card.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\15 A Mover El Culo.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\08 Boogie Nights.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\02 Fallen.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\02 Close To You.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\01 Virtual Insanity.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\01 Rockin - Around the Christmas Tree.wav:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\01 Lose My Breath.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Family\Documents\01 Kirmizi Biber.m4a:Roxio EMC Stream
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:68F4226F
< End of report >


OTL Extras logfile created on: 1/6/2010 6:35:50 AM - Run 1
OTL by OldTimer - Version 3.1.21.0 Folder = C:\Users\Family\Desktop\Spyware Cleaners
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.93 Gb Total Space | 120.64 Gb Free Space | 41.75% Space Free | Partition Type: NTFS
Drive D: | 9.16 Gb Total Space | 1.25 Gb Free Space | 13.63% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE-PC
Current User Name: Family
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03DC9D80-E10D-40B0-B713-4B6380A0B2D2}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{05A14472-D3CB-4300-BBE2-43FB0D0A1026}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{05C7BC90-E71E-4778-8638-CC88B0A54BA3}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{096DB28E-5ECC-44A2-83CC-732812B03C07}" = rport=445 | protocol=6 | dir=out | app=system |
"{096E3599-79AB-4E3A-B12F-BA27925EB292}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{11446705-8439-4F97-8D1E-7718BE16B4B2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{149FCD45-EA0A-4966-9E4D-91C27EE3C5BF}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{1A975644-B3C1-48C7-BF78-0A6977A0E98D}" = lport=10243 | protocol=6 | dir=in | app=system |
"{265A341F-8691-46A4-8518-CCB3EB7C39A8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2CE84665-DAF1-48F7-9AA2-B0F177797B90}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{2EEC0E91-58B5-4739-99C3-3ADBE27C3EB5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{357CC9C8-ABDF-441D-BDD3-3A3374B0A13E}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{3679D79C-FAC9-40EB-8690-A5F18E2E965C}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{3A8BA7AB-0798-4CFC-AA0D-C5EC6EC22F7F}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{4C7ECFB9-B8C7-402A-A216-9B2B2A6AD616}" = rport=137 | protocol=17 | dir=out | app=system |
"{606FE565-213C-4F27-8D3B-B2953A898FAD}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{6C6251CA-C22A-4C3B-9EE5-EF75DDA11814}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{6F2184E6-BA5B-4FFA-879D-87FFC384A9AE}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{711BD7FA-F5FD-4957-906E-A74F69624908}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7FBB71D7-7FBC-4A7E-9ED9-775DEEDDB4AD}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{83CE21A2-341D-4606-9B01-A3FD770C631F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{880599CA-E4C4-4D20-A78C-75E951DFF5E3}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{976AF44C-01EE-4A29-ABD8-ACA82400BD5A}" = lport=138 | protocol=17 | dir=in | app=system |
"{986A2015-07EF-4E10-8932-34A628367A45}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{988E2278-A20E-4934-95AA-1E5893FB22F8}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9AA89118-C5A5-465D-A2F8-B2FA5E5A776F}" = lport=139 | protocol=6 | dir=in | app=system |
"{9D61D07F-0D7A-41FE-8538-6AED4605B6D7}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{9DC0960A-0A83-47B2-B02D-B26111796830}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A0698BB9-9227-4FAE-82C1-82B3BAE518DC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{A6D6ECCA-4E57-425E-AFA5-7336ED791352}" = rport=138 | protocol=17 | dir=out | app=system |
"{A87EC9B0-E902-40E4-B5DA-54B3CA5D91BD}" = lport=445 | protocol=6 | dir=in | app=system |
"{AC497936-C63A-462C-9955-4E3D2225F38E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B0A293E3-6D54-410C-80E7-B563C249B211}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{B4D4B86C-0118-4C94-A276-08C6949CA73B}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B8138C8C-4933-4651-8EF1-616C7A650C51}" = rport=139 | protocol=6 | dir=out | app=system |
"{B8E54C15-D2B4-48E1-BA3F-3F5C1BE2DB4E}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{D866EB8E-9306-459C-A688-21DF9D76BCA3}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{DECB0FA6-A61A-4257-AD06-AF857F21C75D}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{E381D382-3083-4520-B787-70FEB8923C30}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{E73970BA-F750-4D07-B6B1-588360B822CD}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{EA95080A-442D-4180-87D5-EC6D2E84D409}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{ED4942C4-F9C2-45A2-AC21-2D783BB13DD1}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F48D7814-494D-4678-8BAD-341E01EA8778}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FA9201B3-A00A-4C36-BC5B-AA12694BCF01}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003D6B32-00E2-437D-B582-335F646D5B26}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{01CF40A9-F976-49CD-85C1-E56EA1A3F08E}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{05DBE781-2A6A-41D3-B2FE-78457D006165}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{15EDD0D7-2DC8-473A-A924-4EAD589140A5}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{226B537F-C01D-4925-B522-E039CB8A61E9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2447CCE9-246C-4E8A-AA2F-B8A322ACC399}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{284C8A22-1492-41F5-ABD6-EBD24B74EBA2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2BC175BA-63FB-4B30-B6B5-DBAA8CC51E46}" = protocol=1 | dir=out | [email protected],-28544 |
"{34DA112E-6E1D-4C7F-A170-1BFB720ECD79}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{34EFFC34-7994-47EA-87F9-C3EC38C4ABDB}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{43BB3BD1-6CC1-4FC9-AD7E-C12E9D936D7E}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{5FE119B2-CC69-4634-A0E7-5680A61183C1}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{600C8615-27F0-4403-AE10-FE079CA6D61D}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{68B58A0A-1532-4CB7-B53F-E75C3E03A09D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{68E330A4-E97F-4865-8D14-7308B9093FC9}" = protocol=58 | dir=out | [email protected],-28546 |
"{6CFABD87-DB20-4E3F-BDE7-79B8F153F456}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{6DD86DBE-910B-4635-BEB0-F3919D1D25C3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{7201AAD6-C662-4B47-AFD6-86DC76E96518}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7EC4E73B-28A3-42E0-937E-0B14FB4CEC38}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{85B73B0B-2EAD-414E-9FA9-A41A9E1FBB1E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{85E711D7-D4A3-4AD2-A3CA-19103FC82DCF}" = protocol=1 | dir=in | [email protected],-28543 |
"{8AAF0FD2-DEB2-4450-A7F6-293B941199A9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8D0E8965-EEF1-4D48-9C56-51DFE3F776D1}" = protocol=6 | dir=in | app=c:\windows\temp\~osc12d.tmp\rlvknlg.exe |
"{901AF081-5B1F-45EB-83CB-816614091515}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{91373A4A-2AB6-40B9-A632-D45DBE74BEFF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{916DCB18-83A4-4951-97B4-FEF5C26029F4}" = protocol=6 | dir=out | app=system |
"{92DDDF16-D0FC-4832-A265-7F3088CF449D}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{9496E743-3F22-4EFC-8A56-4BF303003CED}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{9869817D-564A-4DB6-8236-46FEF74F3EA3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9C476C3E-3C1D-4AA1-84F3-F9DB2FBA5D2B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9D0D73CF-6AA8-448F-B065-C63B058BC7A3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A93CE7CB-CDA1-4495-9037-C07693D4AA71}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{AD7A67F5-60E6-47E7-BE86-208B4F1F8C1D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{AE970C29-1694-46D0-B24E-7E193A912375}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B88A7DBF-2B62-458C-98D9-A00D2DE76F95}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{BA60ADAA-9585-41DA-86D3-C4FEE1534448}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C24FEB46-769A-4CDC-986C-8D01AAC601F8}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C285F5D2-8CD3-402A-8A7B-9492623E123E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{CA7B0B4C-E29F-45CC-AE5F-69DFC7E6E1E1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{D0A5768F-0A6E-486E-B33F-41B8611C469F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D3301670-E51D-4735-93A4-6A9BD39D43C0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D57B935C-5BE7-4283-B21C-02B023FE2EDF}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D7067976-C786-4A73-A40C-C02C4921D802}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D7C95C16-C219-49F1-BAB3-9C52F1B972F1}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D7D80A49-03D2-4647-9024-F7F995373386}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{DE74A6E3-69E2-4ADF-B42B-D2E9D7243D84}" = protocol=58 | dir=in | [email protected],-28545 |
"{DEE746DA-A284-4D2C-9497-F400B0727AE6}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{E56DF239-13E4-4CDA-A8EA-DF7E1F57A33A}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{EC4E3FBF-61E9-40B3-8BAC-2E17F2F57FBC}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{EF111DCE-55DD-4598-BE50-0C6C806BD252}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FE917A82-E4CD-4F5E-A2B3-375A881281E0}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"TCP Query User{5F7C8CD3-1036-4532-9630-B1FDA5464797}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe |
"TCP Query User{727E88C8-65B6-43A1-BF5B-EA0AB2118533}C:\program files\rhapsody\rhapsody.exe" = protocol=6 | dir=in | app=c:\program files\rhapsody\rhapsody.exe |
"TCP Query User{BF02C609-658A-43FE-AE50-6044FBBF39D3}C:\program files\rhapsody\rhapsody.exe" = protocol=6 | dir=in | app=c:\program files\rhapsody\rhapsody.exe |
"UDP Query User{7023B57F-8465-4F4F-A1BC-4EA12E73B5DC}C:\program files\rhapsody\rhapsody.exe" = protocol=17 | dir=in | app=c:\program files\rhapsody\rhapsody.exe |
"UDP Query User{7F452333-A2FA-4C52-9716-57C8D8FA0DEC}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe |
"UDP Query User{A98F1BB6-6C74-452D-93AC-A7163446A171}C:\program files\rhapsody\rhapsody.exe" = protocol=17 | dir=in | app=c:\program files\rhapsody\rhapsody.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}" = RealNetworks - Microsoft Visual C++ 2005 Runtime
"{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
"{03CAB33F-D1C2-48C6-8766-DAE84DFC25FE}" = Microsoft Sync Framework Services v1.0 (x86)
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0E19A83E-F53B-40CF-8C91-96F32D955E6A}" = LightScribe System Software 1.10.23.1
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{12650598-D7B9-4FB5-91B2-2CAA641AC589}" = Trend Micro RUBotted
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1BCE2581-B7CA-4BB4-BDFB-D113506AA38B}" = HP Easy Setup - Frontend
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24BA79B5-53F9-475C-9D49-EC4BDE8B09CF}" = Notebook Interactive Viewer
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83216013F0}" = Java™ 6 Update 13
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 17
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4394DC3A-5DAC-4C80-A86E-FF462D0AD653}" = Windows 7 Upgrade Advisor Beta
"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials
"{497A1721-088F-41EF-8876-B43C9DA5528B}" = ArcSoft Software Suite
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{5115C036-C0D5-4E1B-81C9-542CA967478A}" = muvee autoProducer 6.1
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{62880A3B-2F9C-4C58-8FFA-1DA280262B5E}" = BlackBerry Device Software Updater
"{6549AA0C-6D93-4E76-9A13-6A6A0AA4FD6D}" = TaxCut California 2008
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{747D1B34-A1FC-4EF3-A6AE-E86F39CEFDE5}" = Roxio Easy Media Creator 7 Basic DVD Edition
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7C2F22D6-547A-4452-AEE3-65344A271844}" = MusicIP MyDJ Plug-in
"{7F2B6338-4C07-49A0-BDF0-AD92E3124A7E}" = Compaq Demo
"{83B9C69A-8A4C-4C9A-BAD7-9CA8AD2E1A1A}" = Digital Audio Player
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009
"{8FF6231F-D670-4AFD-9512-957515E2E1DF}" = Timex Data Link USB
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{98EFD8F0-08DE-48DB-B922-A2EBAB711033}" = Nero 7 Ultra Edition
"{9A9DBEBC-C800-4776-A970-D76D6AA405B1}" = PHOTOfunSTUDIO
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}" = Microsoft Antimalware
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A8BD5A60-E843-46DC-8271-ABF20756BE0F}" = Microsoft Sync Framework Runtime v1.0 (x86)
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.6
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{AEFD48FE-2A76-11D3-928B-00C04FB90523}" = Microsoft Reader for Pocket PC
"{AFDFC350-C142-4790-BE12-8357AECD028F}" = SyncToy 2.0 (x86)
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B607C354-CD79-4D22-86D1-92DC94153F42}" = Apple Application Support
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BBB33AD6-BCF7-4002-B6A0-6DC679AE5C18}" = TaxCut Premium + State + Efile 2008
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8D47273-7A1A-4614-A3D8-263632D8A5ED}" = HP Customer Experience Enhancements
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}" = iTunes
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin
"{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}" = Quicken 2009
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{fef8097e-662d-49b3-aa77-2919db3746d7}" = HP Total Care Advisor
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"ABC Amber BlackBerry Converter" = ABC Amber BlackBerry Converter
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 1.0" = Adobe Photoshop Elements
"AI RoboForm" = AI RoboForm (All Users)
"AI RoboForm for Pocket PC" = RoboForm for Pocket PC
"BlackBerry_{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software
"CCleaner" = CCleaner
"CEIVA Sender_is1" = CEIVA Sender
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"GoldWave v5.23" = GoldWave v5.23
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallWIX_{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MathWFLite1" = Mathematics Worksheet Factory Lite
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"Pdf995" = Pdf995 (installed by TaxCut)
"PdfEdit995" = PdfEdit995 (installed by TaxCut)
"Photodex Presenter" = Photodex Presenter
"ProShow Gold" = ProShow Gold
"PuzzleMaker" = PuzzleMaker
"RealPlayer 12.0" = RealPlayer
"Rhapsody" = Rhapsody
"WildTangent hp Master Uninstall" = My HP Games
"WILLPower" = WILLPower v6

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Sansa Updater" = Sansa Updater

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/1/2010 4:35:45 AM | Computer Name = Office-PC | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.0.6002.18005 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 8fc Start Time: 01ca8a4682bff177 Termination Time: 0

Error - 1/1/2010 5:09:56 AM | Computer Name = Office-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/1/2010 3:42:44 PM | Computer Name = Office-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/1/2010 3:52:10 PM | Computer Name = Office-PC | Source = Microsoft-Windows-RestartManager | ID = 10007
Description =

Error - 1/1/2010 4:21:08 PM | Computer Name = Office-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18865 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1614 Start Time: 01ca8b1f72030420 Termination Time: 12

Error - 1/1/2010 4:22:54 PM | Computer Name = Office-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18865 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1120 Start Time: 01ca8b1ffa578760 Termination Time: 0

Error - 1/1/2010 5:51:22 PM | Computer Name = Office-PC | Source = Application Hang | ID = 1002
Description = The program ccleaner.exe version 2.27.0.1070 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14ac Start Time: 01ca8b2a8bf18040 Termination Time: 37

Error - 1/1/2010 6:09:44 PM | Computer Name = Office-PC | Source = Application Error | ID = 1000
Description = Faulting application MsiExec.exe, version 4.5.6002.18005, time stamp
0x49e01c42, faulting module MSI513F.tmp, version 15.0.0.591, time stamp 0x48c89fcc,
exception code 0xc0000005, fault offset 0x0009a5d1, process id 0x179c, application
start time 0x01ca8b2f1cbee910.

Error - 1/1/2010 6:25:36 PM | Computer Name = Office-PC | Source = VSS | ID = 8194
Description =

Error - 1/1/2010 9:17:27 PM | Computer Name = Office-PC | Source = WinMgmt | ID = 10
Description =

[ Media Center Events ]
Error - 4/29/2009 11:27:18 PM | Computer Name = Office-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/11/2009 11:57:18 PM | Computer Name = Office-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 1/5/2009 3:07:26 AM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1888
seconds with 240 seconds of active time. This session ended with a crash.

Error - 1/5/2009 3:36:41 AM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1744
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/5/2009 5:00:13 AM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 5001
seconds with 960 seconds of active time. This session ended with a crash.

Error - 1/5/2009 11:40:57 AM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 81
seconds with 60 seconds of active time. This session ended with a crash.

Error - 1/5/2009 11:41:25 AM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 18
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/5/2009 12:28:33 PM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1070
seconds with 60 seconds of active time. This session ended with a crash.

Error - 1/6/2009 12:11:20 AM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 103
seconds with 60 seconds of active time. This session ended with a crash.

Error - 1/6/2009 12:11:35 AM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/6/2009 3:46:34 PM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 318
seconds with 300 seconds of active time. This session ended with a crash.

Error - 9/18/2009 2:50:09 PM | Computer Name = Office-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12060
seconds with 600 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/3/2010 7:34:30 PM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 1/3/2010 7:35:49 PM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 1/5/2010 10:16:09 PM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/5/2010 10:16:09 PM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 1/5/2010 10:17:28 PM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 1/6/2010 12:43:46 AM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 1/6/2010 12:46:40 AM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/6/2010 12:46:40 AM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 1/6/2010 12:46:40 AM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 1/6/2010 12:48:07 AM | Computer Name = Office-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >

Malwarebytes' Anti-Malware 1.43
Database version: 3499
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

1/5/2010 9:09:13 PM
mbam-log-2010-01-05 (21-09-13).txt

Scan type: Quick Scan
Objects scanned: 115443
Time elapsed: 6 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Can anyone out there help me? What is wrong with my system?
Thanks

Can anyone out there help me? What is wrong with my system?
Thanks

Edited by ldtate, 16 January 2010 - 02:14 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP