Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Laptop extremely slow, windows restore won't work,screen captures


  • This topic is locked This topic is locked

#16
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts

i'm adding this edit to let you know how my machine is working now and it's still slow and cycling. it does this regardless of the browser that i use. ie9 isn't any better. please advise


Hi,
When you edit your posts, I don't get a notification, so sorry that I missed your edit.
Please just make a new post, so I know when you add info. :)

Could you please describe your symptoms with more detail for me? Is the computer slow, or just browsing the internet slow?
And the cycling, do you mean that it's restarting on it's own?
  • 0

Advertisements


#17
sharokc

sharokc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
sorry bout that.
it seems to be fairly fast offline
i use a cricket broadband wireless card to connect and it connects in just a few seconds from click to connect.
when i click the browser my gmail homepage tab connects within usually 10-15 seconds.
i have 4 other sites i connect to to do my work and have them on tabs too and those are all very slow and sometimes never connect. also in ff when the page does connect and is fully loaded the little icon on the left of the tab continues to spin like it's still working.
downloads work fairly quickly for photos and other images but software and other like things sometimes cycle never getting finished and i used to be able to watch videos, movies and the like easily and with little if any buffering but now won't stream at all. always get an error saying could not be loaded. they always suggest clearing cache and cookies but i don't even begin to select something to watch without first clearing everything and restarting the whole system.
ff ofter has a yellow bar across the top under the toolbars that says that some of the addons used by the site are not up to date with the option to update or close and i've hit update and ff window comes up saying it's looking for needed updates but when it gets finished it says that no new updates are available.

haven't worked with ie9 much yet and btw where's the search bar in ie9? i sometimes have a hard time with change. personal thing, ha. when i do click ie it goes to my gmail page but takes about 2-3 minutes.
  • 0

#18
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts
I will go over these problems with my instructor, but in the mean time, I can tell you that the search bar in IE9 is the url bar. Just type your search terms in there instead of a URL and it will search with the default search engine.

IE9 is pretty safe and quick these days, but it's really a matter of personal choice, if you like Chrome or FF better then by all means use the one you prefer.
I will be looking into your issue this afternoon, and should have a response by the morning. Thanks for your patience! :)
  • 0

#19
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts
Do you have access to a wired internet connection? I would like to rule out your Cricket Broadband.

Maybe a friend or neighbor that you can use an ethernet cable and plug it directly into their router, and do some surfing to see if your speeds are better.
  • 0

#20
sharokc

sharokc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
sorry i don't know where i could hook up with a wire. i guess i could take it to the book store and see if i have the same problems with a wifi connection. i could also go to cricket tech support and ask them to test it?
  • 0

#21
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts
Yes, the book store would be a good option, just to see how it works when you are not using your cricket connection.
Would not be a bad idea to have a cricket tech to check it out also. Please let me know how you make out.
  • 0

#22
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts
Just checking in, have you been able to check your speeds without using the cricket adapter?
  • 0

#23
sharokc

sharokc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
had cricket look at my bb card. they said nothing was wrong however when i got home and hooked up my computer is now exceptionally fast!! much better to work with. i think all is well now. thanks so much. would you like me to run something so you can check things out?

also i have a dell alien laptop about 6 years old. still a great computer and i'd like to start using it again but it's infected. when i try to transfer files between it and this one none will transfer due to infection. can i work with you on this or should i start a new post for it?

thanks
sharon :thumbsup:
  • 0

#24
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts
Glad to hear that this computer is back to normal - I would be more than glad to help you with your other computer. :cool:
Let's work on your other one here in this thread. Look for what I need from the other computer after my cleanup speech and recommendations.

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL by right clicking the icon and selecting Run as Administrator
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.


We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Go to control panel
  • Select folder options (Appearance > Folder options in category view)
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.


Posted Image
Please see this article about a serious exploit in Java. It would be wise to follow those instructions, until Java is updated, probably in the middle of the October.


SPRING CLEAN

To manually create a new Restore Point

  • Go to Control Panel and select System
  • Select System
  • On the left select System Protection and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create

Now we can purge the infected ones

  • Go Start > All programs > Accessories > system tools
  • Right click Disc cleanup and select run as administrator
  • Select Your main drive and accept the warning if you get one
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
Posted Image
Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programs on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?

Keep safe :wave:

Now for your other computer -
Step 1

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
qmgr.dll
/md5stop
%systemdrive%\$Recycle.Bin|@;true;true;true /fp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s
CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs in your next response

Step 2

  • Download RogueKiller and save it on your desktop.
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan

Posted Image

  • Wait for the end of the scan.
  • The report has been created on the desktop.

Please post: All RKreport.txt text files located on your desktop.

In your next reply I would like to see:
  • OTL custom scan log - you should get an extras.txt also, please post that one too
  • RKreport.txt log
  • Can you please describe the problems you are having with this computer?

  • 0

#25
sharokc

sharokc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
followed your instructions down to installing the mbam and when i did that it took almost 2 hours to download and another 2 to update the database and the icon on my tray is now grey and not red like it was before. wondering if there is a problem there and also the whole thing slowed back down again when online. connects quickly and working offline is ok but online it's back to being very slow and about half the time never opens the site i clicked. i ran a scan with mbam and it seemed to work ok. the results said there was nothing found. i'm trying to get back to the cricked tech support now to see if it's the modem. last time i took the card into a cricket store. hoping this time i can get help online or on the phone. if you have any instructions please post and when i get results from cricket on the card i'll let you know what they said. on the other computer: i'm going to wait till we're truely finished here before starting to minimize my own confusion. ( if there was such a thing as a "confusability scale" i'd be off the charts ) :lol:

thanks
shar
  • 0

Advertisements


#26
sharokc

sharokc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
also when i probably need you to know that i went back to the restore point i created with last post and things went better for a bit but then it seemed to freeze up. i could still move the cursor but i couldn't click anything and when i hit ctl+alt+del i got an error. sorry didn't copy the whole error down but it referred to an "logon error". thanks
  • 0

#27
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts
I don't think there is anything I can add, except for plugging in to a router directly, or using your wi-fi in someplace like a friends house or a coffee shop, just to see what the speed difference is. I think you are doing the right thing talking to cricket tech support about the slow speeds.
We can start with your other computer whenever you feel comfortable, no pressure. ;)
  • 0

#28
sharokc

sharokc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
ok 1 more thing then and i'll get the dell hooked up and we'll start with that.

i just got off the phone with cricket and my speed problem is that i've used 7G of data on a 2.5G plan. shucks. so of course they want me to up my plan. BUT i'm connecting through the "connect to" and not with the connection manager software. i have no idea when this started. i have the program in the control panel "programs and features" menu and in the start/all programs but when i try to connect that way nothing happens. the cricket guy says that even if i upgrade my plan it might still be slow because if i don't go through the software the system doesn't recognize my device as a 3g device so my not all me the speed i should have. i hope i'm explaining that ok.

anyway, the reason i'm telling you this is because i tried to uninstall the cricket software so that i could re-install it i could not. i got an error code -5005 in an installshield window. i thought maybe you could help me uninstall this so i could get this right. ???

ok so now i'll get the dell and follow the instructions you posted for it so will be getting back to you with the results of that very shortly. and btw when i use the bbcard to connect it (the dell), i DO get the connection manager window.
thanks
  • 0

#29
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,798 posts
Hi sharokc,
That error when uninstalling is a kind of generic error -
Before we start, I suggest that you make sure you have the Cricket connection manager software package, just in case you can't access the internet. I don't see a link anywhere for the software, but I bet they either gave you a disk, or it's on the Cricket adapter itself. Let me know if you can't find it, and I will try to help you locate it.

Next I would like to have you create a backup of your registry -
The steps that I am about to suggest involve modifying the registry. Modifying the registry can be dangerous so we will make a backup of the registry first.
Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. if you cannot perform some of these steps or if you have ANY questions please ask BEFORE proceeding.

Backing Up Your Registry
  • Download ERUNT
    (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
  • Install ERUNT by following the prompts
    (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
  • Start ERUNT
    (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
  • Choose a location for the backup
    (the default location is C:\WINDOWS\ERDNT which is acceptable).
  • Make sure that at least the first two check boxes are ticked
  • Press OK
  • Press YES to create the folder.
Posted Image

Next:
Please download and install the free version of Revo Uninstaller
  • Run the program
  • From the list of programs double click on the Cricket connection manager (not sure if that is the exact name)
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • If the built-in uninstaller fails, which it probably will, continue on.
  • The green progress bar should continue and when it finishes pressing the Next button should reveal a list of Found Leftover Registry Items
  • Check/tick the bolded items only on the list then click Delete - you may have to click the plus sign on few of the entries to see the bolded items.
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.

This should do the job, and the Cricket program should now be gone.
If so, then please re-install the connection manager.

Let me know the results.
  • 0

#30
sharokc

sharokc

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
following plz find an overview of how my dell is working and what happens with it as well as the otl logs. will continue with the rest of your instructions.

this happens when i'm working offline on files or
docs.
anytime i right click anything i get a window that
says "please wait while windows configures symantic
endpoint protection and there's an option to cancel.
it just sits there so i click cancel. windows
installer box comes up so i click cancel and same
window comes up i click cancel i finally get the
dropdown menu on the file or folder i right clicked
in the first place.

the same thing happens if i highlight something and
then hit the delete button. this time though the
symantic window only comes up once. when i clkick
cancel the delete box asks if i'm sure i want to
delete.

when i use an sd card to transfer files or photos
from this one to my other computer it scans the card
and i get a box saying that the files are infected
so i can't transfer anything.
it won't restore to an earlier time and in most
cases it won't download anything although it did download the otl today.


i haven't used it in a few months so will have to work with it a little bit to refresh my memory about the other problems it gave me.
because i used this computer to do a job i no longer do it has some software and stuff that i don't need any more so there is nothing on it i'm concerned about saving if we have to wipe it. no matter. just want it to work like it did when i got it if possible. it's a great machine.

OTL logfile created on: 10/15/12 11:37:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy

1023.23 Mb Total Physical Memory | 414.13 Mb Available Physical Memory | 40.47% Memory free
2.40 Gb Paging File | 1.84 Gb Available in Paging File | 76.54% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 5.81 Gb Free Space | 10.39% Space Free | Partition Type: NTFS
Drive E: | 119.77 Mb Total Space | 10.67 Mb Free Space | 8.91% Space Free | Partition Type: FAT

Computer Name: WA68A7S1J249 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/15 11:36:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2012/01/13 15:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/01/13 15:53:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/01/13 12:21:10 | 000,095,200 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2012/01/04 14:32:36 | 000,718,888 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2012/01/04 14:32:18 | 000,173,096 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2012/01/04 14:31:48 | 000,165,416 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
PRC - [2011/01/01 09:23:11 | 000,491,168 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2011/01/01 09:23:10 | 000,274,608 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2009/11/12 08:24:48 | 000,323,584 | ---- | M] (Avanquest Software) -- C:\Program Files\Cricket Broadband Connect\mPhonetools.exe
PRC - [2009/10/19 15:51:14 | 000,073,728 | ---- | M] () -- C:\Program Files\Cricket Broadband Connect\AvqAutorun.exe
PRC - [2009/09/23 12:21:40 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009/07/28 18:43:14 | 000,380,928 | ---- | M] (Bytemobile, Inc.) -- C:\Program Files\Cricket Broadband Connect\Bytemobile\bmctl.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 18:30:56 | 000,035,840 | -HS- | M] () -- C:\Documents and Settings\Administrator\Templates\O42525Z\winlogon.exe
PRC - [2008/04/13 18:30:56 | 000,035,840 | -HS- | M] () -- C:\WINDOWS\M13616\EmangEloh.exe
PRC - [2008/04/13 18:30:56 | 000,035,840 | ---- | M] () -- C:\WINDOWS\M13616\smss.exe
PRC - [2008/04/13 18:30:56 | 000,035,840 | ---- | M] () -- C:\Documents and Settings\Administrator\Templates\O42525Z\service.exe
PRC - [2005/04/29 17:15:40 | 000,045,056 | ---- | M] () -- C:\Program Files\TouchFreeze\TouchFreeze.exe
PRC - [2004/10/14 09:11:10 | 001,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
PRC - [2002/09/20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/04 03:47:42 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2009/11/05 08:39:40 | 000,087,552 | ---- | M] () -- C:\WINDOWS\system32\cpwmon2k.dll
MOD - [2009/10/27 14:41:38 | 000,393,216 | ---- | M] () -- C:\Program Files\Cricket Broadband Connect\ModemWiz.dll
MOD - [2009/10/19 15:51:14 | 000,073,728 | ---- | M] () -- C:\Program Files\Cricket Broadband Connect\AvqAutorun.exe
MOD - [2008/04/13 18:30:56 | 000,035,840 | -HS- | M] () -- C:\Documents and Settings\Administrator\Templates\O42525Z\winlogon.exe
MOD - [2008/04/13 18:30:56 | 000,035,840 | -HS- | M] () -- C:\WINDOWS\M13616\EmangEloh.exe
MOD - [2008/04/13 18:30:56 | 000,035,840 | ---- | M] () -- C:\WINDOWS\M13616\smss.exe
MOD - [2008/04/13 18:30:56 | 000,035,840 | ---- | M] () -- C:\Documents and Settings\Administrator\Templates\O42525Z\service.exe
MOD - [2006/11/29 17:26:48 | 000,053,248 | ---- | M] () -- C:\Program Files\Cricket Broadband Connect\VObject.dll
MOD - [2005/04/29 17:15:40 | 000,045,056 | ---- | M] () -- C:\Program Files\TouchFreeze\TouchFreeze.exe
MOD - [2005/04/29 17:15:36 | 000,045,056 | ---- | M] () -- C:\Program Files\TouchFreeze\TouchFreeze.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Bigfoot Networks\Killer Driver\PortManager.exe -- (Killer Port Manager)
SRV - [2012/01/13 15:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/01/13 12:21:10 | 000,095,200 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2012/01/04 14:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/01/06 16:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/11/29 11:41:26 | 000,058,944 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper)
SRV - [2010/11/25 10:49:46 | 000,517,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2010/10/22 05:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/09/06 09:43:32 | 000,120,152 | ---- | M] (WeFi) [On_Demand | Stopped] -- C:\Program Files\WeFi\WefiEngSvc.exe -- (WefiEngSvc)
SRV - [2009/07/02 15:45:58 | 001,799,496 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2009/07/02 15:45:58 | 000,320,840 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2009/07/02 15:45:58 | 000,108,392 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2009/07/02 15:45:58 | 000,108,392 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2009/07/02 15:45:56 | 002,440,120 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2008/12/10 15:46:58 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2002/09/20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\avgtdix.sys -- (Avgtdix)
DRV - File not found [File_System | Disabled | Stopped] -- system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/12/10 16:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/11/01 11:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/11/01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/11/01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/11/01 11:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010/12/08 05:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/10/07 09:40:55 | 000,050,536 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WpsHelper.sys -- (WpsHelper)
DRV - [2010/10/07 09:40:18 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/09/07 04:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/08/03 16:23:36 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/08/03 16:23:34 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/03 16:23:32 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/06/21 18:07:20 | 000,078,720 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\swiwdmbus.sys -- (swiwdmbus)
DRV - [2010/06/21 17:47:13 | 000,156,544 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\swumxa3.sys -- (SWUMXA3)
DRV - [2010/06/21 17:46:49 | 000,201,088 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\swnc8ua3.sys -- (SWNC8UA3)
DRV - [2009/10/27 02:28:48 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PTUMWVsp.sys -- (PTUMWVsp)
DRV - [2009/10/27 02:28:36 | 000,115,216 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PTUMWNET.sys -- (PTUMWNET)
DRV - [2009/10/27 02:28:30 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PTUMWMdm.sys -- (PTUMWMdm)
DRV - [2009/10/27 02:28:24 | 000,012,048 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PTUMWFLT.sys -- (PTUMWFLT)
DRV - [2009/10/27 02:28:12 | 000,022,032 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWCDF.sys -- (PTUMWCDF)
DRV - [2009/10/27 02:28:02 | 000,054,544 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PTUMWBus.sys -- (PTUMWBus)
DRV - [2009/07/02 15:46:00 | 000,319,792 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2009/07/02 15:46:00 | 000,280,112 | ---- | M] (Symantec Corporation) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2009/07/02 15:46:00 | 000,043,824 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/07/02 15:46:00 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys -- (WPS)
DRV - [2009/07/02 15:45:58 | 000,049,536 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Teefer2.sys -- (Teefer2)
DRV - [2009/07/02 15:45:58 | 000,038,056 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\WGX.SYS -- (WGX)
DRV - [2009/07/02 15:45:54 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/04/24 17:39:22 | 000,022,656 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- C:\WINDOWS\system32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2009/04/24 17:39:20 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2009/01/14 02:00:00 | 000,876,112 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090114.024\NAVEX15.SYS -- (NAVEX15)
DRV - [2009/01/14 02:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2009/01/14 02:00:00 | 000,089,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090114.024\NAVENG.SYS -- (NAVENG)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/08/15 07:27:18 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\n558.sys -- (n558)
DRV - [2007/04/16 21:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2006/03/14 13:21:18 | 000,328,237 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2006/03/14 13:19:24 | 000,023,271 | ---- | M] (Broadcom Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\btserial.sys -- (BTSERIAL)
DRV - [2006/03/14 13:18:00 | 000,851,402 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006/03/14 13:15:34 | 000,030,427 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006/03/14 13:14:52 | 000,065,784 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006/03/14 13:12:02 | 000,148,900 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2006/03/14 13:10:56 | 000,045,683 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2006/02/15 17:26:18 | 001,153,728 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/01/04 08:49:00 | 000,243,712 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2005/09/17 11:01:50 | 000,028,672 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/09/14 12:45:24 | 000,050,560 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/08/11 16:49:28 | 000,393,088 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV - [2005/03/09 15:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004/09/14 16:55:44 | 000,088,960 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh....q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearsh...q={searchTerms}
IE - HKLM\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebs...r={searchTerms}


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.yahoo.com/ [binary data]
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://mail.google....en&shva=1#inbox
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask...6E-F2EEE32490CB
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\SearchScopes\{47304EF8-38BE-417A-AEE5-20E94E237522}: "URL" = http://search.avg.co...e}&iy=&ychte=us
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...&rlz=1I7ADRA_en
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\SearchScopes\{88070E74-CC0A-43AE-ACC3-4254A1969FAF}: "URL" = http://search.yahoo....p={SearchTerms}
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\SearchScopes\{E6640DB9-AE70-4F4E-863F-1E69BBB475E4}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-790525478-1682526488-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: [email protected]:1.0
FF - prefs.js..extensions.enabledAddons: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.4.8.20120412011105
FF - prefs.js..extensions.enabledAddons: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.4.1.195
FF - prefs.js..keyword.URL: "http://search.yahoo....h?fr=mcafee&p="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@meadco.com/neptune plugin,version=2.0.0.29: C:\PROGRA~1\MEADCO~1\npmeadax.dll (MeadCo Corp.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.97: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2012/01/30 08:10:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/23 00:23:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Cricket Broadband Connect\Bytemobile\addon\ [2012/05/19 22:45:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/20 22:46:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/30 08:11:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/13 18:35:03 | 000,000,000 | ---D | M]

[2011/02/22 08:46:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2012/06/01 00:45:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4v54krdl.default\extensions
[2011/01/27 22:33:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4v54krdl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/06/01 00:45:17 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4v54krdl.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/02/26 23:38:47 | 000,000,000 | ---D | M] (Microsoft Default Manager) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4v54krdl.default\extensions\DefaultManager@Microsoft
[2012/02/06 01:12:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/22 05:10:14 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/23 00:23:18 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2012/03/20 22:46:41 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/01/22 05:10:14 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/29 08:36:35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/30 21:50:28 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/01/29 08:36:35 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: MeadCo's Neptune (Enabled) = C:\PROGRA~1\MEADCO~1\npmeadax.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files\MSN Toolbar\Platform\5.0.1423.0\npwinext.dll
CHR - plugin: getPlusPlus for Adobe 16297 (Enabled) = C:\Program Files\NOS\bin\np_gp.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/01/18 13:42:48 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [{F9AA8FE2-E89A-E99B-E8b8-E9AE9B9ABA99}] C:\Program Files\Cricket Broadband Connect\AvqAutoRun.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [T25Z627] C:\WINDOWS\sa-77400.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UniPrint] C:\Program Files\UniPrint\Client\SetDfltSettings.exe (UniPrint, a division of GFI Business Solutions Inc.)
O4 - HKU\S-1-5-21-790525478-1682526488-1801674531-500..\Run: [] File not found
O4 - HKU\S-1-5-21-790525478-1682526488-1801674531-500..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-790525478-1682526488-1801674531-500..\Run: [NokiaPCInternetAccess] C:\Program Files\Nokia\PC Internet Access\NPCIA.exe (Nokia)
O4 - HKU\S-1-5-21-790525478-1682526488-1801674531-500..\Run: [T1136400TT4] C:\WINDOWS\system32\16276867285l.exe ()
O4 - HKU\S-1-5-21-790525478-1682526488-1801674531-500..\Run: [TouchFreeze] C:\Program Files\TouchFreeze\TouchFreeze.exe ()
O4 - HKU\S-1-5-21-790525478-1682526488-1801674531-500..\Run: [UniPrint] C:\Program Files\UniPrint\Client\SetDfltSettings.exe (UniPrint, a division of GFI Business Solutions Inc.)
O4 - HKU\S-1-5-21-790525478-1682526488-1801674531-500..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Cricket Broadband Connect.lnk = C:\Program Files\Cricket Broadband Connect\mPhonetools.exe (Avanquest Software)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\sql.cmd ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..Trusted Domains: eset.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..Trusted Domains: google.com ([accounts] https in Trusted sites)
O15 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..Trusted Domains: mycricket.com ([bb] http in Local intranet)
O15 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..Trusted Domains: netflix.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..Trusted Domains: netflix.com ([movies] http in Trusted sites)
O15 - HKU\S-1-5-21-790525478-1682526488-1801674531-500\..Trusted Domains: rapidsurveygroup.com ([www] http in Trusted sites)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1286464238343 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1346393699108 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {C5A7D325-20E3-4183-9FBE-BEF5359188E3} http://www.cisgroup....RapidSketch.cab (EmbeddedRapidSketch.EmbeddedSketchWithSecurityChecks)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} http://www.rapidsurv...RSG/XUpload.ocx (Persits Software XUpload)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F21C5652-4A9C-4478-B930-7179098AA9E5}: NameServer = 10.133.20.11 10.132.20.11
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - ("C:\Documents and Settings\Administrator\Templates\O42525Z\TuxO42525Z.exe") - C:\Documents and Settings\Administrator\Templates\O42525Z\TuxO42525Z.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - ("C:\WINDOWS\M13616\Ja178143bLay.com") - C:\WINDOWS\M13616\Ja178143bLay.com ()
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O27 - HKLM IFEO\msconfig.exe: Debugger - C:\WINDOWS\NOTEPAD.EXE (Microsoft Corporation)
O27 - HKLM IFEO\regedit.exe: Debugger - C:\WINDOWS\NOTEPAD.EXE (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - 16276867285l.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/07 09:35:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/15 11:36:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/10/15 11:03:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012/05/19 22:45:25 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\Documents and Settings\All Users\Application Data\hpe1B.dll
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/15 11:47:02 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1682526488-1801674531-500UA.job
[2012/10/15 11:45:00 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{94F167EE-7096-4173-8F22-F4FFAB67DEAE}.job
[2012/10/15 11:36:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012/10/15 11:28:48 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-790525478-1682526488-1801674531-500.job
[2012/10/15 11:28:48 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-790525478-1682526488-1801674531-500.job
[2012/10/15 10:02:59 | 000,002,322 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/10/15 09:24:07 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Administrator.job
[2012/10/15 09:24:04 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/10/15 09:22:43 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/10/04 11:46:15 | 000,270,984 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/04 11:45:00 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2012/10/04 11:22:16 | 000,594,922 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/10/04 11:22:16 | 000,117,736 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/10/04 11:18:56 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/09/29 06:47:17 | 000,000,438 | ---- | M] () -- C:\WINDOWS\tasks\ReclaimerUpdateFiles_Administrator.job
[2012/09/29 04:23:08 | 000,000,434 | ---- | M] () -- C:\WINDOWS\tasks\ReclaimerUpdateXML_Administrator.job
[2012/09/22 22:47:00 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1682526488-1801674531-500Core.job
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/15 09:51:48 | 000,035,840 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Gallery .scr
[2012/09/29 04:23:06 | 000,000,444 | ---- | C] () -- C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Administrator.job
[2012/09/29 04:23:03 | 000,000,438 | ---- | C] () -- C:\WINDOWS\tasks\ReclaimerUpdateFiles_Administrator.job
[2012/09/29 04:23:02 | 000,000,434 | ---- | C] () -- C:\WINDOWS\tasks\ReclaimerUpdateXML_Administrator.job
[2012/06/03 21:42:19 | 000,000,012 | ---- | C] () -- C:\WINDOWS\bthservsdp.dat
[2012/05/19 22:45:39 | 000,010,440 | ---- | C] () -- C:\WINDOWS\System32\ptumwcit.dll
[2012/02/18 20:34:15 | 000,035,840 | -HS- | C] () -- C:\WINDOWS\Ti867285ta.exe
[2012/02/18 20:34:15 | 000,035,840 | -HS- | C] () -- C:\WINDOWS\sa-77400.exe
[2012/02/18 20:34:15 | 000,035,840 | -HS- | C] () -- C:\WINDOWS\System32\16276867285l.exe
[2012/02/14 22:51:57 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/12/29 01:21:05 | 000,398,336 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\store-pp.db
[2011/11/19 19:16:55 | 000,386,452 | ---- | C] () -- C:\Documents and Settings\Administrator\roof.JPG
[2011/11/19 19:16:52 | 003,049,844 | ---- | C] () -- C:\Documents and Settings\Administrator\rear yard.JPG
[2011/11/19 19:16:52 | 001,820,404 | ---- | C] () -- C:\Documents and Settings\Administrator\side.JPG
[2011/11/19 19:16:49 | 002,850,964 | ---- | C] () -- C:\Documents and Settings\Administrator\rear left.JPG
[2011/11/19 19:16:47 | 002,842,164 | ---- | C] () -- C:\Documents and Settings\Administrator\rear.JPG
[2011/11/19 19:16:47 | 001,603,188 | ---- | C] () -- C:\Documents and Settings\Administrator\plumb.JPG
[2011/11/19 19:16:46 | 002,154,708 | ---- | C] () -- C:\Documents and Settings\Administrator\heater.JPG
[2011/11/19 19:16:44 | 001,392,692 | ---- | C] () -- C:\Documents and Settings\Administrator\collins (10).JPG
[2011/11/19 19:16:41 | 001,613,684 | ---- | C] () -- C:\Documents and Settings\Administrator\bd2.JPG
[2011/11/19 19:16:41 | 001,512,948 | ---- | C] () -- C:\Documents and Settings\Administrator\bd1.JPG
[2011/11/19 19:16:40 | 001,861,076 | ---- | C] () -- C:\Documents and Settings\Administrator\bath.JPG
[2011/11/19 19:16:39 | 001,603,348 | ---- | C] () -- C:\Documents and Settings\Administrator\kit.JPG
[2011/11/19 19:16:37 | 001,850,324 | ---- | C] () -- C:\Documents and Settings\Administrator\liv.JPG
[2011/11/19 19:16:36 | 001,636,084 | ---- | C] () -- C:\Documents and Settings\Administrator\address.JPG
[2011/11/19 19:16:35 | 001,986,292 | ---- | C] () -- C:\Documents and Settings\Administrator\front.JPG
[2011/11/19 17:56:06 | 000,117,383 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0766.jpg
[2011/11/19 17:56:04 | 000,000,360 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0679.jpg
[2011/11/17 15:21:32 | 000,010,901 | ---- | C] () -- C:\Documents and Settings\Administrator\roane.jpg
[2011/11/03 01:03:14 | 001,748,628 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0804.JPG
[2011/11/03 01:03:12 | 002,584,500 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0803.JPG
[2011/11/03 01:03:10 | 001,986,004 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0802.JPG
[2011/11/03 01:03:08 | 001,879,252 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0801.JPG
[2011/11/03 01:03:06 | 001,704,564 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0800.JPG
[2011/11/03 01:03:04 | 002,090,740 | ---- | C] () -- C:\Documents and Settings\Administrator\HPIM0799.JPG
[2011/10/11 09:16:20 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2011/08/07 22:28:08 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/08/07 22:28:08 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/03/18 20:16:09 | 000,749,532 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-790525478-1682526488-1801674531-500-0.dat
[2011/03/18 03:23:16 | 000,284,230 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/03/10 18:13:58 | 000,043,800 | ---- | C] () -- C:\Documents and Settings\Administrator\GRAY1170.jpg
[2011/03/10 18:13:57 | 000,056,803 | ---- | C] () -- C:\Documents and Settings\Administrator\GRAY1169.jpg
[2011/03/10 18:12:34 | 000,001,798 | ---- | C] () -- C:\Documents and Settings\Administrator\a-kohl-jester-in-cap-and-bells.jpg
[2011/03/05 21:29:27 | 000,034,820 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2011/02/20 20:31:35 | 000,001,397 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA7RD794.jpg
[2011/02/20 18:43:28 | 000,003,650 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCARBKD6A.jpg
[2011/02/20 18:42:37 | 000,002,302 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAYQQLS8.jpg
[2011/02/20 18:40:31 | 000,001,718 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA0GW67K.jpg
[2011/02/20 18:38:02 | 000,001,786 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAA5PF59.jpg
[2011/02/20 18:37:08 | 000,004,573 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAPRUIFH.jpg
[2011/02/20 18:36:40 | 000,001,181 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAY7YMSF.jpg
[2011/02/20 18:36:27 | 000,003,214 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCABHAZ4Q.jpg
[2011/02/20 18:35:39 | 000,006,634 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA1FU7KN.jpg
[2011/02/20 18:33:32 | 000,002,408 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAY4DPST.jpg
[2011/02/20 18:33:25 | 000,002,273 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCADDFYXI.jpg
[2011/02/20 18:33:19 | 000,002,790 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA7ES042.jpg
[2011/02/20 18:32:24 | 000,001,736 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA7QB2C7.jpg
[2011/02/20 18:31:27 | 000,004,842 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAHN7R10.jpg
[2011/02/20 18:31:15 | 000,002,317 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCANJP4S8.jpg
[2011/02/20 18:30:53 | 000,001,305 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCARZTWYE.jpg
[2011/02/20 18:30:38 | 000,001,299 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCASFUSAK.jpg
[2011/02/20 18:30:13 | 000,003,959 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAHYBBSU.jpg
[2011/02/20 18:22:55 | 000,002,994 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAS1TYVC.jpg
[2011/02/20 18:22:06 | 000,003,384 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCABIJMRX.jpg
[2011/02/20 18:18:17 | 000,004,351 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA54CG65.jpg
[2011/02/20 18:17:32 | 000,002,836 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAW0MDRW.jpg
[2011/02/20 18:16:03 | 000,004,166 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCARRDA5T.jpg
[2011/02/20 18:15:08 | 000,006,893 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA56XUVV.jpg
[2011/02/20 18:14:39 | 000,008,786 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAA0ADUT.jpg
[2011/02/20 18:14:19 | 000,003,155 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAZI0H9U.jpg
[2011/02/20 18:11:04 | 000,002,329 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAY2L308.jpg
[2011/02/20 18:10:14 | 000,001,838 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA9DVW9N.jpg
[2011/02/20 18:07:27 | 000,001,393 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA3PXANQ.jpg
[2011/02/20 18:04:26 | 000,005,269 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCARF5K14.jpg
[2011/02/20 18:02:37 | 000,003,334 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAPUIMH6.jpg
[2011/02/20 18:01:15 | 000,003,555 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAG3D9JS.jpg
[2011/02/20 18:00:43 | 000,003,682 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA0Y9WHG.jpg
[2011/02/20 17:57:05 | 000,003,154 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAL06CCY.jpg
[2011/02/20 17:56:47 | 000,008,969 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAOPB73Y.jpg
[2011/02/20 17:55:36 | 000,003,054 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAJA6WOW.jpg
[2011/02/20 17:42:50 | 000,007,968 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA156Q3E.jpg
[2011/02/20 17:42:19 | 000,002,146 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCACP0Z04.jpg
[2011/02/20 17:40:44 | 000,002,324 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA28KRYI.jpg
[2011/02/20 17:37:35 | 000,004,106 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA8FM1C6.jpg
[2011/02/20 17:36:57 | 000,006,253 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA9D0P0I.jpg
[2011/02/20 17:36:30 | 000,003,375 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCA4J42IH.jpg
[2011/02/20 17:34:52 | 000,004,341 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCABJJO14.jpg
[2011/02/20 17:34:23 | 000,002,124 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCAPSDOZ5.jpg
[2011/02/20 17:33:30 | 000,003,219 | ---- | C] () -- C:\Documents and Settings\Administrator\ddfrgg.jpg
[2011/02/20 17:32:18 | 000,002,345 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCASR54RU.jpg
[2011/02/20 17:30:44 | 000,005,078 | ---- | C] () -- C:\Documents and Settings\Administrator\imagesCADHLZ31.jpg
[2011/02/20 17:30:17 | 000,004,591 | ---- | C] () -- C:\Documents and Settings\Administrator\oojjloi.jpg
[2011/02/20 17:28:14 | 000,004,538 | ---- | C] () -- C:\Documents and Settings\Administrator\-olnbjhgc.jpg
[2011/02/20 17:27:24 | 000,004,003 | ---- | C] () -- C:\Documents and Settings\Administrator\9-99952.jpg
[2011/02/20 17:25:22 | 000,006,018 | ---- | C] () -- C:\Documents and Settings\Administrator\656565.jpg
[2011/02/20 17:24:10 | 000,004,547 | ---- | C] () -- C:\Documents and Settings\Administrator\mmm.jpg
[2011/02/20 17:23:52 | 000,003,604 | ---- | C] () -- C:\Documents and Settings\Administrator\khkhk.jpg
[2011/02/20 17:19:59 | 000,004,758 | ---- | C] () -- C:\Documents and Settings\Administrator\lkjubgv.jpg
[2011/02/20 17:15:22 | 000,005,313 | ---- | C] () -- C:\Documents and Settings\Administrator\l;p;.jpg
[2011/02/20 17:14:42 | 000,001,240 | ---- | C] () -- C:\Documents and Settings\Administrator\;liuhjh.jpg
[2011/02/20 17:10:59 | 000,007,113 | ---- | C] () -- C:\Documents and Settings\Administrator\,llkjjklk.jpg
[2011/02/20 17:07:07 | 000,005,628 | ---- | C] () -- C:\Documents and Settings\Administrator\kjkjhgui.jpg
[2011/02/20 17:06:24 | 000,006,881 | ---- | C] () -- C:\Documents and Settings\Administrator\,mmbcvvnb.jpg
[2011/02/20 17:05:48 | 000,002,683 | ---- | C] () -- C:\Documents and Settings\Administrator\lkkjnbjbjk.jpg
[2011/02/20 17:05:09 | 000,001,223 | ---- | C] () -- C:\Documents and Settings\Administrator\imageskll;p;.jpg
[2011/02/20 17:02:06 | 000,001,031 | ---- | C] () -- C:\Documents and Settings\Administrator\sublimis_sm.jpg
[2011/02/20 17:01:25 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\Administrator\StudySm.jpg
[2011/02/20 17:01:21 | 000,001,943 | ---- | C] () -- C:\Documents and Settings\Administrator\baraka_sm.jpg
[2011/02/20 17:01:15 | 000,001,253 | ---- | C] () -- C:\Documents and Settings\Administrator\Myriapod_Sm.JPG
[2011/02/20 17:01:10 | 000,002,095 | ---- | C] () -- C:\Documents and Settings\Administrator\ganesa_sm.jpg
[2011/02/20 17:01:01 | 000,002,578 | ---- | C] () -- C:\Documents and Settings\Administrator\amore_sketch_sm.jpg
[2011/02/20 16:59:30 | 000,007,751 | ---- | C] () -- C:\Documents and Settings\Administrator\images mjghj.jpg
[2011/02/17 02:36:45 | 000,714,590 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2011/02/12 07:39:43 | 000,003,093 | ---- | C] () -- C:\Documents and Settings\Administrator\edcvgh.jpg
[2011/01/27 19:21:37 | 000,004,614 | ---- | C] () -- C:\Documents and Settings\Administrator\images.jpg
[2011/01/22 22:34:04 | 000,000,229 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/01/20 11:49:41 | 000,163,328 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/16 20:31:31 | 000,057,788 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/01/08 13:28:59 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/28 18:48:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Dvm.INI
[2010/12/21 19:39:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/12/18 23:19:42 | 000,006,855 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\PrimoPDFSet.xml
[2010/12/17 12:26:29 | 000,017,614 | ---- | C] () -- C:\Documents and Settings\Administrator\golf cart.jpg
[2010/12/15 01:50:58 | 000,001,567 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(35).jpg
[2010/12/15 01:50:58 | 000,001,521 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(24).jpg
[2010/12/15 01:50:58 | 000,001,392 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(22).jpg
[2010/12/15 01:50:58 | 000,001,368 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(23).jpg
[2010/12/15 01:50:58 | 000,001,358 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(29).jpg
[2010/12/15 01:50:58 | 000,001,299 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(34).jpg
[2010/12/15 01:50:58 | 000,001,207 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(32).jpg
[2010/12/15 01:50:58 | 000,001,157 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(30).jpg
[2010/12/15 01:50:58 | 000,001,094 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(25).jpg
[2010/12/15 01:50:58 | 000,001,019 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(28).jpg
[2010/12/15 01:50:58 | 000,001,015 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(31).jpg
[2010/12/15 01:50:58 | 000,000,944 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(36).jpg
[2010/12/15 01:50:58 | 000,000,928 | ---- | C] () -- C:\Documents and Settings\Administrator\log_in.jpg
[2010/12/15 01:50:58 | 000,000,869 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(26).jpg
[2010/12/15 01:50:58 | 000,000,663 | ---- | C] () -- C:\Documents and Settings\Administrator\hr.jpg
[2010/12/15 01:50:58 | 000,000,646 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(5).jpg
[2010/12/15 01:50:58 | 000,000,596 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(9).jpg
[2010/12/15 01:50:58 | 000,000,596 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(6).jpg
[2010/12/15 01:50:58 | 000,000,589 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(2).jpg
[2010/12/15 01:50:58 | 000,000,583 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(8).jpg
[2010/12/15 01:50:58 | 000,000,581 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(3).jpg
[2010/12/15 01:50:58 | 000,000,558 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30.jpg
[2010/12/15 01:50:58 | 000,000,549 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(4).jpg
[2010/12/15 01:50:58 | 000,000,533 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(1).jpg
[2010/12/15 01:50:58 | 000,000,473 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(33).jpg
[2010/12/15 01:50:58 | 000,000,473 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(27).jpg
[2010/12/15 01:50:58 | 000,000,452 | ---- | C] () -- C:\Documents and Settings\Administrator\main_40x30(7).jpg
[2010/12/15 01:50:58 | 000,000,439 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(8).jpg
[2010/12/15 01:50:58 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(7).jpg
[2010/12/15 01:50:58 | 000,000,428 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(6).jpg
[2010/12/15 01:50:58 | 000,000,415 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(2).jpg
[2010/12/15 01:50:58 | 000,000,411 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(9).jpg
[2010/12/15 01:50:58 | 000,000,350 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(5).jpg
[2010/12/15 01:50:58 | 000,000,264 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16.jpg
[2010/12/15 01:50:58 | 000,000,264 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(4).jpg
[2010/12/15 01:50:58 | 000,000,264 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(3).jpg
[2010/12/15 01:50:58 | 000,000,264 | ---- | C] () -- C:\Documents and Settings\Administrator\main_16x16(1).jpg
[2010/12/15 01:50:57 | 000,017,042 | ---- | C] () -- C:\Documents and Settings\Administrator\007_1215381720_466x350.jpg
[2010/12/15 01:50:57 | 000,015,793 | ---- | C] () -- C:\Documents and Settings\Administrator\005_1215381750_466x350.jpg
[2010/12/15 01:50:57 | 000,005,203 | ---- | C] () -- C:\Documents and Settings\Administrator\9748_200x150.jpg
[2010/12/15 01:50:57 | 000,004,275 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(1).jpg
[2010/12/15 01:50:57 | 000,003,719 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(9).jpg
[2010/12/15 01:50:57 | 000,003,681 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(6).jpg
[2010/12/15 01:50:57 | 000,003,618 | ---- | C] () -- C:\Documents and Settings\Administrator\9764_200x150.jpg
[2010/12/15 01:50:57 | 000,003,582 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(11).jpg
[2010/12/15 01:50:57 | 000,003,578 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(5).jpg
[2010/12/15 01:50:57 | 000,002,893 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(8).jpg
[2010/12/15 01:50:57 | 000,002,807 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(2).jpg
[2010/12/15 01:50:57 | 000,002,689 | ---- | C] () -- C:\Documents and Settings\Administrator\9767_200x150.jpg
[2010/12/15 01:50:57 | 000,002,562 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(7).jpg
[2010/12/15 01:50:57 | 000,002,524 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128.jpg
[2010/12/15 01:50:57 | 000,002,423 | ---- | C] () -- C:\Documents and Settings\Administrator\9763_200x150.jpg
[2010/12/15 01:50:57 | 000,002,200 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(17).jpg
[2010/12/15 01:50:57 | 000,002,091 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(10).jpg
[2010/12/15 01:50:57 | 000,002,085 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(6).jpg
[2010/12/15 01:50:57 | 000,001,996 | ---- | C] () -- C:\Documents and Settings\Administrator\leave_a_comment.jpg
[2010/12/15 01:50:57 | 000,001,834 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(6).jpg
[2010/12/15 01:50:57 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(3).jpg
[2010/12/15 01:50:57 | 000,001,799 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(8).jpg
[2010/12/15 01:50:57 | 000,001,760 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(9).jpg
[2010/12/15 01:50:57 | 000,001,691 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(15).jpg
[2010/12/15 01:50:57 | 000,001,641 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75.jpg
[2010/12/15 01:50:57 | 000,001,641 | ---- | C] () -- C:\Documents and Settings\Administrator\main_170x128(4).jpg
[2010/12/15 01:50:57 | 000,001,601 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(18).jpg
[2010/12/15 01:50:57 | 000,001,536 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(21).jpg
[2010/12/15 01:50:57 | 000,001,517 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(1).jpg
[2010/12/15 01:50:57 | 000,001,491 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(2).jpg
[2010/12/15 01:50:57 | 000,001,404 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(13).jpg
[2010/12/15 01:50:57 | 000,001,397 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(2).jpg
[2010/12/15 01:50:57 | 000,001,379 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(7).jpg
[2010/12/15 01:50:57 | 000,001,347 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(9).jpg
[2010/12/15 01:50:57 | 000,001,335 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(7).jpg
[2010/12/15 01:50:57 | 000,001,332 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(16).jpg
[2010/12/15 01:50:57 | 000,001,331 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(11).jpg
[2010/12/15 01:50:57 | 000,001,326 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(3).jpg
[2010/12/15 01:50:57 | 000,001,302 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(1).jpg
[2010/12/15 01:50:57 | 000,001,289 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(7).jpg
[2010/12/15 01:50:57 | 000,001,275 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(14).jpg
[2010/12/15 01:50:57 | 000,001,250 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(8).jpg
[2010/12/15 01:50:57 | 000,001,232 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(14).jpg
[2010/12/15 01:50:57 | 000,001,187 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(1).jpg
[2010/12/15 01:50:57 | 000,001,178 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(13).jpg
[2010/12/15 01:50:57 | 000,001,164 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(3).jpg
[2010/12/15 01:50:57 | 000,001,093 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(2).jpg
[2010/12/15 01:50:57 | 000,001,075 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(9).jpg
[2010/12/15 01:50:57 | 000,001,056 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(5).jpg
[2010/12/15 01:50:57 | 000,000,997 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(5).jpg
[2010/12/15 01:50:57 | 000,000,992 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(11).jpg
[2010/12/15 01:50:57 | 000,000,977 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(10).jpg
[2010/12/15 01:50:57 | 000,000,969 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(8).jpg
[2010/12/15 01:50:57 | 000,000,961 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(3).jpg
[2010/12/15 01:50:57 | 000,000,953 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(19).jpg
[2010/12/15 01:50:57 | 000,000,938 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75(4).jpg
[2010/12/15 01:50:57 | 000,000,861 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(12).jpg
[2010/12/15 01:50:57 | 000,000,473 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(4).jpg
[2010/12/15 01:50:57 | 000,000,473 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(20).jpg
[2010/12/15 01:50:57 | 000,000,473 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(12).jpg
[2010/12/15 01:50:57 | 000,000,473 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(10).jpg
[2010/12/15 01:50:57 | 000,000,412 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(6).jpg
[2010/12/15 01:50:57 | 000,000,412 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64(4).jpg
[2010/12/15 01:50:57 | 000,000,409 | ---- | C] () -- C:\Documents and Settings\Administrator\main_75x75(5).jpg
[2010/12/15 01:50:56 | 000,013,322 | ---- | C] () -- C:\Documents and Settings\Administrator\006_1213846943_466x350.jpg
[2010/12/15 01:50:56 | 000,012,812 | ---- | C] () -- C:\Documents and Settings\Administrator\005_1214121653_466x350.jpg
[2010/12/15 01:50:56 | 000,011,543 | ---- | C] () -- C:\Documents and Settings\Administrator\011_1213865489_466x350.jpg
[2010/12/15 01:50:56 | 000,008,400 | ---- | C] () -- C:\Documents and Settings\Administrator\004_1215139995_466x350.jpg
[2010/12/15 01:50:56 | 000,001,724 | ---- | C] () -- C:\Documents and Settings\Administrator\main_100x75.jpg
[2010/12/15 01:50:56 | 000,001,100 | ---- | C] () -- C:\Documents and Settings\Administrator\sign_up.jpg
[2010/12/15 01:50:56 | 000,001,079 | ---- | C] () -- C:\Documents and Settings\Administrator\main_64x64.jpg
[2010/12/15 01:50:56 | 000,000,870 | ---- | C] () -- C:\Documents and Settings\Administrator\facebook.jpg
[2010/12/08 19:52:21 | 003,933,296 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1322.JPG
[2010/12/08 19:52:20 | 003,291,287 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1321.JPG
[2010/12/08 19:52:19 | 003,848,596 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1320.JPG
[2010/12/08 19:52:18 | 003,803,040 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1319.JPG
[2010/12/08 19:52:18 | 002,262,572 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1762.JPG
[2010/12/08 19:52:17 | 003,037,914 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1761.JPG
[2010/12/08 19:52:16 | 003,773,409 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1760.JPG
[2010/12/08 19:52:16 | 002,809,449 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1759.JPG
[2010/12/08 19:52:15 | 003,823,082 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1758.JPG
[2010/12/08 19:52:15 | 002,095,369 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1757.JPG
[2010/12/08 19:52:14 | 003,879,203 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1756.JPG
[2010/12/08 19:52:13 | 003,595,698 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1755.JPG
[2010/12/08 19:52:13 | 003,585,656 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1754.JPG
[2010/12/08 19:52:12 | 003,549,754 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1753.JPG
[2010/12/08 19:52:11 | 003,383,582 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1752.JPG
[2010/12/08 19:52:11 | 003,182,215 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1751.JPG
[2010/12/08 19:52:10 | 003,684,035 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1749.JPG
[2010/12/08 19:52:10 | 003,286,972 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1750.JPG
[2010/12/08 19:52:09 | 003,845,666 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1748.JPG
[2010/12/08 19:52:08 | 003,870,786 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1747.JPG
[2010/12/08 19:52:08 | 003,582,969 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1746.JPG
[2010/12/08 19:52:07 | 003,666,544 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1745.JPG
[2010/12/08 19:52:07 | 003,160,965 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1744.JPG
[2010/12/08 19:52:06 | 003,113,366 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1743.JPG
[2010/12/08 19:52:05 | 003,941,401 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1742.JPG
[2010/12/08 19:52:05 | 003,811,020 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1741.JPG
[2010/12/08 19:52:04 | 003,832,937 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1740.JPG
[2010/12/08 19:52:03 | 003,903,341 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1739.JPG
[2010/12/08 19:52:02 | 003,981,849 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1738.JPG
[2010/12/08 19:52:01 | 004,004,153 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1737.JPG
[2010/12/08 19:52:00 | 003,523,930 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1736.JPG
[2010/12/08 19:51:58 | 003,748,599 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1734.JPG
[2010/12/08 19:51:58 | 003,724,393 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1735.JPG
[2010/12/08 19:51:57 | 003,588,332 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1733.JPG
[2010/12/08 19:51:56 | 003,738,934 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1731.JPG
[2010/12/08 19:51:56 | 003,570,010 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1732.JPG
[2010/12/08 19:51:55 | 003,293,185 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1730.JPG
[2010/12/08 19:51:54 | 003,984,942 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1729.JPG
[2010/12/08 19:51:54 | 003,715,569 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1728.JPG
[2010/12/08 19:51:53 | 003,698,908 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1726.JPG
[2010/12/08 19:51:53 | 003,487,807 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1727.JPG
[2010/12/08 19:51:52 | 003,696,870 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1725.JPG
[2010/12/08 19:51:52 | 003,439,590 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1724.JPG
[2010/12/08 19:51:51 | 003,837,155 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1723.JPG
[2010/12/08 19:51:50 | 003,745,368 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1722.JPG
[2010/12/08 19:51:50 | 003,556,264 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1721.JPG
[2010/12/08 19:51:49 | 003,733,051 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1719.JPG
[2010/12/08 19:51:49 | 003,672,699 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1720.JPG
[2010/12/08 19:51:48 | 003,835,767 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1718.JPG
[2010/12/08 19:51:47 | 003,998,613 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1717.JPG
[2010/12/08 19:51:47 | 003,800,971 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1716.JPG
[2010/12/08 19:51:46 | 002,038,723 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1715.JPG
[2010/12/08 19:51:46 | 001,957,789 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1714.JPG
[2010/12/08 19:51:45 | 003,871,714 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1713.JPG
[2010/12/08 19:51:45 | 003,792,403 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1712.JPG
[2010/12/08 19:51:44 | 004,003,652 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1711.JPG
[2010/12/08 19:51:43 | 004,013,027 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1710.JPG
[2010/12/08 19:51:42 | 003,823,273 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1709.JPG
[2010/12/08 19:51:42 | 003,726,843 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1708.JPG
[2010/12/08 19:51:41 | 003,805,993 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1707.JPG
[2010/12/08 19:51:40 | 003,853,428 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1706.JPG
[2010/12/08 19:51:39 | 004,002,894 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1705.JPG
[2010/12/08 19:51:39 | 003,736,713 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1704.JPG
[2010/12/08 19:51:38 | 003,969,983 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1703.JPG
[2010/12/08 19:51:37 | 003,872,793 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1701.JPG
[2010/12/08 19:51:37 | 003,563,933 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1702.JPG
[2010/12/08 19:51:36 | 003,926,971 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1700.JPG
[2010/12/08 19:51:35 | 003,813,451 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1699.JPG
[2010/12/08 19:51:35 | 003,804,810 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1698.JPG
[2010/12/08 19:51:34 | 003,527,330 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1697.JPG
[2010/12/08 19:51:33 | 003,118,260 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1696.JPG
[2010/12/08 19:51:33 | 003,099,296 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1695.JPG
[2010/12/08 19:51:32 | 003,792,987 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1694.JPG
[2010/12/08 19:51:31 | 003,651,930 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1693.JPG
[2010/12/08 19:51:31 | 003,399,505 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1692.JPG
[2010/12/08 19:51:30 | 003,616,339 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1691.JPG
[2010/12/08 19:51:30 | 003,477,673 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1690.JPG
[2010/12/08 19:51:29 | 003,824,812 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1689.JPG
[2010/12/08 19:51:29 | 003,518,880 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1688.JPG
[2010/12/08 19:51:28 | 003,374,733 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1687.JPG
[2010/12/08 19:51:27 | 003,804,211 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1686.JPG
[2010/12/08 19:51:27 | 003,729,396 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1685.JPG
[2010/12/08 19:51:26 | 003,883,026 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1684.JPG
[2010/12/08 19:51:25 | 003,530,211 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1683.JPG
[2010/12/08 19:51:25 | 003,296,099 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1682.JPG
[2010/12/08 19:51:24 | 003,711,119 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1680.JPG
[2010/12/08 19:51:24 | 003,549,603 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1681.JPG
[2010/12/08 19:51:23 | 003,824,991 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1679.JPG
[2010/12/08 19:51:22 | 003,854,749 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1678.JPG
[2010/12/08 19:51:21 | 003,879,267 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1677.JPG
[2010/12/08 19:51:21 | 003,475,998 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1676.JPG
[2010/12/08 19:51:20 | 003,879,347 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1674.JPG
[2010/12/08 19:51:20 | 003,525,585 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1675.JPG
[2010/12/08 19:51:19 | 003,834,419 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1673.JPG
[2010/12/08 19:51:18 | 002,841,644 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1671.JPG
[2010/12/08 19:51:18 | 002,642,085 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1672.JPG
[2010/12/08 19:51:17 | 003,829,914 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1670.JPG
[2010/12/08 19:51:16 | 003,561,145 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1669.JPG
[2010/12/08 19:51:15 | 003,998,892 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1667.JPG
[2010/12/08 19:51:15 | 003,851,268 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1668.JPG
[2010/12/08 19:51:14 | 003,844,889 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1665.JPG
[2010/12/08 19:51:14 | 003,550,323 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1666.JPG
[2010/12/08 19:51:13 | 003,717,039 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1664.JPG
[2010/12/08 19:51:12 | 003,723,064 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1663.JPG
[2010/12/08 19:51:12 | 003,547,072 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1662.JPG
[2010/12/08 19:51:11 | 003,877,781 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1661.JPG
[2010/12/08 19:51:10 | 003,753,116 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1659.JPG
[2010/12/08 19:51:10 | 003,529,249 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1660.JPG
[2010/12/08 19:51:09 | 003,997,406 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1658.JPG
[2010/12/08 19:51:09 | 003,675,188 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1657.JPG
[2010/12/08 19:51:08 | 003,741,416 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1656.JPG
[2010/12/08 19:51:07 | 003,931,448 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1655.JPG
[2010/12/08 19:51:06 | 003,802,343 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1654.JPG
[2010/12/08 19:51:06 | 003,301,431 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1653.JPG
[2010/12/08 19:51:05 | 003,215,695 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1652.JPG
[2010/12/08 19:51:04 | 003,365,580 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1650.JPG
[2010/12/08 19:51:04 | 003,022,823 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1651.JPG
[2010/12/08 19:51:03 | 004,059,959 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1648.JPG
[2010/12/08 19:51:03 | 002,840,560 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1649.JPG
[2010/12/08 19:51:02 | 003,859,716 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1647.JPG
[2010/12/08 19:51:02 | 002,595,305 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1646.JPG
[2010/12/08 19:51:01 | 002,804,920 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1645.JPG
[2010/12/08 19:51:01 | 002,774,697 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1644.JPG
[2010/12/08 19:51:00 | 003,847,805 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1643.JPG
[2010/12/08 19:50:59 | 003,867,334 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1642.JPG
[2010/12/08 19:50:59 | 003,833,978 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1641.JPG
[2010/12/08 19:50:58 | 003,838,255 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1640.JPG
[2010/12/08 19:50:57 | 004,039,464 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1638.JPG
[2010/12/08 19:50:57 | 003,948,565 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1639.JPG
[2010/12/08 19:50:56 | 003,817,023 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1637.JPG
[2010/12/08 19:50:55 | 003,776,844 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1636.JPG
[2010/12/08 19:50:55 | 003,497,187 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1635.JPG
[2010/12/08 19:50:54 | 003,944,476 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1634.JPG
[2010/12/08 19:50:54 | 003,419,956 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1633.JPG
[2010/12/08 19:50:53 | 004,080,647 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1631.JPG
[2010/12/08 19:50:53 | 003,951,989 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1632.JPG
[2010/12/08 19:50:52 | 004,065,033 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1630.JPG
[2010/12/08 19:50:51 | 003,968,652 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1628.JPG
[2010/12/08 19:50:51 | 003,964,943 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1629.JPG
[2010/12/08 19:50:50 | 003,786,253 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1627.JPG
[2010/12/08 19:50:49 | 003,822,695 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1625.JPG
[2010/12/08 19:50:49 | 003,811,170 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1626.JPG
[2010/12/08 19:50:48 | 003,836,885 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1624.JPG
[2010/12/08 19:50:47 | 003,807,223 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1622.JPG
[2010/12/08 19:50:47 | 003,774,519 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1623.JPG
[2010/12/08 19:50:46 | 003,832,675 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1621.JPG
[2010/12/08 19:50:45 | 003,798,537 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1620.JPG
[2010/12/08 19:50:45 | 003,742,593 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1619.JPG
[2010/12/08 19:50:44 | 003,807,329 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1618.JPG
[2010/12/08 19:50:44 | 003,739,039 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1617.JPG
[2010/12/08 19:50:43 | 003,895,051 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1616.JPG
[2010/12/08 19:50:42 | 003,788,152 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1615.JPG
[2010/12/08 19:50:42 | 003,756,602 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1614.JPG
[2010/12/08 19:50:41 | 003,776,233 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1612.JPG
[2010/12/08 19:50:41 | 003,758,180 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1613.JPG
[2010/12/08 19:50:40 | 003,476,770 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1611.JPG
[2010/12/08 19:50:39 | 003,691,238 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1609.JPG
[2010/12/08 19:50:39 | 003,655,898 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1610.JPG
[2010/12/08 19:50:38 | 003,861,396 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1607.JPG
[2010/12/08 19:50:38 | 003,568,005 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1608.JPG
[2010/12/08 19:50:37 | 003,911,353 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1606.JPG
[2010/12/08 19:50:36 | 003,838,136 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1605.JPG
[2010/12/08 19:50:36 | 003,761,978 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1604.JPG
[2010/12/08 19:50:35 | 003,967,716 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1603.JPG
[2010/12/08 19:50:34 | 003,953,047 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1602.JPG
[2010/12/08 19:50:34 | 003,777,121 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1601.JPG
[2010/12/08 19:50:32 | 003,858,563 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1600.JPG
[2010/12/08 19:50:32 | 003,814,959 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1599.JPG
[2010/12/08 19:50:31 | 003,846,838 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1598.JPG
[2010/12/08 19:50:30 | 003,794,590 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1596.JPG
[2010/12/08 19:50:30 | 003,790,692 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1597.JPG
[2010/12/08 19:50:29 | 003,856,529 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1595.JPG
[2010/12/08 19:50:28 | 003,825,229 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1593.JPG
[2010/12/08 19:50:28 | 003,804,090 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1594.JPG
[2010/12/08 19:50:27 | 003,872,800 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1592.JPG
[2010/12/08 19:50:26 | 003,883,250 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1591.JPG
[2010/12/08 19:50:26 | 003,826,001 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1590.JPG
[2010/12/08 19:50:25 | 003,825,478 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1588.JPG
[2010/12/08 19:50:25 | 003,811,844 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1589.JPG
[2010/12/08 19:50:24 | 003,614,885 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1587.JPG
[2010/12/08 19:50:23 | 002,913,625 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1585.JPG
[2010/12/08 19:50:23 | 002,906,633 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1586.JPG
[2010/12/08 19:50:22 | 003,862,248 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1583.JPG
[2010/12/08 19:50:22 | 003,286,375 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1584.JPG
[2010/12/08 19:50:21 | 003,810,844 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1582.JPG
[2010/12/08 19:50:21 | 003,645,567 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1581.JPG
[2010/12/08 19:50:20 | 003,878,006 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1580.JPG
[2010/12/08 19:50:20 | 003,504,524 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1579.JPG
[2010/12/08 19:50:19 | 003,616,045 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1578.JPG
[2010/12/08 19:50:18 | 004,018,503 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1577.JPG
[2010/12/08 19:50:18 | 003,877,263 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1576.JPG
[2010/12/08 19:50:17 | 003,890,880 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1575.JPG
[2010/12/08 19:50:17 | 003,807,817 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1574.JPG
[2010/12/08 19:50:15 | 003,799,572 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1573.JPG
[2010/12/08 19:50:15 | 003,799,098 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1572.JPG
[2010/12/08 19:50:14 | 003,831,870 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1570.JPG
[2010/12/08 19:50:14 | 003,801,936 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1571.JPG
[2010/12/08 19:50:13 | 003,837,174 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1569.JPG
[2010/12/08 19:50:12 | 003,843,435 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1567.JPG
[2010/12/08 19:50:12 | 003,829,274 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1568.JPG
[2010/12/08 19:50:11 | 003,607,477 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1565.JPG
[2010/12/08 19:50:11 | 003,579,370 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1566.JPG
[2010/12/08 19:50:10 | 003,854,329 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1564.JPG
[2010/12/08 19:50:10 | 003,820,120 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1563.JPG
[2010/12/08 19:50:09 | 003,808,219 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1562.JPG
[2010/12/08 19:50:08 | 003,799,410 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1561.JPG
[2010/12/08 19:50:08 | 003,789,649 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1560.JPG
[2010/12/08 19:50:07 | 003,819,396 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1558.JPG
[2010/12/08 19:50:07 | 003,800,136 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1559.JPG
[2010/12/08 19:50:06 | 003,332,316 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1556.JPG
[2010/12/08 19:50:06 | 002,932,382 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1557.JPG
[2010/12/08 19:50:05 | 003,934,836 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1555.JPG
[2010/12/08 19:50:04 | 003,863,781 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1554.JPG
[2010/12/08 19:50:04 | 003,792,940 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1553.JPG
[2010/12/08 19:50:03 | 003,865,380 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1551.JPG
[2010/12/08 19:50:03 | 003,826,580 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1552.JPG
[2010/12/08 19:50:02 | 003,869,816 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1550.JPG
[2010/12/08 19:50:01 | 003,862,784 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1549.JPG
[2010/12/08 19:50:01 | 003,862,556 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1548.JPG
[2010/12/08 19:50:00 | 003,818,602 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1546.JPG
[2010/12/08 19:50:00 | 003,816,228 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1547.JPG
[2010/12/08 19:49:59 | 003,831,926 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1545.JPG
[2010/12/08 19:49:59 | 003,826,657 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1544.JPG
[2010/12/08 19:49:58 | 003,890,251 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1543.JPG
[2010/12/08 19:49:57 | 003,849,830 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1542.JPG
[2010/12/08 19:49:57 | 003,837,074 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1541.JPG
[2010/12/08 19:49:56 | 003,848,637 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1540.JPG
[2010/12/08 19:49:55 | 003,860,087 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1539.JPG
[2010/12/08 19:49:54 | 003,858,543 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1538.JPG
[2010/12/08 19:49:54 | 003,762,083 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1537.JPG
[2010/12/08 19:49:53 | 003,751,993 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1536.JPG
[2010/12/08 19:49:53 | 003,703,147 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1535.JPG
[2010/12/08 19:49:52 | 003,718,583 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1534.JPG
[2010/12/08 19:49:52 | 003,674,070 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1533.JPG
[2010/12/08 19:49:51 | 003,601,539 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1531.JPG
[2010/12/08 19:49:51 | 003,563,786 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1532.JPG
[2010/12/08 19:49:50 | 003,545,123 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1529.JPG
[2010/12/08 19:49:50 | 003,524,999 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1530.JPG
[2010/12/08 19:49:49 | 003,980,338 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1527.JPG
[2010/12/08 19:49:49 | 003,670,848 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1528.JPG
[2010/12/08 19:49:48 | 003,902,065 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1526.JPG
[2010/12/08 19:49:47 | 003,907,133 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1525.JPG
[2010/12/08 19:49:47 | 003,889,979 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1524.JPG
[2010/12/08 19:49:46 | 003,884,892 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1523.JPG
[2010/12/08 19:49:45 | 003,908,065 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1521.JPG
[2010/12/08 19:49:45 | 003,879,085 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1522.JPG
[2010/12/08 19:49:44 | 003,800,731 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1519.JPG
[2010/12/08 19:49:44 | 003,051,377 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1520.JPG
[2010/12/08 19:49:43 | 003,800,251 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1517.JPG
[2010/12/08 19:49:43 | 003,422,889 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1518.JPG
[2010/12/08 19:49:42 | 003,256,410 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1515.JPG
[2010/12/08 19:49:42 | 003,172,397 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1516.JPG
[2010/12/08 19:49:41 | 003,870,922 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1514.JPG
[2010/12/08 19:49:41 | 003,651,355 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1513.JPG
[2010/12/08 19:49:40 | 003,709,471 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1512.JPG
[2010/12/08 19:49:39 | 003,848,972 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1510.JPG
[2010/12/08 19:49:39 | 003,685,675 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1511.JPG
[2010/12/08 19:49:38 | 003,786,300 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1509.JPG
[2010/12/08 19:49:38 | 003,753,291 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1508.JPG
[2010/12/08 19:49:37 | 002,838,148 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1506.JPG
[2010/12/08 19:49:37 | 002,472,362 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1507.JPG
[2010/12/08 19:49:36 | 003,848,256 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1504.JPG
[2010/12/08 19:49:36 | 003,799,066 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1505.JPG
[2010/12/08 19:49:35 | 003,817,973 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1503.JPG
[2010/12/08 19:49:34 | 003,596,442 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1501.JPG
[2010/12/08 19:49:34 | 003,542,195 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1502.JPG
[2010/12/08 19:49:33 | 003,820,073 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1499.JPG
[2010/12/08 19:49:33 | 003,642,942 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1500.JPG
[2010/12/08 19:49:32 | 003,790,505 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1498.JPG
[2010/12/08 19:49:31 | 003,383,812 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1497.JPG
[2010/12/08 19:49:30 | 004,010,411 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1496.JPG
[2010/12/08 19:49:30 | 003,801,026 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1495.JPG
[2010/12/08 19:49:29 | 003,785,483 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1494.JPG
[2010/12/08 19:49:28 | 003,560,992 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1493.JPG
[2010/12/08 19:49:28 | 003,411,563 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1492.JPG
[2010/12/08 19:49:27 | 003,598,430 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1490.JPG
[2010/12/08 19:49:27 | 003,033,809 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1491.JPG
[2010/12/08 19:49:26 | 003,830,353 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1488.JPG
[2010/12/08 19:49:26 | 003,805,359 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1489.JPG
[2010/12/08 19:49:25 | 003,919,358 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1487.JPG
[2010/12/08 19:49:25 | 003,828,960 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1486.JPG
[2010/12/08 19:49:24 | 003,604,160 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1485.JPG
[2010/12/08 19:49:23 | 003,652,710 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1484.JPG
[2010/12/08 19:49:23 | 003,559,237 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1483.JPG
[2010/12/08 19:49:22 | 003,755,499 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1481.JPG
[2010/12/08 19:49:22 | 003,689,332 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1482.JPG
[2010/12/08 19:49:21 | 003,856,700 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1480.JPG
[2010/12/08 19:49:21 | 003,803,456 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1479.JPG
[2010/12/08 19:49:20 | 003,820,030 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1477.JPG
[2010/12/08 19:49:20 | 003,650,045 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1478.JPG
[2010/12/08 19:49:19 | 003,845,269 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1476.JPG
[2010/12/08 19:49:18 | 003,800,277 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1475.JPG
[2010/12/08 19:49:17 | 003,876,894 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1473.JPG
[2010/12/08 19:49:17 | 003,756,312 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1474.JPG
[2010/12/08 19:49:16 | 004,016,361 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1471.JPG
[2010/12/08 19:49:16 | 003,947,913 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1472.JPG
[2010/12/08 19:49:15 | 003,443,071 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1470.JPG
[2010/12/08 19:49:14 | 003,787,436 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1469.JPG
[2010/12/08 19:49:14 | 003,764,520 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1468.JPG
[2010/12/08 19:49:13 | 003,824,799 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1466.JPG
[2010/12/08 19:49:13 | 003,770,399 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1467.JPG
[2010/12/08 19:49:12 | 003,874,740 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1464.JPG
[2010/12/08 19:49:12 | 003,791,716 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1465.JPG
[2010/12/08 19:49:11 | 003,856,389 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1463.JPG
[2010/12/08 19:49:10 | 003,723,719 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1461.JPG
[2010/12/08 19:49:10 | 003,592,171 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1462.JPG
[2010/12/08 19:49:09 | 003,858,437 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1459.JPG
[2010/12/08 19:49:09 | 003,749,950 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1460.JPG
[2010/12/08 19:49:08 | 003,824,967 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1458.JPG
[2010/12/08 19:49:08 | 003,746,404 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1457.JPG
[2010/12/08 19:49:07 | 003,828,182 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1456.JPG
[2010/12/08 19:49:06 | 003,900,324 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1454.JPG
[2010/12/08 19:49:06 | 003,832,151 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1455.JPG
[2010/12/08 19:49:05 | 003,900,327 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1453.JPG
[2010/12/08 19:49:04 | 003,967,904 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1452.JPG
[2010/12/08 19:49:04 | 003,507,966 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1451.JPG
[2010/12/08 19:49:03 | 003,748,283 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1450.JPG
[2010/12/08 19:49:03 | 002,574,583 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1449.JPG
[2010/12/08 19:49:02 | 003,020,258 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1448.JPG
[2010/12/08 19:49:01 | 003,231,118 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1446.JPG
[2010/12/08 19:49:01 | 003,131,847 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1447.JPG
[2010/12/08 19:49:00 | 003,583,993 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1444.JPG
[2010/12/08 19:49:00 | 003,274,125 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1445.JPG
[2010/12/08 19:48:59 | 003,752,802 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1443.JPG
[2010/12/08 19:48:58 | 003,895,584 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1441.JPG
[2010/12/08 19:48:58 | 003,863,590 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1442.JPG
[2010/12/08 19:48:57 | 003,760,653 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1440.JPG
[2010/12/08 19:48:56 | 003,857,813 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1439.JPG
[2010/12/08 19:48:56 | 003,807,741 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1438.JPG
[2010/12/08 19:48:55 | 003,849,692 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1437.JPG
[2010/12/08 19:48:55 | 002,903,250 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1436.JPG
[2010/12/08 19:48:53 | 002,949,897 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1435.JPG
[2010/12/08 19:48:52 | 002,872,916 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1434.JPG
[2010/12/08 19:48:51 | 003,616,277 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1433.JPG
[2010/12/08 19:48:51 | 003,599,646 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1432.JPG
[2010/12/08 19:48:50 | 003,882,276 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1430.JPG
[2010/12/08 19:48:50 | 003,580,286 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1431.JPG
[2010/12/08 19:48:49 | 003,880,153 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1428.JPG
[2010/12/08 19:48:49 | 003,877,726 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1429.JPG
[2010/12/08 19:48:48 | 003,933,443 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1427.JPG
[2010/12/08 19:48:47 | 003,796,430 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1425.JPG
[2010/12/08 19:48:47 | 003,791,701 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1426.JPG
[2010/12/08 19:48:46 | 003,877,503 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1423.JPG
[2010/12/08 19:48:46 | 003,874,802 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1424.JPG
[2010/12/08 19:48:45 | 003,761,225 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1422.JPG
[2010/12/08 19:48:45 | 003,736,681 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1421.JPG
[2010/12/08 19:48:44 | 003,835,564 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1420.JPG
[2010/12/08 19:48:43 | 003,837,123 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1419.JPG
[2010/12/08 19:48:43 | 003,781,399 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1418.JPG
[2010/12/08 19:48:42 | 003,625,729 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1417.JPG
[2010/12/08 19:48:42 | 003,208,109 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1416.JPG
[2010/12/08 19:48:41 | 003,294,393 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1415.JPG
[2010/12/08 19:48:40 | 003,778,962 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1413.JPG
[2010/12/08 19:48:40 | 003,461,892 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1414.JPG
[2010/12/08 19:48:39 | 003,767,801 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1412.JPG
[2010/12/08 19:48:39 | 003,218,949 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1411.JPG
[2010/12/08 19:48:38 | 003,819,983 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1409.JPG
[2010/12/08 19:48:38 | 003,607,812 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1410.JPG
[2010/12/08 19:48:37 | 003,836,472 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1407.JPG
[2010/12/08 19:48:37 | 003,818,289 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1408.JPG
[2010/12/08 19:48:36 | 003,797,711 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1406.JPG
[2010/12/08 19:48:36 | 002,819,221 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1405.JPG
[2010/12/08 19:48:35 | 003,021,362 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1403.JPG
[2010/12/08 19:48:35 | 002,739,772 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1404.JPG
[2010/12/08 19:48:34 | 002,899,077 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1401.JPG
[2010/12/08 19:48:34 | 002,874,114 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1402.JPG
[2010/12/08 19:48:33 | 003,807,171 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1399.JPG
[2010/12/08 19:48:33 | 003,792,529 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1400.JPG
[2010/12/08 19:48:32 | 003,806,292 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1398.JPG
[2010/12/08 19:48:31 | 003,837,626 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1397.JPG
[2010/12/08 19:48:31 | 002,130,262 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1395.JPG
[2010/12/08 19:48:31 | 002,018,826 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1396.JPG
[2010/12/08 19:48:30 | 002,721,068 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1394.JPG
[2010/12/08 19:48:30 | 002,059,675 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1393.JPG
[2010/12/08 19:48:29 | 003,765,495 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1392.JPG
[2010/12/08 19:48:29 | 002,245,298 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1391.JPG
[2010/12/08 19:48:29 | 002,210,908 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1390.JPG
[2010/12/08 19:48:28 | 002,484,764 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1388.JPG
[2010/12/08 19:48:28 | 002,261,243 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1389.JPG
[2010/12/08 19:48:27 | 003,818,551 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1387.JPG
[2010/12/08 19:48:27 | 003,594,741 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1386.JPG
[2010/12/08 19:48:26 | 003,820,889 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1384.JPG
[2010/12/08 19:48:26 | 003,498,412 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1385.JPG
[2010/12/08 19:48:25 | 003,558,819 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1382.JPG
[2010/12/08 19:48:25 | 003,556,855 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1383.JPG
[2010/12/08 19:48:24 | 003,448,789 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1381.JPG
[2010/12/08 19:48:24 | 003,427,319 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1380.JPG
[2010/12/08 19:48:23 | 003,637,323 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1379.JPG
[2010/12/08 19:48:22 | 003,984,127 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1378.JPG
[2010/12/08 19:48:22 | 003,974,367 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1377.JPG
[2010/12/08 19:48:21 | 003,649,635 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1376.JPG
[2010/12/08 19:48:21 | 003,316,181 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1375.JPG
[2010/12/08 19:48:20 | 003,800,839 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1373.JPG
[2010/12/08 19:48:20 | 003,190,593 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1374.JPG
[2010/12/08 19:48:19 | 003,793,781 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1371.JPG
[2010/12/08 19:48:19 | 003,780,671 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1372.JPG
[2010/12/08 19:48:18 | 003,824,769 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1370.JPG
[2010/12/08 19:48:17 | 003,822,512 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1368.JPG
[2010/12/08 19:48:17 | 003,814,810 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1369.JPG
[2010/12/08 19:48:16 | 003,806,959 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1366.JPG
[2010/12/08 19:48:16 | 003,798,940 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1367.JPG
[2010/12/08 19:48:15 | 003,826,690 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1365.JPG
[2010/12/08 19:48:14 | 003,872,230 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1363.JPG
[2010/12/08 19:48:14 | 003,855,243 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1364.JPG
[2010/12/08 19:48:13 | 003,854,146 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1361.JPG
[2010/12/08 19:48:13 | 003,808,507 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1362.JPG
[2010/12/08 19:48:12 | 003,857,876 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1360.JPG
[2010/12/08 19:48:12 | 003,475,751 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1359.JPG
[2010/12/08 19:48:11 | 003,467,533 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1358.JPG
[2010/12/08 19:48:10 | 003,778,497 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1356.JPG
[2010/12/08 19:48:10 | 003,759,295 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1357.JPG
[2010/12/08 19:48:09 | 003,875,904 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1354.JPG
[2010/12/08 19:48:09 | 003,814,794 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1355.JPG
[2010/12/08 19:48:08 | 003,898,377 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1352.JPG
[2010/12/08 19:48:08 | 003,764,145 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1353.JPG
[2010/12/08 19:48:07 | 003,880,814 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1351.JPG
[2010/12/08 19:48:06 | 003,915,074 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1349.JPG
[2010/12/08 19:48:06 | 003,873,422 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1350.JPG
[2010/12/08 19:48:05 | 003,938,886 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1348.JPG
[2010/12/08 19:48:05 | 003,859,478 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1347.JPG
[2010/12/08 19:48:04 | 003,820,444 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1346.JPG
[2010/12/08 19:48:03 | 003,990,167 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1345.JPG
[2010/12/08 19:47:57 | 003,859,342 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1333.JPG
[2010/12/08 19:47:56 | 003,849,580 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1332.JPG
[2010/12/08 19:47:55 | 003,910,689 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1330.JPG
[2010/12/08 19:47:55 | 003,795,192 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1331.JPG
[2010/12/08 19:47:54 | 003,919,375 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1329.JPG
[2010/12/08 19:47:54 | 003,847,642 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1328.JPG
[2010/12/08 19:47:53 | 003,795,994 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1326.JPG
[2010/12/08 19:47:53 | 003,772,694 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1327.JPG
[2010/12/08 19:47:52 | 003,778,706 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1325.JPG
[2010/12/08 19:47:52 | 003,555,960 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1324.JPG
[2010/12/08 19:47:51 | 003,545,538 | ---- | C] () -- C:\Documents and Settings\Administrator\DSCI1323.JPG
[2010/12/08 09:18:20 | 000,000,470 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/12/08 09:15:42 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2010/10/07 10:11:04 | 000,000,194 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\menu.old
[2010/10/07 09:53:28 | 000,000,002 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\menu.new
[2010/10/07 09:53:28 | 000,000,002 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\menu.bfm
[2010/02/11 21:36:32 | 003,653,120 | ---- | C] () -- C:\Program Files\SSCERuntime_x64-ENU.msi
[2010/02/11 21:36:18 | 003,164,160 | ---- | C] () -- C:\Program Files\SSCERuntime_x86-ENU.msi

========== ZeroAccess Check ==========

[2010/12/07 23:49:48 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2010/06/24 07:10:44 | 001,509,888 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2009/09/23 12:21:58 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/02/01 16:34:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\AVG10
[2012/03/18 10:11:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Azureus
[2011/11/14 20:44:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\com.pruvan.PruvanOffice.D20FAAC2DD0C878F730FBC057EBFAB9559258FC2.1
[2012/02/19 23:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\com.w3i.musicrockstar
[2011/02/17 02:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Easy MP3 Recorder
[2011/11/17 14:12:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ElevatedDiagnostics
[2011/03/25 15:25:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Harmonisoft
[2012/02/13 21:31:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Nokia
[2012/02/13 21:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Nokia Suite
[2012/02/01 09:38:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PC Suite
[2011/01/20 17:52:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PrimoPDF
[2011/08/16 21:14:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Sierra Wireless
[2010/12/10 11:02:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\UniPrint
[2010/12/17 00:14:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\VTExtra
[2010/12/21 20:20:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2010/12/22 06:05:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Search
[2011/03/17 21:52:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avanquest
[2012/01/30 08:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/03/16 17:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2012/05/19 22:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/10/06 13:01:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/02/01 16:32:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/02/18 23:44:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iMesh
[2011/11/05 23:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2012/01/23 14:05:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/01/08 12:38:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2012/03/17 08:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2011/11/05 23:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2011/08/16 21:14:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sierra Wireless
[2011/08/06 04:12:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/01/16 14:44:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/02/18 23:43:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{BD8912D9-3040-46C4-B96A-4C3AC7E43486}

========== Purity Check ==========



========== Custom Scans ==========

========== Base Services ==========
SRV - [2009/09/23 12:21:31 | 000,044,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\alg.exe -- (ALG)
SRV - [2009/09/23 12:22:01 | 000,006,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv)
SRV - [2009/09/23 12:21:52 | 000,409,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\qmgr.dll -- (BITS)
SRV - [2009/09/23 12:21:32 | 000,077,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\browser.dll -- (Browser)
SRV - [2009/09/23 12:21:35 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\cryptsvc.dll -- (CryptSvc)
SRV - [2009/09/23 12:21:36 | 000,126,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\dhcpcsvc.dll -- (Dhcp)
SRV - [2009/04/20 12:17:26 | 000,045,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\dnsrslvr.dll -- (Dnscache)
SRV - [2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\services.exe -- (Eventlog)
SRV - [2009/09/23 12:21:39 | 000,033,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\eapsvc.dll -- (EapHost)
SRV - [2009/07/27 18:17:41 | 000,135,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (FastUserSwitchingCompatibility)
SRV - [2009/09/23 12:21:58 | 000,015,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\w3ssl.dll -- (HTTPFilter)
SRV - [2008/04/14 05:41:56 | 000,021,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\hidserv.dll -- (HidServ)
SRV - [2009/09/23 12:21:42 | 000,150,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\imapi.exe -- (ImapiService)
SRV - [2009/09/23 12:21:46 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lsass.exe -- (PolicyAgent)
SRV - [2009/09/23 12:21:36 | 000,023,552 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\WINDOWS\system32\dmserver.dll -- (dmserver)
SRV - [2009/09/23 12:21:36 | 000,224,768 | ---- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] -- C:\WINDOWS\System32\dmadmin.exe -- (dmadmin)
SRV - [2009/09/23 12:21:36 | 000,005,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\System32\dllhost.exe -- (SwPrv)
SRV - [2009/09/23 12:21:46 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\lsass.exe -- (Netlogon)
SRV - [2009/09/23 12:21:49 | 000,198,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\netman.dll -- (Netman)
SRV - [2008/06/20 11:02:47 | 000,245,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\mswsock.dll -- (Nla)
SRV - [2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\services.exe -- (PlugPlay)
SRV - [2010/08/17 08:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\spoolsv.exe -- (Spooler)
SRV - [2009/09/23 12:21:46 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lsass.exe -- (ProtectedStorage)
SRV - [2009/09/23 12:21:52 | 000,088,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\rasauto.dll -- (RasAuto)
SRV - [2009/09/23 12:21:52 | 000,186,368 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\rasmans.dll -- (RasMan)
SRV - [2009/02/09 07:10:48 | 000,401,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\rpcss.dll -- (RpcSs)
SRV - [2009/09/23 12:21:50 | 000,435,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\ntmssvc.dll -- (NtmsSvc)
SRV - [2009/09/23 12:21:53 | 000,018,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\seclogon.dll -- (seclogon)
SRV - [2009/09/23 12:21:46 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lsass.exe -- (SamSs)
SRV - [2009/09/23 12:22:00 | 000,080,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wscsvc.dll -- (wscsvc)
SRV - [2010/08/27 00:57:43 | 000,099,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\srvsvc.dll -- (LanmanServer)
SRV - [2009/07/27 18:17:41 | 000,135,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (ShellHWDetection)
SRV - [2009/09/23 12:21:56 | 000,171,008 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\srsvc.dll -- (srservice)
SRV - [2009/09/23 12:21:53 | 000,192,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\schedsvc.dll -- (Schedule)
SRV - [2009/09/23 12:21:46 | 000,013,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lmhsvc.dll -- (LmHosts)
SRV - [2009/09/23 12:21:56 | 000,249,856 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\tapisrv.dll -- (TapiSrv)
SRV - [2009/09/23 12:21:56 | 000,295,424 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\termsrv.dll -- (TermService)
SRV - [2009/07/27 18:17:41 | 000,135,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (Themes)
SRV - [2009/09/23 12:21:58 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\vssvc.exe -- (VSS)
SRV - [2009/09/23 12:21:32 | 000,042,496 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\audiosrv.dll -- (AudioSrv)
SRV - [2009/09/23 12:21:42 | 000,331,264 | ---- | M] (Microsoft Corporation) [Boot | Stopped] -- C:\WINDOWS\system32\ipnathlp.dll -- (SharedAccess)
SRV - [2009/09/23 12:21:58 | 000,333,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wiaservc.dll -- (stisvc)
SRV - [2009/09/23 12:21:47 | 000,078,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\System32\msiexec.exe -- (MSIServer)
SRV - [2009/09/23 12:22:00 | 000,144,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wbem\wmisvc.dll -- (winmgmt)
SRV - [2009/02/09 07:10:48 | 000,617,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\advapi32.dll -- (Wmi)
SRV - [2009/09/23 12:21:36 | 000,132,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\dot3svc.dll -- (Dot3svc)
SRV - [2009/09/23 12:21:55 | 000,483,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wzcsvc.dll -- (WZCSVC)
SRV - [2009/06/10 01:14:49 | 000,132,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wkssvc.dll -- (lanmanworkstation)

< %SYSTEMDRIVE%\*.exe >
[2010/08/24 10:36:11 | 000,057,856 | ---- | M] (KACE Networks, Inc.) -- C:\kcleanup.exe

< MD5 for: EXPLORER.EXE >
[2009/09/23 12:21:40 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2009/09/23 12:21:40 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2009/09/23 12:21:40 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: QMGR.DLL >
[2009/09/23 12:21:52 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ERDNT\cache\qmgr.dll
[2009/09/23 12:21:52 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\dllcache\qmgr.dll
[2009/09/23 12:21:52 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\qmgr.dll

< MD5 for: SERVICES >
[2009/09/23 12:21:53 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CFG >
[2012/01/03 08:10:44 | 000,585,874 | ---- | M] () MD5=0E19E0BEA7B159153258688CF8ED7716 -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.DAT >
[2010/12/22 04:14:10 | 000,010,240 | ---- | M] () MD5=FDD748F423964223EFED00612904DBDC -- C:\Documents and Settings\Administrator\Application Data\Adobe\Acrobat\10.0\Security\services.dat

< MD5 for: SERVICES.EXE >
[2009/02/06 06:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/09/23 12:21:53 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.LNK >
[2011/10/23 08:00:31 | 000,001,602 | ---- | M] () MD5=18A1280B5C8AA4D886F9A1519A028D25 -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2009/09/23 12:21:53 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\WINDOWS\system32\services.msc

< MD5 for: SVCHOST.EXE >
[2009/09/23 12:21:56 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2009/09/23 12:21:56 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2009/09/23 12:21:56 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2012/01/13 15:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2009/09/23 12:21:57 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2009/09/23 12:21:57 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2009/09/23 12:21:57 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/13 18:30:56 | 000,035,840 | -HS- | M] () MD5=3653C2B200CC4FDFEAD0116E13E78103 -- C:\Documents and Settings\Administrator\Templates\O42525Z\winlogon.exe
[2012/01/13 15:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/09/23 12:22:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2009/09/23 12:22:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2009/09/23 12:22:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s >
"Type" = 32
"Start" = 2
"ErrorControl" = 1
"ImagePath" = %SystemRoot%\system32\svchost.exe -k netsvcs -- [2009/09/23 12:21:56 | 000,014,336 | ---- | M] (Microsoft Corporation)
"DisplayName" = Background Intelligent Transfer Service
"DependOnService" = RpcSs [binary data] -- [2009/02/09 07:10:48 | 000,401,408 | ---- | M] (Microsoft Corporation)
"DependOnGroup" = [binary data]
"ObjectName" = LocalSystem
"Description" = Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly.
"FailureActions" = 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 68 E3 0C 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
"ServiceDll" = %systemroot%\system32\qmgr.dll -- [2009/09/23 12:21:52 | 000,409,088 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Security]
"Security" = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Enum]
"0" = Root\LEGACY_BITS\0000
"Count" = 1
"NextInstance" = 1

< End of report >






OTL Extras logfile created on: 10/15/12 11:37:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy

1023.23 Mb Total Physical Memory | 414.13 Mb Available Physical Memory | 40.47% Memory free
2.40 Gb Paging File | 1.84 Gb Available in Paging File | 76.54% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 5.81 Gb Free Space | 10.39% Space Free | Partition Type: NTFS
Drive E: | 119.77 Mb Total Space | 10.67 Mb Free Space | 8.91% Space Free | Partition Type: FAT

Computer Name: WA68A7S1J249 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh -- (iMesh, Inc)
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service -- (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service -- (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email -- (Symantec Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\AT&T\AT&T Communication Manager\SwiApiMuxX.exe" = C:\Program Files\AT&T\AT&T Communication Manager\SwiApiMuxX.exe:*:Enabled:SwiApiMuxX
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08F32589-5E39-42B8-8BC5-6A8126ED2A70}" = Microsoft Visual C++ 2008 Redistributable Package
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series" = Canon MP280 series MP Drivers
"{1C336D20-A089-4818-9C56-96AD81BF5A11}" = PANTECH USB Modem V2
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29879ADC-74EF-40F8-AB1F-6433D96E568D}" = UniPrint Client 4.0
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{3273F0D8-3204-4DE5-BE34-AA6613B0E844}" = Mobile PhoneTools
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{40928C54-F8EE-420D-BD80-07F2F78CFB0D}" = MySQL Connector/ODBC 3.51
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A57592C-FF92-4083-97A9-92783BD5AFB4}" = BisonCam
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{6336C0CC-BA32-4949-9D3D-C86B76147CCA}" = Cricket Broadband Connect
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7088FE08-228A-42B3-97DE-E9DD3B749651}" = Music Rockstar
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{739126B3-1B80-4F9F-8D59-312A19633E1A}_is1" = Moozy
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{80EFBB50-5B6C-4A9D-AFBC-C7664AFF252F}" = Digital Voice Recorder
"{8578DCD4-4448-4B06-A702-B3445A0531E1}" = CIS Sketch Tool
"{89B078C4-50B0-453E-BF53-3A7E6A0D85FA}" = Windows Support Tools
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FB495A1-4A3F-4C1D-BD27-3F3AB2E66763}" = iMesh
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92D1CEBC-7C72-4ECF-BFC6-C131EF3FE6A7}" = Nokia Suite
"{94824ADD-8F26-43D2-84DB-22E11F377E5E}" = Microsoft English TTS Engine
"{96172E04-BB14-45F6-A77B-8EE7A421B903}" = SAPI Wrapper
"{97D0C0A1-7E64-4B05-A2EE-61D2CE23F154}" = TTS Wrapper
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A276502A-8979-44FB-8090-90CF72F22ABC}" = AVG 2011
"{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C1B0BDC8-0624-4036-90D1-F7DF0EE8C96D}" = Symantec Endpoint Protection
"{C82185E8-C27B-4EF4-2008-4444BC2C2B6D}" = Microsoft Streets & Trips 2008
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF6B515D-D99A-4B02-8C92-9EA255035A3D}" = Mobile PhoneTools
"{D031E017-2434-40A7-A352-4DDD0199170D}" = TouchFreeze
"{DB7AE42C-695D-4D36-A8FA-31A1C6454436}" = Nokia PC Internet Access
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F4C68898-EBA5-46A9-82B3-2D30426086BF}" = AVG 2011
"{FD933402-1249-4896-B535-BC5D3BB426EA}" = RapidSketch Web Version
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"AVG" = AVG 2011
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"FastStone Photo Resizer" = FastStone Photo Resizer 3.1
"ie8" = Windows Internet Explorer 8
"iMesh" = iMesh
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nokia PC Internet Access" = Nokia PC Internet Access
"Nokia Suite" = Nokia Suite
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"Picasa 3" = Picasa 3
"PrimoPDF4.1.0.9" = PrimoPDF
"RealPlayer 12.0" = RealPlayer
"SystemRequirementsLab" = System Requirements Lab
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WeFi" = WeFi 4.0.0.16
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-790525478-1682526488-1801674531-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 09/29/12 2:27:42 AM | Computer Name = WA68A7S1J249 | Source = MsiInstaller | ID = 11308
Description = Product: Symantec Endpoint Protection -- Error 1308.Source file not
found: C:\Documents and Settings\All Users\Application Data\Symantec\Cached Installs\{C1B0BDC8-0624-4036-90D1-F7DF0EE8C96D}\COH32\wds.dat.
Verify that the file exists and that you can access it.

Error - 09/29/12 2:27:44 AM | Computer Name = WA68A7S1J249 | Source = MsiInstaller | ID = 11308
Description = Product: Symantec Endpoint Protection -- Error 1308.Source file not
found: C:\Documents and Settings\All Users\Application Data\Symantec\Cached Installs\{C1B0BDC8-0624-4036-90D1-F7DF0EE8C96D}\program
files\Symantec\SEP\GUProxy.plg. Verify that the file exists and that you can access
it.

Error - 09/29/12 2:27:46 AM | Computer Name = WA68A7S1J249 | Source = MsiInstaller | ID = 11308
Description = Product: Symantec Endpoint Protection -- Error 1308.Source file not
found: C:\Documents and Settings\All Users\Application Data\Symantec\Cached Installs\{C1B0BDC8-0624-4036-90D1-F7DF0EE8C96D}\program
files\Symantec\SEP\LuMan.plg. Verify that the file exists and that you can access
it.

Error - 09/29/12 2:27:47 AM | Computer Name = WA68A7S1J249 | Source = MsiInstaller | ID = 11308
Description = Product: Symantec Endpoint Protection -- Error 1308.Source file not
found: C:\Documents and Settings\All Users\Application Data\Symantec\Cached Installs\{C1B0BDC8-0624-4036-90D1-F7DF0EE8C96D}\program
files\Symantec\SEP\SyLink.xml. Verify that the file exists and that you can access
it.

Error - 09/29/12 2:27:49 AM | Computer Name = WA68A7S1J249 | Source = MsiInstaller | ID = 11308
Description = Product: Symantec Endpoint Protection -- Error 1308.Source file not
found: C:\Documents and Settings\All Users\Application Data\Symantec\Cached Installs\{C1B0BDC8-0624-4036-90D1-F7DF0EE8C96D}\program
files\Symantec\SEP\cltdef.dat. Verify that the file exists and that you can access
it.

Error - 09/29/12 2:28:09 AM | Computer Name = WA68A7S1J249 | Source = MsiInstaller | ID = 11308
Description = Product: Symantec Endpoint Protection -- Error 1308.Source file not
found: C:\Documents and Settings\All Users\Application Data\Symantec\Cached Installs\{C1B0BDC8-0624-4036-90D1-F7DF0EE8C96D}\program
files\Symantec\SEP\moniker.dat. Verify that the file exists and that you can access
it.

Error - 10/04/12 12:14:11 PM | Computer Name = WA68A7S1J249 | Source = Application Hang | ID = 1002
Description = Hanging application mPhonetools.exe, version 3.0.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/15/12 10:28:17 AM | Computer Name = WA68A7S1J249 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/15/12 10:58:04 AM | Computer Name = WA68A7S1J249 | Source = Application Hang | ID = 1002
Description = Hanging application PicasaPhotoViewer.exe, version 3.9.135.93, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/15/12 11:33:42 AM | Computer Name = WA68A7S1J249 | Source = Windows Search Service | ID = 3013
Description = The entry <C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DESKTOP\2012-03-29\THUMBS.DB>
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

[ System Events ]
Error - 10/15/12 10:59:17 AM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 10:59:51 AM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 11:00:23 AM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 11:00:54 AM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 11:01:28 AM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 11:02:05 AM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 12:37:49 PM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 12:38:13 PM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 12:38:39 PM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7

Error - 10/15/12 12:39:28 PM | Computer Name = WA68A7S1J249 | Source = AmdK8 | ID = 327682
Description = The Acpi 2.0 _PCT object returned an invalid value of 7


< End of report >
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP