and the otlist
OTListIt logfile created on: 4/10/2009 7:06:14 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Users\Rory Hamilton\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 2.53 Gb Available Physical Memory | 67.64% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.97 Gb Total Space | 153.97 Gb Free Space | 70.00% Space Free | Partition Type: NTFS
Drive D: | 12.91 Gb Total Space | 2.02 Gb Free Space | 15.64% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RORYHAMILTON-PC
Current User Name: Rory Hamilton
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2009/04/03 22:43:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe
PRC - [2008/06/09 10:21:58 | 00,073,728 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/10/22 23:45:51 | 00,115,560 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
PRC - [2008/10/06 08:54:52 | 00,365,952 | —- | M] () – C:\Program Files (x86)\SMINST\BLService.exe
PRC - [2008/06/29 15:10:18 | 00,241,734 | —- | M] () – C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
PRC - [2008/09/24 18:08:26 | 00,296,320 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
PRC - [2008/09/24 18:08:26 | 00,116,096 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
PRC - [2009/04/03 22:43:55 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgemc.exe
PRC - [2009/04/03 22:43:55 | 00,691,992 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe
PRC - [2009/03/19 11:54:50 | 00,321,344 | —- | M] (BitTorrent, Inc.) – C:\Users\Rory Hamilton\Program Files (x86)\DNA\btdna.exe
PRC - [2009/02/06 18:51:28 | 03,885,408 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2008/09/26 02:36:40 | 01,148,200 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2008/09/25 18:41:44 | 01,152,296 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
PRC - [2008/09/25 18:42:24 | 00,189,736 | —- | M] (CyberLink) – C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2008/09/24 18:07:58 | 00,206,120 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
PRC - [2007/05/08 15:24:20 | 00,054,840 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
PRC - [2008/04/15 13:51:00 | 00,488,752 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
PRC - [2009/04/03 22:43:55 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgtray.exe
PRC - [2008/05/01 15:25:56 | 00,165,192 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
PRC - [2009/04/08 13:12:17 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jusched.exe
PRC - [2007/09/26 06:34:40 | 00,316,720 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
PRC - [2008/04/11 08:04:54 | 00,685,360 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
PRC - [2009/04/10 07:04:20 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Users\Rory Hamilton\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/10/15 03:39:50 | 00,089,088 | —- | M] () – C:\Windows\sysnative\DriverStore\FileRepository\stwrt64.inf_5730ce9f\AESTSr64.exe – (AESTFilters [Auto | Running])
SRV - [2007/12/11 12:11:30 | 00,015,872 | —- | M] () – C:\Windows\sysnative\agr64svc.exe – (AgereModemAudio [Auto | Running])
SRV - [2008/09/16 19:14:32 | 00,905,216 | —- | M] () – C:\Windows\sysnative\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
SRV - [2009/04/03 22:43:55 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/04/03 22:43:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2008/07/27 10:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/27 10:01:49 | 00,093,184 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2008/04/03 10:33:26 | 00,193,840 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe – (Com4QLBEx [On_Demand | Stopped])
SRV - [2008/01/20 18:51:36 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/20 18:51:36 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 07:03:48 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2008/06/19 17:17:12 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Running])
SRV - [2008/06/16 07:02:28 | 00,094,208 | —- | M] (Hewlett-Packard) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe – (HP Health Check Service [Auto | Running])
SRV - [2008/05/01 15:25:56 | 00,165,192 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe – (hpqwmiex [On_Demand | Running])
SRV - [2008/03/18 16:25:40 | 00,023,040 | —- | M] () – C:\Windows\sysnative\Hpservice.exe – (hpsrv [Auto | Running])
SRV - [2004/10/22 02:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 17:16:53 | 00,859,648 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/06/09 10:21:58 | 00,073,728 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe – (LightScribeService [Auto | Running])
SRV - [2008/06/19 17:16:54 | 00,119,808 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/10/22 23:45:51 | 00,115,560 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe – (Norton Internet Security [Auto | Running])
SRV - [2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/01/20 18:47:55 | 00,079,360 | —- | M] () – C:\Windows\sysnative\pcasvc.dll – (PcaSvc [Auto | Running])
SRV - [2008/01/20 18:51:00 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\perfhost.exe – (PerfHost [On_Demand | Stopped])
SRV - [2008/10/06 08:54:52 | 00,365,952 | —- | M] () – C:\Program Files (x86)\SMINST\BLService.exe – (Recovery Service for Windows [Auto | Running])
SRV - [2008/06/29 15:10:18 | 00,241,734 | —- | M] () – C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe – (RichVideo [Auto | Running])
SRV - [2008/10/15 03:39:52 | 00,279,040 | —- | M] () – C:\Windows\sysnative\DriverStore\FileRepository\stwrt64.inf_5730ce9f\STacSV64.exe – (STacSV [Auto | Running])
SRV - [2008/09/24 18:08:26 | 00,296,320 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe – (TVCapSvc [Auto | Running])
SRV - [2008/09/24 18:08:26 | 00,116,096 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe – (TVSched [Auto | Running])
SRV - [2008/01/20 18:52:15 | 01,216,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])
========== Driver Services (SafeList) ==========
DRV - [2008/03/27 12:10:14 | 00,040,296 | —- | M] () – C:\Windows\sysnative\DRIVERS\Accelerometer.sys – (Accelerometer [On_Demand | Running])
DRV - [2008/02/29 15:59:32 | 01,252,352 | —- | M] () – C:\Windows\sysnative\DRIVERS\agrsm64.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2008/03/31 01:36:18 | 00,195,120 | —- | M] () – C:\Windows\sysnative\DRIVERS\Apfiltr.sys – (ApfiltrService [On_Demand | Running])
DRV - [2008/09/16 20:01:26 | 04,709,888 | —- | M] () – C:\Windows\sysnative\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running])
DRV - [2008/04/28 00:25:06 | 00,016,400 | —- | M] () – C:\Windows\sysnative\DRIVERS\AtiPcie.sys – (AtiPcie [Boot | Running])
DRV - [2009/04/03 22:44:05 | 00,414,216 | —- | M] () – C:\Windows\sysnative\Drivers\avgldx64.sys – (AvgLdx64 [System | Running])
DRV - [2009/04/03 22:44:02 | 00,033,160 | —- | M] () – C:\Windows\sysnative\Drivers\avgmfx64.sys – (AvgMfx64 [System | Running])
DRV - [2009/04/03 22:44:11 | 00,133,640 | —- | M] () – C:\Windows\sysnative\Drivers\avgtdia.sys – (AvgTdiA [System | Running])
DRV - [2009/02/11 07:40:57 | 01,522,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\bcmwl664.sys – (BCM43XX [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,428,592 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\ccHPx64.sys – (ccHP [System | Running])
DRV - [2008/01/20 18:46:51 | 00,017,792 | —- | M] () – C:\Windows\sysnative\DRIVERS\CmBatt.sys – (CmBatt [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,475,696 | —- | M] (Symantec Corporation) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl [System | Running])
DRV - [2008/01/24 04:24:24 | 00,060,928 | —- | M] () – C:\Windows\sysnative\DRIVERS\enecir.sys – (enecir [On_Demand | Running])
DRV - [2006/11/01 21:28:10 | 00,273,920 | —- | M] () – C:\Windows\sysnative\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
DRV - [2008/03/27 12:10:56 | 00,026,984 | —- | M] () – C:\Windows\sysnative\DRIVERS\hpdskflt.sys – (hpdskflt [Boot | Running])
DRV - [2007/06/18 16:13:12 | 00,018,432 | —- | M] () – C:\Windows\sysnative\DRIVERS\HpqKbFiltr.sys – (HpqKbFiltr [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,395,312 | —- | M] (Symantec Corporation) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20080826.006\IDSVia64.sys – (IDSVia64 [System | Running])
DRV - [2008/07/21 01:53:04 | 00,145,496 | —- | M] () – C:\Windows\sysnative\DRIVERS\jmcr.sys – (JMCR [On_Demand | Stopped])
DRV - [2008/01/20 18:46:57 | 03,154,432 | —- | M] () – C:\Windows\sysnative\DRIVERS\NETw3v64.sys – (NETw3v64 [On_Demand | Stopped])
DRV - [2008/04/15 01:05:42 | 00,161,792 | —- | M] () – C:\Windows\sysnative\DRIVERS\Rtlh64.sys – (RTL8169 [On_Demand | Running])
DRV - [2008/01/20 18:46:55 | 00,111,104 | —- | M] () – C:\Windows\sysnative\DRIVERS\sdbus.sys – (sdbus [On_Demand | Stopped])
DRV - [2008/10/22 23:45:52 | 00,474,672 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SRTSP64.SYS – (SRTSP [On_Demand | Stopped])
DRV - [2008/10/22 23:45:52 | 00,032,304 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SRTSPX64.SYS – (SRTSPX [System | Running])
DRV - [2008/10/15 03:39:54 | 00,465,408 | —- | M] () – C:\Windows\sysnative\DRIVERS\stwrt64.sys – (STHDA [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,016,432 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMDNS.SYS – (SYMDNS [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,402,480 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMEFA64.SYS – (SymEFA [Boot | Running])
DRV - [2009/03/20 04:23:30 | 00,172,080 | —- | M] () – C:\Windows\sysnative\Drivers\SYMEVENT64x86.SYS – (SymEvent [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,138,800 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMFW.SYS – (SYMFW [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,032,304 | R— | M] () – C:\Windows\sysnative\DRIVERS\SymIMv.sys – (SymIM [System | Running])
DRV - [2008/10/22 23:45:52 | 00,046,640 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMNDISV.SYS – (SYMNDISV [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,033,840 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMREDRV.SYS – (SYMREDRV [On_Demand | Running])
DRV - [2008/10/22 23:45:52 | 00,283,696 | —- | M] () – C:\Windows\sysnative\drivers\NISx64\1000000.07D\SYMTDI.SYS – (SYMTDI [System | Running])
DRV - [2008/05/28 17:54:18 | 00,026,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\usbfilter.sys – (usbfilter [On_Demand | Running])
DRV - [2008/01/20 18:47:27 | 00,168,704 | —- | M] () – C:\Windows\sysnative\Drivers\usbvideo.sys – (usbvideo [On_Demand | Running])
DRV - [2006/10/03 17:45:36 | 00,273,408 | —- | M] () – C:\Windows\sysnative\DRIVERS\yk60x64.sys – (yukonx64 [On_Demand | Stopped])
DRV - [2008/09/26 02:36:34 | 00,027,632 | —- | M] (Cyberlink Corp.) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl – ({55662437-DA8C-40c0-AADA-2C816A897A49} [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.0.20080710
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES (X86)\AVG\AVG8\FIREFOX [2009/04/03 22:43:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES (X86)\AVG\AVG8\TOOLBARFF [2009/04/03 22:43:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/04 17:09:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [2009/04/05 09:00:37 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [2009/04/08 13:12:46 | 00,000,000 | —D | M]
[2009/03/19 09:12:54 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Extensions
[2009/03/19 09:12:54 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/09 17:47:52 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions
[2009/04/08 13:17:12 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/04/03 22:27:36 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/03/28 15:36:09 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\[removed]
[2009/04/03 22:27:36 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\[removed]
[2009/03/28 15:36:18 | 00,000,000 | —D | M] – C:\Users\Rory Hamilton\AppData\Roaming\mozilla\Firefox\Profiles\6oseyu8c.default\extensions\[removed]\chrome\mozapps\extensions
[2009/03/28 21:07:48 | 00,002,273 | —- | M] () – C:\Users\Rory Hamilton\AppData\Roaming\Mozilla\FireFox\Profiles\6oseyu8c.default\searchplugins\ask.xml
[2009/03/28 21:07:48 | 00,000,567 | —- | M] () – C:\Users\Rory Hamilton\AppData\Roaming\Mozilla\FireFox\Profiles\6oseyu8c.default\searchplugins\yahoo.xml
[2009/04/08 13:12:49 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/04/05 09:00:37 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/08 13:12:49 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/05 09:00:14 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/04/05 09:00:14 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2009/04/05 09:00:27 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/05 09:00:27 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2009/04/05 09:00:27 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/05 09:00:27 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2009/04/05 09:00:27 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2009/04/05 09:00:27 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/05 09:00:27 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files (x86)\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files (x86)\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files (x86)\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" (CyberLink)
O4 - HKLM..\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" (CyberLink Corp.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Users\Rory Hamilton\Program Files (x86)\DNA\btdna.exe" (BitTorrent, Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/04/10 07:03:59 | 00,500,736 | —- | C] (OldTimer Tools) – C:\Users\Rory Hamilton\Desktop\OTListIt2.exe
[2009/04/09 17:41:38 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Adobe
[2009/04/08 13:27:10 | 00,001,888 | —- | C] () – C:\Users\Rory Hamilton\Desktop\HijackThis.lnk
[2009/04/08 13:24:33 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Desktop\logs
[2009/04/08 13:24:06 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/08 13:24:06 | 00,000,808 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/08 13:24:04 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 22:32:29 | 00,010,888 | —- | C] () – C:\Users\Rory Hamilton\Documents\JAMAICA COMMANDS A POSITION THAT ALLOWS IT TO BE UTILIZED BY CERTAIN PARTIES TO CARRY OUT TRADE IN CONTRABAND.docx
[2009/04/04 16:59:07 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/04/04 16:58:45 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/04/04 16:58:44 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/04/04 16:58:43 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/04/04 16:58:43 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/04/04 16:58:43 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/04/04 16:57:42 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/04/04 16:57:28 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/04/03 23:26:07 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/04/03 23:25:52 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/04/03 23:25:44 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/04/03 23:25:33 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/04/03 23:25:29 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/04/03 23:21:33 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2009/04/03 23:08:15 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/04/03 23:08:14 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/04/03 23:08:13 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/04/03 23:08:12 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/04/03 23:08:12 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/04/03 23:08:12 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2009/04/03 23:07:52 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/04/03 23:07:49 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/03 23:07:48 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/03 23:07:47 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/03 23:07:46 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/03 23:07:46 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/03 23:07:43 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/03 23:07:40 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/03 23:07:40 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/03 23:06:07 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/04/03 23:06:04 | 04,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/04/03 23:05:55 | 03,080,704 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/04/03 23:05:54 | 02,927,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\explorer.exe
[2009/04/03 23:05:44 | 01,191,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3.dll
[2009/04/03 23:05:39 | 02,868,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2009/04/03 23:05:36 | 02,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2009/04/03 23:05:35 | 00,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2009/04/03 23:05:33 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2009/04/03 23:05:28 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schannel.dll
[2009/04/03 23:05:14 | 11,580,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shell32.dll
[2009/04/03 23:05:00 | 01,334,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml6.dll
[2009/04/03 23:04:54 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/04/03 23:04:54 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/04/03 23:04:54 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/04/03 23:04:51 | 00,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/04/03 23:04:42 | 00,443,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2009/04/03 23:04:31 | 01,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2009/04/03 23:04:23 | 00,303,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gdi32.dll
[2009/04/03 23:04:19 | 00,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2009/04/03 22:50:02 | 00,466,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netapi32.dll
[2009/04/03 22:47:21 | 00,000,000 | —D | C] – C:\Windows\System32\drivers\avg
[2009/04/03 22:45:39 | 00,561,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2009/04/03 22:45:39 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2009/04/03 22:45:39 | 00,034,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2009/04/03 22:45:28 | 00,162,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/04/03 22:45:28 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/04/03 22:44:17 | 00,001,649 | —- | C] () – C:\Users\Public\Desktop\AVG Free 8.5.lnk
[2009/04/03 22:43:52 | 00,000,000 | —D | C] – C:\ProgramData\avg8
[2009/04/03 22:43:52 | 00,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2009/04/03 22:28:01 | 40,242,58560 | -HS- | C] () – C:\hiberfil.sys
[2009/04/03 18:43:28 | 00,000,000 | —D | C] – C:\Program Files (x86)\Avira
[2009/04/03 17:48:20 | 00,000,000 | —D | C] – C:\ProgramData\Avira
[2009/04/02 18:44:28 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Microsoft Help
[2009/04/02 14:18:59 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Malwarebytes
[2009/04/02 14:18:53 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/04/02 14:18:52 | 00,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/04/02 04:50:35 | 00,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2009/04/01 13:35:35 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/03/31 20:55:47 | 01,702,434 | -H– | C] () – C:\Users\Rory Hamilton\AppData\Local\IconCache.db
[2009/03/31 18:04:55 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\Downloads
[2009/03/30 16:20:46 | 00,000,000 | —D | C] – C:\BDE32
[2009/03/30 16:19:01 | 00,000,000 | —D | C] – C:\BC5
[2009/03/30 14:51:30 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\InstallShield
[2009/03/29 19:06:57 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\books
[2009/03/29 16:26:11 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\My Received Files
[2009/03/22 12:50:44 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\Webcam
[2009/03/22 06:26:13 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Real
[2009/03/22 06:26:13 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Real
[2009/03/22 06:23:23 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\vlc
[2009/03/22 06:07:56 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\My Library
[2009/03/22 05:09:51 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\FrostWire
[2009/03/22 05:09:45 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\FrostWire
[2009/03/22 05:03:54 | 00,000,000 | —D | C] – C:\Program Files (x86)\FrostWire
[2009/03/22 05:00:09 | 00,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Reader
[2009/03/21 22:52:45 | 00,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2009/03/21 20:27:01 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\BitTorrent
[2009/03/21 20:25:35 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Google
[2009/03/21 20:24:52 | 00,000,000 | —D | C] – C:\ProgramData\Google Updater
[2009/03/21 20:24:49 | 00,000,000 | —D | C] – C:\Program Files (x86)\Google
[2009/03/21 09:33:38 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Opera
[2009/03/21 09:33:38 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Opera
[2009/03/21 08:46:17 | 00,000,000 | —D | C] – C:\Program Files (x86)\free-downloads.net
[2009/03/21 08:45:50 | 00,000,000 | —D | C] – C:\Program Files (x86)\Alcohol Soft
[2009/03/21 07:51:00 | 00,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2009/03/19 13:09:20 | 00,005,632 | —- | C] () – C:\Users\Rory Hamilton\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/19 12:29:41 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\CyberLink
[2009/03/19 11:07:12 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\Documents\Boson NetSim Labs
[2009/03/19 10:57:15 | 00,000,000 | —D | C] – C:\ProgramData\Boson Software
[2009/03/19 10:55:26 | 00,000,000 | —D | C] – C:\Program Files (x86)\Boson Software
[2009/03/19 10:27:56 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\WinRAR
[2009/03/19 10:27:19 | 00,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2009/03/19 10:25:16 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\DNA
[2009/03/19 10:25:15 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\DNA
[2009/03/19 10:25:15 | 00,000,000 | —D | C] – C:\Program Files (x86)\DNA
[2009/03/19 10:25:15 | 00,000,000 | —D | C] – C:\Program Files (x86)\BitTorrent
[2009/03/19 10:25:12 | 00,000,000 | —D | C] – C:\Program Files (x86)\AskBarDis
[2009/03/19 10:08:40 | 00,000,680 | —- | C] () – C:\Users\Rory Hamilton\AppData\Local\d3d9caps.dat
[2009/03/19 09:53:28 | 00,000,000 | —D | C] – C:\Program Files (x86)\Opera
[2009/03/19 09:40:50 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Macromedia
[2009/03/19 09:28:27 | 00,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2009/03/19 09:28:15 | 00,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2009/03/19 09:27:54 | 00,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2009/03/19 09:27:32 | 00,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2009/03/19 09:24:55 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2009/03/19 09:12:52 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Mozilla
[2009/03/19 09:12:52 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Mozilla
[2009/03/19 09:12:47 | 00,001,778 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/03/19 09:12:44 | 00,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2009/03/19 09:09:35 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Adobe
[2009/03/19 08:52:19 | 00,000,000 | —D | C] – C:\installprogram
[2009/03/19 08:46:43 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2009/03/18 21:25:51 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Hewlett-Packard
[2009/03/18 21:24:59 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\ATI
[2009/03/18 21:24:59 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\ATI
[2009/03/18 21:24:56 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Hewlett-Packard
[2009/03/18 21:24:43 | 00,000,402 | -HS- | C] () – C:\Users\Rory Hamilton\Documents\desktop.ini
[2009/03/18 21:24:43 | 00,000,282 | -HS- | C] () – C:\Users\Rory Hamilton\Desktop\desktop.ini
[2009/03/18 21:24:43 | 00,000,174 | -HS- | C] () – C:\Users\Rory Hamilton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2009/03/18 21:24:36 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Identities
[2009/03/18 21:24:30 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\VirtualStore
[2009/03/18 21:23:29 | 00,075,280 | —- | C] () – C:\Users\Rory Hamilton\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/03/18 21:21:23 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\HP TCS
[2009/03/18 21:21:16 | 00,002,105 | —- | C] () – C:\Users\Public\Desktop\eBay.lnk
[2009/03/18 21:20:51 | 00,001,901 | —- | C] () – C:\Users\Public\Desktop\HP Total Care Advisor.lnk
[2009/03/18 21:19:44 | 00,000,000 | —D | C] – C:\Program Files (x86)\AMD
[2009/03/18 21:19:07 | 00,000,000 | RHS- | C] () – C:\Windows\System32\drivers\103C_HP_cNB_Pavilion dv4 Notebook PC_Y5335KV_0U_QCND9071YTH_E505779-001_4A_I30FB_SHP_V01.82_F.33_T081102_WV3-1_L409_M3837_J250_7AMD_8F31_92.10_#090211_N10EC8136;14E44315_(NB200UA#ABA)_XMOBI
LE_CN10_Z_21_G10029612.MRK
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\Documents\My Videos
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\Documents\My Pictures
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\Documents\My Music
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\AppData\Local\Temporary Internet Files
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\AppData\Local\History
[2009/03/18 21:18:10 | 00,000,000 | -HSD | C] – C:\Users\Rory Hamilton\AppData\Local\Application Data
[2009/03/18 21:18:09 | 00,000,000 | –SD | C] – C:\Users\Rory Hamilton\AppData\Roaming\Microsoft
[2009/03/18 21:18:09 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Roaming\Media Center Programs
[2009/03/18 21:18:09 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Temp
[2009/03/18 21:18:09 | 00,000,000 | —D | C] – C:\Users\Rory Hamilton\AppData\Local\Microsoft
[2006/11/02 04:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 04:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini
========== Files - Modified Within 30 Days ==========
[2009/04/10 07:04:20 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Users\Rory Hamilton\Desktop\OTListIt2.exe
[2009/04/10 06:54:41 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/10 06:54:35 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/10 06:54:30 | 40,242,58560 | -HS- | M] () – C:\hiberfil.sys
[2009/04/10 00:54:52 | 01,702,434 | -H– | M] () – C:\Users\Rory Hamilton\AppData\Local\IconCache.db
[2009/04/08 13:27:10 | 00,001,888 | —- | M] () – C:\Users\Rory Hamilton\Desktop\HijackThis.lnk
[2009/04/08 13:24:06 | 00,000,808 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/07 03:21:09 | 00,010,888 | —- | M] () – C:\Users\Rory Hamilton\Documents\JAMAICA COMMANDS A POSITION THAT ALLOWS IT TO BE UTILIZED BY CERTAIN PARTIES TO CARRY OUT TRADE IN CONTRABAND.docx
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/04 01:26:15 | 00,075,280 | —- | M] () – C:\Users\Rory Hamilton\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/04/03 22:44:17 | 00,001,649 | —- | M] () – C:\Users\Public\Desktop\AVG Free 8.5.lnk
[2009/03/20 04:23:26 | 00,000,368 | -HS- | M] () – C:\Users\Public\Desktop\desktop.ini
[2009/03/20 04:23:22 | 00,002,290 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2009/03/19 13:22:08 | 00,005,632 | —- | M] () – C:\Users\Rory Hamilton\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/19 10:08:40 | 00,000,680 | —- | M] () – C:\Users\Rory Hamilton\AppData\Local\d3d9caps.dat
[2009/03/19 09:12:47 | 00,001,778 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/03/18 21:24:49 | 00,000,402 | -HS- | M] () – C:\Users\Rory Hamilton\Documents\desktop.ini
[2009/03/18 21:24:49 | 00,000,282 | -HS- | M] () – C:\Users\Rory Hamilton\Desktop\desktop.ini
[2009/03/18 21:24:49 | 00,000,174 | -HS- | M] () – C:\Users\Rory Hamilton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2009/03/18 21:19:07 | 00,000,000 | RHS- | M] () – C:\Windows\System32\drivers\103C_HP_cNB_Pavilion dv4 Notebook PC_Y5335KV_0U_QCND9071YTH_E505779-001_4A_I30FB_SHP_V01.82_F.33_T081102_WV3-1_L409_M3837_J250_7AMD_8F31_92.10_#090211_N10EC8136;14E44315_(NB200UA#ABA)_XMOBI
LE_CN10_Z_21_G10029612.MRK
========== LOP Check ==========
[2009/04/10 06:54:41 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/04/10 00:55:00 | 00,014,542 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
thanx