This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Fear that my pc is infected

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is my first time here asking for help. Not sure I understand how this is done, but I'll do my best. My computer is running very slow. I've downloaded and used all 3 of the tools required in the instructions.
Here is the result of the OTL scan:

OTL logfile created on: 10/14/2010 10:28:21 AM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Users\Linda\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.13 Gb Total Space | 508.76 Gb Free Space | 85.34% Space Free | Partition Type: NTFS
Drive I: | 614.91 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive K: | 930.86 Gb Total Space | 847.57 Gb Free Space | 91.05% Space Free | Partition Type: NTFS

Computer Name: LINDA-PC | User Name: Linda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Linda\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10i_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\SecureIT\SCMonitor\SCUpdateService.exe (SecurityCoverage Inc.)
PRC - C:\Program Files\SecureIT\SCMonitor\SCMonitorService.exe (SecurityCoverage Inc.)
PRC - C:\Program Files\SecureIT\SCControlPanel.exe (SecurityCoverage Inc.)
PRC - C:\Program Files\SecureIT\SCMonitor\avscan.exe ()
PRC - C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe ()
PRC - C:\Windows\System32\PSIService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Linda\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (NMIndexingService) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe File not found
SRV - (scupdateservice) – C:\Program Files\SecureIT\SCMonitor\SCUpdateService.exe (SecurityCoverage Inc.)
SRV - (SCMonitor) – C:\Program Files\SecureIT\SCMonitor\SCMonitorService.exe (SecurityCoverage Inc.)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (WDSmartWareBackgroundService) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AERTFilters) – C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (wwEngineSvc) – C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
SRV - (ProtexisLicensing) – C:\Windows\System32\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (securitf) – C:\Windows\system32\DRIVERS\scfltr.sys ()
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (timounter) – C:\Windows\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\Windows\System32\drivers\tifsfilt.sys (Acronis)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ipfrwl) – C:\Windows\System32\drivers\ipfrwl.sys (SecurityCoverage Inc.)
DRV - (PCD5SRVC{3F6A8B78-EC003E00-05040104}) – C:\Program Files\Dell Support Center\HWDiag\bin\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (VST_DPV) – C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (VSTHWBS2) – C:\Windows\System32\drivers\VSTBS23.SYS (Conexant Systems, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (wrssweep) – C:\Program Files\Webroot\Washer\wrSSweep.sys (Webroot Software Inc (www.webroot.com))
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/webhp?hl=all
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/08/24 09:18:04 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Mozilla\Extensions
[2010/08/24 09:18:04 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/08/18 09:17:34 | 000,002,074 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (CPub Object) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\SecureIT\PopupBlocker.dll (SecurityCoverage Inc.)
O3 - HKLM\..\Toolbar: (The Weather Channel Toolbar) - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\Windows\System32\TwcToolbarIe7.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Conime] C:\Windows\System32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe ()
O4 - HKLM..\Run: [Corel Photo Downloader] C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe File not found
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SCControlPanel] C:\Program Files\SecureIT\SCControlPanel.exe (SecurityCoverage Inc.)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/da2/PCPitStop2.cab (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/06/18 16:12:18 | 000,000,088 | —- | M] () - I:\autorun.inf – [ UDF ]
O33 - MountPoints2\{f59fe9db-2e16-11df-b26a-00219b109e40}\Shell - "" = AutoRun
O33 - MountPoints2\{f59fe9db-2e16-11df-b26a-00219b109e40}\Shell\AutoRun\command - "" = I:\WD SmartWare.exe – [2009/11/13 14:25:22 | 003,280,672 | —- | M] (Western Digital)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/10/14 10:24:25 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Users\Linda\Desktop\OTL.exe
[2010/10/13 16:04:06 | 000,000,000 | —D | C] – C:\Users\Linda\Desktop\Security Programs
[2010/10/13 14:55:06 | 000,000,000 | —D | C] – C:\Users\Linda\AppData\Roaming\SUPERAntiSpyware.com
[2010/10/13 12:08:20 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/10/13 11:54:04 | 000,000,000 | —D | C] – C:\Users\Linda\AppData\Roaming\AVG10
[2010/10/13 11:52:09 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2010/10/13 11:49:10 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2010/10/13 11:45:06 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2010/10/13 04:38:06 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/13 04:37:47 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/13 04:37:34 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2010/10/13 04:37:32 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/13 04:37:28 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/13 04:37:16 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/13 04:37:12 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/13 04:37:02 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/13 04:37:01 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/13 04:37:00 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/13 04:36:55 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/13 04:36:55 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/13 04:36:52 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/13 04:36:52 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/13 04:36:52 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/13 04:36:52 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/13 04:36:52 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/13 04:36:51 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/13 04:36:51 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/13 04:36:51 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/13 04:36:51 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/13 04:36:51 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/13 04:36:51 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/13 04:36:50 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/13 04:36:01 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/12 20:13:59 | 000,000,000 | —D | C] – C:\ProgramData\Comodo
[2010/10/12 13:20:09 | 000,000,000 | —D | C] – C:\Users\Linda\Documents\rsdownloads
[2010/10/11 15:35:06 | 000,000,000 | —D | C] – C:\Users\Linda\Puzzlers
[2010/10/05 13:32:13 | 000,000,000 | —D | C] – C:\Users\Linda\Desktop\Misc
[2010/09/29 07:47:19 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/09/22 18:34:36 | 000,000,000 | —D | C] – C:\Users\Linda\NorthernLights
[2010/09/15 08:07:12 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2010/09/14 16:03:07 | 000,000,000 | —D | C] – C:\ProgramData\WD_SmartWareCommon
[2010/02/12 21:50:50 | 000,047,360 | —- | C] (VSO Software) – C:\Users\Linda\AppData\Roaming\pcouffin.sys
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[10 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/14 10:24:27 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Users\Linda\Desktop\OTL.exe
[2010/10/14 10:23:20 | 000,359,929 | —- | M] () – C:\Users\Linda\Desktop\dds.scr
[2010/10/14 10:19:28 | 000,004,238 | —- | M] () – C:\Users\Linda\AppData\Roaming\wklnhst.dat
[2010/10/14 10:11:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/14 09:17:46 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/14 09:17:46 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/13 21:11:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/13 19:29:16 | 000,000,082 | —- | M] () – C:\Windows\MPLAYER.INI
[2010/10/13 19:17:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/13 13:41:55 | 000,002,459 | —- | M] () – C:\Users\Linda\Desktop\Re_ I really need your help!.nws
[2010/10/13 07:55:07 | 000,282,848 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/12 20:31:31 | 000,000,036 | —- | M] () – C:\Users\Linda\AppData\Local\housecall.guid.cache
[2010/10/12 18:21:52 | 000,096,748 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/10/12 18:21:52 | 000,000,000 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/10/11 15:35:48 | 008,974,298 | —- | M] () – C:\Users\Linda\Angels.and.Other.Fantastic.Creatures.Jigsaw.regged.zip
[2010/10/10 12:24:44 | 000,007,949 | —- | M] () – C:\Users\Linda\Desktop\Re_ AVG or AVAST_.nws
[2010/10/09 11:40:39 | 000,122,503 | —- | M] () – C:\Users\Linda\777147422.jpg
[2010/10/09 11:40:39 | 000,111,817 | —- | M] () – C:\Users\Linda\700787003.jpg
[2010/10/09 11:40:39 | 000,104,836 | —- | M] () – C:\Users\Linda\843694116.jpg
[2010/10/09 11:40:39 | 000,087,537 | —- | M] () – C:\Users\Linda\960859999.jpg
[2010/10/09 11:40:39 | 000,067,526 | —- | M] () – C:\Users\Linda\156774294.jpg
[2010/10/09 11:40:39 | 000,059,618 | —- | M] () – C:\Users\Linda\628775097.jpg
[2010/10/09 11:40:39 | 000,046,506 | —- | M] () – C:\Users\Linda\1148082910.jpg
[2010/10/09 11:40:39 | 000,043,486 | —- | M] () – C:\Users\Linda\experimentemitdoppelbel1.jpg
[2010/10/09 11:40:39 | 000,038,662 | —- | M] () – C:\Users\Linda\113390255.jpg
[2010/10/09 11:40:39 | 000,037,238 | —- | M] () – C:\Users\Linda\899346388.jpg
[2010/10/07 18:54:49 | 000,000,219 | —- | M] () – C:\Users\Linda\Desktop\TV Listings & Show Schedules - USATODAY.com.url
[2010/10/07 14:51:52 | 035,781,296 | —- | M] () – C:\Users\Linda\he-witching-halloween.zip
[2010/10/05 08:09:49 | 000,024,064 | —- | M] () – C:\Users\Linda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/04 09:44:14 | 000,047,106 | —- | M] () – C:\Users\Linda\6.jpg
[2010/10/04 09:43:08 | 000,030,000 | —- | M] () – C:\Users\Linda\large_TRANSPARENT_blinkingeyes.gif
[2010/10/04 09:43:08 | 000,011,035 | —- | M] () – C:\Users\Linda\ATT000~1333.GIF
[2010/09/29 11:55:53 | 000,021,076 | —- | M] () – C:\Users\Linda\Ralph's family.pdf
[2010/09/28 18:04:47 | 000,002,248 | —- | M] () – C:\Users\Linda\OT a heads up.nws
[2010/09/27 18:59:42 | 000,002,272 | —- | M] () – C:\Users\Linda\Re_ pc still runs slow.nws
[2010/09/27 18:54:22 | 000,003,487 | —- | M] () – C:\Users\Linda\Re_ wireless question.nws
[2010/09/27 10:54:06 | 000,000,249 | —- | M] () – C:\Users\Linda\America's Most Beautiful Coastal Views- Page 2 - Articles - Travel + Leisure.url
[2010/09/27 09:56:02 | 000,226,333 | —- | M] () – C:\Users\Linda\checkitout.jpg
[2010/09/27 09:46:24 | 000,002,578 | —- | M] () – C:\Users\Linda\Re_ cole slaw.nws
[2010/09/26 16:16:31 | 000,127,547 | —- | M] () – C:\Users\Linda\Re_ something you really need to know about a recent Facebook UI change regarding Friend Requests.nws
[2010/09/26 12:58:53 | 000,774,340 | —- | M] () – C:\Users\Linda\Use Your Love - (SPD) Starlight Desiggns.nws
[2010/09/26 11:29:37 | 000,005,413 | —- | M] () – C:\Users\Linda\Re_ Saturday _-) Attention, Debbie–and good night!.nws
[2010/09/25 20:25:10 | 000,000,232 | —- | M] () – C:\Users\Linda\Gettin' Down in the South Paula's Best Dishes Food Network.url
[2010/09/24 10:42:50 | 000,001,018 | —- | M] () – C:\Users\Linda\Flat Screen TV Prices1.nws
[2010/09/24 10:42:21 | 000,000,000 | —- | M] () – C:\Users\Linda\Flat Screen TV Prices.nws
[2010/09/24 10:41:12 | 000,003,839 | —- | M] () – C:\Users\Linda\Re_ Flat Screen TV Prices.nws
[2010/09/24 10:39:45 | 000,022,987 | —- | M] () – C:\Users\Linda\HumorSense.gif
[2010/09/23 19:24:15 | 000,000,201 | —- | M] () – C:\Users\Linda\SlideShows - Watch slideshow Catch the Moment.url
[2010/09/20 22:05:56 | 000,000,998 | —- | M] () – C:\Users\Linda\How's your reaction time_.nws
[2010/09/20 14:30:39 | 000,006,736 | —- | M] () – C:\Users\Linda\Re_ All this talk of custard.nws
[2010/09/18 20:31:36 | 000,089,080 | —- | M] () – C:\Users\Linda\Riding Lawn Mower.nws
[2010/09/18 20:08:18 | 000,022,326 | —- | M] () – C:\Users\Linda\Re_ Boy do I.nws
[2010/09/18 20:00:10 | 000,002,673 | —- | M] () – C:\Users\Linda\Choose the Day.nws
[2010/09/17 15:58:22 | 000,003,319 | —- | M] () – C:\Users\Linda\Re_ Watched America's Got Talent.nws
[2010/09/16 21:09:20 | 000,000,183 | —- | M] () – C:\Users\Linda\Monarc® Subfascial Hammock Procedure Videos - American Medical Systems, Inc..url
[2010/09/15 21:28:40 | 000,013,222 | —- | M] () – C:\Users\Linda\Re_ More on the Burger wars _o).nws
[2010/09/14 17:36:03 | 000,001,518 | —- | M] () – C:\Users\Linda\Re_ What is the program ____.nws
[2010/09/14 14:12:14 | 000,004,548 | —- | M] () – C:\Users\Linda\The Story of a Challenged senior___.nws
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[10 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/14 10:23:19 | 000,359,929 | —- | C] () – C:\Users\Linda\Desktop\dds.scr
[2010/10/13 13:41:52 | 000,002,459 | —- | C] () – C:\Users\Linda\Desktop\Re_ I really need your help!.nws
[2010/10/12 20:31:31 | 000,000,036 | —- | C] () – C:\Users\Linda\AppData\Local\housecall.guid.cache
[2010/10/12 13:17:46 | 001,370,112 | —- | C] () – C:\Users\Linda\RSDownloader231.msi
[2010/10/11 15:35:26 | 008,974,298 | —- | C] () – C:\Users\Linda\Angels.and.Other.Fantastic.Creatures.Jigsaw.regged.zip
[2010/10/10 12:24:42 | 000,007,949 | —- | C] () – C:\Users\Linda\Desktop\Re_ AVG or AVAST_.nws
[2010/10/09 11:40:39 | 000,122,503 | —- | C] () – C:\Users\Linda\777147422.jpg
[2010/10/09 11:40:39 | 000,111,817 | —- | C] () – C:\Users\Linda\700787003.jpg
[2010/10/09 11:40:39 | 000,104,836 | —- | C] () – C:\Users\Linda\843694116.jpg
[2010/10/09 11:40:39 | 000,087,537 | —- | C] () – C:\Users\Linda\960859999.jpg
[2010/10/09 11:40:39 | 000,067,526 | —- | C] () – C:\Users\Linda\156774294.jpg
[2010/10/09 11:40:39 | 000,059,618 | —- | C] () – C:\Users\Linda\628775097.jpg
[2010/10/09 11:40:39 | 000,046,506 | —- | C] () – C:\Users\Linda\1148082910.jpg
[2010/10/09 11:40:39 | 000,043,486 | —- | C] () – C:\Users\Linda\experimentemitdoppelbel1.jpg
[2010/10/09 11:40:39 | 000,038,662 | —- | C] () – C:\Users\Linda\113390255.jpg
[2010/10/09 11:40:39 | 000,037,238 | —- | C] () – C:\Users\Linda\899346388.jpg
[2010/10/07 18:54:49 | 000,000,219 | —- | C] () – C:\Users\Linda\Desktop\TV Listings & Show Schedules - USATODAY.com.url
[2010/10/07 14:51:52 | 035,781,296 | —- | C] () – C:\Users\Linda\he-witching-halloween.zip
[2010/10/04 09:45:31 | 000,047,106 | —- | C] () – C:\Users\Linda\6.jpg
[2010/10/04 09:43:08 | 000,030,000 | —- | C] () – C:\Users\Linda\large_TRANSPARENT_blinkingeyes.gif
[2010/10/04 09:43:08 | 000,011,035 | —- | C] () – C:\Users\Linda\ATT000~1333.GIF
[2010/09/29 11:55:53 | 000,021,076 | —- | C] () – C:\Users\Linda\Ralph's family.pdf
[2010/09/28 18:04:26 | 000,002,248 | —- | C] () – C:\Users\Linda\OT a heads up.nws
[2010/09/27 18:59:41 | 000,002,272 | —- | C] () – C:\Users\Linda\Re_ pc still runs slow.nws
[2010/09/27 18:54:20 | 000,003,487 | —- | C] () – C:\Users\Linda\Re_ wireless question.nws
[2010/09/27 10:54:06 | 000,000,249 | —- | C] () – C:\Users\Linda\America's Most Beautiful Coastal Views- Page 2 - Articles - Travel + Leisure.url
[2010/09/27 09:56:02 | 000,226,333 | —- | C] () – C:\Users\Linda\checkitout.jpg
[2010/09/27 09:46:23 | 000,002,578 | —- | C] () – C:\Users\Linda\Re_ cole slaw.nws
[2010/09/26 16:16:30 | 000,127,547 | —- | C] () – C:\Users\Linda\Re_ something you really need to know about a recent Facebook UI change regarding Friend Requests.nws
[2010/09/26 12:58:46 | 000,774,340 | —- | C] () – C:\Users\Linda\Use Your Love - (SPD) Starlight Desiggns.nws
[2010/09/26 11:29:11 | 000,005,413 | —- | C] () – C:\Users\Linda\Re_ Saturday _-) Attention, Debbie–and good night!.nws
[2010/09/25 20:25:10 | 000,000,232 | —- | C] () – C:\Users\Linda\Gettin' Down in the South Paula's Best Dishes Food Network.url
[2010/09/24 10:42:49 | 000,001,018 | —- | C] () – C:\Users\Linda\Flat Screen TV Prices1.nws
[2010/09/24 10:42:20 | 000,000,000 | —- | C] () – C:\Users\Linda\Flat Screen TV Prices.nws
[2010/09/24 10:41:10 | 000,003,839 | —- | C] () – C:\Users\Linda\Re_ Flat Screen TV Prices.nws
[2010/09/24 10:39:45 | 000,022,987 | —- | C] () – C:\Users\Linda\HumorSense.gif
[2010/09/23 19:24:15 | 000,000,201 | —- | C] () – C:\Users\Linda\SlideShows - Watch slideshow Catch the Moment.url
[2010/09/20 22:05:55 | 000,000,998 | —- | C] () – C:\Users\Linda\How's your reaction time_.nws
[2010/09/20 14:30:38 | 000,006,736 | —- | C] () – C:\Users\Linda\Re_ All this talk of custard.nws
[2010/09/18 20:31:35 | 000,089,080 | —- | C] () – C:\Users\Linda\Riding Lawn Mower.nws
[2010/09/18 20:08:17 | 000,022,326 | —- | C] () – C:\Users\Linda\Re_ Boy do I.nws
[2010/09/18 20:00:09 | 000,002,673 | —- | C] () – C:\Users\Linda\Choose the Day.nws
[2010/09/17 15:58:21 | 000,003,319 | —- | C] () – C:\Users\Linda\Re_ Watched America's Got Talent.nws
[2010/09/16 21:09:20 | 000,000,183 | —- | C] () – C:\Users\Linda\Monarc® Subfascial Hammock Procedure Videos - American Medical Systems, Inc..url
[2010/09/15 21:28:39 | 000,013,222 | —- | C] () – C:\Users\Linda\Re_ More on the Burger wars _o).nws
[2010/09/14 17:36:02 | 000,001,518 | —- | C] () – C:\Users\Linda\Re_ What is the program ____.nws
[2010/09/14 14:12:13 | 000,004,548 | —- | C] () – C:\Users\Linda\The Story of a Challenged senior___.nws
[2010/09/03 09:59:13 | 000,000,082 | —- | C] () – C:\Windows\MPLAYER.INI
[2010/08/24 09:25:01 | 000,002,843 | —- | C] () – C:\Users\Linda\AppData\Local\Osedi.dat
[2010/08/24 09:25:01 | 000,000,000 | —- | C] () – C:\Users\Linda\AppData\Local\Fcutikomeje.bin
[2010/07/29 14:35:58 | 000,044,134 | —- | C] () – C:\Users\Linda\AppData\Local\c4u.log
[2010/07/29 12:56:35 | 000,000,177 | —- | C] () – C:\Users\Linda\AppData\Local\LaunchHomeCenter.log
[2010/07/29 12:40:27 | 000,185,022 | —- | C] () – C:\Users\Linda\AppData\Local\installer.log
[2010/05/29 14:37:42 | 000,000,064 | —- | C] () – C:\Users\Linda\AppData\Roaming\MumboJumbo.ini
[2010/05/29 14:37:42 | 000,000,025 | -H– | C] () – C:\Users\Linda\AppData\Roaming\ud_soundmanager.ini
[2010/03/27 14:09:18 | 000,002,516 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2010/03/27 14:09:18 | 000,000,008 | RHS- | C] () – C:\ProgramData\E0D72957FC.sys
[2010/03/12 19:55:26 | 000,034,304 | —- | C] () – C:\Windows\System32\INETWH32.DLL
[2010/03/01 20:40:45 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2010/03/01 20:40:45 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2010/03/01 20:40:45 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2010/02/24 16:28:34 | 000,002,516 | -HS- | C] () – C:\Windows\System32\KGyGaAvL.sys
[2010/02/24 16:28:34 | 000,000,088 | RHS- | C] () – C:\Windows\System32\E0D72957FC.sys
[2010/02/23 14:09:05 | 000,210,944 | —- | C] () – C:\Windows\System32\Msvcrt10.dll
[2010/02/15 20:43:53 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/02/15 20:43:52 | 000,881,664 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/02/15 20:43:52 | 000,205,824 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/02/14 15:06:22 | 000,331,776 | —- | C] () – C:\Windows\System32\TwcToolbarIe7.dll
[2010/02/14 15:06:22 | 000,098,304 | —- | C] () – C:\Windows\System32\TwcToolbarBho.dll
[2010/02/13 18:07:28 | 000,004,238 | —- | C] () – C:\Users\Linda\AppData\Roaming\wklnhst.dat
[2010/02/13 17:25:44 | 000,000,321 | —- | C] () – C:\Windows\ulead32.ini
[2010/02/13 12:49:40 | 000,006,159 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/02/12 22:41:24 | 000,024,064 | —- | C] () – C:\Users\Linda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/12 21:51:05 | 000,000,034 | —- | C] () – C:\Users\Linda\AppData\Roaming\pcouffin.log
[2010/02/12 21:50:50 | 000,087,608 | —- | C] () – C:\Users\Linda\AppData\Roaming\inst.exe
[2010/02/12 21:50:50 | 000,007,887 | —- | C] () – C:\Users\Linda\AppData\Roaming\pcouffin.cat
[2010/02/12 21:50:50 | 000,001,144 | —- | C] () – C:\Users\Linda\AppData\Roaming\pcouffin.inf
[2010/02/12 17:42:54 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/02/11 22:55:43 | 000,074,880 | —- | C] () – C:\Windows\System32\drivers\SCFltr.sys
[2010/02/11 22:55:32 | 000,684,032 | —- | C] () – C:\Windows\System32\libeay32.dll
[2010/02/11 22:55:32 | 000,155,648 | —- | C] () – C:\Windows\System32\ssleay32.dll
[2010/02/11 22:31:19 | 000,001,356 | —- | C] () – C:\Users\Linda\AppData\Local\d3d9caps.dat
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/01/05 15:44:10 | 000,000,453 | —- | C] () – C:\Windows\bdoscandellang.ini
[2008/02/11 20:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2004/03/08 17:40:12 | 000,057,344 | —- | C] () – C:\Windows\System32\icmfilter.dll

========== LOP Check ==========

[2010/07/04 19:10:37 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\ABSOLUTIST.com
[2010/02/23 14:20:24 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Alien Skin
[2010/10/13 11:54:04 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\AVG10
[2010/09/02 09:23:11 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\FreeBurner
[2010/10/12 19:45:10 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\FTW
[2010/04/20 19:36:59 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Jasc
[2010/08/24 11:17:17 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\LimeWire
[2010/05/14 14:39:10 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Little Games Company
[2010/07/29 15:27:09 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Temp
[2010/02/13 18:07:28 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Template
[2010/04/15 16:09:56 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Uniblue
[2010/09/05 20:33:20 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Vso
[2010/02/14 15:12:21 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\WeatherPulse
[2010/03/14 17:37:10 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\Western Digital
[2010/08/24 09:23:30 | 000,000,000 | —D | M] – C:\Users\Linda\AppData\Roaming\wlkpgoawx
[2010/10/13 18:46:11 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/02/12 00:15:31 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/18 22:49:28 | 006,684,672 | —- | M] () – C:\HarddiskVolume2
[2010/06/22 08:00:40 | 000,065,536 | —- | M] () – C:\HarddiskVolume3
[2010/08/24 12:00:02 | 000,720,896 | —- | M] () – C:\HarddiskVolume7
[2010/04/08 10:35:18 | 000,720,896 | —- | M] () – C:\HarddiskVolume8
[2010/02/13 14:54:10 | 000,000,218 | —- | M] () – C:\INSTALL.LOG
[2009/10/11 12:53:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/11/09 20:54:37 | 000,001,014 | —- | M] () – C:\Live Updater_log.txt
[2009/10/04 15:51:16 | 000,000,052 | —- | M] () – C:\mem.bin
[2009/10/11 12:53:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/10/13 19:17:41 | 3523,690,496 | -HS- | M] () – C:\pagefile.sys
[2009/11/09 20:55:20 | 000,001,164 | —- | M] () – C:\Player Loader_log.txt
[10 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/02/12 18:01:43 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/09/02 15:17:50 | 000,196,608 | —- | M] (Eastman Kodak Company) – C:\Windows\System32\spool\prtprocs\w32x86\EKIJ5000PPR.dll
[2008/01/20 21:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2007/07/04 18:21:36 | 000,641,024 | —- | M] () – C:\Windows\System32\NEROINSTAEC43759.DB
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/03/02 17:51:56 | 000,000,444 | -HS- | M] () – C:\Users\Linda\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/10/14 10:24:27 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Users\Linda\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-13 09:45:21

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 995 bytes -> C:\Users\Linda\[PsP-P-N-P] Tumble Jumble _.eml:OECustomProperty
@Alternate Data Stream - 995 bytes -> C:\Users\Linda\[PsP-P-N-P] 101 Kitty Pets.eml:OECustomProperty
@Alternate Data Stream - 971 bytes -> C:\Users\Linda\SSD - Don't make me come back there by Libby Weifenbach.nws:OECustomProperty
@Alternate Data Stream - 951 bytes -> C:\Users\Linda\Re_ Rapidshare premium account free___ - not so free after all_.nws:OECustomProperty
@Alternate Data Stream - 889 bytes -> C:\Users\Linda\Documents\Your Kodak Registration Confirmation.eml:OECustomProperty
@Alternate Data Stream - 871 bytes -> C:\Users\Linda\Re_ Saturday _-) Attention, Debbie–and good night!.nws:OECustomProperty
@Alternate Data Stream - 861 bytes -> C:\Users\Linda\Benjamin See and Anna Powell children.eml:OECustomProperty
@Alternate Data Stream - 854 bytes -> C:\Users\Linda\TONE Z-Long Hard Times To Come(Official Justified Theme Song).eml:OECustomProperty
@Alternate Data Stream - 851 bytes -> C:\Users\Linda\Clipart Pal PD and Free Cartoons - Cartoon Clipart World.nws:OECustomProperty
@Alternate Data Stream - 839 bytes -> C:\Users\Linda\1912 edition of the Boy Scout Handbook online.nws:OECustomProperty
@Alternate Data Stream - 829 bytes -> C:\Users\Linda\Fwd_ Welcome to the Annex Cafe!.eml:OECustomProperty
@Alternate Data Stream - 819 bytes -> C:\Users\Linda\What was going on when you were born_.nws:OECustomProperty
@Alternate Data Stream - 811 bytes -> C:\Users\Linda\Re_ Some New Geico Commercials _o).nws:OECustomProperty
@Alternate Data Stream - 811 bytes -> C:\Users\Linda\Drug for annoyingly cheerful people.nws:OECustomProperty
@Alternate Data Stream - 803 bytes -> C:\Users\Linda\HP notebook batteries (expanded).nws:OECustomProperty
@Alternate Data Stream - 799 bytes -> C:\Users\Linda\Use Your Love - (SPD) Starlight Desiggns.nws:OECustomProperty
@Alternate Data Stream - 799 bytes -> C:\Users\Linda\Re_ Watched America's Got Talent.nws:OECustomProperty
@Alternate Data Stream - 799 bytes -> C:\Users\Linda\Re_ Google search engine - new look_.nws:OECustomProperty
@Alternate Data Stream - 799 bytes -> C:\Users\Linda\Great On Line BP Chart.nws:OECustomProperty
@Alternate Data Stream - 799 bytes -> C:\Users\Linda\Best Ever Advertising Jingles _o).nws:OECustomProperty
@Alternate Data Stream - 789 bytes -> C:\Users\Linda\Welcome to RapidShare.eml:OECustomProperty
@Alternate Data Stream - 787 bytes -> C:\Users\Linda\Some New Geico Commercials _o).nws:OECustomProperty
@Alternate Data Stream - 779 bytes -> C:\Users\Linda\Ziggle In the Wild KIT.nws:OECustomProperty
@Alternate Data Stream - 779 bytes -> C:\Users\Linda\The Story of a Challenged senior___.nws:OECustomProperty
@Alternate Data Stream - 779 bytes -> C:\Users\Linda\Public Domain Clipart-See List of Categories.nws:OECustomProperty
@Alternate Data Stream - 775 bytes -> C:\Users\Linda\Re_ What is the program ____.nws:OECustomProperty
@Alternate Data Stream - 775 bytes -> C:\Users\Linda\America's Most Livable Cities.nws:OECustomProperty
@Alternate Data Stream - 771 bytes -> C:\Users\Linda\Re_ All this talk of custard.nws:OECustomProperty
@Alternate Data Stream - 767 bytes -> C:\Users\Linda\Re_ AV Bros Page Curl.nws:OECustomProperty
@Alternate Data Stream - 763 bytes -> C:\Users\Linda\Things I Learned in the South.nws:OECustomProperty
@Alternate Data Stream - 763 bytes -> C:\Users\Linda\Security Updates From Adobe.nws:OECustomProperty
@Alternate Data Stream - 759 bytes -> C:\Users\Linda\atten G-Ma Lyn and Barb Murphy.nws:OECustomProperty
@Alternate Data Stream - 753 bytes -> C:\Users\Linda\Question for you!.eml:OECustomProperty
@Alternate Data Stream - 751 bytes -> C:\Users\Linda\How's your reaction time_.nws:OECustomProperty
@Alternate Data Stream - 747 bytes -> C:\Users\Linda\Re_ Unknown Login Request_Virus2.nws:OECustomProperty
@Alternate Data Stream - 747 bytes -> C:\Users\Linda\Re_ Unknown Login Request_Virus.nws:OECustomProperty
@Alternate Data Stream - 747 bytes -> C:\Users\Linda\Re_ More on the Burger wars _o).nws:OECustomProperty
@Alternate Data Stream - 747 bytes -> C:\Users\Linda\Re_ 100% CPU usage.nws:OECustomProperty
@Alternate Data Stream - 741 bytes -> C:\Users\Linda\FW_ Polish Divorce.eml:OECustomProperty
@Alternate Data Stream - 739 bytes -> C:\Users\Linda\Re_ Thank you! Re_ Sharon_ Someone_.nws:OECustomProperty
@Alternate Data Stream - 739 bytes -> C:\Users\Linda\Eve's Side of the Story.nws:OECustomProperty
@Alternate Data Stream - 735 bytes -> C:\Users\Linda\Re_ having problems.nws:OECustomProperty
@Alternate Data Stream - 735 bytes -> C:\Users\Linda\Fantasy Moments Sandstorm Scrap Kit.nws:OECustomProperty
@Alternate Data Stream - 735 bytes -> C:\Users\Linda\Desktop\Re_ I really need your help!.nws:OECustomProperty
@Alternate Data Stream - 727 bytes -> C:\Users\Linda\Re_ just so you know.nws:OECustomProperty
@Alternate Data Stream - 727 bytes -> C:\Users\Linda\Flat Screen TV Prices1.nws:OECustomProperty
@Alternate Data Stream - 727 bytes -> C:\Users\Linda\Dumbest Criminals _o).nws:OECustomProperty
@Alternate Data Stream - 723 bytes -> C:\Users\Linda\Re_ Am I Doing this Right_.nws:OECustomProperty
@Alternate Data Stream - 719 bytes -> C:\Users\Linda\7-Up Pot Roast, Crock Pot Style.nws:OECustomProperty
@Alternate Data Stream - 715 bytes -> C:\Users\Linda\Tools Explained _o).nws:OECustomProperty
@Alternate Data Stream - 715 bytes -> C:\Users\Linda\Riding Lawn Mower.nws:OECustomProperty
@Alternate Data Stream - 715 bytes -> C:\Users\Linda\Redneck Retirement.nws:OECustomProperty
@Alternate Data Stream - 715 bytes -> C:\Users\Linda\Re_ pc still runs slow.nws:OECustomProperty
@Alternate Data Stream - 715 bytes -> C:\Users\Linda\All the guys need this.nws:OECustomProperty
@Alternate Data Stream - 711 bytes -> C:\Users\Linda\Re_ What's for supper_.nws:OECustomProperty
@Alternate Data Stream - 711 bytes -> C:\Users\Linda\Re_ ARG!!!!!!!.nws:OECustomProperty
@Alternate Data Stream - 711 bytes -> C:\Users\Linda\Faith gold and colored frame.nws:OECustomProperty
@Alternate Data Stream - 707 bytes -> C:\Users\Linda\Re_ Adobe Flash Player Add-Ons.nws:OECustomProperty
@Alternate Data Stream - 707 bytes -> C:\Users\Linda\Drafting Guys Over 60.nws:OECustomProperty
@Alternate Data Stream - 707 bytes -> C:\Users\Linda\_Bacon-Flavored Dog Biscuits_.nws:OECustomProperty
@Alternate Data Stream - 703 bytes -> C:\Users\Linda\got ribs in the oven.nws:OECustomProperty
@Alternate Data Stream - 699 bytes -> C:\Users\Linda\Re_ weird Thunderbird.nws:OECustomProperty
@Alternate Data Stream - 699 bytes -> C:\Users\Linda\Re_ great place to get fonts.nws:OECustomProperty
@Alternate Data Stream - 695 bytes -> C:\Users\Linda\Re_ Does anyone have__.nws:OECustomProperty
@Alternate Data Stream - 695 bytes -> C:\Users\Linda\Re_ BP News flash___.nws:OECustomProperty
@Alternate Data Stream - 695 bytes -> C:\Users\Linda\Egg recall - safe list.nws:OECustomProperty
@Alternate Data Stream - 695 bytes -> C:\Users\Linda\Crock Pot Zucchini Italiano.nws:OECustomProperty
@Alternate Data Stream - 691 bytes -> C:\Users\Linda\Re_ Zucchini Bread.nws:OECustomProperty
@Alternate Data Stream - 691 bytes -> C:\Users\Linda\Re_ ___David___.nws:OECustomProperty
@Alternate Data Stream - 691 bytes -> C:\Users\Linda\Choose the Day.nws:OECustomProperty
@Alternate Data Stream - 687 bytes -> C:\Users\Linda\Re_ wireless question.nws:OECustomProperty
@Alternate Data Stream - 687 bytes -> C:\Users\Linda\Re_ Java for Windows2.nws:OECustomProperty
@Alternate Data Stream - 687 bytes -> C:\Users\Linda\Judas Asparagus.nws:OECustomProperty
@Alternate Data Stream - 686 bytes -> C:\Users\Linda\Elvis Presley - Rare Elvis Duets.eml:OECustomProperty
@Alternate Data Stream - 683 bytes -> C:\Users\Linda\Re_ online conversion table.nws:OECustomProperty
@Alternate Data Stream - 683 bytes -> C:\Users\Linda\Link for family info.nws:OECustomProperty
@Alternate Data Stream - 683 bytes -> C:\Users\Linda\Better Than Sex Oreo Pie.nws:OECustomProperty
@Alternate Data Stream - 683 bytes -> C:\Users\Linda\Bacon-Cheese Pull-Aparts.nws:OECustomProperty
@Alternate Data Stream - 679 bytes -> C:\Users\Linda\Re_ Spinach quiche.nws:OECustomProperty
@Alternate Data Stream - 679 bytes -> C:\Users\Linda\OT a baby hummingbird!.nws:OECustomProperty
@Alternate Data Stream - 679 bytes -> C:\Users\Linda\heard this one_.nws:OECustomProperty
@Alternate Data Stream - 675 bytes -> C:\Users\Linda\Re_ Stew anyone_.nws:OECustomProperty
@Alternate Data Stream - 675 bytes -> C:\Users\Linda\Re_ email address owner.nws:OECustomProperty
@Alternate Data Stream - 675 bytes -> C:\Users\Linda\Chocolate Love Scrap Kit.nws:OECustomProperty
@Alternate Data Stream - 674 bytes -> C:\Users\Linda\Any DVD Cloner Platinum v1_0_5.eml:OECustomProperty
@Alternate Data Stream - 672 bytes -> C:\Users\Linda\BounceOutBlitz.eml:OECustomProperty
@Alternate Data Stream - 671 bytes -> C:\Users\Linda\Re_ Flat Screen TV Prices.nws:OECustomProperty
@Alternate Data Stream - 671 bytes -> C:\Users\Linda\Homemade Glass Cleaner.nws:OECustomProperty
@Alternate Data Stream - 671 bytes -> C:\Users\Linda\Ground Beef Stroganoff.nws:OECustomProperty
@Alternate Data Stream - 671 bytes -> C:\Users\Linda\Free-to-use Vector Graphics.nws:OECustomProperty
@Alternate Data Stream - 671 bytes -> C:\Users\Linda\APPLE PIE CAKE RECIPE.nws:OECustomProperty
@Alternate Data Stream - 668 bytes -> C:\Users\Linda\Re_ FRIEND TEST.eml:OECustomProperty
@Alternate Data Stream - 667 bytes -> C:\Users\Linda\Mini Monet.nws:OECustomProperty
@Alternate Data Stream - 667 bytes -> C:\Users\Linda\Custard recipe.nws:OECustomProperty
@Alternate Data Stream - 663 bytes -> C:\Users\Linda\Rhubarb Cream Cake.nws:OECustomProperty
@Alternate Data Stream - 663 bytes -> C:\Users\Linda\Desktop\Re_ AVG or AVAST_.nws:OECustomProperty
@Alternate Data Stream - 663 bytes -> C:\Users\Linda\7_26~ Good Morning!.nws:OECustomProperty
@Alternate Data Stream - 659 bytes -> C:\Users\Linda\Skillet Chicken Divan.nws:OECustomProperty
@Alternate Data Stream - 659 bytes -> C:\Users\Linda\Re_ pancakes_.nws:OECustomProperty
@Alternate Data Stream - 659 bytes -> C:\Users\Linda\Re_ Caught up.nws:OECustomProperty
@Alternate Data Stream - 659 bytes -> C:\Users\Linda\Re_ 02 Oregon.nws:OECustomProperty
@Alternate Data Stream - 659 bytes -> C:\Users\Linda\Greek Salad Dressing.nws:OECustomProperty
@Alternate Data Stream - 659 bytes -> C:\Users\Linda\Ambrosia Fruit Salad.nws:OECustomProperty
@Alternate Data Stream - 655 bytes -> C:\Users\Linda\Anyone _.nws:OECustomProperty
@Alternate Data Stream - 655 bytes -> C:\Users\Linda\5 new movies _).nws:OECustomProperty
@Alternate Data Stream - 651 bytes -> C:\Users\Linda\Re_ Pulled Pork.nws:OECustomProperty
@Alternate Data Stream - 651 bytes -> C:\Users\Linda\Programs for PSP.nws:OECustomProperty
@Alternate Data Stream - 647 bytes -> C:\Users\Linda\Re_ Security Updates.nws:OECustomProperty
@Alternate Data Stream - 647 bytes -> C:\Users\Linda\Re_ Java for Windows.nws:OECustomProperty
@Alternate Data Stream - 647 bytes -> C:\Users\Linda\Cinnamon Roll Cake.nws:OECustomProperty
@Alternate Data Stream - 643 bytes -> C:\Users\Linda\Re_ Pie.nws:OECustomProperty
@Alternate Data Stream - 643 bytes -> C:\Users\Linda\Re_ meatloaf.nws:OECustomProperty
@Alternate Data Stream - 643 bytes -> C:\Users\Linda\Happy F D.nws:OECustomProperty
@Alternate Data Stream - 643 bytes -> C:\Users\Linda\Finally.nws:OECustomProperty
@Alternate Data Stream - 639 bytes -> C:\Users\Linda\Re_ Crash2.nws:OECustomProperty
@Alternate Data Stream - 639 bytes -> C:\Users\Linda\Re_ Crash.nws:OECustomProperty
@Alternate Data Stream - 635 bytes -> C:\Users\Linda\Re_ Roomba.nws:OECustomProperty
@Alternate Data Stream - 631 bytes -> C:\Users\Linda\Test.nws:OECustomProperty
@Alternate Data Stream - 631 bytes -> C:\Users\Linda\Re_ EEK!.nws:OECustomProperty
@Alternate Data Stream - 631 bytes -> C:\Users\Linda\Re_ Americo - Various.nws:OECustomProperty
@Alternate Data Stream - 627 bytes -> C:\Users\Linda\Re_ Rapidshare_.nws:OECustomProperty
@Alternate Data Stream - 623 bytes -> C:\Users\Linda\Sign In Florida.nws:OECustomProperty
@Alternate Data Stream - 623 bytes -> C:\Users\Linda\Re_ Boy do I.nws:OECustomProperty
@Alternate Data Stream - 623 bytes -> C:\Users\Linda\Geek Mom.nws:OECustomProperty
@Alternate Data Stream - 623 bytes -> C:\Users\Linda\Free Fonts Archive.nws:OECustomProperty
@Alternate Data Stream - 619 bytes -> C:\Users\Linda\Re_ maybe.nws:OECustomProperty
@Alternate Data Stream - 615 bytes -> C:\Users\Linda\Re_ maybe2.nws:OECustomProperty
@Alternate Data Stream - 615 bytes -> C:\Users\Linda\ice tea.nws:OECustomProperty
@Alternate Data Stream - 599 bytes -> C:\Users\Linda\Re_ cole slaw.nws:OECustomProperty
@Alternate Data Stream - 599 bytes -> C:\Users\Linda\More PublicDomain Sites.nws:OECustomProperty
@Alternate Data Stream - 579 bytes -> C:\Users\Linda\Re_ Attn Liz.nws:OECustomProperty
@Alternate Data Stream - 579 bytes -> C:\Users\Linda\OT a heads up.nws:OECustomProperty
@Alternate Data Stream - 578 bytes -> C:\Users\Linda\1_2 boy 1_2 man.eml:OECustomProperty
@Alternate Data Stream - 554 bytes -> C:\Users\Linda\quarantine.eml:OECustomProperty
@Alternate Data Stream - 494 bytes -> C:\Users\Linda\my do not call list.eml:OECustomProperty
@Alternate Data Stream - 1617 bytes -> C:\Users\Linda\FW_ Cartoons for twisted people___ some old and some new.eml:OECustomProperty
@Alternate Data Stream - 143 bytes -> C:\Users\Linda\Flat Screen TV Prices.nws:OECustomProperty
@Alternate Data Stream - 1343 bytes -> C:\Users\Linda\[LurkersCove] [Music] VA - Country Radio Promo Only September 2010 [HF].eml:OECustomProperty
@Alternate Data Stream - 1159 bytes -> C:\Users\Linda\Re_ something you really need to know about a recent Facebook UI change regarding Friend Requests.nws:OECustomProperty
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:6FE17A89
@Alternate Data Stream - 1055 bytes -> C:\Users\Linda\[PsP-P-N-P] Old Folks Health Care.eml:OECustomProperty
@Alternate Data Stream - 1015 bytes -> C:\Users\Linda\Re_ PC advice Share Files and Printers between Windows 7 and XP_doc [1_5].eml:OECustomProperty
@Alternate Data Stream - 1007 bytes -> C:\Users\Linda\Gmail's 'Undo Send' Lets You Recall E-mail Up to 30 Seconds After Sending.nws:OECustomProperty
@Alternate Data Stream - 1007 bytes -> C:\Users\Linda\[PsP-P-N-P] Jumpin Jack v1_01.eml:OECustomProperty

< End of report >
The Extras Text:
OTL Extras logfile created on: 10/14/2010 10:28:21 AM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Users\Linda\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.13 Gb Total Space | 508.76 Gb Free Space | 85.34% Space Free | Partition Type: NTFS
Drive I: | 614.91 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive K: | 930.86 Gb Total Space | 847.57 Gb Free Space | 91.05% Space Free | Partition Type: NTFS

Computer Name: LINDA-PC | User Name: Linda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [RapidShareManagerMail] – C:\Program Files\RapidShareManager\RapidShareManager.exe -mailto "%1" (RapidShare AG)
Directory [RapidShareManagerUpload] – C:\Program Files\RapidShareManager\RapidShareManager.exe -sendto "%1" (RapidShare AG)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiSpyWareDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-705215455-2888499284-29337537-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-705215455-2888499284-29337537-500]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-705215455-2888499284-29337537-501]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02742EEF-F2F3-4B40-8FE0-241B9A988A30}" = rport=139 | protocol=6 | dir=out | app=system |
"{2633D0DB-2DCF-427F-9120-8F72280674A6}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{59048217-CDBB-4846-8503-B1A5812618E4}" = lport=137 | protocol=17 | dir=in | app=system |
"{733C3E0A-64C8-45BE-8BAD-68B3E384F4B1}" = rport=137 | protocol=17 | dir=out | app=system |
"{88B23C23-A7FE-44BB-BA2E-607C8780C723}" = lport=138 | protocol=17 | dir=in | app=system |
"{923E1464-7A6B-490E-B365-C4EB8054853C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{A3286171-BAFA-456A-98FB-73A0927ED267}" = lport=445 | protocol=6 | dir=in | app=system |
"{ABC4CD20-A36F-46C7-BA99-259F2D456961}" = rport=138 | protocol=17 | dir=out | app=system |
"{DC2EFBC9-667B-4302-9DF3-20C35176F714}" = lport=139 | protocol=6 | dir=in | app=system |
"{DCFD4A51-F244-476F-90C6-C40AF8A39C6F}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{FB746BE3-FBF1-4CB8-8244-3ECE2D8926E3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FD7D5B69-706D-43DB-B409-62AE715FDB34}" = rport=445 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E591932-02D2-4438-BB6B-5A1F362BB61B}" = protocol=17 | dir=in | app=c:\program files\secureit\tools\cleverassist\scremote.exe |
"{27ECB1C2-1EEA-4116-B35D-D6558646B5F9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{31B34697-1F5E-4075-91A2-1F4DE93974D0}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{31FA780E-99CE-4767-9031-B0F85CDDC115}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6182076C-EDA5-4DAA-97DE-9DDFF24CD7D5}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{620E12DA-F050-4DFC-9F82-1D6FC8DDFF05}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{646D00E7-CE42-47EB-BAC1-BD8739A42AB5}" = protocol=6 | dir=in | app=c:\program files\secureit\tools\cleverassist\scremote.exe |
"{7023F1E5-467C-4E20-A298-81819DD6E6C9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{70F1EF26-10EE-4E3D-A9B1-686C11C5021E}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{A504A87E-F667-431A-BA49-CB9B719294A3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{E88D099D-478A-4055-90AE-60739AE5B4ED}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{F6581346-7030-4470-8655-8B6C47EECB42}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6}" = WD SmartWare
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BF3EAC6-8764-4FBC-99FD-E2826B9C2FCD}" = Gutterball 3D
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64E72FB1-2343-4977-B4A8-262CD53D0BD3}" = Corel Paint Shop Pro Photo X2
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections 12.1.11.0
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89EAD745-088B-4160-B964-42C4D4D273AD}" = Family Tree Maker 2010
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B136E4A4-7660-4F15-9752-EF8E6BA7866D}" = Family Tree Maker 2005
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.2.3.258
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 ESD
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center
"{E258A840-7E9A-443A-B156-67102C48BF17}" = TPP Storage Driver Installation
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}" = Microsoft WSE 3.0
"{EE295D30-A10C-44F6-B14C-05E0D99429E4}" = FTMVistaUpdater
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9
"{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_HSF" = Conexant D850 PCI V.92 Modem
"Diamond Mine 1.34" = Diamond Mine 1.34
"DreamSuite" = Uninstall DreamSuite
"DreamSuite Bonus" = Uninstall DreamSuite Bonus
"dsbF1V1" = the flux collection
"EdgeWizardV2.0" = EdgeWizard
"EyeCandy5Impact" = Alien Skin Eye Candy 5 Impact
"Family Tree Maker 2010" = Family Tree Maker 2010
"Fast AVI MPEG Joiner_is1" = Fast AVI MPEG Joiner 1.0.2
"Filters Unlimited_is1" = Filters Unlimited 2.0
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.1.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mystical" = Uninstall Mystical
"PROSetDX" = Intel® PRO Network Connections 12.1.11.0
"RapidShare Manager" = RapidShare Manager
"RealArcade - AstroPop Deluxe v1.0" = RealArcade - AstroPop Deluxe v1.0
"SANYO Digital Camera Driver" = SANYO Digital Camera Driver
"SecureIT_is1" = SecureIT
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"The Weather Channel Toolbar" = The Weather Channel Toolbar
"Window Washer" = Window Washer
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/13/2010 4:52:18 PM | Computer Name = Linda-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/13/2010 7:26:36 PM | Computer Name = Linda-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/13/2010 7:48:55 PM | Computer Name = Linda-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/13/2010 7:50:43 PM | Computer Name = Linda-PC | Source = MsiInstaller | ID = 11308
Description =

Error - 10/13/2010 8:04:48 PM | Computer Name = Linda-PC | Source = ESENT | ID = 484
Description = WinMail (2112) WindowsMail0: An attempt to remove the folder "C:\Users\Linda\AppData\Local\Microsoft\Windows
Mail\Backup\old" failed with system error 145 (0x00000091): "The directory is not
empty. ". The remove folder operation will fail with error -1022 (0xfffffc02).

Error - 10/13/2010 8:04:48 PM | Computer Name = Linda-PC | Source = ESENT | ID = 215
Description = WinMail (2112) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 10/13/2010 8:19:32 PM | Computer Name = Linda-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/13/2010 8:31:58 PM | Computer Name = Linda-PC | Source = ESENT | ID = 484
Description = WinMail (2896) WindowsMail0: An attempt to remove the folder "C:\Users\Linda\AppData\Local\Microsoft\Windows
Mail\Backup\old" failed with system error 145 (0x00000091): "The directory is not
empty. ". The remove folder operation will fail with error -1022 (0xfffffc02).

Error - 10/13/2010 8:31:58 PM | Computer Name = Linda-PC | Source = ESENT | ID = 215
Description = WinMail (2896) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 10/13/2010 9:55:35 PM | Computer Name = Linda-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ System Events ]
Error - 5/15/2010 4:45:15 PM | Computer Name = Linda-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk5\DR5, has a bad block.

Error - 5/15/2010 4:45:16 PM | Computer Name = Linda-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk5\DR5, has a bad block.

Error - 5/15/2010 4:45:17 PM | Computer Name = Linda-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk5\DR5, has a bad block.

Error - 5/15/2010 4:45:18 PM | Computer Name = Linda-PC | Source = disk | ID = 262151
Description = The device, \Device\Harddisk5\DR5, has a bad block.

Error - 5/29/2010 4:24:53 PM | Computer Name = Linda-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/29/2010 4:25:00 PM | Computer Name = Linda-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 5/29/2010 4:25:06 PM | Computer Name = Linda-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 6/8/2010 10:28:08 PM | Computer Name = Linda-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/11/2010 12:11:43 PM | Computer Name = Linda-PC | Source = DCOM | ID = 10016
Description =

Error - 6/12/2010 11:43:31 AM | Computer Name = Linda-PC | Source = Service Control Manager | ID = 7009
Description =


< End of report >
What do I do next? Thank you for any help.
Thank you so very much. I did a clean install on this machine, and everything is going well at this time. I hope if I have problems in the future, you will allow me to send a hijack this report.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI