This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need Help Removing Hijacker, Please

94 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Calicocat Your online McAfee AV log is clean Your HJT log is clean Specifically what is the computer doing at this time, errors, speed, general behavior?
Another thing that would help now is to put the OS CD in the drive and with all other windows closed use:

Start>Run and in the box type sfc /scannow
Let it run and complete the replacement of any system files that have changed or are missing.
The computer is still very slow - slower than it was before all of this started. I still get the '16 bit DOS subsystem' error message when I try to install any new programme. I have also lost the connection to the printer. This is the HP3100 All-In-One with which we have a driver problem all the time. The computer recognizes the printer at startup but then 'disappears' from the task tray after some error messages. I'll put in the O/S CD and see what happens and do the sfc /scannow and see if things improve.
I have run the sfc /scannow with the O/S system disk. No error messages, though it took about an hour. I had uninstalled Jetsuite (which is predominantly a fax/scanner function interface) and was trying to reinstall. After I put the CD in the drive I received the following error message: 16 bit Windows subsystem C:\winnt\system32\autoexec.nt. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Chose 'close' to terminate the application.'
Here are the results of my most recent scan with AdAware SE (scanning for ADS) Lavasoft Ad-Aware Plus Build 1.02 Logfile created on:Tuesday, September 28, 2004 8:32:48 PM Using definitions file:SE1R10 28.09.2004 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» CoolWebSearch(TAC index:10):21 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Reffile status: ========================= Definitions File Loaded: Reference Number : SE1R9 23.09.2004 Internal build : 14 File location : C:\Program Files\Lavasoft\Ad-Aware SE Plus\defs.ref File size : 350370 Bytes Total size : 1116399 Bytes Signature data size : 1092723 Bytes Reference data size : 23164 Bytes Signatures total : 30821 Fingerprints total : 187 Fingerprints size : 8340 Bytes Target categories : 15 Target families : 566 (Requires Ad-Aware SE or higher) 9-28-2004 8:30:27 PM WebUpdate Installing Update… Definitions File Loaded: Reference Number : SE1R10 28.09.2004 Internal build : 15 File location : C:\Program Files\Lavasoft\Ad-Aware SE Plus\defs.ref File size : 352256 Bytes Total size : 1115088 Bytes Signature data size : 1091215 Bytes Reference data size : 23361 Bytes Signatures total : 30729 Fingerprints total : 203 Fingerprints size : 9194 Bytes Target categories : 15 Target families : 573 (Requires Ad-Aware SE or higher) 9-28-2004 8:31:03 PM Success Update successfully downloaded and installed. Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium Memory available:26 % Total physical memory:253432 kb Available physical memory:63832 kb Total page file size:621488 kb Available on page file:479188 kb Total virtual memory:2097024 kb Available virtual memory:2045996 kb OS:Microsoft Windows XP Professional Service Pack 1 (Build 2600) Ad-Aware Settings =========================== Set : Move deleted files to Recycle Bin Set : Safe mode (always request confirmation) Set : Don't log streams smaller than 0 Bytes Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware Settings =========================== Set : Unload recognized processes & modules during scan Set : Ignore spanned files when scanning cab archives Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Automatically select problematic objects in results lists Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Backup current definitions file before updating Set : Play sound at scan completion if scan locates critical objects 9-28-2004 8:32:48 PM - Scan started. (ADS scan) Performing deep Scan and listing Alternate Data Streams… Setting back browser settings… ca_inoculateit Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» C: Drive supports Alternate Data Streams. Scanning and Enumerating ADS… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : ajcro Category : Malware Comment : Object : C:\WINNT\MedCtrOC.log:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : tjvwi Category : Malware Comment : Object : C:\WINNT\MF_C421.lfa:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : lkgkk Category : Malware Comment : Object : C:\WINNT\MozillaUninstall.exe:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : wmruh Category : Malware Comment : Object : C:\WINNT\MSOPrefs.232:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : ufvsu Category : Malware Comment : Object : C:\WINNT\PCS6.LIC:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : vkwmo Category : Malware Comment : Object : C:\WINNT\PCSPATS.DAT:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : olgzq Category : Malware Comment : Object : C:\WINNT\Prairie Wind.bmp:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : gmzel Category : Malware Comment : Object : C:\WINNT\QTFont.for:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : fsgtw Category : Malware Comment : Object : C:\WINNT\QTW.INI:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : rmskn Category : Malware Comment : Object : C:\WINNT\QTW.INI:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : qmrms Category : Malware Comment : Object : C:\WINNT\RESULT.QTW:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : woskb Category : Malware Comment : Object : C:\WINNT\setupact.log:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : uajmb Category : Malware Comment : Object : C:\WINNT\SYSINI.QTW:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : mturv Category : Malware Comment : Object : C:\WINNT\tl32v20.dll:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : tlfgu Category : Malware Comment : Object : C:\WINNT\tsoc.log:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : eumxx Category : Malware Comment : Object : C:\WINNT\twain.dll:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : lmxmw Category : Malware Comment : Object : C:\WINNT\twunk_16.exe:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : wnaek Category : Malware Comment : Object : C:\WINNT\uninstall-temp.exe:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : pgwkc Category : Malware Comment : Object : C:\WINNT\Webshots.scr:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : hhhpe Category : Malware Comment : Object : C:\WINNT\wiadebug.log:\ CoolWebSearch Object Recognized! Type : Alternate Data Stream Data : aizcy Category : Malware Comment : Object : C:\WINNT\win.002:\ C: Enumerating detected ADS… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\33479_wallpaper110.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:5220 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\33479_wallpaper110.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\angel-of-the-morn-ll.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:7288 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\angel-of-the-morn-ll.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\animated sig1.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:3076 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\animated sig1.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\animated sig2.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4608 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\animated sig2.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\applebutter_makers.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:11068 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\applebutter_makers.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Arctic_fox.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:3452 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Arctic_fox.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Barn_owl.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4368 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Barn_owl.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\bellywarmers.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8340 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\bellywarmers.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Capecod_christmas.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:11904 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Capecod_christmas.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\capecod_coldfishparty.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8100 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\capecod_coldfishparty.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\carnival_capers1.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8552 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\carnival_capers1.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\carver_coggins.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8252 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\carver_coggins.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\christmaseve.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:10784 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\christmaseve.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\clammers-at-hodges-horn.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8256 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\clammers-at-hodges-horn.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\cotton_country.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:9656 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\cotton_country.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\country_race.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8520 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\country_race.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\daddys_coming_home.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4900 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\daddys_coming_home.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\dahlia_dinalhaven_makesa_do.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8712 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\dahlia_dinalhaven_makesa_do.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\devilstoneharbor.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:9080 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\devilstoneharbor.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\dreamers.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6840 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\dreamers.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\elmr.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:12180 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\elmr.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\ethel_the_gourmet.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:9376 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\ethel_the_gourmet.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\fairhavenbythesea.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:5464 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\fairhavenbythesea.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\feathered_critics.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4100 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\feathered_critics.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\foxrun.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:11652 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\foxrun.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\foxyfox_outfoxes_foxHunters.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8300 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\foxyfox_outfoxes_foxHunters.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\fredrick_the_literate.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8712 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\fredrick_the_literate.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\fun_lovin_silly_folks_1.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6204 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\fun_lovin_silly_folks_1.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\GenPuck.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:1676 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\GenPuck.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\goalie - dumb.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8588 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\goalie - dumb.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\handscoloured2a.bmp:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8760 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\handscoloured2a.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\hickory_haven_canal.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:10408 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\hickory_haven_canal.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\home_is_my_sailor.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:9276 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\home_is_my_sailor.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Iceridersonchesapeakebay.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6432 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Iceridersonchesapeakebay.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\jingle_bell_teddy_and_friends.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:12040 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\jingle_bell_teddy_and_friends.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\jollyhillfarms.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:10116 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\jollyhillfarms.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\laborday.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6768 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\laborday.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\LL-53.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:7244 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\LL-53.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\logo-gens.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:3976 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\logo-gens.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\love.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:7216 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\love.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\McAshphaltlogo.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:5824 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\McAshphaltlogo.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Monarch.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4520 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Monarch.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\New_Orleans.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4948 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\New_Orleans.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\player - dumb.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6592 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\player - dumb.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Sample.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4592 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Sample.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\twas_twilight_b4_christmas_.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:13052 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\twas_twilight_b4_christmas_.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\underconstruction1.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4540 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\underconstruction1.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\warm_christmas_love.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:11612 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\warm_christmas_love.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\ws_xmas-1991.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:9616 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\My Pictures\ws_xmas-1991.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\OMH Site\images\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Administrator.GATEWAY\My Documents\OMH Site\omh-history_files\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\All Users.WINNT\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGens graphics\Christmas\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGens graphics\Halloween\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGens graphics\orbiter\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGens graphics\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGensPics Unformatted\02-10-16 Cobourg formatted\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGensPics Unformatted\02-10-28 Whitby formatted\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGensPics Unformatted\02-11-06 Peterborough formatted\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGensPics Unformatted\02-11-09 Team Meeting formatted\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\MinGensPics Unformatted\03-30-03 Avalanche\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Derry's Hockey\Website\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\Local Settings\Application Data\Microsoft\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\My Documents\Documents\Centennial College\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\My Documents\Documents\Community College Article for Web Site_files\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\124-640x480.bmp:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:10104 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\124-640x480.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\139am.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8804 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\139am.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\3dflagsdotcom_canad2wm.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:3080 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\3dflagsdotcom_canad2wm.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\3dflagsdotcom_usa2wm.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:3988 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\3dflagsdotcom_usa2wm.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\89am.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:10084 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\89am.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132429.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4772 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132429.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132430.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:5076 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132430.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132431.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4692 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132431.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132432.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:5220 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\ATT132432.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Dogfight.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6712 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Dogfight.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Gesundheit.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:5204 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Gesundheit.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Goose.bmp:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:1808 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Goose.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\How_Do_They_Answer_Their_Phone_.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6128 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\How_Do_They_Answer_Their_Phone_.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Jobrating.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:7868 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Jobrating.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\MVC-014F.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6812 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\MVC-014F.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\MVC-015F.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:7628 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\MVC-015F.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\MVC-016F.JPG:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:2428 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\MVC-016F.JPG:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\new2.bmp:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:1232 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\new2.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Okay1… We apologize!.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:5992 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Okay1… We apologize!.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Pumpkin.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:10176 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Pumpkin.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Rooster.bmp:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6440 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Rooster.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Sample.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:4592 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Sample.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\supplychain.gif:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6116 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\supplychain.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\teamwork.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6904 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\teamwork.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Thumbs.db:encryptable StreamName:encryptable StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:36 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\tt.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:8396 Bytes NameSize:68 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\tt.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamName:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:0 Bytes NameSize:90 Bytes Location:C:\Documents and Settings\Gateway\My Documents\My Pictures\Womandri.jpg:#5Q30lsldxJoudresxAaaqpcawXc StreamName:#5Q30lsldxJoudresxAaaqpcawXc StreamID:BACKUP_ALTERNATE_DATA (4) StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0) DataSize:6932 Bytes NameSize:68 Bytes
Due to dgoslings other committments (she is an admin here now) I have been asked to take over helping you.

What I would like to do is step back a little, and start with some fresh infomation for me to work with.

So please provide a fresh HJT log taken immediatly after a reboot - without anything being stopped by MSCONFIG or any other tool.

Also a getservices log. please download the file from here:

Getservice.zip

Extract the file to the c:\ drive. Then navigate to the c:\getservices and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad as a reply to this post.
PsService v1.1 - local and remote services viewer/controller
Copyright © 2001-2003 Mark Russinovich
Sysinternals - www.sysinternals.com

SERVICE_NAME: Alerter
Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k LocalService
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Alerter
DEPENDENCIES : LanmanWorkstation
SERVICE_START_NAME: NT AUTHORITY\LocalService

SERVICE_NAME: ALG
Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\alg.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Application Layer Gateway Service
DEPENDENCIES :
SERVICE_START_NAME: NT AUTHORITY\LocalService

SERVICE_NAME: AppMgmt
Provides software installation services such as Assign, Publish, and Remove.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Application Management
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: AudioSrv
Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : AudioGroup
TAG : 0
DISPLAY_NAME : Windows Audio
DEPENDENCIES : PlugPlay
: RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: BITS
Uses idle network bandwidth to transfer data.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Background Intelligent Transfer Service
DEPENDENCIES : LanmanWorkstation
: RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Browser
Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Computer Browser
DEPENDENCIES : LanmanWorkstation
: LanmanServer
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: cisvc
Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\cisvc.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Indexing Service
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: ClipSrv
Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\clipsrv.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : ClipBook
DEPENDENCIES : NetDDE
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: COMSysApp
Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : COM+ System Application
DEPENDENCIES : rpcss
SERVICE_START_NAME: LocalSystem
FAIL_RESET_PERIOD : 30 seconds
FAILURE_ACTIONS : Restart DELAY: 1000 seconds
: Restart DELAY: 5000 seconds
: None DELAY: 1000 seconds

SERVICE_NAME: CryptSvc
Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Cryptographic Services
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Dhcp
Manages network configuration by registering and updating IP addresses and DNS names.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : TDI
TAG : 0
DISPLAY_NAME : DHCP Client
DEPENDENCIES : Tcpip
: Afd
: NetBT
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: dmadmin
Configures hard disk drives and volumes. The service only runs for configuration processes and then stops.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\dmadmin.exe /com
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Logical Disk Manager Administrative Service
DEPENDENCIES : RpcSs
: PlugPlay
: DmServer
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: dmserver
Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Logical Disk Manager
DEPENDENCIES : RpcSs
: PlugPlay
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Dnscache
Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k NetworkService
LOAD_ORDER_GROUP : TDI
TAG : 0
DISPLAY_NAME : DNS Client
DEPENDENCIES : Tcpip
SERVICE_START_NAME: NT AUTHORITY\NetworkService

SERVICE_NAME: ERSvc
Allows error reporting for services and applictions running in non-standard environments.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Error Reporting Service
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Eventlog
Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\services.exe
LOAD_ORDER_GROUP : Event log
TAG : 0
DISPLAY_NAME : Event Log
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: EventSystem
Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : Network
TAG : 0
DISPLAY_NAME : COM+ Event System
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: FastUserSwitchingCompatibility
Provides management for applications that require assistance in a multiple user environment.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Fast User Switching Compatibility
DEPENDENCIES : TermService
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Fax
Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\fxssvc.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Fax
DEPENDENCIES : TapiSrv
: RpcSs
: PlugPlay
: Spooler
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: helpsvc
Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Help and Support
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem
FAIL_RESET_PERIOD : 86400 seconds
FAILURE_ACTIONS : Restart DELAY: 100 seconds
: Restart DELAY: 100 seconds
: None DELAY: 100 seconds

SERVICE_NAME: HidServ
Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 4 DISABLED
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Human Interface Device Access
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: ImapiService
Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\imapi.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : IMAPI CD-Burning COM Service
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: LanmanServer
Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Server
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: LanmanWorkstation
Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : NetworkProvider
TAG : 0
DISPLAY_NAME : Workstation
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: LmHosts
Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k LocalService
LOAD_ORDER_GROUP : TDI
TAG : 0
DISPLAY_NAME : TCP/IP NetBIOS Helper
DEPENDENCIES : NetBT
: Afd
SERVICE_START_NAME: NT AUTHORITY\LocalService

SERVICE_NAME: McShield
(null)
TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : c:\PROGRA~1\mcafee.com\vso\mcshield.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : McAfee.com McShield
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: mcupdmgr.exe
(null)
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : McAfee SecurityCenter Update Manager
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: MCVSRte
(null)
TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe /Embedding
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : McAfee.com VirusScan Online Realtime Engine
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Messenger
Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Messenger
DEPENDENCIES : LanmanWorkstation
: NetBIOS
: PlugPlay
: RpcSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: mnmsrvc
Allows authorized people to remotely access your Windows desktop using NetMeeting.
TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\mnmsrvc.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : NetMeeting Remote Desktop Sharing
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: MSDTC
Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\msdtc.exe
LOAD_ORDER_GROUP : MS Transactions
TAG : 1
DISPLAY_NAME : Distributed Transaction Coordinator
DEPENDENCIES : RPCSS
: SamSS
SERVICE_START_NAME: NT AUTHORITY\NetworkService

SERVICE_NAME: MSIServer
Installs, repairs and removes software according to instructions contained in .MSI files.
TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\msiexec.exe /V
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Windows Installer
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: NetDDE
Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\netdde.exe
LOAD_ORDER_GROUP : NetDDEGroup
TAG : 0
DISPLAY_NAME : Network DDE
DEPENDENCIES : NetDDEDSDM
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: NetDDEdsdm
Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\netdde.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Network DDE DSDM
DEPENDENCIES :
: EGrLocalSystem
: Network DDE DSDM
: etwork DDE
: Service
: Distributed Transaction Coordinator
: ion
: rogramFiles=h
: 
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Netlogon
Supports pass-through authentication of account logon events for computers in a domain.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\lsass.exe
LOAD_ORDER_GROUP : RemoteValidation
TAG : 0
DISPLAY_NAME : Net Logon
DEPENDENCIES : LanmanWorkstation
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Netman
Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Network Connections
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Nla
Collects and stores network configuration and location information, and notifies applications when this information changes.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Network Location Awareness (NLA)
DEPENDENCIES : Tcpip
: Afd
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: NtLmSsp
Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\lsass.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : NT LM Security Support Provider
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: NtmsSvc
Manages removable media, drives, and libraries.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Removable Storage
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: PlugPlay
Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\services.exe
LOAD_ORDER_GROUP : PlugPlay
TAG : 0
DISPLAY_NAME : Plug and Play
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: PolicyAgent
Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\lsass.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : IPSEC Services
DEPENDENCIES : RPCSS
: Tcpip
: IPSec
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: ProtectedStorage
Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\lsass.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Protected Storage
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: RasAuto
Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Access Auto Connection Manager
DEPENDENCIES : RasMan
: Tapisrv
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: RasMan
Creates a network connection.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Access Connection Manager
DEPENDENCIES : Tapisrv
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: RDSessMgr
Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\sessmgr.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Desktop Help Session Manager
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: RemoteAccess
Offers routing services to businesses in local area and wide area network environments.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 4 DISABLED
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Routing and Remote Access
DEPENDENCIES : RpcSS
: +NetBIOSGroup
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: RemoteRegistry
Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k LocalService
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Registry
DEPENDENCIES : RPCSS
SERVICE_START_NAME: NT AUTHORITY\LocalService
FAIL_RESET_PERIOD : 0 seconds
FAILURE_ACTIONS : Restart DELAY: 1000 seconds

SERVICE_NAME: RpcLocator
Manages the RPC name service database.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\locator.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Procedure Call (RPC) Locator
DEPENDENCIES : LanmanWorkstation
SERVICE_START_NAME: NT AUTHORITY\NetworkService

SERVICE_NAME: RpcSs
Provides the endpoint mapper and other miscellaneous RPC services.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost -k rpcss
LOAD_ORDER_GROUP : COM Infrastructure
TAG : 0
DISPLAY_NAME : Remote Procedure Call (RPC)
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem
FAIL_RESET_PERIOD : 0 seconds
FAILURE_ACTIONS : Reboot DELAY: 60000 seconds

SERVICE_NAME: RSVP
Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\rsvp.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : QoS RSVP
DEPENDENCIES : TcpIp
: Afd
: RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: SamSs
Stores security information for local user accounts.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\lsass.exe
LOAD_ORDER_GROUP : LocalValidation
TAG : 0
DISPLAY_NAME : Security Accounts Manager
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: SCardDrv
Enables support for legacy non-plug and play smart-card readers used by this computer. If this service is stopped, this computer will not support legacy reader. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\System32\SCardSvr.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Smart Card Helper
DEPENDENCIES : +Smart Card Reader
SERVICE_START_NAME: NT AUTHORITY\LocalService

SERVICE_NAME: SCardSvr
Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\System32\SCardSvr.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Smart Card
DEPENDENCIES : PlugPlay
SERVICE_START_NAME: NT AUTHORITY\LocalService

SERVICE_NAME: Schedule
Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : SchedulerGroup
TAG : 0
DISPLAY_NAME : Task Scheduler
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: seclogon
Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Secondary Logon
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: SENS
Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : Network
TAG : 0
DISPLAY_NAME : System Event Notification
DEPENDENCIES : EventSystem
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: SharedAccess
Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)
DEPENDENCIES : Netman
: NLA
: RasMan
: ALG
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: ShellHWDetection
(null)
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : ShellSvcGroup
TAG : 0
DISPLAY_NAME : Shell Hardware Detection
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Spooler
Loads files to memory for later printing.
TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\spoolsv.exe
LOAD_ORDER_GROUP : SpoolerGroup
TAG : 0
DISPLAY_NAME : Print Spooler
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem
FAIL_RESET_PERIOD : 86400 seconds
FAILURE_ACTIONS : Restart DELAY: 60000 seconds
: Restart DELAY: 60000 seconds
: None DELAY: 0 seconds

SERVICE_NAME: srservice
Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : System Restore Service
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: SSDPSRV
Enables discovery of UPnP devices on your home network.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k LocalService
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : SSDP Discovery Service
DEPENDENCIES :
SERVICE_START_NAME: NT AUTHORITY\LocalService

SERVICE_NAME: stisvc
Provides image acquisition services for scanners and cameras.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k imgsvc
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Windows Image Acquisition (WIA)
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: SwPrv
Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\System32\dllhost.exe /Processid:{00D6799D-72CE-4566-8E49-BD17F03A239E}
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : MS Software Shadow Copy Provider
DEPENDENCIES : rpcss
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: SysmonLog
Configures performance logs and alerts.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\smlogsvc.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Performance Logs and Alerts
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: TapiSrv
Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Telephony
DEPENDENCIES : PlugPlay
: RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: TermService
Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Terminal Services
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Themes
Provides user experience theme management.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : UIGroup
TAG : 0
DISPLAY_NAME : Themes
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem
FAIL_RESET_PERIOD : 86400 seconds
FAILURE_ACTIONS : Restart DELAY: 60000 seconds
: Restart DELAY: 60000 seconds
: None DELAY: 0 seconds

SERVICE_NAME: TlntSvr
Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\tlntsvr.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Telnet
DEPENDENCIES : RPCSS
: TCPIP
: NTLMSSP
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: TrkWks
Maintains links between NTFS files within a computer or across computers in a network domain.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Distributed Link Tracking Client
DEPENDENCIES : RpcSs
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: uploadmgr
Manages synchronous and asynchronous file transfers between clients and servers on the network. If this service is stopped, synchronous and asynchronous file transfers between clients and servers on the network will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Upload Manager
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem
FAIL_RESET_PERIOD : 86400 seconds
FAILURE_ACTIONS : Restart DELAY: 100 seconds
: Restart DELAY: 100 seconds
: None DELAY: 100 seconds

SERVICE_NAME: upnphost
Provides support to host Universal Plug and Play devices.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k LocalService
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Universal Plug and Play Device Host
DEPENDENCIES : SSDPSRV
SERVICE_START_NAME: NT AUTHORITY\LocalService
FAIL_RESET_PERIOD : -1 seconds
FAILURE_ACTIONS : Restart DELAY: 0 seconds

SERVICE_NAME: UPS
Manages an uninterruptible power supply (UPS) connected to the computer.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\ups.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Uninterruptible Power Supply
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: UtilMan
Starts and configures accessibility tools from one window
TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\UtilMan.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Utility Manager
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: VSS
Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\vssvc.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Volume Shadow Copy
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: W32Time
Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.


TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Windows Time
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: WebClient
Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k LocalService
LOAD_ORDER_GROUP : NetworkProvider
TAG : 0
DISPLAY_NAME : WebClient
DEPENDENCIES : MRxDAV
SERVICE_START_NAME: NT AUTHORITY\LocalService

SERVICE_NAME: winmgmt
Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Windows Management Instrumentation
DEPENDENCIES : RPCSS
: Eventlog
SERVICE_START_NAME: LocalSystem
FAIL_RESET_PERIOD : 86400 seconds
FAILURE_ACTIONS : Restart DELAY: 60000 seconds
: Restart DELAY: 60000 seconds

SERVICE_NAME: WmdmPmSp
Retrieves the serial number of any portable music player connected to your computer
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Portable Media Serial Number
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: Wmi
Provides systems management information to and from drivers.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Windows Management Instrumentation Driver Extensions
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: WmiApSrv
Provides performance library information from WMI HiPerf providers.
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\wbem\wmiapsrv.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : WMI Performance Adapter
DEPENDENCIES : RPCSS
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: wuauserv
Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated at the Windows Update Web site.
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Automatic Updates
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

SERVICE_NAME: WZCSVC
Provides automatic configuration for the 802.11 adapters
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : TDI
TAG : 0
DISPLAY_NAME : Wireless Zero Configuration
DEPENDENCIES : RpcSs
: Ndisuio
SERVICE_START_NAME: LocalSystem

Logfile of HijackThis v1.98.2
Scan saved at 9:03:33 AM, on 9/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Webshots\WebshotsTray.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\HiJackThis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [REGSHAVE] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [Lavasoft Adwatch] C:\Program Files\Lavasoft Ad-Aware\Ad-watch.exe /min
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} (McAfee.com Download+Installer Class) -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11E4B354-2AC4-4F60-BEB9-A9E59ED71D86}: NameServer = 24.153.22.195
O17 - HKLM\System\CS1\Services\Tcpip\..\{11E4B354-2AC4-4F60-BEB9-A9E59ED71D86}: NameServer = 24.153.22.195
O17 - HKLM\System\CS2\Services\Tcpip\..\{11E4B354-2AC4-4F60-BEB9-A9E59ED71D86}: NameServer = 24.153.22.195
Hi Well as I find time I have another look at your log and service list. I can still find no malware in those. Are you still having problems - if so - please try to explain blow by blow what happens and what is reported on your computer.
I am glad that we were able to help! I am closing this topic now, but if you need it reopened, please send an email to the following link(Click for address) with the Subject line of the email "Reopen".
To receive a response, please include in your email: the user name used in the post, details of why you need it reopened, and a valid link to the post.

Emails with bad links to the post, emails that are not from the original poster, and emails that do not have "ReOpen" as the subject line, will be deleted without being opening.

Please start a New Topic if this is not your thread. Thank-you for your co-operation.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI