Howdy Beynac-
Sounds like lovely weather. Nothing but fog and rain here, no surprise.
Here are reports (broken into multiple replies). Activescan reported infections but they appear to be simple cookies. I did not delete them yet, I wanted to check with you first.
BG
Logfile created on: 2/6/2007 8:44:53 PM
WinPFind2 by OldTimer - Version 1.0.15 Folder = C:\Documents and Settings\dave and michelle\Desktop\WinPFind2\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)
< Processes (Non-Microsoft Only) >
c:\program files\adobe\acrobat 7.0\distillr\acrotray.exe - (Adobe Systems Inc. )
c:\program files\adobe\acrobat 7.0\distillr\acrotray.exe - (Adobe Systems Inc. )
c:\windows\system32\ati2evxx.exe - ( )
c:\windows\system32\ati2evxx.exe - ( )
c:\windows\system32\ati2evxx.exe - ( )
c:\program files\ati technologies\ati control panel\atiptaxx.exe - (ATI Technologies, Inc. )
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe - (Anti-Malware Development a.s. )
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe - (Anti-Malware Development a.s. )
c:\program files\kodakeasyshare\kodak easyshare software\bin\easyshare.exe - ( )
c:\program files\kodakeasyshare\kodak easyshare software\bin\easyshare.exe - ( )
c:\program files\google\googletoolbarnotifier\1.2.908.5008\googletoolbarnotifier.exe - (File not found))
c:\program files\google\googletoolbarnotifier\1.2.1128.5462\googletoolbarnotifier.exe - (Google Inc. )
c:\program files\grisoft\avg anti-spyware 7.5\guard.exe - (Anti-Malware Development a.s. )
c:\program files\hewlett-packard\digital imaging\bin\hpoevm08.exe - (Hewlett-Packard Co. )
c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe - (Hewlett-Packard )
c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe - (Hewlett-Packard )
c:\program files\ipod\bin\ipodservice.exe - (Apple Computer, Inc. )
c:\program files\itunes\ituneshelper.exe - (Apple Computer, Inc. )
c:\program files\java\jre1.6.0\bin\jusched.exe - (Sun Microsystems, Inc. )
c:\program files\java\jre1.6.0\bin\jusched.exe - (Sun Microsystems, Inc. )
c:\windows\mixer.exe - (C-Media Electronic Inc. (www.cmedia.com.tw) )
c:\windows\mixer.exe - (C-Media Electronic Inc. (www.cmedia.com.tw) )
c:\program files\trend micro\internet security 2007\pccguide.exe - (Trend Micro Inc. )
c:\program files\trend micro\internet security 2007\pccguide.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\pcctlcom.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\pcscnsrv.exe - (Trend Micro Inc. )
c:\program files\quicktime\qttask.exe - (Apple Computer, Inc. )
c:\program files\quicktime\qttask.exe - (Apple Computer, Inc. )
c:\program files\common files\real\update_ob\realsched.exe - (RealNetworks, Inc. )
c:\program files\common files\real\update_ob\realsched.exe - (RealNetworks, Inc. )
c:\program files\rhapsody\rhaphlpr.exe - (RealNetworks, Inc. )
c:\program files\analog devices\soundmax\smagent.exe - (Analog Devices, Inc. )
c:\program files\analog devices\soundmax\smax4pnp.exe - (Analog Devices, Inc. )
c:\program files\analog devices\soundmax\smax4pnp.exe - (Analog Devices, Inc. )
c:\program files\trend micro\internet security 2007\tmas_oe\tmas_oemon.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\tmntsrv.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\tmpfw.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\tmproxy.exe - (Trend Micro Inc. )
c:\documents and settings\dave and michelle\desktop\winpfind2\winpfind2.exe - (OldTimer Tools )
< Registry Entries >
[>> Internet Explorer Settings <<]
HKLM->Main\\Start Page - about:blank
HKLM->Main\\Search Page -
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM->Main\\Default_Page_URL -
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
HKLM->Main\\Default_Search_URL - http://www.google.com/ie
HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm
HKCU->Main\\Start Page -
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
HKCU->Main\\Search Bar - http://www.google.com/ie
HKCU->Main\\Search Page -
http://www.google.com
HKCU->Main\\Local Page - C:\WINDOWS\system32\blank.htm
HKLM->Search\\CustomizeSearch - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM->Search\\SearchAssistant - http://www.google.com/ie
HKCU->Search\\SearchAssistant - http://www.google.com/ie
HKCU->URLSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
HKCU->Internet Settings\\ProxyEnable - 0
[>> BHO's <<]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - Adobe PDF Reader Link Helper = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated )
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - SSVHelper Class = C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc. )
{AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper = c:\program files\google\googletoolbar4.dll (Google Inc. )
{AE7CD045-E861-484f-8273-0445EE161910} - AcroIEToolbarHelper Class = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )
[>> Internet Explorer Bars, Toolbars and Extensions <<]
[HKLM-> Internet Explorer Bars]
{182EC0BE-5110-49C8-A062-BEB1D02A220B} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )
{4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
[HKCU-> Internet Explorer Bars]
{30D02401-6A81-11D0-8274-00C04FD5AE38} - Search Band = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
{32683183-48a0-441b-a342-7c2a440a9478} - Reg Data - Key not found = Reg Data - Key not found (File not found)
{EFA24E61-B078-11D0-89E4-00C04FC9E26E} - Favorites Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
{EFA24E62-B078-11D0-89E4-00C04FC9E26E} - History Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
[HKLM-> Internet Explorer ToolBars]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar4.dll (Google Inc. )
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )
[HKCU-> Internet Explorer ToolBars]
ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar4.dll (Google Inc. )
ShellBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )
WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar4.dll (Google Inc. )
WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )
[HKCU-> Internet Explorer CmdMapping]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8194 - Sun Java Console
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - 8193 - Reg Data - Key not found
{FB5F1910-F110-11d2-BB9E-00C04F795683} - 8196 - Windows Messenger
NextId - 8197
[HKLM-> Internet Explorer Extensions]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc. )
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} (HKCU CLSID) - MenuText: Sun Java Console = C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc. )
{FB5F1910-F110-11d2-BB9E-00C04F795683} - ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation )
[HKCU-> Internet Explorer Menu Extensions]
Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated )
Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated )
Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated )
Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated )
Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated )
Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated )
Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated )
Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated )
E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation )
[>> Approved Shell Extensions (Non-Microsoft only) <<]
[HKLM-> Approved Shell Extensions]
{0DF44EAA-FF21-4412-828E-260A8728E7F1} - Taskbar and Start Menu = Reg Data - Key not found (File not found)
{32683183-48a0-441b-a342-7c2a440a9478} - Media Band = Reg Data - Key not found (File not found)
{42071714-76d4-11d1-8b24-00a0c9068ff3} - Display Panning CPL Extension = deskpan.dll (File not found)
{48F45200-91E6-11CE-8A4F-0080C81A28D4} - TMD Shell Extension = C:\Program Files\Trend Micro\Internet Security 2007\Tmdshell.dll (Trend Micro Inc. )
{764BF0E1-F219-11ce-972D-00AA00A14F56} - Shell extensions for file compression = Reg Data - Key not found (File not found)
{771A9DA0-731A-11CE-993C-00AA004ADB6C} - VBPropSheet = C:\Program Files\Trend Micro\Internet Security 2007\VBProp.dll (Trend Micro Inc. )
{7A9D77BD-5403-11d2-8785-2E0420524153} - User Accounts = Reg Data - Key not found (File not found)
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Encryption Context Menu = Reg Data - Key not found (File not found)
{88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal Icon Ext = C:\WINDOWS\System32\hticons.dll (Hilgraeve, Inc. )
{acb4a560-3606-11d3-aef4-00104bd0f92d} - KodakShellExtension = C:\Program Files\Common Files\Kodak\ifscore\KodakShX.dll (Eastman Kodak Company )
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - iTunes = C:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Computer, Inc. )
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} - Adobe.Acrobat.ContextMenu = C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. )
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - Shell Extensions for RealOne Player = C:\Program Files\Real\RealPlayer\rpshell.dll (RealNetworks, Inc. )
[>> ContextMenuHandlers (Non-Microsoft only) <<]
[HKLM-> ContextMenuHandlers]
* - {48F45200-91E6-11CE-8A4F-0080C81A28D4} - = C:\Program Files\Trend Micro\Internet Security 2007\Tmdshell.dll (Trend Micro Inc. )
* - Adobe.Acrobat.ContextMenu - {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. )
* - AVG Anti-Spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll (Anti-Malware Development a.s. )
Directory - AVG Anti-Spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll (Anti-Malware Development a.s. )
Folder - {48F45200-91E6-11CE-8A4F-0080C81A28D4} - = C:\Program Files\Trend Micro\Internet Security 2007\Tmdshell.dll (Trend Micro Inc. )
[>> ColumnHandlers (Non-Microsoft only) <<]
[HKLM-> ColumnHandlers]
Folder - {F9DB5320-233E-11D1-9F84-707F02C10627} - PDF Shell Extension = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll (Adobe Systems, Inc. )
[>> File Associations Keys <<]
HKLM->SOFTWARE\Classes\.bat\\'' - batfile
HKLM->SOFTWARE\Classes\batfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.cmd\\'' - cmdfile
HKLM->SOFTWARE\Classes\cmdfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.com\\'' - comfile
HKLM->SOFTWARE\Classes\comfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.exe\\'' - exefile
HKLM->SOFTWARE\Classes\exefile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.hta\\'' - htafile
HKLM->SOFTWARE\Classes\htafile\shell\open\command\\'' - C:\WINDOWS\System32\mshta.exe "%1" %*
HKLM->SOFTWARE\Classes\.js\\'' - JSFile
HKLM->SOFTWARE\Classes\jsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.jse\\'' - JSEFile
HKLM->SOFTWARE\Classes\jsefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.scr\\'' - scrfile
HKLM->SOFTWARE\Classes\scrfile\shell\open\command\\'' - "%1" /S
HKLM->SOFTWARE\Classes\.vbe\\'' - VBEFile
HKLM->SOFTWARE\Classes\vbefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.vbs\\'' - VBSFile
HKLM->SOFTWARE\Classes\vbsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsf\\'' - WSFFile
HKLM->SOFTWARE\Classes\wsffile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsh\\'' - WSHFile
HKLM->SOFTWARE\Classes\wshfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.txt\\'' - txtfile
HKLM->SOFTWARE\Classes\txtfile\shell\open\command\\'' - %SystemRoot%\system32\NOTEPAD.EXE %1
[>> Registry Run Keys <<]
HKLM->Run\\ - (File not found)
HKLM->Run\\!AVG Anti-Spyware - "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized (Anti-Malware Development a.s. )
HKLM->Run\\Acrobat Assistant 7.0 - "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" (Adobe Systems Inc. )
HKLM->Run\\ATIPTA - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc. )
HKLM->Run\\C-Media Mixer - Mixer.exe /startup (C-Media Electronic Inc. (www.cmedia.com.tw) )
HKLM->Run\\iTunesHelper - "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc. )
HKLM->Run\\pccguide.exe - "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" (Trend Micro Inc. )
HKLM->Run\\QuickTime Task - "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc. )
HKLM->Run\\SoundMax - "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray (Analog Devices, Inc. )
HKLM->Run\\SoundMAXPnP - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc. )
HKLM->Run\\SunJavaUpdateSched - "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" (Sun Microsystems, Inc. )
HKLM->Run\\TkBellExe - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc. )
HKLM->RunOnceEx\\ - (File not found)
HKLM->Run\OptionalComponents\IMAIL - Installed = 1
HKLM->Run\OptionalComponents\MAPI - Installed = 1
HKLM->Run\OptionalComponents\MSFS - Installed = 1
HKCU->Run\\OE - "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" (Trend Micro Inc. )
HKCU->Run\\swg - C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe (File not found)
[>> Miscellaneous Startup Keys <<]
[AppInit DLLs]
AppInit_DLL - (File not found)
[Image File Execution Options]
Your Image File Name Here without a path - Debugger = ntsd -d
[Shell Service Object Delay Load]
CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll (Microsoft Corporation )
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll (Microsoft Corporation )
[Shell Execute Hooks]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} - CShellExecuteHookImpl Object = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (Anti-Malware Development a.s. )
{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation )
[Shared Task Scheduler]
{438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
{8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
[SafeBoot Option]
[HKLM Command Processor AutoRun]
HKLM->Command Processor\\AutoRun -
[HKCU Command Processor AutoRun]
[Security Providers]
SecurityProviders\\SecurityProviders - msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[BootExecute]
Session Manager\\BootExecute - autocheck autochk *;
[PendingFileRenameOperations]
Session Manager\\PendingFileRenameOperations - \??\C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\swg3.tmp;
[FileRenameOperations]
[ExcludeFromKnownDlls]
Session Manager\\ExcludeFromKnownDlls -
[>> Disabled MSConfig Items <<]
[>> User Agent Post Platform <<]
SV1 -
[>> Winlogon <<]
HMLM->AltDefaultDomainName - FUR
HMLM->AltDefaultUserName - dave and michelle
HMLM->AutoAdminLogon - Reg Data - Value does not exist
HMLM->DefaultDomainName - FUR
HMLM->DefaultUserName - dave and michelle
HKLM->Shell - Explorer.exe (Microsoft Corporation )
HKLM->System - (File not found)
HMLM->UserInit - C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation )
HKLM->VMApplet - rundll32 shell32,Control_RunDLL "sysdm.cpl"
Notify\AtiExtEvent - Ati2evxx.dll ( )
Notify\crypt32chain - crypt32.dll (Microsoft Corporation )
Notify\cryptnet - cryptnet.dll (Microsoft Corporation )
Notify\cscdll - cscdll.dll (Microsoft Corporation )
Notify\ScCertProp - wlnotify.dll (Microsoft Corporation )
Notify\Schedule - wlnotify.dll (Microsoft Corporation )
Notify\sclgntfy - sclgntfy.dll (Microsoft Corporation )
Notify\SensLogn - WlNotify.dll (Microsoft Corporation )
Notify\termsrv - wlnotify.dll (Microsoft Corporation )
Notify\wlballoon - wlnotify.dll (Microsoft Corporation )
[>> DNS Name Servers <<]
{C2586ADE-A4AC-4D53-9359-3779599B6936} - (Marvell Yukon Gigabit Ethernet 10/100/1000Base-T Adapter, Copper RJ-45)
[>> All Winsock2 Catalogs <<]
NameSpace_Catalog5\Catalog_Entries\000000000001 (Tcpip) - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000002 (NTDS) - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000003 (Network Location Awareness (NLA) Namespace) - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
[>> Protocol Handlers (Non-Microsoft only) <<]
ipp - (File not found)
msdaipp - (File not found)
[>> Protocol Filters (Non-Microsoft only) <<]
< Services (Non-Microsoft Only) >
Ati HotKey Poller (Ati HotKey Poller) - C:\WINDOWS\System32\Ati2evxx.exe ( ) [Automatic - Running - Win32, running in it's own process]
AVG Anti-Spyware Guard (AVG Anti-Spyware Guard) - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (Anti-Malware Development a.s. ) [Automatic - Running - Win32, running in it's own process]
iPodService (iPodService) - C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc. ) [On Demand - Running - Win32, running in it's own process]
Trend Micro Central Control Component (PcCtlCom) - C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Protection Against Spyware (PcScnSrv) - "C:\PROGRA~1\TRENDM~1\INTERN~3\PcScnSrv.exe" (Trend Micro Inc. ) [On Demand - Running - Win32, running in it's own process]
SoundMAX Agent Service (SoundMAX Agent Service (default)) - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Real-time Service (Tmntsrv) - C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Personal Firewall (TmPfw) - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Proxy Service (tmproxy) - C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]
< Files >
Auto-Start Folders
HKLM->Explorer\Shell Folders\\Common Startup = C:\Documents and Settings\All Users\Start Menu\Programs\Startup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Date = 11/4/1999 3:06:48 PM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated [Ver = 7.0.5.2005092300 | Size = 29696 bytes | Date = 9/23/2005 9:05:26 PM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 1/5/2002 10:49:00 PM | Attr = HS])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co. [Ver = 4.2.0.020 | Size = 323646 bytes | Date = 4/5/2003 11:37:10 PM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard [Ver = 1, 0, 0, 1 | Size = 28672 bytes | Date = 4/6/2003 12:06:58 AM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk - C:\Program Files\KodakEasyShare\Kodak EasyShare software\bin\EasyShare.exe ( [Ver = 5, 0, 25, 230 | Size = 151552 bytes | Date = 7/22/2005 3:47:22 AM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation [Ver = 10.0.2609 | Size = 83360 bytes | Date = 2/13/2001 1:01:04 AM | Attr = ])
HKLM->Explorer\User Shell Folders\\Common Startup = %ALLUSERSPROFILE%\Start Menu\Programs\Startup
HKLM->Explorer\Shell Folders\\Startup = C:\Documents and Settings\dave and michelle\Start Menu\Programs\Startup
C:\Documents and Settings\dave and michelle\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 1/5/2002 10:49:00 PM | Attr = HS])
HKCU->Explorer\User Shell Folders\\Startup = %USERPROFILE%\Start Menu\Programs\Startup
Miscellaneous Auto-Start Files
System.ini->[Boot]\\Shell - Explorer.exe
Miscellaneous Folders
AllUsers ApplicationData Folder
C:\Documents and Settings\All Users\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 1/5/2002 2:21:00 PM | Attr = HS])
C:\Documents and Settings\All Users\Application Data\hpzinstall.log - ( [Ver = | Size = 188 bytes | Date = 10/3/2004 5:16:00 PM | Attr = ])
C:\Documents and Settings\All Users\Application Data\OutlookFail.20070113.log - ( [Ver = | Size = 175 bytes | Date = 1/13/2007 7:42:10 PM | Attr = ])
C:\Documents and Settings\All Users\Application Data\OutlookFail.20070204.log - ( [Ver = | Size = 175 bytes | Date = 2/4/2007 10:56:28 AM | Attr = ])
CurrentUser ApplicationData Folder
C:\Documents and Settings\dave and michelle\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 1/5/2002 2:21:00 PM | Attr = HS])
C:\Documents and Settings\dave and michelle\Application Data\dm.ini - ( [Ver = | Size = 0 bytes | Date = 10/7/2004 4:39:26 PM | Attr = ])
C:\Documents and Settings\dave and michelle\Application Data\GDIPFONTCACHEV1.DAT - ( [Ver = | Size = 145640 bytes | Date = 1/24/2007 7:39:44 PM | Attr = ])
Program Files Folder
Common Files Folder
DPF files
{02BCC737-B171-4746-94C9-0D8A0B2C0089} - Microsoft Office Template and Media Control - CodeBase =
http://office.microsoft.com/templates/ieawsdc.cab
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - CKAVWebScan Object - CodeBase = http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
{17492023-C23A-453E-A040-C7C580BBF700} - Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - MUWebControl Class - CodeBase =
http://update.microsoft.com/microsoftupdat…b?1168658939905
{8AD9C840-044E-11D1-B3E9-00805F499D93} - Java Plug-in 1.6.0 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - Java Plug-in 1.6.0 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - Java Plug-in 1.6.0 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} - - CodeBase = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
Hosts file = 734 bytes. Reading all entries. C:\WINDOWS\System32\drivers\etc\Hosts
# Copyright © 1993-1999 Microsoft Corp. -
# -
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows. -
# -
# This file contains the mappings of IP addresses to host names. Each -
# entry should be kept on an individual line. The IP address should -
# be placed in the first column followed by the corresponding host name. -
# The IP address and the host name should be separated by at least one -
# space. -
# -
# Additionally, comments (such as these) may be inserted on individual -
# lines or following the machine name denoted by a '#' symbol. -
# -
# For example: -
# -
# 102.54.94.97 rhino.acme.com # source server -
# 38.25.63.10 x.acme.com # x client host -
-
127.0.0.1 localhost -
< Add On's >
>>>>Output for AddOn file awf.def<<<<
DIR - C:\*.* - Parameters = Size of 21504; Include SubFolders
C:\Documents and Settings\All Users\Application Data\Broderbund Software\Print\Address Book 6.0 for Windows\ab6.cfg - ( [Ver = | Size = 21504 bytes | Date = 1/24/2007 7:39:22 PM | Attr = ])
C:\Documents and Settings\dave and michelle\My Documents\Dave\Blinders\jasmine-8-01-05-dt.doc - ( [Ver = | Size = 21504 bytes | Date = 8/10/2005 10:44:00 AM | Attr = ])
C:\Documents and Settings\dave and michelle\My Documents\Dave\war pigeon\bio-wp.doc - ( [Ver = | Size = 21504 bytes | Date = 10/12/2005 3:41:18 PM | Attr = ])
C:\Documents and Settings\Sweet Pea\My Documents\Copy of student project\Summary.doc - ( [Ver = | Size = 21504 bytes | Date = 10/22/2005 8:33:04 PM | Attr = ])
C:\Documents and Settings\Sweet Pea\My Documents\student project\Summary.doc - ( [Ver = | Size = 21504 bytes | Date = 10/22/2005 8:33:04 PM | Attr = ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfCUT13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 21504 bytes | Date = 9/25/2002 5:37:22 PM | Attr = R ])
C:\Program Files\Microsoft Office\Templates\Presentation Designs\Capsules.pot - ( [Ver = | Size = 21504 bytes | Date = 11/27/2000 11:54:32 PM | Attr = ])
C:\Program Files\The Print Shop 20\Thesaurus.dll - (Broderbund Properties LLC [Ver = 6, 0, 0, 1336 | Size = 21504 bytes | Date = 7/29/2003 7:43:30 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\CUSTOMGR.CDR - ( [Ver = | Size = 21504 bytes | Date = 12/1/2000 2:39:46 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\phframes.KDR - ( [Ver = | Size = 21504 bytes | Date = 7/9/1999 11:36:04 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\PS15ART4.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/15/2003 11:47:38 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\Ps15PrtH.KDR - ( [Ver = | Size = 21504 bytes | Date = 5/19/2003 1:25:02 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\PS20HIRES.KDR - ( [Ver = | Size = 21504 bytes | Date = 6/3/2003 3:03:30 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\Ps20OnPj.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/17/2003 11:02:12 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\ps20prj1.SD1 - ( [Ver = | Size = 21504 bytes | Date = 7/7/2003 1:58:34 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\ps20prj2.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/19/2003 10:45:34 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\ps20prj4.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/17/2003 11:16:48 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\PS20Sets.CDR - ( [Ver = | Size = 21504 bytes | Date = 7/14/2003 12:51:16 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\STAMPS.CDR - ( [Ver = | Size = 21504 bytes | Date = 5/25/2001 1:02:32 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB840987\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB841356\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB841533\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB873376\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB887822\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 12:22:02 PM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\agentpsh.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\agtintl.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\dmserver.dll - (Microsoft Corp. [Ver = 2600.0.503.0 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\iisadmin.dll - (Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\shmgrate.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\udhisapi.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\userinit.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\wsock32.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\Fonts\smallf.fon - (Microsoft Corporation [Ver = 3.10 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = H ])
C:\WINDOWS\msagent\intl\agt0407.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\msagent\intl\agt040c.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\brpinfo.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\dpvacm.dll - (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\feclient.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\hidserv.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\rcp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\spupdwxp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\lang\cintlgnt.ime - (Microsoft Corporation [Ver = 4.4.2714 | Size = 21504 bytes | Date = 8/3/2004 9:31:54 PM | Attr = ])
C:\WINDOWS\system32\dpvacm.dll - (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\system32\feclient.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\system32\ipxrip.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\pathping.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\rcp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\system32\spupdwxp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\system32\dllcache\agt0407.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\agt040c.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\brpinfo.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\cintlgnt.ime - (Microsoft Corporation [Ver = 4.4.2714 | Size = 21504 bytes | Date = 8/3/2004 9:31:54 PM | Attr = ])
C:\WINDOWS\system32\dllcache\ipxrip.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\pathping.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
DIR - C:\*.* - Parameters = Size of 25600; Include SubFolders
C:\Documents and Settings\dave and michelle\My Documents\Dave\Blinders\test-7-21-05-meeting-dt.doc - ( [Ver = | Size = 25600 bytes | Date = 11/13/2006 9:43:50 AM | Attr = ])
C:\Documents and Settings\dave and michelle\My Documents\Dave\war pigeon\WAR PIGEON MASTER LOGIN LIST.doc - ( [Ver = | Size = 25600 bytes | Date = 9/27/2006 3:53:00 PM | Attr = ])
C:\Documents and Settings\Sweet Pea\My Documents\Wedding\~WRL0004.tmp - ( [Ver = | Size = 25600 bytes | Date = 4/16/2006 10:53:26 AM | Attr = H ])
C:\Program Files\Adobe\Acrobat 7.0\Designer 7.0\xfatraversalservice.dll - (Adobe Systems Incorporated [Ver = 2.2.4330.0 | Size = 25600 bytes | Date = 11/26/2004 10:51:42 AM | Attr = R ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfani13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 25600 bytes | Date = 9/25/2002 5:37:22 PM | Attr = R ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfavi12n.dll - (LEAD Technologies, Inc. [Ver = 12.1.0.000 | Size = 25600 bytes | Date = 8/13/2001 9:03:06 AM | Attr = ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfxwd13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 25600 bytes | Date = 9/25/2002 5:37:26 PM | Attr = R ])
C:\Program Files\Java\jre1.6.0\bin\keytool.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\kinit.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\klist.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\ktab.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\orbd.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\pack200.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\policytool.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\rmid.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\rmiregistry.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\servertool.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\PictureViewer.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:08 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\da.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:14 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\de.lproj\PictureViewerLocalized.dll - ( [Ver = | Size = 25600 bytes | Date = 8/25/2005 3:41:14 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\en.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:08 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\es.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\fi.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\fr.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\it.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\ja.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\ko.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\nl.lproj\PictureViewerLocalized.dll - ( [Ver = | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\no.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\sv.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\zh_CN.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\zh_TW.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\PanelHelperBase.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\CoreVideo.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:00 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\da.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\en.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:06:58 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\es.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\fi.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\fr.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\ja.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\ko.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\no.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\sv.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_TW.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\Trend Micro\PCC2005_1244\Setup\program files\Trend Micro\PC-cillin\MEMBOOT.DLL - ( [Ver = | Size = 25600 bytes | Date = 5/11/2004 12:48:42 PM | Attr = ])
C:\Program Files\Trend Micro\TIS11_1120\Setup\program files\Trend Micro\PC-cillin\MEMBOOT.DLL - ( [Ver = | Size = 25600 bytes | Date = 4/4/2003 7:42:14 PM | Attr = ])
C:\WINDOWS\twunk_32.exe - (Twain Working Group [Ver = 1,7,1,0 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\pstorsvc.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\winipsec.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\hidbth.sys - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 10:10:36 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\netsetup.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\udhisapi.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:46 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\usbser.sys - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 10:08:42 PM | Attr = ])
C:\WINDOWS\system32\aaaamon.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\comaddin.dll - (Microsoft Corporation [Ver = 2001.12.4414.42 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\format.com - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\msvidc32.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\netsetup.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\system32\routemon.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\udhisapi.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:46 PM | Attr = ])
C:\WINDOWS\system32\utildll.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\aaaamon.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\comaddin.dll - (Microsoft Corporation [Ver = 2001.12.4414.42 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\msvidc32.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\routemon.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\twunk_32.exe - (Twain Working Group [Ver = 1,7,1,0 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\utildll.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\drivers\hidbth.sys - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 10:10:36 PM | Attr = ])
DIR - C:\*.* - Parameters = Size of 27510; Include SubFolders
DIR - C:\*.* - Parameters = Size of 26450; Include SubFolders
DIR - C:\*.* - Parameters = Size of 31232; Include SubFolders
C:\Program Files\Adobe\Acrobat 7.0\Designer 7.0\jfprotocol.dll - (Adobe Systems Incorporated [Ver = 2.2.4330.0 | Size = 31232 bytes | Date = 11/26/2004 10:03:16 AM | Attr = R ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\LFPNM13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 31232 bytes | Date = 9/25/2002 5:37:26 PM | Attr = R ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\es.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fr.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ja.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\nl.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\QuickTime3GPPAuthoring.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 31232 bytes | Date = 9/1/2005 4:06:58 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\QuickTimeMPEG.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 31232 bytes | Date = 9/1/2005 4:07:00 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:02 PM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\inetmib1.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\wpabaln.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\sethc.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 31232 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\system32\sc.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\sethc.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 31232 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\system32\traffic.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\sc.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\tools.dll - (Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\traffic.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\wbemads.tlb - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\weitekp9.sys - (Microsoft Corporation [Ver = 5.1.2600.0 (XPClient.010817-1148) | Size = 3123