OTL logfile created on: 5/17/2012 5:08:25 PM - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Documents and Settings\James\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 0.69 Gb Available Physical Memory | 46.32% Memory free
2.85 Gb Paging File | 2.09 Gb Available in Paging File | 73.32% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 138.76 Gb Free Space | 59.58% Space Free | Partition Type: NTFS
Drive E: | 3.29 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: FAMILYRUIZ | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\James\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0I332UQ9\aswMBR[1].exe (AVAST Software)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Agfa\IMPAX Client\Agfa.Client.Updater.Service.exe (Agfa Healthcare)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsOrganizer.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
========== Modules (No Company Name) ========== MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_e7470410\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_76e12144\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_50dc789c\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\Track2Filter.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\Track1Filter.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\DetectionUtils.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\Aoc.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\AdobeXMP.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\QtPlugins\imageformats\qjpeg1.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\QtGui4.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\QtNetwork4.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\QtXml4.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\QtCore4.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\OperaMgr.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\libmmd.dll ()
MOD - c:\windows\assembly\gac\system.data\1.0.5000.0__b77a5c561934e089\system.data.dll ()
MOD - c:\windows\assembly\gac\system.serviceprocess\1.0.5000.0__b03f5f7f11d50a3a\system.serviceprocess.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
========== Win32 Services (SafeList) ========== SRV - (WZASZYMY) -- C:\DOCUME~1\James\LOCALS~1\Temp\WZASZYMY.exe File not found
SRV - (TUA) -- C:\DOCUME~1\James\LOCALS~1\Temp\TUA.exe File not found
SRV - (LxrSII1s) -- LxrSII1s.exe File not found
SRV - (HGKSM) -- C:\DOCUME~1\James\LOCALS~1\Temp\HGKSM.exe File not found
SRV - (SpyHunter 4 Service) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (LBTServ) -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (PACS Client Updater) -- C:\Program Files\Agfa\IMPAX Client\Agfa.Client.Updater.Service.exe (Agfa Healthcare)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (AdobeActiveFileMonitor6.0) -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (mbr) -- C:\ComboFix\mbr.sys File not found
DRV - (LMouKE) -- System32\Drivers\LMouKE.sys File not found
DRV - (lbrtfdc) -- File not found
DRV - (Lbd) -- system32\DRIVERS\Lbd.sys File not found
DRV - (iniNpfs) -- C:\WINDOWS\system32\drivers\cdfltmgr.sys File not found
DRV - (i2omgmt) -- File not found
DRV - (cpuz132) -- C:\DOCUME~1\James\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\DOCUME~1\James\LOCALS~1\Temp\catchme.sys File not found
DRV - (aswMBR) -- C:\DOCUME~1\James\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (ASUSHWIO) -- C:\WINDOWS\system32\drivers\ASUSHWIO.sys File not found
DRV - (SBRE) -- C:\WINDOWS\system32\drivers\SBREDrv.sys (GFI Software)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (SbFw) -- C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) -- C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (sbhips) -- C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCLMP) -- C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) -- C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (LUsbFilt) -- C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidEqd) -- C:\WINDOWS\system32\drivers\LHidEqd.sys (Logitech, Inc.)
DRV - (LEqdUsb) -- C:\WINDOWS\system32\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV - (LBeepKE) -- C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (L8042Kbd) -- C:\WINDOWS\system32\drivers\L8042Kbd.sys (Logitech, Inc.)
DRV - (USB_RNDIS) Linksys Cable Modem (CM100) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) -- C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (P17) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (Cdralw2k) -- C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (prodrv06) -- C:\WINDOWS\system32\drivers\prodrv06.sys (Protection Technology)
DRV - (prohlp02) -- C:\WINDOWS\system32\drivers\prohlp02.sys (Protection Technology)
DRV - (prosync1) -- C:\WINDOWS\system32\drivers\prosync1.sys (Protection Technology)
DRV - (LxrSII1d) -- C:\WINDOWS\system32\drivers\LxrSII1d.sys ()
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (atitray) -- C:\Program Files\NGO ATI Optimized Driver v2.4\ATT\atitray.sys ()
DRV - (Afc) -- C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (CVPNDRVA) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (CVirtA) -- C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Zone Labs Inc.)
DRV - (ndiscm) -- C:\WINDOWS\system32\drivers\NetMotCM.sys (Motorola Inc.)
DRV - (itchfltr) -- C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (yukonx86) -- C:\WINDOWS\system32\drivers\yukonx86.sys (Marvell Semiconductor Inc.)
DRV - (sfhlp01) -- C:\WINDOWS\system32\drivers\sfhlp01.sys (Protection Technology)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (SDVC05) -- C:\WINDOWS\system32\drivers\SDVC05.sys (HaSoInTech)
DRV - (MidiSyn) -- C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (ctlsb16) Creative SB16/AWE32/AWE64 Driver (WDM) -- C:\WINDOWS\system32\drivers\ctlsb16.sys (Copyright © Creative Technology Ltd. 1994-2001)
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (aslm75) -- C:\WINDOWS\system32\drivers\ASLM75.SYS ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-746137067-1292428093-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-746137067-1292428093-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8IE - HKU\S-1-5-21-746137067-1292428093-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://search-gala.com/?uid=157&q={searchTerms}&rlz=1I7GGLL_enIE - HKU\S-1-5-21-746137067-1292428093-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-746137067-1292428093-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/18 00:12:04 | 000,000,000 | ---D | M]
[2010/07/11 18:03:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\James\Application Data\Mozilla\Extensions
O1 HOSTS File: ([2012/05/17 07:53:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Newsflash.lnk = C:\Program Files\Common Files\MySoftware\Newsflsh.exe (Avanquest USA LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..Trusted Domains: avanquest.com ([shop] https in Trusted sites)
O15 - HKU\S-1-5-21-746137067-1292428093-839522115-1003\..Trusted Domains: womansonline.com ([www] https in Trusted sites)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824}
http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab (Reg Error: Key error.)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.0.84.cab (Reg Error: Key error.)
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF}
http://moneycentral.msn.com/cabs/pmupd806.exe (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {741747F6-83B4-4FB9-A268-8CA4010762C8}
http://www2.snapfish.com/SnapfishActivia2.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC}
http://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab (Reg Error: Key error.)
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D}
http://a.download.toontown.com/sv1.0.38.33/ttinst.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In
https://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.99
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1AF3B3D1-174F-4476-988A-3084B5FA4446}: DhcpNameServer = 192.168.0.99
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:1 () -
http://www.howrse.com/O24 - Desktop WallPaper: C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/27 03:20:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/05/17 17:07:24 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\James\Desktop\OTL.exe
[2012/05/17 07:37:31 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/05/17 07:37:31 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/05/17 07:37:31 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/05/17 07:37:31 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/05/17 07:37:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/05/17 07:36:23 | 004,495,594 | R--- | C] (Swearware) -- C:\Documents and Settings\James\Desktop\ComboFix.exe
[2012/05/16 15:54:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2012/05/16 15:54:22 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012/05/16 11:54:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\Start Menu\Programs\SpyHunter
[2012/05/15 15:43:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\Desktop\tdsskiller
[2012/05/15 15:43:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\My Documents\New Folder (2)
[2012/05/15 09:46:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\My Documents\My Digital Editions
[2012/05/15 09:41:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\Start Menu\Programs\CompuClever
[2012/05/15 09:41:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\Application Data\CompuClever
[2012/05/15 09:41:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CompuClever
[2012/05/15 09:41:12 | 000,000,000 | ---D | C] -- C:\Program Files\CompuClever
[2012/05/14 21:30:39 | 000,101,112 | R--- | C] (GFI Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/05/14 21:30:39 | 000,042,864 | R--- | C] (GFI Software) -- C:\WINDOWS\System32\SBBD.EXE
[2012/05/13 22:51:37 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012/05/13 22:51:37 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/05/13 21:32:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2012/05/13 21:29:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\Desktop\HostsXpert
[2012/05/03 19:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\My Documents\New Folder
[2012/04/26 10:18:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\James\Desktop\curriculm
[2012/04/18 20:56:30 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2012/04/18 20:56:30 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/05/17 17:29:00 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{9ECE0870-82F7-463F-881D-6285D06B31D3}.job
[2012/05/17 17:07:33 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\James\Desktop\OTL.exe
[2012/05/17 17:05:33 | 000,079,207 | ---- | M] () -- C:\Documents and Settings\James\Desktop\pho22to.JPG
[2012/05/17 15:08:05 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\James\Desktop\MBR.dat
[2012/05/17 14:48:39 | 000,034,526 | ---- | M] () -- C:\Documents and Settings\James\Desktop\55.JPG
[2012/05/17 09:34:54 | 000,000,296 | ---- | M] () -- C:\Documents and Settings\James\Desktop\Womans Online.url
[2012/05/17 09:31:51 | 000,000,215 | ---- | M] () -- C:\Documents and Settings\James\Desktop\WOMANS.url
[2012/05/17 07:53:45 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/05/17 07:32:28 | 004,495,594 | R--- | M] (Swearware) -- C:\Documents and Settings\James\Desktop\ComboFix.exe
[2012/05/16 16:28:54 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2012/05/16 16:28:54 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2012/05/16 15:54:47 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2012/05/16 14:56:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/05/16 11:54:50 | 000,001,973 | ---- | M] () -- C:\Documents and Settings\James\Desktop\SpyHunter.lnk
[2012/05/16 03:26:02 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\PC TuneUp Maestro Scan.job
[2012/05/15 10:09:09 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\James\defogger_reenable
[2012/05/15 09:57:19 | 000,358,774 | ---- | M] () -- C:\Documents and Settings\James\Desktop\CPI Breast Radiology 2011-answersheet.pdf
[2012/05/15 09:46:02 | 000,001,837 | ---- | M] () -- C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions.lnk
[2012/05/15 09:46:02 | 000,001,819 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Digital Editions.lnk
[2012/05/15 09:41:13 | 000,000,960 | ---- | M] () -- C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Quick Launch\PC TuneUp Maestro.lnk
[2012/05/15 09:41:13 | 000,000,942 | ---- | M] () -- C:\Documents and Settings\James\Desktop\PC TuneUp Maestro.lnk
[2012/05/15 09:40:25 | 006,902,784 | ---- | M] () -- C:\Documents and Settings\James\Desktop\Breast_Radiology_2011.epub
[2012/05/15 07:13:32 | 000,000,268 | ---- | M] () -- C:\Documents and Settings\James\Desktop\Rad Assoc.url
[2012/05/14 21:55:20 | 000,001,296 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2012/05/14 21:52:54 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/14 21:52:26 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-746137067-1292428093-839522115-1003.job
[2012/05/14 21:52:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/14 21:51:58 | 1609,879,552 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/14 07:42:45 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 18:20:46 | 000,262,144 | ---- | M] () -- C:\Documents and Settings\James\My Documents\old christmasmml.bcf
[2012/05/13 18:20:46 | 000,086,872 | ---- | M] () -- C:\Documents and Settings\James\My Documents\old christmas.mml
[2012/05/13 18:20:46 | 000,002,788 | ---- | M] () -- C:\Documents and Settings\James\My Documents\old christmasmml.fsif
[2012/05/13 18:20:46 | 000,002,028 | ---- | M] () -- C:\Documents and Settings\James\My Documents\old christmasmml.msif
[2012/05/13 09:55:53 | 000,267,776 | ---- | M] () -- C:\Documents and Settings\James\My Documents\return addressmml.bcf
[2012/05/13 09:55:53 | 000,001,924 | ---- | M] () -- C:\Documents and Settings\James\My Documents\return address.mml
[2012/05/13 09:55:53 | 000,000,156 | ---- | M] () -- C:\Documents and Settings\James\My Documents\return addressmml.fsif
[2012/05/13 09:55:53 | 000,000,148 | ---- | M] () -- C:\Documents and Settings\James\My Documents\return addressmml.msif
[2012/05/12 23:13:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-746137067-1292428093-839522115-1003.job
[2012/05/10 22:34:25 | 000,000,235 | ---- | M] () -- C:\Documents and Settings\James\Desktop\Welcome to edline.net.url
[2012/05/10 06:42:46 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2012/05/10 03:48:49 | 000,407,896 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/10 03:26:11 | 000,484,620 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/05/10 03:26:11 | 000,080,634 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/05/10 03:17:05 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/05/09 10:25:22 | 000,000,202 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/05/07 19:25:55 | 000,060,900 | ---- | M] () -- C:\Documents and Settings\James\Desktop\picture-1_edited.jpg
[2012/05/05 13:23:06 | 023,552,369 | ---- | M] () -- C:\Documents and Settings\James\Desktop\angi.psd
[2012/05/03 16:49:58 | 002,107,228 | ---- | M] () -- C:\Documents and Settings\James\Desktop\angi.jpg
[2012/05/03 13:47:00 | 000,887,074 | ---- | M] () -- C:\Documents and Settings\James\Desktop\6thpg2-Brookshers.jpg
[2012/05/03 13:47:00 | 000,781,428 | ---- | M] () -- C:\Documents and Settings\James\Desktop\5thpgr3-Rogers-Sotile.jpg
[2012/05/03 13:44:38 | 001,155,806 | R--- | M] () -- C:\Documents and Settings\James\Desktop\IMGP9764.jpg
[2012/05/03 13:31:00 | 002,145,508 | ---- | M] () -- C:\Documents and Settings\James\Desktop\3boys.JPG
[2012/05/03 13:31:00 | 001,085,902 | ---- | M] () -- C:\Documents and Settings\James\Desktop\001_all_leaders2-with_Heidi_T1.jpg
[2012/05/03 13:31:00 | 000,781,428 | ---- | M] () -- C:\Documents and Settings\James\Desktop\5thpgr3-Rogers-Sotile1.jpg
[2012/05/03 13:31:00 | 000,777,031 | ---- | M] () -- C:\Documents and Settings\James\Desktop\3rdpgr3-Gudiel1.jpg
[2012/04/26 22:35:55 | 000,010,271 | ---- | M] () -- C:\Documents and Settings\James\Desktop\Tiger Rant - LSU Sports Forum @ TigerDroppings.com.url
[2012/04/23 08:49:41 | 000,612,298 | ---- | M] () -- C:\Documents and Settings\James\Desktop\dupeCertPrintImage.jpg
[2012/04/18 20:56:30 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2012/04/18 20:56:30 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/05/17 15:08:05 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\James\Desktop\MBR.dat
[2012/05/17 14:48:50 | 000,079,207 | ---- | C] () -- C:\Documents and Settings\James\Desktop\pho22to.JPG
[2012/05/17 14:48:39 | 000,034,526 | ---- | C] () -- C:\Documents and Settings\James\Desktop\55.JPG
[2012/05/17 07:37:31 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/05/17 07:37:31 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/05/17 07:37:31 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/05/16 15:54:47 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2012/05/16 11:54:50 | 000,001,973 | ---- | C] () -- C:\Documents and Settings\James\Desktop\SpyHunter.lnk
[2012/05/15 10:09:09 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\James\defogger_reenable
[2012/05/15 09:57:19 | 000,358,774 | ---- | C] () -- C:\Documents and Settings\James\Desktop\CPI Breast Radiology 2011-answersheet.pdf
[2012/05/15 09:46:02 | 000,001,837 | ---- | C] () -- C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions.lnk
[2012/05/15 09:46:02 | 000,001,825 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Digital Editions.lnk
[2012/05/15 09:46:02 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Digital Editions.lnk
[2012/05/15 09:41:16 | 000,000,384 | ---- | C] () -- C:\WINDOWS\tasks\PC TuneUp Maestro Scan.job
[2012/05/15 09:41:13 | 000,000,960 | ---- | C] () -- C:\Documents and Settings\James\Application Data\Microsoft\Internet Explorer\Quick Launch\PC TuneUp Maestro.lnk
[2012/05/15 09:41:13 | 000,000,942 | ---- | C] () -- C:\Documents and Settings\James\Desktop\PC TuneUp Maestro.lnk
[2012/05/15 09:40:16 | 006,902,784 | ---- | C] () -- C:\Documents and Settings\James\Desktop\Breast_Radiology_2011.epub
[2012/05/14 21:55:09 | 000,001,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2012/05/07 19:27:10 | 000,060,900 | ---- | C] () -- C:\Documents and Settings\James\Desktop\picture-1_edited.jpg
[2012/05/04 14:34:25 | 023,552,369 | ---- | C] () -- C:\Documents and Settings\James\Desktop\angi.psd
[2012/05/03 16:49:55 | 002,107,228 | ---- | C] () -- C:\Documents and Settings\James\Desktop\angi.jpg
[2012/05/03 15:47:09 | 001,155,806 | R--- | C] () -- C:\Documents and Settings\James\Desktop\IMGP9764.jpg
[2012/05/03 14:53:12 | 000,777,031 | ---- | C] () -- C:\Documents and Settings\James\Desktop\3rdpgr3-Gudiel1.jpg
[2012/05/03 14:53:09 | 000,887,074 | ---- | C] () -- C:\Documents and Settings\James\Desktop\6thpg2-Brookshers.jpg
[2012/05/03 14:52:28 | 000,781,428 | ---- | C] () -- C:\Documents and Settings\James\Desktop\5thpgr3-Rogers-Sotile.jpg
[2012/05/03 14:52:25 | 000,781,428 | ---- | C] () -- C:\Documents and Settings\James\Desktop\5thpgr3-Rogers-Sotile1.jpg
[2012/05/03 14:52:20 | 001,085,902 | ---- | C] () -- C:\Documents and Settings\James\Desktop\001_all_leaders2-with_Heidi_T1.jpg
[2012/05/03 14:52:16 | 002,145,508 | ---- | C] () -- C:\Documents and Settings\James\Desktop\3boys.JPG
[2012/04/23 08:49:41 | 000,612,298 | ---- | C] () -- C:\Documents and Settings\James\Desktop\dupeCertPrintImage.jpg
[2012/04/20 21:54:46 | 000,000,268 | ---- | C] () -- C:\Documents and Settings\James\Desktop\Rad Assoc.url
[2012/04/19 06:38:37 | 000,000,215 | ---- | C] () -- C:\Documents and Settings\James\Desktop\WOMANS.url
[2011/06/11 23:56:12 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2011/04/25 22:22:34 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/04/25 22:22:34 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/01/11 20:03:28 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\ptj.exe
[2011/01/11 20:03:28 | 001,103,360 | ---- | C] () -- C:\WINDOWS\System32\cidfont.dll
[2011/01/11 20:03:26 | 004,369,408 | ---- | C] () -- C:\WINDOWS\System32\pdftk.exe
[2011/01/11 20:03:26 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\office.exe
[2010/12/18 09:07:33 | 000,000,200 | ---- | C] () -- C:\WINDOWS\MML_PRT.INI
[2010/12/07 10:48:20 | 000,519,551 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-746137067-1292428093-839522115-1003-0.dat
[2010/12/07 10:48:13 | 000,361,174 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/08/24 00:10:50 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/08/24 00:10:50 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/06/01 10:26:26 | 000,012,989 | ---- | C] () -- C:\Documents and Settings\James\Application Data\Microsoft Excel.CAL
========== Files - Unicode (All) ==========[2012/04/10 21:22:41 | 000,000,262 | ---- | M] ()(C:\Documents and Settings\James\Desktop\On this retreat.docx?(19KB)?.url) -- C:\Documents and Settings\James\Desktop\On this retreat.docx(19KB).url
[2012/04/10 21:22:41 | 000,000,262 | ---- | C] ()(C:\Documents and Settings\James\Desktop\On this retreat.docx?(19KB)?.url) -- C:\Documents and Settings\James\Desktop\On this retreat.docx(19KB).url
< End of report >