CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 30 Days ==========
[2010/12/10 18:23:16 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tricia\Desktop\OTL.exe
[2010/12/10 16:26:59 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tricia\Desktop\OTL.com
[2010/12/10 14:04:31 | 000,000,000 | ---D | C] -- C:\Program Files\ATS2
[2010/12/10 13:40:50 | 000,212,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\RICHTX32.OCX
[2010/12/10 13:40:49 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msstdfmt.dll
[2010/12/10 13:40:47 | 000,000,000 | ---D | C] -- C:\Program Files\freedom GUi
[2010/12/10 13:03:17 | 000,000,000 | ---D | C] -- C:\Program Files\The Cleaner
[2010/12/10 12:23:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/12/10 10:35:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/12/09 19:47:15 | 000,000,000 | --SD | C] -- C:\ComboFix
[2010/12/09 19:33:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/12/09 18:44:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/12/09 18:11:42 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/12/09 18:11:42 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/12/09 18:11:42 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/12/09 18:11:42 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/12/09 18:11:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/12/09 18:11:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/12/09 17:52:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tricia\Application Data\Malwarebytes
[2010/12/09 15:37:33 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/09 15:37:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/12/09 15:37:28 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/09 15:37:28 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/09 14:10:33 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/12/09 14:10:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/12/09 13:45:04 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/12/09 13:45:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/12/04 17:12:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tricia\Desktop\China Pics
[2010/11/28 18:57:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2010/11/28 18:57:46 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/10 18:29:06 | 010,620,928 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2010/12/10 18:28:58 | 008,299,520 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2010/12/10 18:26:38 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/12/10 18:25:34 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2010/12/10 18:25:33 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/10 18:25:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/12/10 18:25:22 | 527,892,480 | -HS- | M] () -- C:\hiberfil.sys
[2010/12/10 18:16:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2010/12/10 18:16:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2010/12/10 16:23:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tricia\Desktop\OTL.com
[2010/12/10 16:20:04 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tricia\Desktop\OTL.exe
[2010/12/10 14:01:01 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/12/10 14:01:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/10 14:00:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2010/12/10 14:00:55 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2010/12/09 21:29:14 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2010/12/09 21:29:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2010/12/09 18:54:24 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2010/12/09 18:54:23 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2010/12/09 18:47:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2010/12/09 18:47:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2010/12/09 18:33:38 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/09 17:57:01 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2010/12/09 17:57:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2010/12/09 16:21:19 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2010/12/09 16:21:19 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2010/12/09 15:37:38 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/09 14:06:29 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/12/09 13:50:25 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2010/12/09 13:50:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2010/12/09 12:58:17 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2010/12/09 12:58:17 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2010/12/08 18:01:46 | 000,002,016 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
[2010/12/07 21:50:47 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2010/12/07 21:50:47 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2010/12/04 13:27:50 | 000,002,361 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RitzPix E-Z Print & Share.lnk
[2010/12/02 19:10:43 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2010/12/02 19:10:43 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010/11/29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/27 21:44:07 | 000,000,438 | ---- | M] () -- C:\WINDOWS\tasks\EasyShare Registration Task.job
[2010/11/20 16:04:18 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/12 23:01:05 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/10 16:24:15 | 527,892,480 | -HS- | C] () -- C:\hiberfil.sys
[2010/12/09 18:11:42 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/09 18:11:42 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/09 18:11:42 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/09 18:11:42 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/09 18:11:42 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/12/09 16:05:58 | 000,001,595 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2010/12/09 15:37:38 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/02 19:10:43 | 000,001,619 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2010/12/02 19:10:43 | 000,001,611 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010/02/28 12:06:36 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/11/08 10:25:25 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\Tricia\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/13 21:43:29 | 000,000,023 | ---- | C] () -- C:\WINDOWS\kodakpcd.Tricia.ini
[2007/08/30 20:21:16 | 000,001,611 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2007/06/22 22:16:26 | 000,000,047 | ---- | C] () -- C:\WINDOWS\VistaEmail.ini
[2007/02/24 14:29:00 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Tricia\Local Settings\Application Data\fusioncache.dat
[2006/11/18 21:17:40 | 000,001,890 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/11/18 21:17:40 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\7779E155AE.sys
[2006/10/14 21:16:38 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\Tricia\Application Data\PFP120JPR.{PB
[2006/10/14 21:16:38 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\Tricia\Application Data\PFP120JCM.{PB
[2006/09/01 22:02:13 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/10/06 16:38:29 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/10/06 16:32:27 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/10/06 16:25:02 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/10/06 16:01:40 | 000,000,390 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/10/04 13:48:24 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\OPShDwn.dll
[2005/01/28 06:08:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 11:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 11:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 10:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2002/02/16 22:14:32 | 000,319,488 | ---- | C] () -- C:\WINDOWS\doorsdll.dll
[2000/09/08 16:53:50 | 000,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll
========== Custom Scans ==========
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2010/09/09 06:38:00 | 000,347,136 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2010/09/09 06:38:00 | 000,214,528 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2004/08/10 10:56:48 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/08/10 10:56:46 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/08/10 10:56:46 | 000,872,448 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2009/11/30 21:14:25 | 000,000,056 | RHS- | M] () -- C:\WINDOWS\system32\7779E155AE.sys
[2004/08/04 03:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2004/08/04 03:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2004/06/09 08:29:56 | 000,006,977 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\DDMI2.sys
[2005/03/13 14:54:00 | 000,006,656 | ---- | M] (GTek Technologies Ltd.) -- C:\WINDOWS\system32\DLPT2.sys
[2005/02/08 10:37:52 | 000,007,626 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GPCIEnum.sys
[2004/06/15 14:55:56 | 000,007,882 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GTKCMOS.sys
[2004/08/04 03:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2004/08/04 03:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2004/08/04 03:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2009/11/30 21:14:25 | 000,001,890 | -HS- | M] () -- C:\WINDOWS\system32\KGyGaAvL.sys
[2004/08/04 03:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2004/08/04 03:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2004/08/04 03:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2004/08/04 03:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2004/08/04 03:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/04 03:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/04 03:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/04 03:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/04 03:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/04 03:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/04/13 11:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2010/08/31 06:42:52 | 001,852,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
[2008/04/13 17:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/13 17:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/13 17:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/13 17:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/13 17:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/13 17:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/13 17:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/13 17:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/13 17:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/13 17:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/13 17:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/13 17:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/13 17:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/13 17:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/13 17:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %SYSTEMDRIVE%\*.* >
[2004/08/10 11:04:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2006/03/19 11:14:28 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2004/08/10 11:04:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/10/06 16:06:06 | 000,004,498 | RH-- | M] () -- C:\dell.sdr
[2007/05/12 10:34:51 | 000,738,091 | ---- | M] () -- C:\EasyShare.dmp
[2010/12/10 18:25:22 | 527,892,480 | -HS- | M] () -- C:\hiberfil.sys
[2006/04/28 20:38:10 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2004/08/10 11:04:08 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2005/10/06 16:32:09 | 000,000,827 | -H-- | M] () -- C:\IPH.PH
[2004/08/10 11:04:08 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2004/08/04 03:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/03/31 20:44:15 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/12/10 18:25:20 | 792,723,456 | -HS- | M] () -- C:\pagefile.sys
[2010/12/09 18:54:24 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2010/12/09 21:29:14 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2010/12/10 14:00:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2010/12/10 18:16:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/11/10 23:03:16 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2009/11/25 21:00:36 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2010/01/12 22:25:36 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2010/01/21 21:50:44 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2010/02/09 22:34:48 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2010/02/23 22:24:01 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2010/02/28 11:29:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2010/02/28 12:08:48 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2010/03/10 22:28:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2010/05/15 23:10:30 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2010/12/07 21:50:47 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2010/12/09 12:58:17 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2010/12/09 13:50:25 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2010/12/09 16:21:19 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2010/12/09 17:57:01 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2010/12/09 18:47:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2010/12/09 18:54:23 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2010/12/09 21:29:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2010/12/10 14:00:55 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2010/12/10 18:16:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/11/10 23:03:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009/11/25 21:00:36 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2010/01/12 22:25:36 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2010/01/21 21:50:44 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2010/02/09 22:34:48 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2010/02/23 22:24:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2010/02/28 11:29:36 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2010/02/28 12:08:48 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2010/03/10 22:28:50 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2010/05/15 23:10:30 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2010/12/07 21:50:47 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2010/12/09 12:58:17 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2010/12/09 13:50:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2010/12/09 16:21:19 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2010/12/09 17:57:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2010/12/09 18:47:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2006/03/19 10:56:28 | 000,000,071 | ---- | M] () -- C:\SystemInfo.ini
< %PROGRAMFILES%\*. >
[2007/11/09 20:10:48 | 000,000,000 | ---D | M] -- C:\Program Files\2Wire
[2007/11/09 20:10:44 | 000,000,000 | ---D | M] -- C:\Program Files\Actiontec
[2008/12/03 09:11:31 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2010/12/09 13:45:04 | 000,000,000 | ---D | M] -- C:\Program Files\Alwil Software
[2008/08/31 17:16:39 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/12/10 14:05:43 | 000,000,000 | ---D | M] -- C:\Program Files\ATS2
[2009/09/09 23:54:50 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2005/10/06 16:20:28 | 000,000,000 | ---D | M] -- C:\Program Files\Broadcom
[2010/12/09 18:22:28 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2004/08/10 11:02:08 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2005/10/06 16:21:23 | 000,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2005/10/06 16:25:29 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2005/10/06 16:25:01 | 000,000,000 | ---D | M] -- C:\Program Files\Dell
[2005/10/06 16:29:30 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Inc
[2008/01/31 16:48:56 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Support Center
[2007/04/22 20:50:26 | 000,000,000 | ---D | M] -- C:\Program Files\DellSupport
[2005/10/06 16:25:21 | 000,000,000 | ---D | M] -- C:\Program Files\Digital Line Detect
[2010/12/10 13:40:47 | 000,000,000 | ---D | M] -- C:\Program Files\freedom GUi
[2010/02/08 22:55:01 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2008/06/07 13:41:10 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2005/10/06 16:24:14 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2010/10/14 08:50:13 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/09/09 23:58:40 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/09/10 00:00:31 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2005/10/06 16:28:49 | 000,000,000 | ---D | M] -- C:\Program Files\Jasc Software Inc
[2005/10/06 16:19:28 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2007/06/19 20:28:04 | 000,000,000 | ---D | M] -- C:\Program Files\Kodak
[2005/10/06 16:32:07 | 000,000,000 | ---D | M] -- C:\Program Files\Learn2.com
[2010/12/09 15:37:39 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/11 10:47:54 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee
[2010/12/02 19:10:35 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee Security Scan
[2010/09/11 17:49:41 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee.com
[2009/03/31 21:00:19 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2004/08/10 11:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2005/10/06 16:27:55 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition
[2005/10/06 16:28:00 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Photo Story 2 LE
[2005/10/06 16:25:06 | 000,000,000 | ---D | M] -- C:\Program Files\Modem Helper
[2010/08/12 09:02:54 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2007/08/10 22:21:50 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/03/31 22:25:05 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2004/08/10 11:01:16 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2004/08/10 11:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/03/31 21:25:35 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Messenger
[2006/11/16 21:31:51 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2010/12/04 15:12:02 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2009/03/31 20:48:29 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2005/10/06 16:25:14 | 000,000,000 | ---D | M] -- C:\Program Files\NetWaiting
[2010/12/09 20:20:20 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/05/11 20:38:21 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2008/10/09 21:34:38 | 000,000,000 | ---D | M] -- C:\Program Files\Pakon
[2009/09/09 23:53:32 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2007/11/09 20:27:48 | 000,000,000 | ---D | M] -- C:\Program Files\Qwest
[2005/10/06 16:31:46 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2009/03/31 22:24:49 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2007/07/01 21:18:39 | 000,000,000 | ---D | M] -- C:\Program Files\RitzPix E-Z Print & Share
[2005/10/06 16:21:15 | 000,000,000 | ---D | M] -- C:\Program Files\Sigmatel
[2005/10/06 16:33:00 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2008/06/07 13:36:48 | 000,000,000 | ---D | M] -- C:\Program Files\Sony
[2010/12/09 15:32:36 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2005/10/06 16:07:10 | 000,000,000 | ---D | M] -- C:\Program Files\Synaptics
[2010/12/10 16:15:44 | 000,000,000 | ---D | M] -- C:\Program Files\The Cleaner
[2004/08/10 11:08:30 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2005/10/06 16:32:06 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2005/10/06 16:35:26 | 000,000,000 | ---D | M] -- C:\Program Files\WebCyberCoach
[2007/11/29 22:27:00 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live Toolbar
[2009/03/31 20:48:23 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/03/31 20:48:23 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2004/08/10 11:02:52 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2004/08/10 11:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2005/10/06 16:29:35 | 000,000,000 | ---D | M] -- C:\Program Files\Your Company Name
< %appdata%\*.* >
[2004/08/10 10:57:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Tricia\Application Data\desktop.ini
[2006/10/14 21:16:38 | 000,012,358 | ---- | M] () -- C:\Documents and Settings\Tricia\Application Data\PFP120JCM.{PB
[2006/10/14 21:16:38 | 000,061,678 | ---- | M] () -- C:\Documents and Settings\Tricia\Application Data\PFP120JPR.{PB
< MD5 for: AGP440.SYS >
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 21:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\i386\AGP440.SYS
[2004/08/03 21:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\i386\atapi.sys
[2004/08/03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/03 20:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:disk.sys
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/04 03:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\i386\disk.sys
[2004/08/04 03:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 11:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 11:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 03:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\i386\eventlog.dll
[2004/08/04 03:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 03:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\i386\netlogon.dll
[2004/08/04 03:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 03:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\i386\scecli.dll
[2004/08/04 03:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\i386\sp2.cab:usbstor.sys
[2004/08/04 03:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2009/03/31 20:38:26 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/03 23:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 11:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 11:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 01:30:12