2nd half of file
------------------------------------------------
O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Harmony Hollow Software Toolbar) - {3806b089-6759-411d-b2c3-b7995a9f34d7} - C:\Program Files\Harmony_Hollow_Software\tbHarm.dll (Conduit Ltd.)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (CIEDownload Object) - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Technologies\SMART Notebook\NotebookPlugin.dll (SMART Technologies ULC.)
O3 - HKLM\..\Toolbar: (Harmony Hollow Software Toolbar) - {3806b089-6759-411d-b2c3-b7995a9f34d7} - C:\Program Files\Harmony_Hollow_Software\tbHarm.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Harmony Hollow Software Toolbar) - {3806B089-6759-411D-B2C3-B7995A9F34D7} - C:\Program Files\Harmony_Hollow_Software\tbHarm.dll (Conduit Ltd.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [SCFTrayStartUp] C:\Program Files\Sophos\Sophos Client Firewall\SCFTray.exe (Sophos Plc)
O4 - HKLM..\Run: [SMART Board Service] C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe (SMART Technologies)
O4 - HKLM..\Run: [SMART SNMP Agent] C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe (SMART Technologies ULC)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains:
http://about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains:
http://VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}
http://java.sun.com/update/1.4.2/jinstall-1_4_2_04-windows-i586.cab (Java Plug-in 1.4.2_04)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\windows\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/08/06 20:12:56 | 000,000,000 | ---D | C] -- C:\ProgramData\ParetoLogic
[2010/08/06 20:12:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ParetoLogic
[2010/08/06 20:12:55 | 000,000,000 | ---D | C] -- C:\Program Files\ParetoLogic
[2010/08/06 20:11:21 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2010/08/04 20:55:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2010/08/04 20:39:32 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe
[2010/08/04 19:50:52 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\{7148F0A6-6813-11D6-A77B-00B0D0142040}
[2010/08/04 19:41:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/08/04 19:41:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/08/04 19:40:57 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\deployJava1.dll
[2010/08/04 19:40:56 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe
[2010/08/04 19:40:56 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe
[2010/08/04 19:40:46 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010/08/02 16:07:39 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\year 5 2010
[2010/07/30 20:13:33 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/07/30 19:54:25 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Harmony_Hollow_Software
[2010/07/30 19:54:06 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2010/07/30 19:53:57 | 000,000,000 | ---D | C] -- C:\Program Files\Harmony_Hollow_Software
[2010/07/30 19:53:55 | 000,000,000 | ---D | C] -- C:\Program Files\The Hat
[2010/07/30 17:00:21 | 003,954,568 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntkrnlpa.exe
[2010/07/30 17:00:21 | 003,899,280 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntoskrnl.exe
[2010/07/30 16:46:59 | 000,086,016 | ---- | C] (MindVision) -- C:\windows\unvise32qt.exe
[2010/07/30 16:46:45 | 000,000,000 | ---D | C] -- C:\ProgramData\QuickTime
[2010/07/30 16:46:38 | 000,000,000 | ---D | C] -- C:\windows\System32\QuickTime
[2010/07/30 16:46:33 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/07/30 16:44:26 | 000,000,000 | ---D | C] -- C:\Program Files\Myst III Exile
[2010/07/30 16:42:43 | 000,000,000 | ---D | C] -- C:\Program Files\The Adventure Company
[2010/07/30 16:40:51 | 000,000,000 | ---D | C] -- C:\Program Files\Busy Bees
[2010/07/30 16:35:40 | 000,000,000 | ---D | C] -- C:\Program Files\Teaching Tables
[2010/07/30 16:34:26 | 000,000,000 | ---D | C] -- C:\Program Files\Teaching Time
[2010/07/30 16:33:12 | 000,000,000 | ---D | C] -- C:\Program Files\Primary Games Vol.2
[2010/07/30 16:31:39 | 000,000,000 | ---D | C] -- C:\Program Files\Primary Games Vol.1
[2010/07/30 16:30:11 | 000,000,000 | ---D | C] -- C:\Program Files\Maths Pack 2
[2010/07/30 16:26:59 | 000,720,896 | ---- | C] (Indigo Rose Corporation) -- C:\windows\iun6002.exe
[2010/07/30 16:26:57 | 000,000,000 | ---D | C] -- C:\Program Files\Maths Pack 1
[2010/07/30 16:24:10 | 000,000,000 | ---D | C] -- C:\Program Files\10 Maths Miracles
[2010/07/21 09:41:55 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\My Downloads
[2010/07/21 09:41:38 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\management
[2010/07/21 09:41:14 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Literacy
[2010/07/21 09:41:03 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Leadership pathways
[2010/07/21 09:40:59 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Improving Literacy PG study Lit matters
[2010/07/21 09:40:54 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\ITT etc
[2010/07/21 09:40:48 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\ICT
[2010/07/21 09:40:38 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Governance
[2010/07/21 09:40:29 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Downloads
[2010/07/21 09:39:51 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\AST
[2010/07/21 09:39:41 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\courses etc
[2010/07/21 09:39:33 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\CyberLink
[2010/07/21 08:47:53 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Diagnostics
[2010/07/13 08:33:37 | 000,057,344 | ---- | C] (Sophos Plc) -- C:\windows\System32\drivers\scfdriver.sys
[2010/07/13 08:33:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sophos
[2010/07/13 08:32:49 | 000,130,104 | ---- | C] (Sophos Plc) -- C:\windows\System32\sdccoinstaller.dll
[2010/07/13 08:32:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Cisco Systems
[2010/07/13 08:32:42 | 000,023,552 | ---- | C] (Sophos Plc) -- C:\windows\System32\SophosBootTasks.exe
[2010/07/13 08:32:31 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2010/07/13 08:32:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2010/07/13 08:27:17 | 000,093,192 | ---- | C] (Sophos Plc) -- C:\windows\System32\drivers\savonaccess.sys
[2010/07/13 08:27:17 | 000,027,136 | ---- | C] (Sophos Plc) -- C:\windows\System32\drivers\scflwf.sys
[2010/07/13 08:27:17 | 000,020,288 | ---- | C] (Sophos Plc) -- C:\windows\System32\drivers\SophosBootDriver.sys
[2010/07/13 08:27:01 | 000,000,000 | ---D | C] -- C:\escwsa
[2010/07/09 10:56:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Softease
[2010/07/09 10:54:02 | 000,000,000 | ---D | C] -- C:\Program Files\Lightbox Education
[2010/07/09 09:35:34 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Microsoft Help
[2010/07/09 09:35:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2010/07/09 09:33:58 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010/07/09 08:46:56 | 000,000,000 | ---D | C] -- C:\windows\System32\Wat
[2010/07/09 00:42:28 | 000,000,000 | ---D | C] -- C:\windows\System32\Lang
[2010/07/09 00:42:27 | 000,997,912 | ---- | C] (Intel Corporation) -- C:\windows\System32\igxpun.exe
[2010/07/09 00:42:19 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2010/07/09 00:41:27 | 000,000,000 | ---D | C] -- C:\windows\Prefetch
[2010/07/08 21:55:40 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\PresentationHost.exe
[2010/07/08 21:55:40 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\PresentationHostProxy.dll
[2010/07/08 21:55:40 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\netfxperf.dll
[2010/07/08 21:46:22 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\browserchoice.exe
[2010/07/08 21:43:23 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\My Notebook Content
[2010/07/08 21:43:15 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\SMART Technologies Inc
[2010/07/08 21:43:11 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\SMART Notebook
[2010/07/08 21:43:11 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\LabVIEW Data
[2010/07/08 21:43:02 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\SMART Technologies
[2010/07/08 20:55:16 | 000,000,000 | ---D | C] -- C:\Users\user\Documents\Bluetooth Exchange Folder
[2010/07/08 20:48:55 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\SMART Technologies
[2010/07/08 20:42:51 | 000,033,064 | ---- | C] (SMART Technologies ULC) -- C:\windows\System32\smrtlocalmon.dll
[2010/07/08 20:42:51 | 000,023,848 | ---- | C] (SMART Technologies Inc.) -- C:\windows\System32\smrtlocalui.dll
[2010/07/08 19:51:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SMART Technologies
[2010/07/08 19:51:34 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\SMART Technologies Inc
[2010/07/08 19:50:55 | 000,000,000 | ---D | C] -- C:\Program Files\National Instruments
[2010/07/08 19:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\SMART Technologies
[2010/07/08 19:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SMART Technologies
[2010/07/08 19:49:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2010/07/08 18:23:37 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mstime.dll
[2010/07/08 18:23:37 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2010/07/08 18:23:36 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2010/07/08 18:23:36 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2010/07/08 18:23:29 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\windows\explorer.exe
[2010/07/08 18:23:27 | 001,037,312 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\lsasrv.dll
[2010/07/08 18:23:27 | 000,133,720 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\drivers\ksecpkg.sys
[2010/07/08 18:23:23 | 002,326,528 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys
[2010/07/08 18:23:22 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\CertEnroll.dll
[2010/07/08 18:23:22 | 000,507,568 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\winload.exe
[2010/07/08 18:23:21 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\wmploc.DLL
[2010/07/08 18:23:21 | 000,442,920 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\winresume.exe
[2010/07/08 18:23:14 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\asycfilt.dll
[2010/07/08 18:23:13 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\CPFilters.dll
[2010/07/08 18:23:12 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\psisdecd.dll
[2010/07/08 18:23:12 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msdri.dll
[2010/07/08 18:23:12 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\MSNP.ax
[2010/07/08 18:23:12 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mpg2splt.ax
[2010/07/08 18:23:07 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jscript.dll
[2010/07/08 18:23:06 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\t2embed.dll
[2010/07/08 18:23:05 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\quartz.dll
[2010/07/08 18:23:05 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\avifil32.dll
[2010/07/08 18:23:05 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mciavi32.dll
[2010/07/08 18:23:04 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\vbscript.dll
[2010/07/08 18:23:04 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\secproc.dll
[2010/07/08 18:23:04 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\secproc_isv.dll
[2010/07/08 18:23:03 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\RMActivate_isv.exe
[2010/07/08 18:23:03 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\RMActivate.exe
[2010/07/08 18:23:03 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\RMActivate_ssp.exe
[2010/07/08 18:23:03 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\RMActivate_ssp_isv.exe
[2010/07/08 18:23:03 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\secproc_ssp_isv.dll
[2010/07/08 18:23:03 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\secproc_ssp.dll
[2010/07/08 18:23:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\tzres.dll
[2010/07/08 18:19:01 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\System32\atmfd.dll
[2010/07/08 18:19:01 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\fontsub.dll
[2010/07/08 18:19:01 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\windows\System32\atmlib.dll
[2010/07/08 18:09:13 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Macromedia
[2010/07/08 18:09:09 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Adobe
[2010/07/08 18:08:16 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Hewlett-Packard
[2010/07/08 18:08:11 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\SiteAdvisor
[2010/07/08 18:08:11 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\PDFC
[2010/07/08 18:08:04 | 000,000,000 | R--D | C] -- C:\Users\user\Searches
[2010/07/08 18:08:04 | 000,000,000 | -H-D | C] -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2010/07/08 18:07:57 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\Identities
[2010/07/08 18:07:56 | 000,000,000 | R--D | C] -- C:\Users\user\Contacts
[2010/07/08 18:07:48 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Hewlett-Packard
[2010/07/08 18:07:47 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Hewlett-Packard_Company
[2010/07/08 18:04:46 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\HP TCS
[2010/07/08 18:01:46 | 000,000,000 | ---D | C] -- C:\windows\HPQ
[2010/07/08 18:01:34 | 000,313,904 | ---- | C] (Sonix) -- C:\windows\System32\vsnp2uvc.dll
[2010/07/08 18:01:34 | 000,256,560 | ---- | C] ( ) -- C:\windows\System32\rsnp2uvc.dll
[2010/07/08 18:01:33 | 000,203,312 | ---- | C] ( ) -- C:\windows\System32\csnp2uvc.dll
[2010/07/08 18:01:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SNP2UVC
[2010/07/08 18:01:11 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\InstallShield
[2010/07/08 18:00:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2010/07/08 18:00:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010/07/08 18:00:25 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2010/07/08 18:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2010/07/08 17:59:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2010/07/08 17:59:01 | 000,061,440 | ---- | C] (LSI Corporation) -- C:\windows\System32\agrsmdel.exe
[2010/07/08 17:59:01 | 000,014,848 | ---- | C] (LSI Corporation) -- C:\windows\System32\agrsco64.dll
[2010/07/08 17:58:59 | 000,000,000 | ---D | C] -- C:\Program Files\LSI SoftModem
[2010/07/08 17:58:49 | 000,000,000 | ---D | C] -- C:\windows\Options
[2010/07/08 17:58:22 | 000,490,496 | ---- | C] (IDT, Inc.) -- C:\windows\System32\stapi32.dll
[2010/07/08 17:57:43 | 000,368,640 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\System32\aestecap.dll
[2010/07/08 17:57:43 | 000,142,848 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\System32\aestacap.dll
[2010/07/08 17:57:43 | 000,061,440 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\System32\aestaren.dll
[2010/07/08 17:57:42 | 012,030,044 | ---- | C] (IDT, Inc.) -- C:\windows\System32\idtcpl.cpl
[2010/07/08 17:57:42 | 000,458,844 | ---- | C] (IDT, Inc.) -- C:\windows\sttray.exe
[2010/07/08 17:57:42 | 000,086,016 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\System32\AESTCom.dll
[2010/07/08 17:57:41 | 003,600,384 | ---- | C] (IDT, Inc.) -- C:\windows\System32\stlang.dll
[2010/07/08 17:57:03 | 000,408,576 | ---- | C] (IDT, Inc.) -- C:\windows\System32\drivers\stwrt.sys
[2010/07/08 17:57:02 | 000,915,456 | ---- | C] (IDT, Inc.) -- C:\windows\System32\stapo.dll
[2010/07/08 17:57:02 | 000,405,504 | ---- | C] (IDT, Inc.) -- C:\windows\System32\stcplx.dll
[2010/07/08 17:57:02 | 000,175,616 | ---- | C] (IDT, Inc.) -- C:\windows\System32\st326222.dll
[2010/07/08 17:56:37 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2010/07/08 17:56:14 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Broadcom
[2010/07/08 17:55:14 | 000,108,072 | ---- | C] (Broadcom Corporation.) -- C:\windows\System32\drivers\btwavdt.sys
[2010/07/08 17:55:14 | 000,029,472 | ---- | C] (Broadcom Corporation.) -- C:\windows\System32\drivers\btwl2cap.sys
[2010/07/08 17:55:14 | 000,018,344 | ---- | C] (Broadcom Corporation.) -- C:\windows\System32\drivers\btwrchid.sys
[2010/07/08 17:55:13 | 000,086,056 | ---- | C] (Broadcom Corporation.) -- C:\windows\System32\drivers\btwaudio.sys
[2010/07/08 17:55:00 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM
[2010/07/08 17:53:38 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Roaming\hpqLog
[2010/07/08 17:53:02 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\VirtualStore
[2010/07/08 17:52:59 | 000,000,000 | --SD | C] -- C:\Users\user\AppData\Roaming\Microsoft
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Videos
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Saved Games
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Pictures
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Music
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Links
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Favorites
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Downloads
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\My Documents
[2010/07/08 17:52:59 | 000,000,000 | R--D | C] -- C:\Users\user\Desktop
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\Temporary Internet Files
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Templates
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Start Menu
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\SendTo
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Recent
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\PrintHood
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\NetHood
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Videos
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Pictures
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Documents\My Music
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\My Documents
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Local Settings
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\History
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Cookies
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\Application Data
[2010/07/08 17:52:59 | 000,000,000 | -HSD | C] -- C:\Users\user\AppData\Local\Application Data
[2010/07/08 17:52:59 | 000,000,000 | -H-D | C] -- C:\Users\user\AppData
[2010/07/08 17:52:59 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Temp
[2010/07/08 17:52:59 | 000,000,000 | ---D | C] -- C:\Users\user\AppData\Local\Microsoft
[2010/07/08 17:50:09 | 000,000,000 | ---D | C] -- C:\windows\SoftwareDistribution
========== Files - Modified Within 30 Days ========== [2010/08/07 09:13:04 | 000,000,142 | ---- | M] () -- C:\windows\ODBC.INI
[2010/08/07 09:13:02 | 000,000,442 | ---- | M] () -- C:\windows\tasks\ParetoLogic Registration3.job
[2010/08/07 09:13:02 | 000,000,416 | ---- | M] () -- C:\windows\tasks\ParetoLogic Update Version3.job
[2010/08/07 09:13:02 | 000,000,374 | ---- | M] () -- C:\windows\tasks\PC Health Advisor Defrag.job
[2010/08/07 09:13:02 | 000,000,356 | ---- | M] () -- C:\windows\tasks\PC Health Advisor.job
[2010/08/07 09:13:02 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2010/08/07 09:12:53 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2010/08/07 09:12:48 | 2409,078,784 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/06 22:13:01 | 001,310,720 | -HS- | M] () -- C:\Users\user\NTUSER.DAT
[2010/08/06 22:12:54 | 002,002,029 | -H-- | M] () -- C:\Users\user\AppData\Local\IconCache.db
[2010/08/06 21:28:21 | 000,726,316 | ---- | M] () -- C:\windows\System32\PerfStringBackup.INI
[2010/08/06 21:28:21 | 000,628,460 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2010/08/06 21:28:21 | 000,110,612 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2010/08/06 20:12:57 | 000,001,067 | ---- | M] () -- C:\Users\user\Desktop\ParetoLogic PC Health Advisor.lnk
[2010/08/06 20:11:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2010/08/06 15:49:12 | 000,020,720 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/06 15:49:12 | 000,020,720 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/04 20:39:22 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\deployJava1.dll
[2010/08/04 20:39:22 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe
[2010/08/04 20:39:22 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe
[2010/08/04 20:39:22 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe
[2010/08/04 19:33:57 | 000,127,536 | ---- | M] () -- C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/04 19:33:13 | 000,470,232 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2010/08/02 15:52:35 | 000,000,149 | ---- | M] () -- C:\Users\user\Desktop\Inbox.url
[2010/07/30 19:53:55 | 000,000,888 | ---- | M] () -- C:\Users\user\Desktop\The Hat.lnk
[2010/07/30 16:46:45 | 000,001,031 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2010/07/30 16:46:41 | 000,001,007 | ---- | M] () -- C:\Users\user\Desktop\QuickTime Player.lnk
[2010/07/30 16:46:41 | 000,000,000 | ---- | M] () -- C:\windows\System32\QuickTime.qtp
[2010/07/30 16:45:09 | 000,001,935 | ---- | M] () -- C:\Users\Public\Desktop\Myst III Exile.lnk
[2010/07/30 16:45:09 | 000,001,024 | ---- | M] () -- C:\Users\Public\Desktop\Ubi Soft Web Site.lnk
[2010/07/30 16:40:55 | 000,000,923 | ---- | M] () -- C:\Users\user\Desktop\Busy Bees.lnk
[2010/07/30 16:35:13 | 000,720,896 | ---- | M] (Indigo Rose Corporation) -- C:\windows\iun6002.exe
[2010/07/30 16:24:20 | 000,000,934 | ---- | M] () -- C:\Users\user\Desktop\10 Maths Miracles.lnk
[2010/07/13 08:34:41 | 000,000,951 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
[2010/07/09 09:50:24 | 000,002,693 | ---- | M] () -- C:\Users\user\Desktop\Microsoft Office Word 2007.lnk
[2010/07/09 08:48:52 | 000,001,750 | ---- | M] () -- C:\Users\Public\Desktop\Browser Choice.lnk
[2010/07/09 00:45:58 | 000,040,833 | ---- | M] () -- C:\windows\System32\license.rtf
[2010/07/09 00:42:23 | 000,000,000 | -H-- | M] () -- C:\windows\System32\drivers\Msft_Kernel_SynTP_01007.Wdf
[2010/07/08 21:49:03 | 000,000,478 | ---- | M] () -- C:\windows\win.ini
[2010/07/08 20:50:33 | 000,524,288 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/07/08 20:50:33 | 000,524,288 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/07/08 20:50:33 | 000,065,536 | -HS- | M] () -- C:\Users\user\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/07/08 20:47:20 | 000,002,252 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SMART Board Tools.lnk
[2010/07/08 19:51:29 | 000,002,152 | ---- | M] () -- C:\Users\Public\Desktop\SMART Notebook 10.lnk
[2010/07/08 18:08:54 | 000,001,407 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/08 17:55:21 | 000,000,892 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2010/07/08 17:53:47 | 000,000,000 | RHS- | M] () -- C:\windows\System32\drivers\103C_HP_bNB_610_Y5336AN_0U_QCNU002318T_E536858-A41_4A_I308A_SHP_V26.08_68PVU F.0B_T091120_WU48-0_L409_M3064_J320_7Intel_86FD_92.00_#090915_N11AB4357;80864237_(VQ627EA#ABU)_XMOBILE_CN10_Z_2F.0B_G80862A12;80862A13.MRK
[2010/07/08 17:53:32 | 000,015,232 | ---- | M] () -- C:\windows\System32\results.xml
========== Files Created - No Company Name ========== [2010/08/06 20:13:06 | 000,000,442 | ---- | C] () -- C:\windows\tasks\ParetoLogic Registration3.job
[2010/08/06 20:12:57 | 000,001,067 | ---- | C] () -- C:\Users\user\Desktop\ParetoLogic PC Health Advisor.lnk
[2010/08/06 20:12:57 | 000,000,374 | ---- | C] () -- C:\windows\tasks\PC Health Advisor Defrag.job
[2010/08/06 20:12:57 | 000,000,356 | ---- | C] () -- C:\windows\tasks\PC Health Advisor.job
[2010/08/06 20:12:56 | 000,000,416 | ---- | C] () -- C:\windows\tasks\ParetoLogic Update Version3.job
[2010/08/02 15:52:35 | 000,000,149 | ---- | C] () -- C:\Users\user\Desktop\Inbox.url
[2010/07/30 19:53:55 | 000,000,888 | ---- | C] () -- C:\Users\user\Desktop\The Hat.lnk
[2010/07/30 16:46:45 | 000,001,031 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2010/07/30 16:46:41 | 000,001,007 | ---- | C] () -- C:\Users\user\Desktop\QuickTime Player.lnk
[2010/07/30 16:46:41 | 000,000,000 | ---- | C] () -- C:\windows\System32\QuickTime.qtp
[2010/07/30 16:45:09 | 000,001,935 | ---- | C] () -- C:\Users\Public\Desktop\Myst III Exile.lnk
[2010/07/30 16:45:09 | 000,001,024 | ---- | C] () -- C:\Users\Public\Desktop\Ubi Soft Web Site.lnk
[2010/07/30 16:40:55 | 000,000,923 | ---- | C] () -- C:\Users\user\Desktop\Busy Bees.lnk
[2010/07/30 16:24:20 | 000,000,934 | ---- | C] () -- C:\Users\user\Desktop\10 Maths Miracles.lnk
[2010/07/21 09:41:59 | 001,803,427 | ---- | C] () -- C:\Users\user\Desktop\countDownClock.zip
[2010/07/13 08:36:04 | 000,000,142 | ---- | C] () -- C:\windows\ODBC.INI
[2010/07/13 08:34:41 | 000,000,951 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
[2010/07/09 09:50:24 | 000,002,693 | ---- | C] () -- C:\Users\user\Desktop\Microsoft Office Word 2007.lnk
[2010/07/09 08:48:52 | 000,001,750 | ---- | C] () -- C:\Users\Public\Desktop\Browser Choice.lnk
[2010/07/09 00:42:23 | 000,000,000 | -H-- | C] () -- C:\windows\System32\drivers\Msft_Kernel_SynTP_01007.Wdf
[2010/07/09 00:40:54 | 2409,078,784 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/08 20:47:20 | 000,002,252 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SMART Board Tools.lnk
[2010/07/08 19:51:29 | 000,002,152 | ---- | C] () -- C:\Users\Public\Desktop\SMART Notebook 10.lnk
[2010/07/08 18:08:54 | 000,001,407 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/08 18:08:16 | 000,000,000 | ---- | C] () -- C:\Users\user\AppData\Local\QSwitch.txt
[2010/07/08 18:08:16 | 000,000,000 | ---- | C] () -- C:\Users\user\AppData\Local\DSwitch.txt
[2010/07/08 18:08:16 | 000,000,000 | ---- | C] () -- C:\Users\user\AppData\Local\AtStart.txt
[2010/07/08 18:01:34 | 001,765,168 | ---- | C] () -- C:\windows\System32\drivers\snp2uvc.sys
[2010/07/08 18:01:34 | 000,027,184 | ---- | C] () -- C:\windows\snuvcdsm.exe
[2010/07/08 18:01:34 | 000,013,022 | ---- | C] () -- C:\windows\snp2uvc.src
[2010/07/08 18:01:33 | 000,034,480 | ---- | C] () -- C:\windows\System32\drivers\sncduvc.sys
[2010/07/08 18:01:33 | 000,015,497 | ---- | C] () -- C:\windows\snp2uvc.ini
[2010/07/08 17:57:42 | 000,015,222 | ---- | C] () -- C:\windows\System32\nbspkrs.ico
[2010/07/08 17:57:42 | 000,003,774 | ---- | C] () -- C:\windows\System32\bltinmic.ico
[2010/07/08 17:57:42 | 000,003,774 | ---- | C] () -- C:\windows\System32\2hps.ico
[2010/07/08 17:55:09 | 000,000,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2010/07/08 17:53:47 | 000,000,000 | RHS- | C] () -- C:\windows\System32\drivers\103C_HP_bNB_610_Y5336AN_0U_QCNU002318T_E536858-A41_4A_I308A_SHP_V26.08_68PVU F.0B_T091120_WU48-0_L409_M3064_J320_7Intel_86FD_92.00_#090915_N11AB4357;80864237_(VQ627EA#ABU)_XMOBILE_CN10_Z_2F.0B_G80862A12;80862A13.MRK
[2010/07/08 17:53:32 | 000,015,232 | ---- | C] () -- C:\windows\System32\results.xml
[2010/07/08 17:52:59 | 000,524,288 | -HS- | C] () -- C:\Users\user\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/07/08 17:52:59 | 000,524,288 | -HS- | C] () -- C:\Users\user\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/07/08 17:52:59 | 000,262,144 | -HS- | C] () -- C:\Users\user\ntuser.dat.LOG1
[2010/07/08 17:52:59 | 000,065,536 | -HS- | C] () -- C:\Users\user\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/07/08 17:52:59 | 000,000,290 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/07/08 17:52:59 | 000,000,272 | ---- | C] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/07/08 17:52:59 | 000,000,000 | -HS- | C] () -- C:\Users\user\ntuser.dat.LOG2
[2010/07/08 17:52:58 | 001,310,720 | -HS- | C] () -- C:\Users\user\NTUSER.DAT
[2010/07/08 17:52:58 | 000,000,020 | -HS- | C] () -- C:\Users\user\ntuser.ini
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\windows\System32\OGACheckControl.dll
[2009/07/16 01:50:42 | 000,013,312 | ---- | C] () -- C:\windows\LPRES.DLL
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\windows\System32\BWContextHandler.dll
< End of report >