This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Wife's complaining her computer is running very slow

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 9/8/2010 4:22:33 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Shannon O'Conner\Documents\downloads\whatthetech
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 367.00 Mb Available Physical Memory | 36.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 261.23 Gb Free Space | 87.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHANNONOCONNER
Current User Name: Shannon O'Conner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 360 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Shannon O'Conner\Documents\downloads\whatthetech\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\tbh\base\bin\tbhSystray.exe (eBay)
PRC - c:\Program Files\tbh\base\bin\tbhDaemon.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10d.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\tbh\monitor\bin\tbhMonitor.exe ()
PRC - c:\Program Files\AIM Toolbar\aimtbServer.exe (AOL LLC.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Shannon O'Conner\Documents\downloads\whatthetech\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (tbhMonitor.exe) – C:\Program Files\tbh\monitor\bin\tbhMonitor.exe ()
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)


========== Driver Services (SafeList) ==========

DRV - (RimUsb) – C:\Windows\System32\Drivers\RimUsb.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (epfwtdir) – C:\Windows\System32\drivers\epfwtdir.sys (ESET)
DRV - (ehdrv) – C:\Windows\System32\drivers\ehdrv.sys (ESET)
DRV - (eamon) – C:\Windows\System32\drivers\eamon.sys (ESET)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (BCM43XV) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (R5U870FLx86) – C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) – C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSFHWAZL) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.5.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: [removed]:1.0.17641
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50-ff-aim-ab-en-us&query="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/12/30 16:36:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/03 08:02:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/03 08:02:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009/12/19 20:10:36 | 000,000,000 | —D | M]

[2009/12/30 15:37:34 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Extensions
[2009/12/25 08:18:09 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/08/09 03:00:48 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions
[2010/01/01 08:36:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/18 05:59:41 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/01/11 14:27:52 | 000,000,000 | —D | M] (AIM Toolbar) – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/07/18 06:00:12 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions\[removed]
[2010/08/09 03:00:48 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions\staged-xpis
[2010/01/11 14:28:48 | 000,004,554 | —- | M] () – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\searchplugins\aim-search.xml
[2010/01/11 14:28:00 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/10 08:55:35 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 14:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/19 14:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [tbhSystray] C:\Program Files\tbh\base\bin\tbhSystray.exe (eBay)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Shannon O'Conner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Shannon O'Conner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0f33a120-280b-11df-a02f-001b2438095d}\Shell - "" = AutoRun
O33 - MountPoints2\{0f33a120-280b-11df-a02f-001b2438095d}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{2b97340a-eee2-11de-b8c0-001b2438095d}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe – File not found
O33 - MountPoints2\{35adfb3c-f728-11de-a37f-001b2438095d}\Shell\AutoRun\command - "" = E:\.\Vado\Vado.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 360 Days ==========

[2010/09/08 16:14:03 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\downloads
[2010/06/24 14:28:46 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/06/24 14:24:44 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/06/24 14:21:45 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/06/24 13:57:03 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/06/24 13:48:28 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010/06/07 14:22:47 | 000,000,000 | —D | C] – C:\6c1cbcf0b82c218e82c9291b62
[2010/05/18 16:35:16 | 000,197,920 | —- | C] (Apple Inc.) – C:\Windows\System32\dnssdX.dll
[2010/05/18 16:35:16 | 000,107,808 | —- | C] (Apple Inc.) – C:\Windows\System32\dns-sd.exe
[2010/05/18 16:35:16 | 000,091,424 | —- | C] (Apple Inc.) – C:\Windows\System32\dnssd.dll
[2010/05/15 07:23:48 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Canon Easy-PhotoPrint EX
[2010/05/10 08:55:35 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\E-centives
[2010/05/04 09:43:28 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2010/04/19 20:47:44 | 003,062,048 | —- | C] (Apple, Inc.) – C:\Windows\System32\usbaaplrc.dll
[2010/04/15 03:11:26 | 003,502,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/04/15 03:11:26 | 003,468,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010/04/15 03:11:01 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010/04/15 03:09:56 | 000,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiougc.exe
[2010/04/15 03:09:55 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2010/04/15 03:08:51 | 000,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2010/04/15 03:08:50 | 000,220,672 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codecp.acm
[2010/04/11 09:44:15 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/04/11 09:44:13 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/04/11 09:44:06 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/04/11 09:43:55 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/04/11 09:43:51 | 001,830,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/04/11 09:43:46 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/04/11 09:43:41 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2010/04/11 09:43:35 | 000,459,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/04/11 09:43:32 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/04/11 09:43:27 | 000,192,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/04/11 09:43:26 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/04/11 09:43:23 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2010/04/11 09:43:23 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2010/04/11 09:43:18 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/04/11 09:43:15 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/04/11 09:43:13 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/04/11 09:43:07 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2010/04/11 09:43:04 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/04/11 09:43:02 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/04/11 09:43:00 | 001,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/04/11 09:43:00 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2010/04/11 09:43:00 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2010/03/18 22:16:16 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/03/18 22:16:16 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/03/11 08:42:30 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2010/03/11 08:42:13 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2010/03/09 11:18:31 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\DUANE FAMILY PICS
[2010/03/04 18:16:54 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\REBECCA
[2010/02/24 10:20:32 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/02/24 10:17:40 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2010/02/24 10:17:39 | 000,473,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2010/02/24 10:17:27 | 000,435,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2010/02/24 10:17:23 | 000,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2010/02/24 10:17:00 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2010/02/24 10:16:47 | 000,431,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/02/24 10:16:43 | 000,154,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2010/02/24 10:16:43 | 000,154,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2010/02/24 10:16:42 | 000,312,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2010/02/15 21:38:32 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Microsoft Games
[2010/02/15 14:39:55 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\CALEDONIA
[2010/02/10 12:59:40 | 001,327,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2010/02/10 12:59:26 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2010/02/10 12:59:24 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2010/02/10 12:59:21 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvfw32.dll
[2010/02/10 12:59:20 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avicap32.dll
[2010/02/08 22:01:26 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\AIM Toolbar
[2010/01/24 16:15:20 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2010/01/21 10:38:25 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/01/18 14:37:01 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\CHRISTINE FERRARE
[2010/01/14 13:09:46 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Move Networks
[2010/01/13 08:49:34 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/01/13 08:49:33 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/01/13 08:49:29 | 000,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/01/13 08:49:29 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2010/01/13 08:49:27 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/01/11 14:25:29 | 000,000,000 | —D | C] – C:\ProgramData\AIM Toolbar
[2010/01/11 14:25:29 | 000,000,000 | —D | C] – C:\Program Files\AIM Toolbar
[2010/01/11 14:25:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2010/01/11 14:25:17 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\acccore
[2010/01/11 14:25:15 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\AOL
[2010/01/11 14:25:15 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\AIM
[2010/01/11 14:23:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AOL
[2010/01/07 17:47:44 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\skypePM
[2010/01/07 17:43:34 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Skype
[2010/01/07 17:43:28 | 000,000,000 | —D | C] – C:\Program Files\tbh
[2010/01/07 17:41:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/01/07 17:41:14 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/01/07 17:40:43 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2010/01/01 14:03:01 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2010/01/01 14:00:20 | 000,000,000 | —D | C] – C:\Program Files\CONEXANT
[2010/01/01 13:58:29 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/01/01 13:47:54 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Scansoft
[2010/01/01 11:40:48 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\TomTom
[2010/01/01 08:36:50 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Google
[2010/01/01 08:33:27 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\TO BE FILED
[2010/01/01 08:32:54 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\DR PHIL
[2010/01/01 08:32:06 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\FURION
[2010/01/01 02:00:55 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2009/12/31 12:03:29 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Apple Computer
[2009/12/31 12:03:28 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Apple Computer
[2009/12/31 12:02:46 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2009/12/31 12:02:45 | 000,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2009/12/31 12:00:07 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2009/12/31 11:59:58 | 000,000,000 | —D | C] – C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/31 11:59:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2009/12/31 11:54:51 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2009/12/31 11:53:39 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Apple
[2009/12/31 11:48:38 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2009/12/31 11:48:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2009/12/30 16:38:45 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2009/12/30 16:38:35 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2009/12/30 16:36:42 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2009/12/30 15:37:20 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Mozilla
[2009/12/30 15:36:51 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/12/30 13:10:32 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2009/12/30 11:21:27 | 000,000,000 | —D | C] – C:\ProgramData\InstallShield
[2009/12/30 11:21:15 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\ScanSoft
[2009/12/30 11:20:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2009/12/30 11:20:54 | 000,000,000 | —D | C] – C:\ProgramData\ScanSoft
[2009/12/30 11:20:28 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2009/12/30 11:17:42 | 000,000,000 | —D | C] – C:\Program Files\ArcSoft
[2009/12/30 11:17:41 | 000,212,480 | —- | C] (Eastman Kodak) – C:\Windows\PCDLIB32.DLL
[2009/12/30 11:17:31 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2009/12/30 11:16:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\InstallShield
[2009/12/30 11:16:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2009/12/30 11:08:30 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonBJ
[2009/12/30 11:08:08 | 000,000,000 | -H-D | C] – C:\Windows\System32\CanonIJ Uninstaller Information
[2009/12/30 11:05:50 | 000,215,040 | —- | C] (CANON INC.) – C:\Windows\System32\CNMLM91.DLL
[2009/12/30 11:05:43 | 000,208,896 | —- | C] (CANON INC.) – C:\Windows\System32\CNC970L.DLL
[2009/12/30 11:05:43 | 000,188,416 | —- | C] (Canon Inc.) – C:\Windows\System32\CNC970O.DLL
[2009/12/30 11:05:43 | 000,098,304 | —- | C] (CANON INC.) – C:\Windows\System32\CNC970I.DLL
[2009/12/30 11:05:42 | 001,400,832 | —- | C] (CANON INC.) – C:\Windows\System32\CNC970C.DLL
[2009/12/30 11:05:30 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2009/12/30 11:05:17 | 000,362,496 | —- | C] (CANON INC.) – C:\Windows\System32\CNMNPPM.DLL
[2009/12/30 11:05:17 | 000,142,336 | —- | C] (CANON INC.) – C:\Windows\System32\CNMNPUI.DLL
[2009/12/30 11:04:55 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2009/12/25 14:44:47 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Adobe
[2009/12/25 10:53:07 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deploytk.dll
[2009/12/25 10:53:07 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2009/12/25 10:53:06 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2009/12/25 10:53:06 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2009/12/25 10:52:11 | 000,000,000 | —D | C] – C:\Program Files\Java
[2009/12/25 09:03:07 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2009/12/25 09:02:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2009/12/25 09:02:32 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2009/12/25 08:18:34 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\TomTom by duane
[2009/12/25 08:18:31 | 000,000,000 | —D | C] – C:\ProgramData\TomTom
[2009/12/25 08:18:05 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\TomTom
[2009/12/25 08:18:05 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\TomTom
[2009/12/25 08:18:05 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla
[2009/12/25 08:17:51 | 000,000,000 | —D | C] – C:\Program Files\TomTom International B.V
[2009/12/25 08:17:23 | 000,000,000 | —D | C] – C:\Program Files\TomTom HOME 2
[2009/12/25 08:12:49 | 000,000,000 | —D | C] – C:\Program Files\TomTom DesktopSuite
[2009/12/22 02:47:33 | 000,371,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2009/12/22 02:47:33 | 000,313,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rstrui.exe
[2009/12/22 02:47:33 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srdelayed.exe
[2009/12/22 02:47:31 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2009/12/22 02:47:30 | 000,019,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2009/12/22 02:47:29 | 000,905,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2009/12/22 02:47:27 | 000,944,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2009/12/22 02:47:24 | 000,620,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2009/12/22 02:47:22 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2009/12/22 02:47:22 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cfgmgr32.dll
[2009/12/22 02:47:20 | 000,260,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpx.dll
[2009/12/22 02:47:20 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kbd106n.dll
[2009/12/22 02:47:17 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lodctr.exe
[2009/12/22 02:47:16 | 000,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\loadperf.dll
[2009/12/22 02:47:16 | 000,032,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unlodctr.exe
[2009/12/22 02:47:16 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prflbmsg.dll
[2009/12/22 02:47:11 | 000,035,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2009/12/22 02:47:09 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2009/12/22 02:47:08 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dispci.dll
[2009/12/22 02:47:08 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\batt.dll
[2009/12/22 02:44:53 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/12/22 02:44:52 | 000,654,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/12/22 02:44:46 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/12/22 02:44:46 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/12/22 02:44:46 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/12/22 02:44:46 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/12/22 02:43:42 | 000,512,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/12/22 02:42:15 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMASF.DLL
[2009/12/22 02:42:15 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\LAPRXY.DLL
[2009/12/22 02:42:15 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asferror.dll
[2009/12/22 02:41:48 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/12/22 02:41:48 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/12/22 02:40:24 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLC.dll
[2009/12/22 02:40:22 | 000,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcbuilder.exe
[2009/12/22 02:40:22 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2009/12/22 02:40:18 | 000,566,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2009/12/22 02:40:17 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2009/12/22 02:40:16 | 000,186,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2009/12/22 02:39:17 | 000,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/12/22 02:39:16 | 000,712,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/12/22 02:39:14 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/12/22 02:34:15 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2009/12/22 02:34:15 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.exe
[2009/12/22 02:34:12 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcmonitor.dll
[2009/12/22 02:34:11 | 001,984,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2009/12/22 02:34:11 | 000,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2009/12/22 02:33:18 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printcom.dll
[2009/12/22 02:33:17 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2009/12/22 02:32:48 | 002,031,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/12/22 02:32:24 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2009/12/22 02:32:24 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshrm.dll
[2009/12/22 02:31:44 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.tlb
[2009/12/22 02:31:44 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amcompat.tlb
[2009/12/22 02:30:27 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbunattend.exe
[2009/12/22 02:29:32 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2009/12/22 02:24:16 | 000,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/12/22 02:24:15 | 000,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/12/22 02:24:15 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/12/22 02:24:14 | 000,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/12/22 02:23:59 | 000,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/12/22 02:23:55 | 000,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/12/22 02:23:54 | 000,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/12/22 02:23:53 | 000,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/12/21 05:37:34 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2009/12/21 05:37:33 | 000,272,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\polstore.dll
[2009/12/21 05:37:33 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winipsec.dll
[2009/12/21 05:34:39 | 000,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched20.dll
[2009/12/21 05:34:38 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched32.dll
[2009/12/21 05:34:32 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kmddsp.tsp
[2009/12/21 05:34:30 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rascfg.dll
[2009/12/21 05:34:30 | 000,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasser.dll
[2009/12/21 05:34:29 | 000,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2009/12/21 05:34:29 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ndptsp.tsp
[2009/12/21 05:34:28 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmxs.dll
[2009/12/21 05:34:27 | 000,564,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2009/12/21 05:34:27 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcfgx.dll
[2009/12/21 05:34:24 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icsunattend.exe
[2009/12/21 05:34:20 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshqos.dll
[2009/12/21 05:34:19 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\traffic.dll
[2009/12/21 05:34:18 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pacerprf.dll
[2009/12/21 05:34:16 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2009/12/21 05:31:35 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/12/21 05:31:34 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2009/12/21 05:31:34 | 000,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/12/21 05:28:46 | 000,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msoeacct.dll
[2009/12/21 05:28:46 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msoert2.dll
[2009/12/21 05:28:46 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ACCTRES.dll
[2009/12/21 05:25:32 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2009/12/21 05:25:31 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MRINFO.EXE
[2009/12/21 05:25:31 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TCPSVCS.EXE
[2009/12/21 05:25:30 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2009/12/21 05:25:30 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HOSTNAME.EXE
[2009/12/21 05:25:29 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\finger.exe
[2009/12/21 05:25:28 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NETSTAT.EXE
[2009/12/21 05:25:28 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2009/12/21 05:25:27 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ARP.EXE
[2009/12/21 05:25:20 | 000,213,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2009/12/21 05:21:32 | 000,704,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2009/12/21 05:21:28 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wtsapi32.dll
[2009/12/21 05:21:20 | 000,028,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\battc.sys
[2009/12/21 05:15:53 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2009/12/21 05:15:51 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanapi.dll
[2009/12/21 05:15:50 | 000,297,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2009/12/21 05:15:50 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2009/12/21 05:15:50 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanhlp.dll
[2009/12/21 05:12:53 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2009/12/21 05:12:52 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml6r.dll
[2009/12/21 05:07:17 | 001,233,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/12/21 05:04:38 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2009/12/21 05:04:37 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2009/12/21 05:02:12 | 002,855,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2009/12/21 05:02:12 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2009/12/21 05:02:11 | 000,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rrinstaller.exe
[2009/12/21 05:02:11 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mferror.dll
[2009/12/21 05:02:10 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfpmp.exe
[2009/12/21 05:02:07 | 002,433,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2009/12/21 04:31:25 | 002,452,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/12/21 04:24:52 | 000,500,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/12/21 04:24:52 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/12/21 04:20:31 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2009/12/21 04:20:31 | 000,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2009/12/21 04:15:37 | 000,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2009/12/21 04:10:36 | 000,414,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2009/12/21 04:08:27 | 000,713,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2009/12/21 04:05:59 | 000,356,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2009/12/21 04:03:31 | 000,392,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FirewallAPI.dll
[2009/12/21 04:03:28 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icfupgd.dll
[2009/12/21 04:03:28 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wfapigp.dll
[2009/12/21 04:03:27 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmifw.dll
[2009/12/21 03:54:45 | 001,244,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2009/12/21 03:54:45 | 000,177,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/12/21 03:54:44 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/12/21 03:54:42 | 000,292,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/12/21 03:54:42 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/12/21 03:54:42 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/12/21 03:54:42 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2009/12/21 03:54:42 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2009/12/21 03:48:08 | 000,696,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2009/12/21 03:41:31 | 000,045,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pciidex.sys
[2009/12/21 03:41:30 | 000,109,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2009/12/21 03:39:41 | 000,104,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWWIN.EXE
[2009/12/21 03:37:57 | 002,923,520 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/12/21 03:34:07 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcfg.exe
[2009/12/21 03:31:43 | 001,808,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0046.dll
[2009/12/21 03:31:43 | 001,793,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0045.dll
[2009/12/21 03:31:43 | 001,411,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0047.dll
[2009/12/21 03:31:42 | 001,782,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0039.dll
[2009/12/21 03:31:42 | 001,558,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0049.dll
[2009/12/21 03:31:42 | 001,236,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0020.dll
[2009/12/21 03:31:41 | 005,499,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0022.dll
[2009/12/21 03:31:41 | 002,136,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0021.dll
[2009/12/21 03:31:40 | 007,964,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0024.dll
[2009/12/21 03:31:40 | 005,791,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0026.dll
[2009/12/21 03:31:39 | 006,224,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0027.dll
[2009/12/21 03:31:38 | 004,175,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0010.dll
[2009/12/21 03:31:38 | 002,466,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0011.dll
[2009/12/21 03:31:37 | 004,981,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0013.dll
[2009/12/21 03:31:37 | 003,331,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0018.dll
[2009/12/21 03:31:36 | 006,781,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0019.dll
[2009/12/21 03:31:35 | 011,722,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0001.dll
[2009/12/21 03:31:35 | 004,164,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0002.dll
[2009/12/21 03:31:35 | 001,452,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0003.dll
[2009/12/21 03:31:33 | 012,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2009/12/21 03:31:33 | 002,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2009/12/21 03:31:32 | 004,093,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004c.dll
[2009/12/21 03:31:32 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004a.dll
[2009/12/21 03:31:32 | 001,702,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004b.dll
[2009/12/21 03:31:31 | 004,045,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons003e.dll
[2009/12/21 03:31:31 | 001,972,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004e.dll
[2009/12/21 03:31:30 | 006,014,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons001a.dll
[2009/12/21 03:31:30 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons002a.dll
[2009/12/21 03:31:29 | 006,585,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons001b.dll
[2009/12/21 03:31:29 | 006,346,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons001d.dll
[2009/12/21 03:31:28 | 009,892,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000a.dll
[2009/12/21 03:31:27 | 006,237,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000c.dll
[2009/12/21 03:31:27 | 001,722,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000d.dll
[2009/12/21 03:31:26 | 005,654,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000f.dll
[2009/12/21 03:31:26 | 004,616,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0414.dll
[2009/12/21 03:31:25 | 005,090,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0416.dll
[2009/12/21 03:31:25 | 005,031,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0816.dll
[2009/12/21 03:31:24 | 007,042,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons081a.dll
[2009/12/21 03:31:24 | 005,071,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsModels0011.dll
[2009/12/21 03:31:23 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0046.dll
[2009/12/21 03:31:23 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0045.dll
[2009/12/21 03:31:22 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0049.dll
[2009/12/21 03:31:22 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0047.dll
[2009/12/21 03:31:21 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0039.dll
[2009/12/21 03:31:21 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0020.dll
[2009/12/21 03:31:20 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0024.dll
[2009/12/21 03:31:20 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0022.dll
[2009/12/21 03:31:20 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0021.dll
[2009/12/21 03:31:19 | 001,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0027.dll
[2009/12/21 03:31:19 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0026.dll
[2009/12/21 03:31:18 | 004,493,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0010.dll
[2009/12/21 03:31:18 | 002,655,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0011.dll
[2009/12/21 03:31:17 | 003,464,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0013.dll
[2009/12/21 03:31:17 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0018.dll
[2009/12/21 03:31:16 | 004,495,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0019.dll
[2009/12/21 03:31:16 | 002,597,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0001.dll
[2009/12/21 03:31:16 | 001,523,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0000.dll
[2009/12/21 03:31:15 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0003.dll
[2009/12/21 03:31:15 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0002.dll
[2009/12/21 03:31:14 | 004,874,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0009.dll
[2009/12/21 03:31:14 | 002,241,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0007.dll
[2009/12/21 03:31:13 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004b.dll
[2009/12/21 03:31:13 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004a.dll
[2009/12/21 03:31:12 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004e.dll
[2009/12/21 03:31:12 | 003,102,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004c.dll
[2009/12/21 03:31:11 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData001a.dll
[2009/12/21 03:31:11 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData003e.dll
[2009/12/21 03:31:11 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData002a.dll
[2009/12/21 03:31:10 | 004,493,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData001d.dll
[2009/12/21 03:31:10 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData001b.dll
[2009/12/21 03:31:09 | 009,845,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000a.dll
[2009/12/21 03:31:08 | 002,641,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000c.dll
[2009/12/21 03:31:08 | 002,340,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000d.dll
[2009/12/21 03:31:08 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000f.dll
[2009/12/21 03:31:07 | 004,493,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0414.dll
[2009/12/21 03:31:06 | 004,493,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0816.dll
[2009/12/21 03:31:06 | 004,493,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0416.dll
[2009/12/21 03:31:06 | 000,797,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2009/12/21 03:31:05 | 006,917,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0c1a.dll
[2009/12/21 03:31:05 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData081a.dll
[2009/12/21 03:31:04 | 001,963,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0c1a.dll
[2009/12/21 03:12:59 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2009/12/21 03:08:09 | 008,138,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ssBranded.scr
[2009/12/21 02:36:58 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/12/21 02:36:47 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/12/21 02:36:47 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/12/21 02:16:29 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/12/21 02:16:23 | 004,247,552 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/12/21 02:16:22 | 001,686,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2009/12/21 02:15:24 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2009/12/21 02:15:23 | 000,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2009/12/21 02:14:28 | 000,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2009/12/21 02:13:54 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\INETRES.dll
[2009/12/21 02:13:01 | 001,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2009/12/21 02:12:34 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmi.dll
[2009/12/21 02:08:15 | 000,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2009/12/21 02:08:15 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2009/12/21 02:07:53 | 000,321,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2009/12/21 02:06:06 | 000,604,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2009/12/21 02:05:19 | 008,147,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2009/12/21 02:05:17 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2009/12/21 02:05:15 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2009/12/21 02:05:14 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2009/12/21 02:05:04 | 000,311,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unregmp2.exe
[2009/12/20 15:43:54 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\PeerNetworking
[2009/12/20 12:01:08 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Macromedia
[2009/12/20 12:01:08 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Adobe
[2009/12/20 10:44:06 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2009/12/20 05:20:13 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2009/12/19 21:35:02 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\zoie
[2009/12/19 21:35:01 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\wedding
[2009/12/19 21:35:00 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Documents\Videos
[2009/12/19 21:35:00 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Documents\Searches
[2009/12/19 21:35:00 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Documents\Saved Games
[2009/12/19 21:32:15 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Documents\Pictures
[2009/12/19 21:32:08 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\new cevia pics
[2009/12/19 21:29:48 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Documents\Music
[2009/12/19 21:29:48 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Documents\Links
[2009/12/19 21:29:06 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\Halloween pics 09
[2009/12/19 21:29:05 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\flat zoie
[2009/12/19 21:28:52 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\familt pics
[2009/12/19 21:28:52 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\Dr. Phil Releases
[2009/12/19 21:28:52 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\Dr. Phil Field Shoots
[2009/12/19 21:28:45 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\OneNote Notebooks
[2009/12/19 21:28:15 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Desktop\DCIM
[2009/12/19 21:28:09 | 002,032,936 | —- | C] (Skype Technologies S.A.) – C:\Users\Shannon O'Conner\Desktop\SkypeSetup.exe
[2009/12/19 21:28:05 | 051,418,424 | —- | C] (Apple Inc.) – C:\Users\Shannon O'Conner\Desktop\iTunesSetup.exe
[2009/12/19 21:28:02 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\bach party
[2009/12/19 20:48:38 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\2009-08-17 Callie's birthday
[2009/12/19 20:47:39 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\Documents\2007-04-30 SO pictures
[2009/12/19 20:10:35 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2009/12/19 20:10:35 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2009/12/19 19:36:12 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2009/12/19 19:35:55 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2009/12/19 19:35:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2009/12/19 19:35:21 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2009/12/19 19:35:21 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2009/12/19 19:33:23 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Microsoft Help
[2009/12/19 19:33:19 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2009/12/19 19:33:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2009/12/19 19:33:01 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2009/12/19 19:32:44 | 000,000,000 | RH-D | C] – C:\MSOCache
[2009/12/19 19:16:46 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\GetRightToGo
[2009/12/19 18:53:22 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2009/12/19 18:52:03 | 000,000,000 | —D | C] – C:\Windows\Debug
[2009/12/19 18:50:56 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2009/12/19 18:50:45 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2009/12/19 18:48:44 | 000,000,000 | —D | C] – C:\Windows\Panther
[2009/12/19 18:48:30 | 000,000,000 | -HSD | C] – C:\Boot
[2009/12/19 18:41:52 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2009/12/19 18:37:44 | 000,356,352 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvusmu.exe
[2009/12/19 18:37:04 | 001,079,840 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcpluir.dll
[2009/12/19 18:37:04 | 000,768,544 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcplui.exe
[2009/12/19 18:37:04 | 000,453,152 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvuninst.exe
[2009/12/19 18:37:04 | 000,420,384 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcpl.cpl
[2009/12/19 18:37:04 | 000,313,888 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvexpbar.dll
[2009/12/19 18:37:03 | 000,000,000 | —D | C] – C:\swsetup
[2009/12/19 18:30:59 | 002,421,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/12/19 18:30:59 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/12/19 18:30:41 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2009/12/19 18:30:41 | 000,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2009/12/19 18:30:41 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2009/12/19 18:30:29 | 000,171,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/12/19 18:30:29 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/12/19 17:55:33 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Searches
[2009/12/19 17:55:26 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Identities
[2009/12/19 17:55:24 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Contacts
[2009/12/19 17:55:23 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\VirtualStore
[2009/12/19 17:55:20 | 000,000,000 | –SD | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Microsoft
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Videos
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Saved Games
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Pictures
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Music
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Links
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Favorites
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Downloads
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Documents
[2009/12/19 17:55:20 | 000,000,000 | R–D | C] – C:\Users\Shannon O'Conner\Desktop
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\AppData\Local\Temporary Internet Files
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Templates
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Start Menu
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\SendTo
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Recent
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\PrintHood
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\NetHood
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Documents\My Videos
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Documents\My Pictures
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Documents\My Music
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\My Documents
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Local Settings
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\AppData\Local\History
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Cookies
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\Application Data
[2009/12/19 17:55:20 | 000,000,000 | -HSD | C] – C:\Users\Shannon O'Conner\AppData\Local\Application Data
[2009/12/19 17:55:20 | 000,000,000 | -H-D | C] – C:\Users\Shannon O'Conner\AppData
[2009/12/19 17:55:20 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Temp
[2009/12/19 17:55:20 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Local\Microsoft
[2009/12/19 17:55:20 | 000,000,000 | —D | C] – C:\Users\Shannon O'Conner\AppData\Roaming\Media Center Programs
[3 C:\Users\Shannon O'Conner\Desktop\*.tmp files -> C:\Users\Shannon O'Conner\Desktop\*.tmp -> ]

========== Files - Modified Within 360 Days ==========

[2010/09/08 16:22:38 | 003,145,728 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT
[2010/09/08 16:19:50 | 000,043,348 | —- | M] () – C:\ProgramData\nvModes.001
[2010/09/08 16:19:12 | 000,000,881 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\HiJackThis.exe - Shortcut.lnk
[2010/09/08 16:18:55 | 000,000,840 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\OTL.exe - Shortcut.lnk
[2010/09/08 16:02:47 | 000,004,080 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/08 16:02:47 | 000,004,080 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/08 16:02:40 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/08 16:02:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/08 16:02:28 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2010/09/08 15:58:18 | 157,825,226 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/07/11 12:28:07 | 000,043,348 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/06/24 14:25:21 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/06/24 14:05:28 | 002,605,304 | -H– | M] () – C:\Users\Shannon O'Conner\AppData\Local\IconCache.db
[2010/06/24 13:49:10 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/24 13:49:10 | 000,001,854 | —- | M] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/06/13 06:38:26 | 001,048,576 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.2.regtrans-ms
[2010/06/13 06:38:26 | 001,048,576 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.1.regtrans-ms
[2010/06/13 06:38:26 | 001,048,576 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.0.regtrans-ms
[2010/06/13 06:38:26 | 000,065,536 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.blf
[2010/06/04 16:44:10 | 000,029,696 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\RESUME NEW.doc
[2010/06/04 10:45:31 | 000,029,696 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\heights newsletter.doc
[2010/06/03 18:21:07 | 000,026,112 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\Family address.doc
[2010/06/03 18:19:52 | 000,002,627 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\Microsoft Office Word 2007.lnk
[2010/06/03 09:45:22 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$ights newsletter.doc
[2010/05/25 13:27:27 | 000,032,768 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\VIP.doc
[2010/05/25 13:27:27 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$VIP.doc
[2010/05/25 10:41:50 | 000,621,552 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/25 10:41:50 | 000,104,868 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/25 10:41:49 | 000,720,952 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/21 14:14:28 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/20 15:24:33 | 000,024,576 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\UFO.doc
[2010/05/18 16:35:16 | 000,197,920 | —- | M] (Apple Inc.) – C:\Windows\System32\dnssdX.dll
[2010/05/18 16:35:16 | 000,107,808 | —- | M] (Apple Inc.) – C:\Windows\System32\dns-sd.exe
[2010/05/18 16:35:16 | 000,091,424 | —- | M] (Apple Inc.) – C:\Windows\System32\dnssd.dll
[2010/05/15 13:00:58 | 000,011,225 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\duane game.jpg
[2010/05/07 05:45:33 | 000,009,878 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\mombeehive.jpg
[2010/04/19 20:47:44 | 003,062,048 | —- | M] (Apple, Inc.) – C:\Windows\System32\usbaaplrc.dll
[2010/04/12 08:58:48 | 000,000,943 | —- | M] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/04/02 13:57:40 | 000,026,624 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\Dr. Phil Invoice Jasper.doc
[2010/03/18 22:16:16 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/03/18 22:16:16 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/03/17 17:55:23 | 000,558,008 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\ham dijon recipe.docx
[2010/03/17 09:37:04 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$m dijon recipe.docx
[2010/03/14 23:18:05 | 000,000,227 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\Sound - Shortcut.lnk
[2010/03/14 19:55:22 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$-Mission-OWN-100310.doc
[2010/03/09 09:54:01 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2010/03/09 09:52:37 | 000,671,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/03/09 09:52:20 | 000,459,264 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/03/09 09:51:10 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/03/09 09:50:57 | 001,830,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/03/09 09:50:34 | 000,192,512 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/03/09 09:50:34 | 000,180,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/03/09 09:50:34 | 000,056,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/03/09 09:50:34 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/03/09 09:50:25 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/03/09 09:50:25 | 000,078,336 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/03/09 09:50:24 | 000,380,928 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/03/09 09:50:24 | 000,230,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/03/09 09:50:24 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2010/03/09 09:49:34 | 000,347,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2010/03/09 09:49:34 | 000,214,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2010/03/09 09:48:34 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2010/03/09 07:50:28 | 000,389,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/03/09 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/03/09 07:17:37 | 000,070,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/03/09 05:43:52 | 000,048,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2010/03/09 05:37:03 | 001,383,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/03/04 12:24:26 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010/03/02 18:43:48 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$2 CF-113-SweetEnd-Outline-OWN-100224.doc
[2010/03/02 18:42:37 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$-113-SweetEnd-Outline-OWN-100224.doc
[2010/02/26 10:53:46 | 000,100,432 | —- | M] () – C:\Users\Shannon O'Conner\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/26 10:52:08 | 000,374,488 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/02/20 16:54:40 | 000,024,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2010/02/20 16:51:43 | 000,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2010/02/19 15:14:56 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$Holiday Feast breakdown.doc
[2010/02/19 13:11:25 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$liday Feast breakdown.doc
[2010/02/18 07:54:09 | 003,502,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/02/18 07:54:03 | 003,468,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010/02/18 07:22:03 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2010/02/18 05:04:51 | 000,022,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netiougc.exe
[2010/02/02 14:40:20 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$ntryraidssnacksbreakdown.doc
[2010/01/31 12:24:27 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$31 pantryraid breakfastbreakdown.doc
[2010/01/29 12:05:41 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$29 cookingwithguysbreakdown.doc
[2010/01/25 05:58:44 | 000,473,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2010/01/25 05:58:44 | 000,154,624 | —- | M] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2010/01/25 05:58:44 | 000,154,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2010/01/25 05:58:29 | 000,472,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2010/01/25 05:56:33 | 000,312,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2010/01/25 01:36:22 | 000,435,712 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2010/01/25 01:36:19 | 000,515,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2010/01/25 01:36:05 | 000,431,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/01/25 01:35:58 | 000,523,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2010/01/24 16:46:30 | 000,238,023 | —- | M] () – C:\Windows\hpoins21.dat
[2010/01/24 16:19:38 | 000,420,405 | —- | M] () – C:\Windows\hpoins21.dat.temp
[2010/01/24 16:11:08 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$ff notesMovieNight_100121.doc
[2010/01/23 01:05:07 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/01/21 09:02:10 | 000,220,672 | —- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codecp.acm
[2010/01/21 09:02:10 | 000,062,464 | —- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2010/01/19 20:09:51 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$VORY POPCORN.doc
[2010/01/19 17:03:46 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$rsonal.doc
[2010/01/18 14:06:14 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$nini party recipe.doc
[2010/01/18 10:20:14 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$untry Chicken with heads of garlic.doc
[2010/01/14 16:32:33 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$rman menu.doc
[2010/01/14 11:16:49 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$KE YOUR OWN PIZZA BUFFET.docx
[2010/01/12 18:21:40 | 000,000,162 | -H– | M] () – C:\Users\Shannon O'Conner\Desktop\~$cotta Cheesecake with Amaretti Cookie crust and fresh berries.docx
[2010/01/11 14:25:16 | 000,000,349 | -H– | M] () – C:\IPH.PH
[2010/01/09 17:45:53 | 000,002,487 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/01/07 17:47:45 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2010/01/01 14:05:25 | 000,873,310 | —- | M] () – C:\Windows\System32\oem18.inf
[2010/01/01 14:03:36 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2010/01/01 13:49:31 | 000,000,333 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\CD Drive - Shortcut.lnk
[2010/01/01 11:40:32 | 000,000,713 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\TomTom HOME 2.lnk
[2009/12/31 14:14:21 | 000,000,256 | —- | M] () – C:\Windows\System32\pool.bin
[2009/12/31 12:36:04 | 014,829,413 | —- | M] () – C:\Users\Shannon O'Conner\Documents\LoaderBackup-(2009-12-31).ipd
[2009/12/31 12:02:57 | 000,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/12/31 11:55:11 | 000,000,938 | —- | M] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2009/12/31 08:50:07 | 000,005,632 | —- | M] () – C:\Users\Shannon O'Conner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/30 15:37:11 | 000,001,748 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\Mozilla Firefox.lnk
[2009/12/30 15:37:11 | 000,001,724 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/12/30 11:25:30 | 000,001,843 | —- | M] () – C:\Users\Public\Desktop\Canon MP970 series User Registration.LNK
[2009/12/30 11:21:29 | 000,000,412 | —- | M] () – C:\Windows\MAXLINK.INI
[2009/12/30 11:12:00 | 000,001,784 | —- | M] () – C:\Users\Public\Desktop\My Printer.lnk
[2009/12/30 11:11:48 | 000,001,820 | —- | M] () – C:\Users\Public\Desktop\Canon Solution Menu.lnk
[2009/12/30 11:11:35 | 000,001,874 | —- | M] () – C:\Users\Public\Desktop\Easy-PhotoPrint EX.lnk
[2009/12/30 11:10:08 | 000,001,876 | —- | M] () – C:\Users\Public\Desktop\MP Navigator EX 1.0.lnk
[2009/12/30 11:09:34 | 000,001,802 | —- | M] () – C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
[2009/12/30 11:09:16 | 000,002,114 | —- | M] () – C:\Users\Public\Desktop\MP970 series On-screen Manual.lnk
[2009/12/28 14:24:47 | 000,000,938 | —- | M] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2009/12/28 05:35:48 | 001,327,616 | —- | M] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2009/12/28 05:34:29 | 000,123,904 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msvfw32.dll
[2009/12/28 05:33:24 | 000,082,944 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2009/12/28 05:30:47 | 000,088,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2009/12/28 05:30:47 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\avicap32.dll
[2009/12/25 10:52:26 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2009/12/25 10:52:26 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2009/12/25 10:52:25 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2009/12/25 10:52:22 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deploytk.dll
[2009/12/25 09:03:41 | 000,001,887 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/12/25 08:07:01 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\UMDF\Msft_User_WpdFs_01_00_00.Wdf
[2009/12/22 02:47:39 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\i8042prt.sys.mui
[2009/12/22 02:47:39 | 000,005,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\sermouse.sys.mui
[2009/12/22 02:47:39 | 000,004,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\mouclass.sys.mui
[2009/12/22 02:47:39 | 000,004,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\kbdclass.sys.mui
[2009/12/22 02:47:39 | 000,003,072 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\mouhid.sys.mui
[2009/12/22 02:47:39 | 000,003,072 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\kbdhid.sys.mui
[2009/12/22 02:47:33 | 000,371,712 | —- | M] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2009/12/22 02:47:33 | 000,313,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rstrui.exe
[2009/12/22 02:47:33 | 000,016,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\srdelayed.exe
[2009/12/22 02:47:31 | 000,613,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2009/12/22 02:47:30 | 000,019,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2009/12/22 02:47:29 | 000,905,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2009/12/22 02:47:27 | 000,944,184 | —- | M] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2009/12/22 02:47:24 | 000,620,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2009/12/22 02:47:22 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2009/12/22 02:47:22 | 000,019,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cfgmgr32.dll
[2009/12/22 02:47:20 | 000,260,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dpx.dll
[2009/12/22 02:47:20 | 000,006,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\kbd106n.dll
[2009/12/22 02:47:17 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\lodctr.exe
[2009/12/22 02:47:16 | 000,115,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\loadperf.dll
[2009/12/22 02:47:16 | 000,032,256 | —- | M] (Microsoft Corporation) – C:\Windows\System32\unlodctr.exe
[2009/12/22 02:47:16 | 000,017,408 | —- | M] (Microsoft Corporation) – C:\Windows\System32\prflbmsg.dll
[2009/12/22 02:47:11 | 000,035,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2009/12/22 02:47:09 | 000,007,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2009/12/22 02:47:08 | 000,035,328 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dispci.dll
[2009/12/22 02:47:08 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\batt.dll
[2009/12/22 02:44:53 | 000,024,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/12/22 02:44:52 | 000,654,336 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/12/22 02:44:46 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/12/22 02:44:46 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/12/22 02:44:46 | 000,053,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/12/22 02:44:46 | 000,037,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/12/22 02:43:42 | 000,512,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/12/22 02:42:15 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMASF.DLL
[2009/12/22 02:42:15 | 000,009,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\LAPRXY.DLL
[2009/12/22 02:42:15 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\asferror.dll
[2009/12/22 02:41:48 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/12/22 02:41:48 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/12/22 02:40:24 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLC.dll
[2009/12/22 02:40:22 | 000,268,288 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mcbuilder.exe
[2009/12/22 02:40:22 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2009/12/22 02:40:18 | 000,566,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2009/12/22 02:40:17 | 000,351,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2009/12/22 02:40:16 | 000,186,368 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2009/12/22 02:39:17 | 000,425,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/12/22 02:39:16 | 000,712,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/12/22 02:39:14 | 000,347,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/12/22 02:34:15 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2009/12/22 02:34:15 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntprint.exe
[2009/12/22 02:34:12 | 000,010,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dhcpcmonitor.dll
[2009/12/22 02:34:11 | 001,984,512 | —- | M] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2009/12/22 02:34:11 | 000,120,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2009/12/22 02:33:18 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printcom.dll
[2009/12/22 02:33:17 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2009/12/22 02:32:48 | 002,031,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/12/22 02:32:24 | 000,113,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2009/12/22 02:32:24 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wshrm.dll
[2009/12/22 02:31:44 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msdxm.tlb
[2009/12/22 02:31:44 | 000,018,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\amcompat.tlb
[2009/12/22 02:30:27 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sbunattend.exe
[2009/12/22 02:29:32 | 000,024,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2009/12/22 02:24:16 | 000,622,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/12/22 02:24:15 | 000,097,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/12/22 02:24:15 | 000,011,264 | —- | M] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/12/22 02:24:14 | 000,037,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/12/22 02:23:59 | 000,105,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/12/22 02:23:55 | 000,326,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/12/22 02:23:54 | 000,043,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/12/22 02:23:53 | 000,781,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/12/22 02:13:53 | 026,869,760 | —- | M] () – C:\Windows\ocsetup_install_NetFx3.etl
[2009/12/22 02:13:53 | 000,081,920 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2009/12/22 02:13:53 | 000,016,384 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2009/12/21 06:04:52 | 000,000,749 | RH– | M] () – C:\Windows\WindowsShell.Manifest
[2009/12/21 05:37:34 | 000,028,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2009/12/21 05:37:33 | 000,272,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\polstore.dll
[2009/12/21 05:37:33 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\winipsec.dll
[2009/12/21 05:34:39 | 000,467,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\riched20.dll
[2009/12/21 05:34:38 | 000,008,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\riched32.dll
[2009/12/21 05:34:32 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\kmddsp.tsp
[2009/12/21 05:34:30 | 000,077,824 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rascfg.dll
[2009/12/21 05:34:30 | 000,022,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rasser.dll
[2009/12/21 05:34:29 | 000,052,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2009/12/21 05:34:29 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ndptsp.tsp
[2009/12/21 05:34:28 | 000,032,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rasmxs.dll
[2009/12/21 05:34:28 | 000,001,820 | —- | M] () – C:\Windows\System32\rasctrnm.h
[2009/12/21 05:34:27 | 000,564,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2009/12/21 05:34:27 | 000,384,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netcfgx.dll
[2009/12/21 05:34:24 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\System32\icsunattend.exe
[2009/12/21 05:34:20 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wshqos.dll
[2009/12/21 05:34:19 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\traffic.dll
[2009/12/21 05:34:18 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pacerprf.dll
[2009/12/21 05:34:16 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2009/12/21 05:31:35 | 000,241,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/12/21 05:31:34 | 000,160,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2009/12/21 05:31:34 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/12/21 05:28:46 | 000,205,824 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msoeacct.dll
[2009/12/21 05:28:46 | 000,087,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msoert2.dll
[2009/12/21 05:28:46 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ACCTRES.dll
[2009/12/21 05:25:32 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2009/12/21 05:25:31 | 000,011,264 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MRINFO.EXE
[2009/12/21 05:25:31 | 000,009,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TCPSVCS.EXE
[2009/12/21 05:25:30 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2009/12/21 05:25:30 | 000,008,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\HOSTNAME.EXE
[2009/12/21 05:25:29 | 000,010,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\finger.exe
[2009/12/21 05:25:28 | 000,027,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NETSTAT.EXE
[2009/12/21 05:25:28 | 000,017,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2009/12/21 05:25:27 | 000,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ARP.EXE
[2009/12/21 05:25:20 | 000,213,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2009/12/21 05:21:32 | 000,704,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2009/12/21 05:21:28 | 000,024,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wtsapi32.dll
[2009/12/21 05:21:20 | 000,028,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\battc.sys
[2009/12/21 05:15:53 | 000,123,904 | —- | M] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2009/12/21 05:15:52 | 001,657,350 | —- | M] () – C:\Windows\System32\wlan.tmf
[2009/12/21 05:15:51 | 000,047,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wlanapi.dll
[2009/12/21 05:15:50 | 000,297,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2009/12/21 05:15:50 | 000,290,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2009/12/21 05:15:50 | 000,067,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wlanhlp.dll
[2009/12/21 05:12:53 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2009/12/21 05:12:52 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msxml6r.dll
[2009/12/21 05:07:17 | 001,233,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/12/21 05:04:38 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2009/12/21 05:04:37 | 000,376,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2009/12/21 05:02:12 | 002,855,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2009/12/21 05:02:12 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2009/12/21 05:02:11 | 000,052,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rrinstaller.exe
[2009/12/21 05:02:11 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mferror.dll
[2009/12/21 05:02:10 | 000,024,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfpmp.exe
[2009/12/21 05:02:08 | 002,433,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2009/12/21 04:31:25 | 002,452,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/12/21 04:24:52 | 000,500,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/12/21 04:24:52 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/12/21 04:20:31 | 000,116,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2009/12/21 04:20:31 | 000,036,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2009/12/21 04:15:37 | 000,303,616 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2009/12/21 04:10:36 | 000,414,208 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2009/12/21 04:08:27 | 000,713,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2009/12/21 04:05:59 | 000,356,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2009/12/21 04:03:31 | 000,392,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\FirewallAPI.dll
[2009/12/21 04:03:28 | 000,086,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\icfupgd.dll
[2009/12/21 04:03:28 | 000,016,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wfapigp.dll
[2009/12/21 04:03:27 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cmifw.dll
[2009/12/21 03:54:45 | 001,244,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2009/12/21 03:54:45 | 000,177,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/12/21 03:54:44 | 000,428,032 | —- | M] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/12/21 03:54:42 | 000,292,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/12/21 03:54:42 | 000,217,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/12/21 03:54:42 | 000,080,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/12/21 03:54:42 | 000,068,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2009/12/21 03:54:42 | 000,057,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2009/12/21 03:48:08 | 000,696,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2009/12/21 03:41:31 | 000,045,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\pciidex.sys
[2009/12/21 03:41:30 | 000,109,624 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2009/12/21 03:39:41 | 000,104,448 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWWIN.EXE
[2009/12/21 03:37:57 | 002,923,520 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/12/21 03:34:07 | 000,024,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netcfg.exe
[2009/12/21 03:31:43 | 001,808,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0046.dll
[2009/12/21 03:31:43 | 001,793,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0045.dll
[2009/12/21 03:31:43 | 001,411,072 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0047.dll
[2009/12/21 03:31:42 | 001,782,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0039.dll
[2009/12/21 03:31:42 | 001,558,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0049.dll
[2009/12/21 03:31:42 | 001,236,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0020.dll
[2009/12/21 03:31:41 | 005,499,904 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0022.dll
[2009/12/21 03:31:41 | 002,136,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0021.dll
[2009/12/21 03:31:40 | 007,964,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0024.dll
[2009/12/21 03:31:40 | 005,791,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0026.dll
[2009/12/21 03:31:39 | 006,224,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0027.dll
[2009/12/21 03:31:39 | 004,175,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0010.dll
[2009/12/21 03:31:38 | 004,981,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0013.dll
[2009/12/21 03:31:38 | 002,466,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0011.dll
[2009/12/21 03:31:37 | 006,781,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0019.dll
[2009/12/21 03:31:37 | 003,331,072 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0018.dll
[2009/12/21 03:31:36 | 011,722,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0001.dll
[2009/12/21 03:31:35 | 004,164,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0002.dll
[2009/12/21 03:31:35 | 001,452,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0003.dll
[2009/12/21 03:31:34 | 012,240,896 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2009/12/21 03:31:33 | 002,644,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2009/12/21 03:31:32 | 004,093,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004c.dll
[2009/12/21 03:31:32 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004a.dll
[2009/12/21 03:31:32 | 001,702,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004b.dll
[2009/12/21 03:31:31 | 004,045,824 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons003e.dll
[2009/12/21 03:31:31 | 001,972,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons004e.dll
[2009/12/21 03:31:30 | 006,014,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons001a.dll
[2009/12/21 03:31:30 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons002a.dll
[2009/12/21 03:31:29 | 006,585,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons001b.dll
[2009/12/21 03:31:29 | 006,346,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons001d.dll
[2009/12/21 03:31:28 | 009,892,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000a.dll
[2009/12/21 03:31:27 | 006,237,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000c.dll
[2009/12/21 03:31:27 | 001,722,368 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000d.dll
[2009/12/21 03:31:26 | 005,654,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons000f.dll
[2009/12/21 03:31:26 | 004,616,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0414.dll
[2009/12/21 03:31:25 | 005,090,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0416.dll
[2009/12/21 03:31:25 | 005,031,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0816.dll
[2009/12/21 03:31:24 | 007,042,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons081a.dll
[2009/12/21 03:31:24 | 005,071,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsModels0011.dll
[2009/12/21 03:31:23 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0046.dll
[2009/12/21 03:31:23 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0045.dll
[2009/12/21 03:31:22 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0049.dll
[2009/12/21 03:31:22 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0047.dll
[2009/12/21 03:31:21 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0039.dll
[2009/12/21 03:31:21 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0020.dll
[2009/12/21 03:31:20 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0024.dll
[2009/12/21 03:31:20 | 001,799,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0022.dll
[2009/12/21 03:31:20 | 001,799,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0021.dll
[2009/12/21 03:31:19 | 001,965,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0027.dll
[2009/12/21 03:31:19 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0026.dll
[2009/12/21 03:31:18 | 004,493,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0010.dll
[2009/12/21 03:31:18 | 002,655,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0011.dll
[2009/12/21 03:31:17 | 003,464,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0013.dll
[2009/12/21 03:31:17 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0018.dll
[2009/12/21 03:31:16 | 004,495,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0019.dll
[2009/12/21 03:31:16 | 002,597,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0001.dll
[2009/12/21 03:31:16 | 001,523,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0000.dll
[2009/12/21 03:31:15 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0003.dll
[2009/12/21 03:31:15 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0002.dll
[2009/12/21 03:31:14 | 004,874,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0009.dll
[2009/12/21 03:31:14 | 002,241,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0007.dll
[2009/12/21 03:31:13 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData004b.dll
[2009/12/21 03:31:13 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData004a.dll
[2009/12/21 03:31:12 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData004e.dll
[2009/12/21 03:31:12 | 003,102,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData004c.dll
[2009/12/21 03:31:11 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData001a.dll
[2009/12/21 03:31:11 | 001,799,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData003e.dll
[2009/12/21 03:31:11 | 001,799,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData002a.dll
[2009/12/21 03:31:10 | 004,493,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData001d.dll
[2009/12/21 03:31:10 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData001b.dll
[2009/12/21 03:31:09 | 009,845,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData000a.dll
[2009/12/21 03:31:08 | 002,641,408 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData000c.dll
[2009/12/21 03:31:08 | 002,340,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData000d.dll
[2009/12/21 03:31:08 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData000f.dll
[2009/12/21 03:31:07 | 004,493,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0416.dll
[2009/12/21 03:31:07 | 004,493,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0414.dll
[2009/12/21 03:31:06 | 004,493,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0816.dll
[2009/12/21 03:31:06 | 000,797,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2009/12/21 03:31:05 | 006,917,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0c1a.dll
[2009/12/21 03:31:05 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData081a.dll
[2009/12/21 03:31:04 | 001,963,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\NlsData0c1a.dll
[2009/12/21 03:12:59 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2009/12/21 03:08:09 | 008,138,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ssBranded.scr
[2009/12/21 02:36:58 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/12/21 02:36:47 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/12/21 02:36:47 | 000,083,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/12/21 02:16:29 | 000,028,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/12/21 02:16:23 | 004,247,552 | —- | M] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/12/21 02:16:22 | 001,686,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2009/12/21 02:15:24 | 000,094,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2009/12/21 02:15:23 | 000,996,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2009/12/21 02:14:28 | 000,148,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2009/12/21 02:13:54 | 000,084,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\INETRES.dll
[2009/12/21 02:13:01 | 001,645,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2009/12/21 02:12:34 | 000,005,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wmi.dll
[2009/12/21 02:08:15 | 000,274,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2009/12/21 02:08:15 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2009/12/21 02:07:53 | 000,321,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2009/12/21 02:06:06 | 000,604,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2009/12/21 02:05:19 | 008,147,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2009/12/21 02:05:17 | 000,007,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2009/12/21 02:05:15 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2009/12/21 02:05:14 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2009/12/21 02:05:04 | 000,311,296 | —- | M] (Microsoft Corporation) – C:\Windows\System32\unregmp2.exe
[2009/12/20 18:17:16 | 000,001,708 | -H– | M] () – C:\Users\Shannon O'Conner\Documents\Default.rdp
[2009/12/20 15:43:54 | 000,024,064 | —- | M] () – C:\Users\Shannon O'Conner\AppData\Roaming\UserTile.png
[2009/12/20 10:39:32 | 000,000,632 | RHS- | M] () – C:\Users\Shannon O'Conner\ntuser.pol
[2009/12/20 05:36:04 | 000,001,597 | —- | M] () – C:\Users\Shannon O'Conner\Desktop\Remote Desktop Connection.lnk
[2009/12/19 19:33:56 | 000,000,219 | —- | M] () – C:\Windows\win.ini
[2009/12/19 18:53:49 | 000,041,176 | —- | M] () – C:\Windows\System32\license.rtf
[2009/12/19 18:48:32 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2009/12/19 18:39:16 | 000,524,288 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2009/12/19 18:39:16 | 000,524,288 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009/12/19 18:39:16 | 000,065,536 | -HS- | M] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009/12/19 18:30:59 | 002,421,760 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/12/19 18:30:59 | 000,044,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/12/19 18:30:41 | 000,575,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2009/12/19 18:30:41 | 000,087,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2009/12/19 18:30:41 | 000,035,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2009/12/19 18:30:29 | 000,171,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/12/19 18:30:29 | 000,033,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/12/19 17:55:41 | 000,000,680 | —- | M] () – C:\Users\Shannon O'Conner\AppData\Local\d3d9caps.dat
[2009/12/19 17:55:20 | 000,000,020 | -HS- | M] () – C:\Users\Shannon O'Conner\ntuser.ini
[2009/11/19 14:16:27 | 000,068,824 | —- | M] () – C:\Windows\CouponPrinter.ocx
[2009/11/15 07:36:22 | 001,321,011 | —- | M] () – C:\Users\Shannon O'Conner\Documents\007.JPG
[2009/11/05 08:07:50 | 000,538,074 | —- | M] () – C:\Users\Shannon O'Conner\Documents\DSCF0939.JPG
[2009/11/03 13:42:44 | 000,015,626 | —- | M] () – C:\Users\Shannon O'Conner\Documents\Dunbeath-Castle-Highlands-Caithness-wiki.jpg
[2009/11/03 06:12:18 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\http.sys.mui
[2009/10/19 07:42:37 | 000,156,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2009/10/19 07:37:42 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2009/10/19 07:37:11 | 000,010,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2009/10/19 07:36:08 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2009/10/19 04:45:12 | 000,289,792 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[3 C:\Users\Shannon O'Conner\Desktop\*.tmp files -> C:\Users\Shannon O'Conner\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/08 16:19:12 | 000,000,881 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\HiJackThis.exe - Shortcut.lnk
[2010/09/08 16:18:55 | 000,000,840 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\OTL.exe - Shortcut.lnk
[2010/06/24 14:25:21 | 000,001,726 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/06/24 13:49:10 | 000,001,854 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/24 13:49:10 | 000,001,854 | —- | C] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/06/13 06:38:26 | 001,048,576 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.2.regtrans-ms
[2010/06/13 06:38:26 | 001,048,576 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.1.regtrans-ms
[2010/06/13 06:38:26 | 001,048,576 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.0.regtrans-ms
[2010/06/13 06:38:26 | 000,065,536 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.blf
[2010/06/04 16:43:56 | 000,029,696 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\RESUME NEW.doc
[2010/06/03 18:21:05 | 000,026,112 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Family address.doc
[2010/06/03 09:45:22 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$ights newsletter.doc
[2010/06/03 09:45:20 | 000,029,696 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\heights newsletter.doc
[2010/05/25 13:27:27 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$VIP.doc
[2010/05/25 13:27:24 | 000,032,768 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\VIP.doc
[2010/05/20 14:41:29 | 000,024,576 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\UFO.doc
[2010/05/15 13:00:57 | 000,011,225 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\duane game.jpg
[2010/05/07 05:45:28 | 000,009,878 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\mombeehive.jpg
[2010/04/02 13:57:38 | 000,026,624 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Dr. Phil Invoice Jasper.doc
[2010/03/17 09:37:04 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$m dijon recipe.docx
[2010/03/14 23:18:05 | 000,000,227 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Sound - Shortcut.lnk
[2010/03/14 19:55:22 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$-Mission-OWN-100310.doc
[2010/03/12 11:08:22 | 000,558,008 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\ham dijon recipe.docx
[2010/03/02 18:43:48 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$2 CF-113-SweetEnd-Outline-OWN-100224.doc
[2010/03/02 18:42:37 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$-113-SweetEnd-Outline-OWN-100224.doc
[2010/02/19 15:14:56 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$Holiday Feast breakdown.doc
[2010/02/19 13:11:25 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$liday Feast breakdown.doc
[2010/02/02 14:40:20 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$ntryraidssnacksbreakdown.doc
[2010/01/31 12:24:27 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$31 pantryraid breakfastbreakdown.doc
[2010/01/29 12:05:41 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$29 cookingwithguysbreakdown.doc
[2010/01/24 16:38:13 | 000,420,405 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2010/01/24 16:38:13 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2010/01/24 16:15:45 | 000,238,023 | —- | C] () – C:\Windows\hpoins21.dat
[2010/01/24 16:15:45 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat
[2010/01/24 16:11:08 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$ff notesMovieNight_100121.doc
[2010/01/24 16:00:47 | 000,000,943 | —- | C] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/01/21 10:38:09 | 157,825,226 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/01/19 20:09:51 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$VORY POPCORN.doc
[2010/01/19 17:03:46 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$rsonal.doc
[2010/01/18 14:06:14 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$nini party recipe.doc
[2010/01/18 10:20:14 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$untry Chicken with heads of garlic.doc
[2010/01/14 16:32:33 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$rman menu.doc
[2010/01/14 11:16:49 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$KE YOUR OWN PIZZA BUFFET.docx
[2010/01/12 18:21:40 | 000,000,162 | -H– | C] () – C:\Users\Shannon O'Conner\Desktop\~$cotta Cheesecake with Amaretti Cookie crust and fresh berries.docx
[2010/01/11 14:23:44 | 000,000,349 | -H– | C] () – C:\IPH.PH
[2010/01/07 17:47:45 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/01/07 17:41:25 | 000,002,487 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2010/01/01 14:05:45 | 000,873,310 | —- | C] () – C:\Windows\System32\oem18.inf
[2010/01/01 14:03:36 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2010/01/01 14:01:46 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/01/01 11:40:32 | 000,000,713 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\TomTom HOME 2.lnk
[2009/12/31 12:36:04 | 014,829,413 | —- | C] () – C:\Users\Shannon O'Conner\Documents\LoaderBackup-(2009-12-31).ipd
[2009/12/31 12:32:11 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2009/12/31 12:02:57 | 000,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/12/31 11:55:11 | 000,000,938 | —- | C] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2009/12/30 15:37:11 | 000,001,748 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Mozilla Firefox.lnk
[2009/12/30 15:37:11 | 000,001,724 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/12/30 11:25:30 | 000,001,843 | —- | C] () – C:\Users\Public\Desktop\Canon MP970 series User Registration.LNK
[2009/12/30 11:21:29 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2009/12/30 11:12:00 | 000,001,784 | —- | C] () – C:\Users\Public\Desktop\My Printer.lnk
[2009/12/30 11:11:48 | 000,001,820 | —- | C] () – C:\Users\Public\Desktop\Canon Solution Menu.lnk
[2009/12/30 11:11:35 | 000,001,874 | —- | C] () – C:\Users\Public\Desktop\Easy-PhotoPrint EX.lnk
[2009/12/30 11:10:08 | 000,001,876 | —- | C] () – C:\Users\Public\Desktop\MP Navigator EX 1.0.lnk
[2009/12/30 11:09:34 | 000,001,802 | —- | C] () – C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
[2009/12/30 11:09:16 | 000,002,114 | —- | C] () – C:\Users\Public\Desktop\MP970 series On-screen Manual.lnk
[2009/12/30 11:05:17 | 000,117,850 | —- | C] () – C:\Windows\System32\Cnmnput.chm
[2009/12/28 14:24:47 | 000,000,938 | —- | C] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2009/12/25 09:03:41 | 000,001,887 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/12/21 05:34:28 | 000,001,820 | —- | C] () – C:\Windows\System32\rasctrnm.h
[2009/12/21 05:15:52 | 001,657,350 | —- | C] () – C:\Windows\System32\wlan.tmf
[2009/12/21 02:43:45 | 026,869,760 | —- | C] () – C:\Windows\ocsetup_install_NetFx3.etl
[2009/12/21 02:43:45 | 000,081,920 | —- | C] () – C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2009/12/21 02:43:45 | 000,016,384 | —- | C] () – C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2009/12/20 15:43:54 | 000,024,064 | —- | C] () – C:\Users\Shannon O'Conner\AppData\Roaming\UserTile.png
[2009/12/20 06:53:45 | 000,000,632 | RHS- | C] () – C:\Users\Shannon O'Conner\ntuser.pol
[2009/12/20 05:36:04 | 000,001,597 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Remote Desktop Connection.lnk
[2009/12/20 05:16:11 | 000,001,708 | -H– | C] () – C:\Users\Shannon O'Conner\Documents\Default.rdp
[2009/12/19 21:40:32 | 000,005,632 | —- | C] () – C:\Users\Shannon O'Conner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/19 21:28:49 | 000,059,392 | —- | C] () – C:\Users\Shannon O'Conner\Documents\template.doc
[2009/12/19 21:28:48 | 000,585,728 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Menu.doc
[2009/12/19 21:28:48 | 000,138,752 | —- | C] () – C:\Users\Shannon O'Conner\Documents\EXCLU_letter.doc
[2009/12/19 21:28:48 | 000,094,720 | —- | C] () – C:\Users\Shannon O'Conner\Documents\NEW_RUNDOWN_SEASON_3.doc
[2009/12/19 21:28:48 | 000,086,528 | —- | C] () – C:\Users\Shannon O'Conner\Documents\NEW_RUNDOWN_Sowell vs. Jenner.doc
[2009/12/19 21:28:48 | 000,086,016 | —- | C] () – C:\Users\Shannon O'Conner\Documents\NEW_RUNDOWN_Knickerson vs. Gonzales.doc
[2009/12/19 21:28:48 | 000,077,312 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Miller vs Gossett.doc
[2009/12/19 21:28:48 | 000,072,704 | —- | C] () – C:\Users\Shannon O'Conner\Documents\CABERARA SMITH 2.doc
[2009/12/19 21:28:48 | 000,052,224 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Lovve and therapy 2 revised.doc
[2009/12/19 21:28:48 | 000,050,688 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Knickerson vs. Gonzales.doc
[2009/12/19 21:28:48 | 000,045,568 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Julie_Nise_Shooting_Script.doc
[2009/12/19 21:28:48 | 000,041,472 | —- | C] () – C:\Users\Shannon O'Conner\Documents\SOWELL_vs_JENNER.doc
[2009/12/19 21:28:48 | 000,034,304 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Sowell Picture.doc
[2009/12/19 21:28:48 | 000,033,792 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Davis vs brown bullets and chyrons.doc
[2009/12/19 21:28:48 | 000,032,768 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Abney_vs._Conyers_Bullets_and_Chyrons.doc
[2009/12/19 21:28:48 | 000,029,966 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Judge Arthur L. Hunter.docx
[2009/12/19 21:28:48 | 000,021,858 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Sowell Picture.docx
[2009/12/19 21:28:48 | 000,011,576 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Gina reyes.docx
[2009/12/19 21:28:48 | 000,010,106 | —- | C] () – C:\Users\Shannon O'Conner\Documents\mark g list.docx
[2009/12/19 21:28:48 | 000,009,807 | —- | C] () – C:\Users\Shannon O'Conner\Documents\carts.docx
[2009/12/19 21:28:45 | 001,300,480 | —- | C] () – C:\Users\Shannon O'Conner\Documents\untitled bandbox script.doc
[2009/12/19 21:28:45 | 000,181,478 | —- | C] () – C:\Users\Shannon O'Conner\Documents\taste of tears2.fdr
[2009/12/19 21:28:45 | 000,147,744 | —- | C] () – C:\Users\Shannon O'Conner\Documents\THE NIGHT RAJA.fdr
[2009/12/19 21:28:45 | 000,023,552 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Taste of Tear Manuscript.doc
[2009/12/19 21:28:45 | 000,011,776 | —- | C] () – C:\Users\Shannon O'Conner\Documents\bailey vs barboza.docx
[2009/12/19 21:28:45 | 000,010,052 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Bombi.docx
[2009/12/19 21:28:44 | 000,276,028 | —- | C] () – C:\Users\Shannon O'Conner\Documents\night raja Final Draft.fdr
[2009/12/19 21:28:44 | 000,074,787 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Redline.fdr
[2009/12/19 21:28:44 | 000,026,624 | —- | C] () – C:\Users\Shannon O'Conner\Documents\party list.doc
[2009/12/19 21:28:44 | 000,021,504 | —- | C] () – C:\Users\Shannon O'Conner\Documents\short story.doc
[2009/12/19 21:28:44 | 000,017,547 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Limo_story[1].docx
[2009/12/19 21:28:44 | 000,010,105 | —- | C] () – C:\Users\Shannon O'Conner\Documents\ruth holmes.docx
[2009/12/19 21:28:44 | 000,006,715 | —- | C] () – C:\Users\Shannon O'Conner\Documents\mob date.fdr
[2009/12/19 21:28:43 | 000,950,272 | —- | C] () – C:\Users\Shannon O'Conner\Documents\LaunchU3.exe
[2009/12/19 21:28:43 | 000,281,075 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Copy of night raja 2.fdr
[2009/12/19 21:28:43 | 000,150,528 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Golden Empire.doc
[2009/12/19 21:28:43 | 000,043,756 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Golden Empire.fdr
[2009/12/19 21:28:43 | 000,036,864 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Juan vs Townsley Bullets and chyrons.doc
[2009/12/19 21:28:43 | 000,034,304 | —- | C] () – C:\Users\Shannon O'Conner\Documents\horse case.doc
[2009/12/19 21:28:43 | 000,032,256 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Hall vs Gannon bullets and chyrons.doc
[2009/12/19 21:28:43 | 000,031,232 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Dr. Phil Invoice.doc
[2009/12/19 21:28:43 | 000,031,232 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Dr. Phil Invoice cypress texas (2).doc
[2009/12/19 21:28:43 | 000,029,184 | —- | C] () – C:\Users\Shannon O'Conner\Documents\I.doc
[2009/12/19 21:28:43 | 000,028,160 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Dr. Anderson list.doc
[2009/12/19 21:28:43 | 000,022,016 | —- | C] () – C:\Users\Shannon O'Conner\Documents\IrishProjectoutline.doc
[2009/12/19 21:28:43 | 000,021,309 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Golden empire draft1.fdr
[2009/12/19 21:28:43 | 000,006,967 | —- | C] () – C:\Users\Shannon O'Conner\Documents\la femme concita.fdr
[2009/12/19 21:28:43 | 000,001,816 | —- | C] () – C:\Users\Shannon O'Conner\Documents\hercules-shannon.RDP
[2009/12/19 21:28:42 | 000,041,472 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Art_Clark_Interview_2[1].doc
[2009/12/19 21:28:42 | 000,009,813 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Bailey's book.docx
[2009/12/19 21:28:09 | 000,000,179 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Removable Disk (F) - Shortcut.lnk
[2009/12/19 21:28:04 | 000,000,333 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\CD Drive - Shortcut.lnk
[2009/12/19 20:47:39 | 002,724,914 | —- | C] () – C:\Users\Shannon O'Conner\Documents\xmas pic.tif
[2009/12/19 20:47:39 | 001,245,017 | —- | C] () – C:\Users\Shannon O'Conner\Documents\wedding pic fmaily.jpg
[2009/12/19 20:47:39 | 000,828,377 | —- | C] () – C:\Users\Shannon O'Conner\Documents\wedding pics 382.jpg
[2009/12/19 20:47:39 | 000,115,371 | —- | C] () – C:\Users\Shannon O'Conner\Documents\wedding pics 166.jpg
[2009/12/19 20:47:39 | 000,095,414 | —- | C] () – C:\Users\Shannon O'Conner\Documents\wedding pics 046.jpg
[2009/12/19 20:47:39 | 000,055,090 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Walker.jpg
[2009/12/19 20:47:39 | 000,048,640 | —- | C] () – C:\Users\Shannon O'Conner\Documents\your boozin busted up my buick.doc
[2009/12/19 20:47:39 | 000,032,256 | —- | C] () – C:\Users\Shannon O'Conner\Documents\TREATMENT.doc
[2009/12/19 20:47:39 | 000,019,111 | —- | C] () – C:\Users\Shannon O'Conner\Documents\wedding pics 070.jpg
[2009/12/19 20:47:38 | 000,752,382 | —- | C] () – C:\Users\Shannon O'Conner\Documents\SO pictures 050 (2).JPG
[2009/12/19 20:47:38 | 000,195,584 | —- | C] () – C:\Users\Shannon O'Conner\Documents\RESEARCH.doc
[2009/12/19 20:47:38 | 000,075,264 | —- | C] () – C:\Users\Shannon O'Conner\Documents\RIVERA_VS_TRAITANO.doc
[2009/12/19 20:47:38 | 000,053,248 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Snider_vs_Adaway.doc
[2009/12/19 20:47:38 | 000,046,592 | —- | C] () – C:\Users\Shannon O'Conner\Documents\rivera vs taitano.doc
[2009/12/19 20:47:38 | 000,035,328 | —- | C] () – C:\Users\Shannon O'Conner\Documents\shannon pankhurst resume.doc
[2009/12/19 20:47:38 | 000,034,304 | —- | C] () – C:\Users\Shannon O'Conner\Documents\shannon_pankhurst_resume[1].doc
[2009/12/19 20:47:38 | 000,033,280 | —- | C] () – C:\Users\Shannon O'Conner\Documents\resume.doc
[2009/12/19 20:47:38 | 000,033,280 | —- | C] () – C:\Users\Shannon O'Conner\Documents\RESEARCH ITEMS.doc
[2009/12/19 20:47:38 | 000,030,208 | —- | C] () – C:\Users\Shannon O'Conner\Documents\RESUME0908.doc
[2009/12/19 20:47:38 | 000,029,184 | —- | C] () – C:\Users\Shannon O'Conner\Documents\resume (1).doc
[2009/12/19 20:47:38 | 000,028,672 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Shannonlee Oconner resume.doc
[2009/12/19 20:47:38 | 000,024,064 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Revised_Pawn_Shop.doc
[2009/12/19 20:47:38 | 000,005,309 | —- | C] () – C:\Users\Shannon O'Conner\Documents\s1218134115_30150611_1801[1].jpg
[2009/12/19 20:47:38 | 000,004,702 | —- | C] () – C:\Users\Shannon O'Conner\Documents\s1218134115_30409148_141788[1].jpg
[2009/12/19 20:47:38 | 000,004,580 | —- | C] () – C:\Users\Shannon O'Conner\Documents\s1218134115_30150619_4893[1].jpg
[2009/12/19 20:47:38 | 000,003,954 | —- | C] () – C:\Users\Shannon O'Conner\Documents\s1218134115_30307081_6562[1].jpg
[2009/12/19 20:47:38 | 000,001,037 | —- | C] () – C:\Users\Shannon O'Conner\Documents\RealPlayer.lnk
[2009/12/19 20:47:38 | 000,000,813 | —- | C] () – C:\Users\Shannon O'Conner\Documents\TAO Image Transfer 4.4.lnk
[2009/12/19 20:47:38 | 000,000,490 | —- | C] () – C:\Users\Shannon O'Conner\Documents\resume - Shortcut.lnk
[2009/12/19 20:47:37 | 002,115,600 | —- | C] () – C:\Users\Shannon O'Conner\Documents\P5300107_0051_051.jpg
[2009/12/19 20:47:37 | 000,864,819 | —- | C] () – C:\Users\Shannon O'Conner\Documents\phillip.jpg
[2009/12/19 20:47:37 | 000,378,966 | —- | C] () – C:\Users\Shannon O'Conner\Documents\pic1.JPG
[2009/12/19 20:47:37 | 000,056,832 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Phillips_vs._Koch-Revised_Packet.doc
[2009/12/19 20:47:37 | 000,056,450 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Pro Bono Pilot.fdr
[2009/12/19 20:47:37 | 000,033,280 | —- | C] () – C:\Users\Shannon O'Conner\Documents\pay up mama's boy.doc
[2009/12/19 20:47:37 | 000,031,232 | —- | C] () – C:\Users\Shannon O'Conner\Documents\OUTLINE VEGAS.doc
[2009/12/19 20:47:37 | 000,029,184 | —- | C] () – C:\Users\Shannon O'Conner\Documents\oconnerresume.doc
[2009/12/19 20:47:37 | 000,020,654 | —- | C] () – C:\Users\Shannon O'Conner\Documents\patrick.jpg
[2009/12/19 20:47:37 | 000,001,726 | —- | C] () – C:\Users\Shannon O'Conner\Documents\QuickTime Player.lnk
[2009/12/19 20:47:37 | 000,001,627 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Quicken 2006 Premier.lnk
[2009/12/19 20:47:37 | 000,000,218 | —- | C] () – C:\Users\Shannon O'Conner\Documents\One Month FREE - pay bills right from Quicken.url
[2009/12/19 20:47:36 | 000,037,376 | —- | C] () – C:\Users\Shannon O'Conner\Documents\new_case.doc
[2009/12/19 20:47:36 | 000,032,256 | —- | C] () – C:\Users\Shannon O'Conner\Documents\NOLA.doc
[2009/12/19 20:47:35 | 002,724,914 | —- | C] () – C:\Users\Shannon O'Conner\Documents\l2r_mike_pankiewich_nancy_pankhurst_glenn_pankhurst_duane_pankhurst_keith_h
enderson_neil_henderson_toronto_1967.tif
[2009/12/19 20:47:35 | 001,350,794 | —- | C] () – C:\Users\Shannon O'Conner\Documents\new 004.JPG
[2009/12/19 20:47:35 | 000,885,043 | —- | C] () – C:\Users\Shannon O'Conner\Documents\new 005.JPG
[2009/12/19 20:47:35 | 000,753,841 | —- | C] () – C:\Users\Shannon O'Conner\Documents\l2r_mike_pankiewich_nancy_pankhurst_xmas 1967.jpg
[2009/12/19 20:47:35 | 000,232,843 | —- | C] () – C:\Users\Shannon O'Conner\Documents\koi2.jpg
[2009/12/19 20:47:35 | 000,222,687 | —- | C] () – C:\Users\Shannon O'Conner\Documents\kely phone pic.jpg
[2009/12/19 20:47:35 | 000,095,414 | —- | C] () – C:\Users\Shannon O'Conner\Documents\mom.jpg
[2009/12/19 20:47:35 | 000,056,320 | —- | C] () – C:\Users\Shannon O'Conner\Documents\job faker.doc
[2009/12/19 20:47:35 | 000,049,498 | —- | C] () – C:\Users\Shannon O'Conner\Documents\legalprogam.pdf
[2009/12/19 20:47:35 | 000,048,640 | —- | C] () – C:\Users\Shannon O'Conner\Documents\lau vs Bostic.doc
[2009/12/19 20:47:35 | 000,033,280 | —- | C] () – C:\Users\Shannon O'Conner\Documents\lau vs Bostic bullets.doc
[2009/12/19 20:47:35 | 000,028,672 | —- | C] () – C:\Users\Shannon O'Conner\Documents\neighbors bullets & chyrons.doc
[2009/12/19 20:47:35 | 000,002,114 | —- | C] () – C:\Users\Shannon O'Conner\Documents\MP970 series On-screen Manual.lnk
[2009/12/19 20:47:35 | 000,001,876 | —- | C] () – C:\Users\Shannon O'Conner\Documents\MP Navigator EX 1.0.lnk
[2009/12/19 20:47:35 | 000,001,784 | —- | C] () – C:\Users\Shannon O'Conner\Documents\My Printer.lnk
[2009/12/19 20:47:35 | 000,001,724 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Mozilla Firefox.lnk
[2009/12/19 20:47:35 | 000,000,184 | —- | C] () – C:\Users\Shannon O'Conner\Documents\NetBank.url
[2009/12/19 20:47:34 | 000,958,614 | —- | C] () – C:\Users\Shannon O'Conner\Documents\IMG_2635.JPG
[2009/12/19 20:47:34 | 000,797,911 | —- | C] () – C:\Users\Shannon O'Conner\Documents\IMG_2641.JPG
[2009/12/19 20:47:34 | 000,633,538 | —- | C] () – C:\Users\Shannon O'Conner\Documents\IMG_2573.JPG
[2009/12/19 20:47:34 | 000,581,556 | —- | C] () – C:\Users\Shannon O'Conner\Documents\IMG_2585.JPG
[2009/12/19 20:47:34 | 000,392,871 | —- | C] () – C:\Users\Shannon O'Conner\Documents\houston snow.jpg
[2009/12/19 20:47:34 | 000,067,584 | —- | C] () – C:\Users\Shannon O'Conner\Documents\horse_thief.doc
[2009/12/19 20:47:34 | 000,057,344 | —- | C] () – C:\Users\Shannon O'Conner\Documents\graham vs nortey.doc
[2009/12/19 20:47:34 | 000,041,984 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Graham_vs._Nortye2.doc
[2009/12/19 20:47:34 | 000,033,280 | —- | C] () – C:\Users\Shannon O'Conner\Documents\graham and nortey bullets.doc
[2009/12/19 20:47:34 | 000,032,256 | —- | C] () – C:\Users\Shannon O'Conner\Documents\JAB FAKER BULLETS.doc
[2009/12/19 20:47:34 | 000,030,298 | —- | C] () – C:\Users\Shannon O'Conner\Documents\IMG00052.jpg
[2009/12/19 20:47:34 | 000,028,160 | —- | C] () – C:\Users\Shannon O'Conner\Documents\horse thief bullets and chyrons.doc
[2009/12/19 20:47:34 | 000,019,088 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Furion Pic.jpg
[2009/12/19 20:47:33 | 001,364,779 | —- | C] () – C:\Users\Shannon O'Conner\Documents\fall2007 058.JPG
[2009/12/19 20:47:33 | 000,538,074 | —- | C] () – C:\Users\Shannon O'Conner\Documents\DSCF0939.JPG
[2009/12/19 20:47:33 | 000,152,701 | —- | C] () – C:\Users\Shannon O'Conner\Documents\dad phone pic.jpg
[2009/12/19 20:47:33 | 000,112,465 | —- | C] () – C:\Users\Shannon O'Conner\Documents\emmy 1.jpg
[2009/12/19 20:47:33 | 000,107,040 | —- | C] () – C:\Users\Shannon O'Conner\Documents\emmy 2.jpg
[2009/12/19 20:47:33 | 000,067,584 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Ex_Needs_to_grow_up_&_pay_up!.doc
[2009/12/19 20:47:33 | 000,062,774 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie20.jpg
[2009/12/19 20:47:33 | 000,060,416 | —- | C] () – C:\Users\Shannon O'Conner\Documents\DeLuke_vs_Lopez.doc
[2009/12/19 20:47:33 | 000,035,840 | —- | C] () – C:\Users\Shannon O'Conner\Documents\cruise_ship_case.doc
[2009/12/19 20:47:33 | 000,031,232 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Dr. Phil Invoice Jacksonville Florida.doc
[2009/12/19 20:47:33 | 000,031,232 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Dr. Phil Invoice cypress texas.doc
[2009/12/19 20:47:33 | 000,031,232 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Dr. Phil Invoice cypress texas show 7092.doc
[2009/12/19 20:47:33 | 000,015,626 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Dunbeath-Castle-Highlands-Caithness-wiki.jpg
[2009/12/19 20:47:33 | 000,001,874 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Easy-PhotoPrint EX.lnk
[2009/12/19 20:47:33 | 000,001,843 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Canon MP970 series User Registration.LNK
[2009/12/19 20:47:33 | 000,001,820 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Canon Solution Menu.lnk
[2009/12/19 20:47:33 | 000,001,802 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Canon IJ Network Tool.lnk
[2009/12/19 20:47:32 | 010,231,088 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie nov 059.AVI
[2009/12/19 20:47:32 | 000,961,640 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Callie's birthday 016.JPG
[2009/12/19 20:47:31 | 010,232,370 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie nov 040.AVI
[2009/12/19 20:47:31 | 007,159,784 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie nov 023.AVI
[2009/12/19 20:47:31 | 000,874,216 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie new2 035.JPG
[2009/12/19 20:47:31 | 000,733,057 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie new2 010.JPG
[2009/12/19 20:47:31 | 000,602,551 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie new2 012 (1).JPG
[2009/12/19 20:47:31 | 000,170,553 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie new2 012.JPG
[2009/12/19 20:47:30 | 001,291,585 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie new 003.JPG
[2009/12/19 20:47:30 | 001,277,986 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie new 015.JPG
[2009/12/19 20:47:30 | 000,806,071 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie 013.JPG
[2009/12/19 20:47:30 | 000,797,060 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie 015.JPG
[2009/12/19 20:47:30 | 000,724,517 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie 018.JPG
[2009/12/19 20:47:30 | 000,636,221 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie 020.JPG
[2009/12/19 20:47:30 | 000,493,549 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie having sushi.jpg
[2009/12/19 20:47:30 | 000,271,331 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie chrsitmas pic 003.jpg
[2009/12/19 20:47:30 | 000,092,014 | —- | C] () – C:\Users\Shannon O'Conner\Documents\callie 121.JPG
[2009/12/19 20:47:30 | 000,061,952 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Biopic[1].doc
[2009/12/19 20:47:30 | 000,035,328 | —- | C] () – C:\Users\Shannon O'Conner\Documents\C885_Revised_Bullets_Chyrons.doc
[2009/12/19 20:47:30 | 000,030,720 | —- | C] () – C:\Users\Shannon O'Conner\Documents\boozin bullets.doc
[2009/12/19 20:47:29 | 001,159,562 | —- | C] () – C:\Users\Shannon O'Conner\Documents\beercan.JPG
[2009/12/19 20:47:29 | 000,613,376 | —- | C] () – C:\Users\Shannon O'Conner\Documents\10-03_7034_JENNIFER_Jacksonville,_FL_SHELITA_HOME_INVASION.doc
[2009/12/19 20:47:29 | 000,604,160 | —- | C] () – C:\Users\Shannon O'Conner\Documents\9-28_7034_JENNIFER_Cypress,_TX_SCARED.doc
[2009/12/19 20:47:29 | 000,093,454 | —- | C] () – C:\Users\Shannon O'Conner\Documents\502169130_d8ec0cade3[1].jpg
[2009/12/19 20:47:29 | 000,027,991 | —- | C] () – C:\Users\Shannon O'Conner\Documents\bandbox script.fdr
[2009/12/19 20:47:29 | 000,026,112 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Bayou House notes.doc
[2009/12/19 20:47:29 | 000,002,080 | —- | C] () – C:\Users\Shannon O'Conner\Documents\BapForm052307.xml
[2009/12/19 20:47:29 | 000,001,887 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Adobe Reader 8.lnk
[2009/12/19 20:47:29 | 000,000,233 | —- | C] () – C:\Users\Shannon O'Conner\Documents\Best Card for Quicken Users - low APR, optional rewards program.url
[2009/12/19 20:47:28 | 009,130,292 | —- | C] () – C:\Users\Shannon O'Conner\Documents\030309_911_multiple_1-2.mp3
[2009/12/19 20:47:28 | 001,321,011 | —- | C] () – C:\Users\Shannon O'Conner\Documents\007.JPG
[2009/12/19 20:47:28 | 000,613,888 | —- | C] () – C:\Users\Shannon O'Conner\Documents\1-18_7092_ASTRA_Cypress,_TX_SEXTING.doc
[2009/12/19 20:47:28 | 000,576,953 | —- | C] () – C:\Users\Shannon O'Conner\Documents\012.jpg
[2009/12/19 20:47:28 | 000,094,871 | —- | C] () – C:\Users\Shannon O'Conner\Documents\002.jpg
[2009/12/19 19:46:27 | 000,043,348 | —- | C] () – C:\ProgramData\nvModes.001
[2009/12/19 19:46:25 | 000,043,348 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/12/19 19:37:19 | 000,002,627 | —- | C] () – C:\Users\Shannon O'Conner\Desktop\Microsoft Office Word 2007.lnk
[2009/12/19 18:55:59 | 1072,283,648 | -HS- | C] () – C:\hiberfil.sys
[2009/12/19 18:48:32 | 000,008,192 | R-S- | C] () – C:\BOOTSECT.BAK
[2009/12/19 18:48:31 | 000,438,840 | RHS- | C] () – C:\bootmgr
[2009/12/19 18:37:44 | 000,000,528 | —- | C] () – C:\Windows\System32\nvsmu.nvu
[2009/12/19 17:55:21 | 000,000,680 | —- | C] () – C:\Users\Shannon O'Conner\AppData\Local\d3d9caps.dat
[2009/12/19 17:55:20 | 003,145,728 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT
[2009/12/19 17:55:20 | 000,524,288 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2009/12/19 17:55:20 | 000,524,288 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009/12/19 17:55:20 | 000,262,144 | -H– | C] () – C:\Users\Shannon O'Conner\ntuser.dat.LOG2
[2009/12/19 17:55:20 | 000,262,144 | -H– | C] () – C:\Users\Shannon O'Conner\ntuser.dat.LOG1
[2009/12/19 17:55:20 | 000,065,536 | -HS- | C] () – C:\Users\Shannon O'Conner\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009/12/19 17:55:20 | 000,000,258 | —- | C] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2009/12/19 17:55:20 | 000,000,240 | —- | C] () – C:\Users\Shannon O'Conner\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2009/12/19 17:55:20 | 000,000,020 | -HS- | C] () – C:\Users\Shannon O'Conner\ntuser.ini
[2009/11/09 20:21:03 | 000,068,824 | —- | C] () – C:\Windows\CouponPrinter.ocx
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 15:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/05/06 18:06:00 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll

========== LOP Check ==========

[2010/01/11 14:30:53 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\acccore
[2010/05/10 08:55:35 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\E-centives
[2009/12/19 19:38:53 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\GetRightToGo
[2009/12/20 15:43:54 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\PeerNetworking
[2009/12/30 11:21:15 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\ScanSoft
[2009/12/25 08:18:05 | 000,000,000 | —D | M] – C:\Users\Shannon O'Conner\AppData\Roaming\TomTom
[2010/07/04 11:39:44 | 000,032,606 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2006/11/02 02:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2009/12/19 18:48:32 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/08 16:02:28 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2010/01/11 14:25:16 | 000,000,349 | -H– | M] () – C:\IPH.PH
[2010/09/08 16:02:27 | 1386,217,472 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 05:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/21 22:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPD91.DLL
[2007/05/21 22:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPP91.DLL
[2006/11/02 02:46:05 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/12/21 06:04:52 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 03:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/12 08:58:48 | 000,000,286 | -HS- | M] () – C:\Users\Shannon O'Conner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2007/09/16 08:38:55 | 051,418,424 | —- | M] (Apple Inc.) – C:\Users\Shannon O'Conner\Desktop\iTunesSetup.exe
[2009/07/10 10:08:28 | 002,032,936 | —- | M] (Skype Technologies S.A.) – C:\Users\Shannon O'Conner\Desktop\SkypeSetup.exe
[3 C:\Users\Shannon O'Conner\Desktop\*.tmp files -> C:\Users\Shannon O'Conner\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-08 22:52:28
< End of report >

OTL Extras logfile created on: 9/8/2010 4:22:33 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Shannon O'Conner\Documents\downloads\whatthetech
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 367.00 Mb Available Physical Memory | 36.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 261.23 Gb Free Space | 87.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHANNONOCONNER
Current User Name: Shannon O'Conner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 360 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 1
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5CB3AF15-5BC4-408B-AB9F-FCEF84488255}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{D875C69D-4545-4171-8ACE-A18F7C2642E9}" = lport=5191 | protocol=6 | dir=in | name=the browser highlighter xcom |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02DD14BA-5881-4311-BC59-BE031C9F8BBC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{15EC44DB-5D49-4ED5-96F8-21EC5631953B}" = protocol=6 | dir=in | app=c:\program files\tbh\monitor\bin\tbhmonitor.exe |
"{31634E08-67B6-4A9D-8FCF-5692D7B8F107}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{35AED468-FA15-4AC0-BAF5-79F91171CEB1}" = protocol=6 | dir=in | app=c:\program files\tbh\base\bin\tbhdaemon.exe |
"{4133BAD9-9860-4467-8EE2-D3DB4D8B64A7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6CFAEBFC-88D1-4B34-B750-08A03A252359}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{BA46C493-13DF-4C5D-A53C-ADE78C9005E9}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{BFE75299-776D-4376-9F59-3128DD290497}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C1C625F3-06EE-48D5-93F3-6FAE5CAFA135}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DC3D80A4-B685-4161-BB94-3676AB7A3B9C}" = protocol=17 | dir=in | app=c:\program files\tbh\base\bin\tbhdaemon.exe |
"{F62DA421-9AD8-46E1-96E5-28474E9EEBC2}" = protocol=17 | dir=in | app=c:\program files\tbh\monitor\bin\tbhmonitor.exe |
"TCP Query User{D618F653-6D7B-454C-B924-381F5C358A91}C:\program files\microsoft office\office12\winword.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\winword.exe |
"UDP Query User{B606BC84-A58B-4DF4-9415-6E29FA1EC07E}C:\program files\microsoft office\office12\winword.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\winword.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP970_series" = Canon MP970 series
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{3B62CF95-5E25-4720-A3D6-B4A2B0501961}" = Browser Highlighter - Firefox
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{76756402-BF1E-4A0F-AFCC-0EE6CF58F58C}" = ESET NOD32 Antivirus
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM Toolbar" = AIM Toolbar
"Canon MP970 series User Registration" = Canon MP970 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.10)" = Mozilla Firefox (3.5.10)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.7.3.1894

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/9/2010 6:03:50 AM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/10/2010 6:11:46 AM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 8/10/2010 6:13:57 AM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 9/8/2010 6:48:56 PM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 9/8/2010 6:53:13 PM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 9/8/2010 7:07:33 PM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 9/8/2010 7:07:35 PM | Computer Name = ShannonOConner | Source = Application Error | ID = 1000
Description = Faulting application ekrn.exe, version 4.0.424.0, time stamp 0x49ddea76,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x0339d7d4, process id 0x1c8, application start time 0x01cb4faa0be227ac.

Error - 9/8/2010 7:08:00 PM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 9/8/2010 7:09:04 PM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 9/8/2010 7:18:41 PM | Computer Name = ShannonOConner | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ System Events ]
Error - 12/30/2009 1:44:04 PM | Computer Name = ShannonOConner | Source = DCOM | ID = 10016
Description =

Error - 12/30/2009 1:44:04 PM | Computer Name = ShannonOConner | Source = DCOM | ID = 10016
Description =

Error - 12/30/2009 1:44:04 PM | Computer Name = ShannonOConner | Source = DCOM | ID = 10016
Description =

Error - 12/30/2009 1:44:31 PM | Computer Name = ShannonOConner | Source = DCOM | ID = 10016
Description =

Error - 12/30/2009 1:44:31 PM | Computer Name = ShannonOConner | Source = DCOM | ID = 10016
Description =

Error - 12/30/2009 1:44:31 PM | Computer Name = ShannonOConner | Source = DCOM | ID = 10016
Description =

Error - 1/1/2010 4:46:14 PM | Computer Name = ShannonOConner | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
2, function 0. Please contact your system vendor for technical assistance.

Error - 1/1/2010 4:46:14 PM | Computer Name = ShannonOConner | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
3, function 0. Please contact your system vendor for technical assistance.

Error - 1/1/2010 4:46:14 PM | Computer Name = ShannonOConner | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
4, function 0. Please contact your system vendor for technical assistance.

Error - 1/1/2010 4:47:34 PM | Computer Name = ShannonOConner | Source = Microsoft-Windows-Kernel-General | ID = 5
Description =


< End of report >

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:37:49 PM, on 9/8/2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\tbh\base\bin\tbhSystray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aim toolbar\aimtbServer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Users\Shannon O'Conner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [tbhSystray] C:\Program Files\tbh\base\bin\tbhSystray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: The Browser Highlighter Monitor (tbhMonitor.exe) - Unknown owner - C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7091 bytes


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:39:59.42 on Wed 09/08/2010
Internet Explorer: 7.0.6000.17037
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1022.272 [GMT -7:00]

AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: ESET NOD32 Antivirus 4.0 *enabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
c:\Program Files\tbh\base\bin\tbhDaemon.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\tbh\base\bin\tbhSystray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aim toolbar\aimtbServer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Shannon O'Conner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [tbhSystray] c:\program files\tbh\base\bin\tbhSystray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\windows\system32\wpclsp.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-4-9 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-4-9 94360]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-4-9 731840]
R2 tbhMonitor.exe;The Browser Highlighter Monitor;c:\program files\tbh\monitor\bin\tbhMonitor.exe [2009-10-22 70952]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-11-13 92008]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2006-12-18 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2006-12-18 43904]

=============== Created Last 30 ================


==================== Find3M ====================

2010-07-11 12:28 43,348 a——- c:\programdata\nvModes.dat
2010-07-11 12:28 43,348 a——- c:\progra~2\nvModes.dat
2010-06-24 13:59 86,016 a——- c:\windows\inf\infstrng.dat
2010-06-24 13:59 86,016 a——- c:\windows\inf\infstor.dat
2010-06-24 13:59 51,200 a——- c:\windows\inf\infpub.dat
2010-01-07 17:47 56 a—h— c:\programdata\ezsidmv.dat
2010-01-07 17:47 56 a—h— c:\progra~2\ezsidmv.dat
2009-12-22 03:09 665,600 a——- c:\windows\inf\drvindex.dat
2009-12-21 06:04 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2010-03-04 20:57 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2010-03-04 20:57 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-12-21 18:11 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2009-12-21 18:11 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2009-12-21 18:11 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2010-03-04 20:57 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2009-12-30 10:47 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-12-30 10:47 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-12-30 10:47 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 16:41:08.89 ===============


Your guy's/gal's help is appreciated. Duane
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hi,you have AIM installed on this machine,it can be a drain on resources.Do you use it?



Please do the following.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.








Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.




In your next reply please post the following.
  • MBRCheck log
  • GMER log
Mowman, I asked my wife about AIM (AOL interface) and she said she doesn't use it. I disabled the add-on. Also, Microsoft in a problem repair suggestion box advised the NVideo driver should be updated to the HP version since the MS driver had conflicts. I allowed the update. I hope these 2 changes don't interfere with your work/interpretation of the problems. Had to run GMER in safe mode. I've attached the GMER and MBRCheck logs. Duane
Please do the following.

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Mowman, To run ComboFix, I disabled the 'real-time file system protection' on our malware checker ESET NOD32 however ComboFix did not recognize this. I double checked ESET and it was off. I ran ComboFix anyway despite the warning of unpredictable results. Further, upon completion when I attempted to launch Mozzilla Firefox to open this thread, I got the following message: 'c:\Program Files\Mozilla Firefox\firefox.exe Illegal operation attempted on a registry key that has been marked for deletion' Mozilla would not open. I rebooted and it did. Duane

Attachments:

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please





I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.



How's your computer running now?
You appear clean of infections,please do the following.


ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)






Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.






Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.





[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 21 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 21 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u21 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.




Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI