wenjef1216
2011-01-10, 16:10
OTL logfile created on: 1/10/2011 8:52:53 AM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = E:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 112.00 Mb Available Physical Memory | 22.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 55.59 Gb Free Space | 74.60% Space Free | Partition Type: NTFS
Drive E: | 488.00 Mb Total Space | 271.05 Mb Free Space | 55.54% Space Free | Partition Type: FAT
Computer Name: HOME | User Name: George Barboza | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - E:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Webroot\Security\Current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\Security\Current\plugins\antimalware\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (SafeList) ==========
MOD - E:\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (WRConsumerService) -- C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) -- C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (sftvsa) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (SoundMAX Agent Service (default)) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Driver Services (SafeList) ==========
DRV - (SSIDRV) -- C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSFMONM) -- C:\WINDOWS\system32\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (SSHRMD) -- C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (CO_Mon) -- C:\WINDOWS\system32\drivers\CO_Mon.sys ()
DRV - (Sftredir) -- C:\WINDOWS\system32\drivers\Sftredirxp.sys (Microsoft Corporation)
DRV - (Sftvol) -- C:\WINDOWS\system32\drivers\Sftvolxp.sys (Microsoft Corporation)
DRV - (Sftplay) -- C:\WINDOWS\system32\drivers\Sftplayxp.sys (Microsoft Corporation)
DRV - (Sftfs) -- C:\WINDOWS\system32\drivers\Sftfsxp.sys (Microsoft Corporation)
DRV - (AFS2K) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (N100) -- C:\WINDOWS\system32\drivers\n100325.sys (Compaq Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://echo.entertainment.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:59274
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: FFToolbar@bitdefender.com:2.0
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.8.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 1
FF - HKLM\software\mozilla\Firefox\Extensions\\FFToolbar@bitdefender.com: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\ [2010/09/03 13:25:07 | 000,000,000 | ---D | M]
[2008/09/02 10:13:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\George Barboza\Application Data\Mozilla\Extensions
[2010/07/10 17:52:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\George Barboza\Application Data\Mozilla\Firefox\Profiles\zwptel38.default\extensions
[2009/08/11 12:17:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\George Barboza\Application Data\Mozilla\Firefox\Profiles\zwptel38.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/10 17:52:20 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\George Barboza\Application Data\Mozilla\Firefox\Profiles\zwptel38.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/12/02 16:36:37 | 000,000,000 | ---D | M] ("BitDefender QuickScanner") -- C:\Documents and Settings\George Barboza\Application Data\Mozilla\Firefox\Profiles\zwptel38.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/08/11 23:05:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/25 19:58:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2009\FFTOOLBAR
[2010/04/25 19:57:40 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/11/19 16:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/04/25 19:57:37 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2005/04/27 15:10:49 | 000,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
O1 HOSTS File: ([2010/12/21 15:35:48 | 000,000,707 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe (HP)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [WebrootTrayApp] C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
O4 - HKCU..\Run: [{E441DBD4-9B12-4E72-2F00-C2B924233F30}] C:\Documents and Settings\George Barboza\Application Data\Diytb\hiqoh.exe File not found
O4 - HKCU..\Run: [aydcdgqx] C:\Documents and Settings\George Barboza\Local Settings\Temp\dyekuhmoe\cpeildcaffm.exe ()
O4 - HKCU..\Run: [CyberDefender Registry Cleaner] C:\Program Files\CyberDefender\Registry Cleaner\CDregclean.exe File not found
O4 - HKCU..\Run: [JP595IR86O] C:\DOCUME~1\GEORGE~1\LOCALS~1\Temp\Vkl.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab (Keynote Connector Launcher 2)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://entertainment.webex.com/client/T27L10NSP11EP5/training/ieatgpc.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\George Barboza\Application Data\hotfix.exe) - C:\Documents and Settings\George Barboza\Application Data\hotfix.exe File not found
O20 - Winlogon\Notify\cryptnet32: DllName - cryptnet32.dll - C:\WINDOWS\System32\cryptnet32.dll ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\George Barboza\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\George Barboza\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (ows\s) - File not found
O30 - LSA: Security Packages - (indows.common-controls_6595b641) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/09/14 14:35:42 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{46abfafa-779f-11de-9c74-000bcd2e84c3}\Shell - "" = AutoRun
O33 - MountPoints2\{46abfafa-779f-11de-9c74-000bcd2e84c3}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{46abfafa-779f-11de-9c74-000bcd2e84c3}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{5cc4e1af-62fa-11dc-93b7-e40a6c83ac99}\Shell - "" = AutoRun
O33 - MountPoints2\{5cc4e1af-62fa-11dc-93b7-e40a6c83ac99}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5cc4e1af-62fa-11dc-93b7-e40a6c83ac99}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{5cc4e1b0-62fa-11dc-93b7-e40a6c83ac99}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5cc4e1b0-62fa-11dc-93b7-e40a6c83ac99}\Shell\Open(0)\command - "" = Recycled\ctfmon.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\EasySuite.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/10 08:22:50 | 001,345,624 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\George Barboza\Desktop\TDSSKiller.exe
[2010/12/21 07:35:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\SoftGrid Client
[2010/12/21 07:35:23 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Application Virtualization Client
[2010/12/21 07:35:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Microsoft
[2010/12/21 07:34:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\George Barboza\Application Data\TP
[2010/12/15 10:08:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2007/12/15 19:26:12 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/10 08:49:00 | 000,000,216 | -H-- | M] () -- C:\WINDOWS\tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2011/01/10 08:46:15 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/10 08:46:05 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/10 08:44:00 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2011/01/10 08:31:00 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At56.job
[2011/01/10 08:28:59 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/10 08:28:35 | 000,297,952 | ---- | M] () -- C:\WINDOWS\System32\shimg.dll
[2011/01/10 08:28:26 | 000,000,306 | -H-- | M] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/01/10 08:28:26 | 000,000,012 | ---- | M] () -- C:\WINDOWS\System32\crt.dat
[2011/01/10 08:27:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At32.job
[2011/01/10 08:27:45 | 000,026,112 | ---- | M] () -- C:\WINDOWS\System32\dll.dll
[2011/01/10 08:27:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/10 08:22:00 | 000,000,258 | -H-- | M] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2011/01/10 08:11:31 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At59.job
[2011/01/10 08:11:31 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2011/01/03 11:22:37 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At47.job
[2011/01/03 11:22:37 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At70.job
[2011/01/03 11:22:36 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2011/01/02 21:50:02 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At69.job
[2011/01/02 21:35:14 | 000,294,400 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\exeHelper.com
[2011/01/02 21:16:43 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At45.job
[2011/01/02 21:16:43 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2011/01/02 20:36:38 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/12/25 00:42:09 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At25.job
[2010/12/25 00:42:09 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At48.job
[2010/12/25 00:01:52 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At71.job
[2010/12/23 11:25:40 | 000,780,283 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\rkill.exe
[2010/12/21 15:34:04 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At63.job
[2010/12/21 11:18:30 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At35.job
[2010/12/21 10:44:17 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At34.job
[2010/12/21 10:44:17 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At58.job
[2010/12/21 10:12:29 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2010/12/21 09:42:56 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At57.job
[2010/12/21 09:28:53 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At33.job
[2010/12/21 09:28:53 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At31.job
[2010/12/21 09:28:53 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At55.job
[2010/12/21 09:28:53 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2010/12/21 07:36:15 | 000,466,302 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/12/21 07:36:15 | 000,079,804 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At43.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At42.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At41.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At40.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At39.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At38.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At37.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At66.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At65.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At64.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At62.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At61.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2010/12/21 07:05:35 | 000,278,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/20 17:32:27 | 000,388,087 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\CB Prize Report 121410.xls
[2010/12/20 16:51:52 | 000,039,083 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Arcola Elementary School.JPG
[2010/12/20 14:36:15 | 000,061,263 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Spotsy Cty Foudation letter to schools Fall 2010.pdf
[2010/12/20 14:33:14 | 000,048,128 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\PWCty Foundation letter Fall 2010.doc
[2010/12/18 19:47:04 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At36.job
[2010/12/18 19:47:04 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At60.job
[2010/12/18 19:47:04 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\At54.job
[2010/12/18 19:47:04 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2010/12/18 19:47:04 | 000,000,408 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2010/12/17 15:35:12 | 000,064,038 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\ArcolaDragon_color_outlined.JPG
[2010/12/17 10:08:52 | 000,096,256 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Retail Locations Verification[1].doc
[2010/12/16 12:21:52 | 002,997,791 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Arcola Preview[1].pdf
[2010/12/16 11:34:35 | 001,792,512 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Store Audit form K-O.xls
[2010/12/16 11:33:51 | 004,306,944 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Store Audit form A-C.xls
[2010/12/16 10:33:09 | 002,773,914 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Legacy Preview 12-16[1].pdf
[2010/12/16 09:47:52 | 001,345,624 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\George Barboza\Desktop\TDSSKiller.exe
[2010/12/16 09:33:57 | 001,627,136 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Kilmer Detail Report 092010.xls
[2010/12/16 09:33:02 | 000,011,882 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Jeff's 10FACP Updates(1).xlsx
[2010/12/15 16:14:23 | 000,818,688 | ---- | M] () -- C:\Documents and Settings\George Barboza\Desktop\Jeff Elliott Collection Tracker 12-15-10.xls
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/10 08:28:06 | 000,000,012 | ---- | C] () -- C:\WINDOWS\System32\crt.dat
[2011/01/02 21:37:29 | 000,294,400 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\exeHelper.com
[2011/01/02 21:37:19 | 000,780,283 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\rkill.exe
[2010/12/20 17:32:23 | 000,388,087 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\CB Prize Report 121410.xls
[2010/12/20 16:51:52 | 000,039,083 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Arcola Elementary School.JPG
[2010/12/20 14:36:15 | 000,061,263 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Spotsy Cty Foudation letter to schools Fall 2010.pdf
[2010/12/20 14:33:13 | 000,048,128 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\PWCty Foundation letter Fall 2010.doc
[2010/12/17 15:35:11 | 000,064,038 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\ArcolaDragon_color_outlined.JPG
[2010/12/17 10:08:51 | 000,096,256 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Retail Locations Verification[1].doc
[2010/12/16 15:23:27 | 000,028,160 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Wendy Payback Schedule.xls
[2010/12/16 12:21:52 | 002,997,791 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Arcola Preview[1].pdf
[2010/12/16 11:34:34 | 001,792,512 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Store Audit form K-O.xls
[2010/12/16 11:33:47 | 004,306,944 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Store Audit form A-C.xls
[2010/12/16 10:33:08 | 002,773,914 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Legacy Preview 12-16[1].pdf
[2010/12/16 09:33:01 | 000,011,882 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Jeff's 10FACP Updates(1).xlsx
[2010/12/15 16:14:23 | 000,818,688 | ---- | C] () -- C:\Documents and Settings\George Barboza\Desktop\Jeff Elliott Collection Tracker 12-15-10.xls
[2010/12/06 16:38:39 | 000,297,952 | ---- | C] () -- C:\WINDOWS\System32\shimg.dll
[2010/12/06 16:38:39 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\dll.dll
[2010/12/06 16:38:37 | 000,048,128 | ---- | C] () -- C:\WINDOWS\System32\cryptnet32.dll
[2010/11/15 19:26:16 | 000,030,424 | ---- | C] () -- C:\WINDOWS\System32\wrLZMA.dll
[2010/11/04 07:39:38 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\George Barboza\Application Data\start
[2010/11/04 07:38:21 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\George Barboza\Application Data\completescan
[2010/11/02 07:03:11 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\George Barboza\Application Data\install
[2010/11/02 06:17:48 | 000,000,237 | ---- | C] () -- C:\Documents and Settings\George Barboza\Application Data\dkfjasdfshd.bat
[2009/09/11 15:17:48 | 000,034,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\CO_Mon.sys
[2009/03/14 12:29:44 | 000,561,152 | R--- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2008/12/26 19:47:43 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/12/26 05:52:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\UltimateBuddy.INI
[2007/10/08 05:14:00 | 000,011,776 | ---- | C] () -- C:\Documents and Settings\George Barboza\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/09/18 21:54:41 | 000,000,121 | ---- | C] () -- C:\WINDOWS\bdagent.INI
[2007/09/14 16:00:12 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/09/14 15:31:08 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2007/09/14 14:27:40 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[1999/01/22 13:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2010/09/03 13:25:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BitDefender
[2008/09/02 12:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
[2007/09/14 16:12:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Geek Squad
[2010/03/05 14:18:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PassMark
[2010/11/05 14:50:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/09/02 12:51:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/11/15 19:23:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{E15A1CA7-D908-4C28-ADCF-C23723A9D28D}
[2008/09/02 12:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\eBay
[2010/11/05 10:58:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\Ecicha
[2008/09/14 16:30:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\funkitron
[2009/10/02 10:29:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\Juniper Networks
[2010/11/15 17:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\Keynote Systems
[2008/02/16 10:00:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\Leadertech
[2009/11/08 12:21:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\QuickScan
[2008/02/16 09:46:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\RegSweep
[2010/12/21 07:59:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\TP
[2009/12/21 15:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\Uniblue
[2010/12/20 16:23:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\webex
[2009/12/11 21:27:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\Windows Desktop Search
[2010/02/24 20:01:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\George Barboza\Application Data\Windows Search
[2011/01/02 20:36:38 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2010/12/21 10:12:29 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2011/01/10 08:11:31 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2010/12/18 19:47:04 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2010/12/21 07:05:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2010/12/03 16:19:55 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2010/11/09 06:54:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2011/01/02 21:16:43 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2010/12/06 06:38:20 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2011/01/03 11:22:36 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2010/11/09 06:54:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2010/11/09 06:54:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2010/12/25 00:42:09 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At25.job
[2010/11/09 06:54:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At26.job
[2010/11/09 06:54:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At27.job
[2010/11/09 04:14:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At28.job
[2010/11/09 05:14:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At29.job
[2010/11/09 06:54:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2010/11/09 06:14:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At30.job
[2010/12/21 09:28:53 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At31.job
[2011/01/10 08:27:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At32.job
[2010/12/21 09:28:53 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At33.job
[2010/12/21 10:44:17 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At34.job
[2010/12/21 11:18:30 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At35.job
[2010/12/18 19:47:04 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At36.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At37.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At38.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At39.job
[2010/11/09 06:54:48 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At40.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At41.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At42.job
[2010/12/21 07:05:48 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At43.job
[2010/11/16 06:26:15 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At44.job
[2011/01/02 21:16:43 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At45.job
[2010/12/06 06:38:20 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At46.job
[2011/01/03 11:22:37 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At47.job
[2010/12/25 00:42:09 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At48.job
[2010/11/09 06:54:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At49.job
[2010/11/09 04:44:00 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2010/11/09 06:54:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At50.job
[2010/11/09 06:54:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At51.job
[2010/11/09 04:31:00 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At52.job
[2010/11/09 05:31:00 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At53.job
[2010/12/18 19:47:04 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At54.job
[2010/12/21 09:28:53 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At55.job
[2011/01/10 08:31:00 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At56.job
[2010/12/21 09:42:56 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At57.job
[2010/12/21 10:44:17 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At58.job
[2011/01/10 08:11:31 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At59.job
[2010/11/09 05:44:00 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2010/12/18 19:47:04 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At60.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At61.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At62.job
[2010/12/21 15:34:04 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At63.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At64.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At65.job
[2010/12/21 07:05:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At66.job
[2010/12/03 16:19:55 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At67.job
[2010/11/16 06:26:15 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At68.job
[2011/01/02 21:50:02 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At69.job
[2010/12/18 19:47:04 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2011/01/03 11:22:37 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At70.job
[2010/12/25 00:01:52 | 000,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\At71.job
[2010/12/21 09:28:53 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2011/01/10 08:44:00 | 000,000,408 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job
[2010/11/09 03:30:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\RegSweep Scheduled Scan.job
[2010/12/08 11:37:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job
[2007/12/22 07:26:17 | 000,000,410 | ---- | M] () -- C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
[2011/01/10 08:28:26 | 000,000,306 | -H-- | M] () -- C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/01/10 08:49:00 | 000,000,216 | -H-- | M] () -- C:\WINDOWS\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2011/01/10 08:22:00 | 000,000,258 | -H-- | M] () -- C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A121498D
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BF1BA808
< End of report >