second half of one result =txt file
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/24 14:18:23 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\fran\Desktop\OTL.exe
[2012/01/24 14:11:18 | 000,000,000 | ---D | C] -- C:\ProgramData\HPSS
[2012/01/24 14:10:48 | 000,000,000 | ---D | C] -- C:\Users\fran\AppData\Roaming\HP SimpleSave Application
[2012/01/24 14:10:13 | 000,000,000 | ---D | C] -- C:\Users\fran\AppData\Roaming\HPSS
[2012/01/23 16:30:36 | 000,000,000 | --SD | C] -- C:\YourApp
[2012/01/22 11:56:05 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/01/22 11:56:05 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/01/22 11:56:05 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/01/22 11:55:58 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/01/22 11:47:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/22 11:46:25 | 004,388,468 | R--- | C] (Swearware) -- C:\Users\fran\Desktop\Combofix.exe
[2012/01/20 16:51:53 | 002,054,448 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\fran\Desktop\MY APP.exe
[2012/01/20 16:18:00 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\fran\Desktop\boot_cleaner.exe
[2012/01/20 15:37:22 | 004,713,472 | ---- | C] (AVAST Software) -- C:\Users\fran\Desktop\aswMBR.exe
[2012/01/18 16:33:41 | 007,734,240 | -H-- | C] (Malwarebytes Corporation ) -- C:\Users\fran\Desktop\explorer.exe.exe
[2012/01/18 14:52:15 | 000,000,000 | -H-D | C] -- C:\Users\fran\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2011/12/28 19:48:36 | 000,000,000 | -H-D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/12/28 19:48:36 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/12/28 19:46:35 | 016,409,960 | -H-- | C] (Safer Networking Limited ) -- C:\Users\fran\Documents\spybotsd162.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\fran\*.tmp files -> C:\Users\fran\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/24 14:18:25 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\fran\Desktop\OTL.exe
[2012/01/24 14:13:10 | 000,617,226 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/01/24 14:13:10 | 000,108,360 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/01/24 14:09:59 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F623431B-85FC-4B49-9266-D17D838F2373}.job
[2012/01/24 14:08:15 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 14:08:15 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 14:08:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/23 14:15:40 | 004,388,468 | R--- | M] (Swearware) -- C:\Users\fran\Desktop\Combofix.exe
[2012/01/22 14:05:46 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/01/22 14:05:23 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/01/21 21:17:41 | 000,000,512 | ---- | M] () -- C:\Users\fran\Desktop\MBR.dat
[2012/01/20 16:52:00 | 002,054,448 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\fran\Desktop\MY APP.exe
[2012/01/20 16:17:21 | 000,044,607 | ---- | M] () -- C:\Users\fran\Desktop\bootkit_remover.zip
[2012/01/20 15:37:23 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\fran\Desktop\aswMBR.exe
[2012/01/20 15:14:35 | 253,952,373 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/01/19 17:21:33 | 000,000,448 | -H-- | M] () -- C:\ProgramData\k7vUREwXGlnIiC
[2012/01/19 17:19:53 | 000,000,296 | -H-- | M] () -- C:\ProgramData\~k7vUREwXGlnIiC
[2012/01/19 17:19:53 | 000,000,176 | -H-- | M] () -- C:\ProgramData\~k7vUREwXGlnIiCr
[2012/01/19 17:19:51 | 000,000,631 | -H-- | M] () -- C:\Users\fran\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/19 16:26:03 | 000,000,456 | -H-- | M] () -- C:\ProgramData\q5Tf4nr63zhUx2
[2012/01/19 16:24:23 | 000,000,296 | -H-- | M] () -- C:\ProgramData\~q5Tf4nr63zhUx2
[2012/01/19 16:24:23 | 000,000,176 | -H-- | M] () -- C:\ProgramData\~q5Tf4nr63zhUx2r
[2012/01/19 16:15:47 | 000,448,768 | -H-- | M] () -- C:\ProgramData\123.exe
[2012/01/18 17:06:14 | 000,014,186 | -HS- | M] () -- C:\Users\fran\Documents\Folder.jpg
[2012/01/18 17:06:14 | 000,014,186 | -HS- | M] () -- C:\Users\fran\Documents\AlbumArt_{EFCC2E09-1FAB-4AF3-8F7B-C3273BFBD6CF}_Large.jpg
[2012/01/18 17:05:40 | 000,003,171 | -HS- | M] () -- C:\Users\fran\Documents\AlbumArtSmall.jpg
[2012/01/18 17:05:40 | 000,003,171 | -HS- | M] () -- C:\Users\fran\Documents\AlbumArt_{EFCC2E09-1FAB-4AF3-8F7B-C3273BFBD6CF}_Small.jpg
[2012/01/18 17:03:49 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/18 14:55:22 | 000,000,440 | -H-- | M] () -- C:\ProgramData\ofMZsqDhhCLj4V
[2012/01/18 14:52:17 | 000,000,296 | -H-- | M] () -- C:\ProgramData\~ofMZsqDhhCLj4V
[2012/01/18 14:52:17 | 000,000,176 | -H-- | M] () -- C:\ProgramData\~ofMZsqDhhCLj4Vr
[2012/01/18 14:52:15 | 000,000,607 | -H-- | M] () -- C:\Users\fran\Desktop\System Check.lnk
[2012/01/16 19:37:38 | 000,008,754 | ---- | M] () -- C:\ProgramData\52423c85
[2012/01/16 16:04:43 | 000,062,459 | -H-- | M] () -- C:\Users\fran\Documents\The_Descendants_2011_REPACK_SCREENER_XviD_-_ZOMBiES.6959683.TPB.torrent
[2012/01/16 15:49:14 | 000,029,738 | -H-- | M] () -- C:\Users\fran\Documents\Moneyball_2011_BRRip_XviD-FTW.6892152.TPB.torrent
[2012/01/15 14:03:03 | 000,001,854 | -H-- | M] () -- C:\Users\fran\Desktop\PeerBlock.lnk
[2012/01/15 14:03:03 | 000,001,825 | -H-- | M] () -- C:\Users\fran\Desktop\BitTorrent.lnk
[2012/01/14 20:43:45 | 000,014,666 | -H-- | M] () -- C:\Users\fran\Documents\Person.of.Interest.S01E10.HDTV.XviD-ASAP [AGENT][1337x.org].torrent
[2012/01/13 17:58:32 | 000,007,476 | -H-- | M] () -- C:\Users\fran\Documents\The.Mentalist.S04E11.HDTV.XviD-ASAP.[VTV].avi.6951405.TPB.torrent
[2012/01/13 17:01:24 | 000,014,499 | -H-- | M] () -- C:\Users\fran\Documents\Person_of_Interest_S01E11_HDTV_XviD-ASAP_[eztv].6951579.TPB.torrent
[2012/01/12 14:19:44 | 000,014,593 | -H-- | M] () -- C:\Users\fran\Documents\Unforgettable_S01E12_HDTV_XviD-ASAP_[eztv][1337x.org].torrent
[2012/01/12 14:17:56 | 000,014,590 | -H-- | M] () -- C:\Users\fran\Documents\Unforgettable_S01E13_HDTV_XviD-2HD_[eztv][1337x.org].torrent
[2012/01/12 14:14:21 | 000,014,490 | -H-- | M] () -- C:\Users\fran\Documents\Harrys_Law_S02E11_HDTV_XviD-LOL_[eztv].6949132.TPB.torrent
[2012/01/12 14:11:44 | 000,014,479 | -H-- | M] () -- C:\Users\fran\Documents\Law.and.Order.SVU.S13E11.HDTV.XviD-LOL.[VTV].avi.6949230.TPB.torrent
[2012/01/09 17:13:27 | 017,364,199 | -H-- | M] () -- C:\Users\fran\Desktop\Excel 2010 For Dummies - (Maalestrom).pdf
[2012/01/09 17:12:20 | 000,006,337 | -H-- | M] () -- C:\Users\fran\Documents\Excel 2010 For Dummies - (Malestrom) [h33t].torrent
[2012/01/09 16:35:45 | 000,006,726 | -H-- | M] () -- C:\Users\fran\AppData\Roaming\wklnhst.dat
[2011/12/30 12:58:41 | 000,031,232 | -H-- | M] () -- C:\Users\fran\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/28 19:47:43 | 016,409,960 | -H-- | M] (Safer Networking Limited ) -- C:\Users\fran\Documents\spybotsd162.exe
[2011/12/26 13:13:52 | 000,008,105 | -H-- | M] () -- C:\Users\fran\Documents\Sibling.Rivalry.1990.DVDRip.x264.6384000.TPB.torrent
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\fran\*.tmp files -> C:\Users\fran\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/22 11:56:05 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/01/22 11:56:05 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/01/22 11:56:05 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/01/22 11:56:05 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/01/22 11:56:05 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/01/20 16:17:20 | 000,044,607 | ---- | C] () -- C:\Users\fran\Desktop\bootkit_remover.zip
[2012/01/20 16:10:17 | 000,000,512 | ---- | C] () -- C:\Users\fran\Desktop\MBR.dat
[2012/01/19 17:19:53 | 000,000,296 | -H-- | C] () -- C:\ProgramData\~k7vUREwXGlnIiC
[2012/01/19 17:19:53 | 000,000,176 | -H-- | C] () -- C:\ProgramData\~k7vUREwXGlnIiCr
[2012/01/19 17:19:51 | 000,000,631 | -H-- | C] () -- C:\Users\fran\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/19 17:19:46 | 000,000,448 | -H-- | C] () -- C:\ProgramData\k7vUREwXGlnIiC
[2012/01/19 16:24:23 | 000,000,296 | -H-- | C] () -- C:\ProgramData\~q5Tf4nr63zhUx2
[2012/01/19 16:24:23 | 000,000,176 | -H-- | C] () -- C:\ProgramData\~q5Tf4nr63zhUx2r
[2012/01/19 16:24:14 | 000,000,456 | -H-- | C] () -- C:\ProgramData\q5Tf4nr63zhUx2
[2012/01/19 16:15:47 | 000,448,768 | -H-- | C] () -- C:\ProgramData\123.exe
[2012/01/18 17:06:16 | 000,014,186 | -HS- | C] () -- C:\Users\fran\Documents\Folder.jpg
[2012/01/18 17:06:16 | 000,014,186 | -HS- | C] () -- C:\Users\fran\Documents\AlbumArt_{EFCC2E09-1FAB-4AF3-8F7B-C3273BFBD6CF}_Large.jpg
[2012/01/18 17:06:16 | 000,003,171 | -HS- | C] () -- C:\Users\fran\Documents\AlbumArtSmall.jpg
[2012/01/18 17:06:16 | 000,003,171 | -HS- | C] () -- C:\Users\fran\Documents\AlbumArt_{EFCC2E09-1FAB-4AF3-8F7B-C3273BFBD6CF}_Small.jpg
[2012/01/18 17:03:49 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/18 14:52:17 | 000,000,296 | -H-- | C] () -- C:\ProgramData\~ofMZsqDhhCLj4V
[2012/01/18 14:52:17 | 000,000,176 | -H-- | C] () -- C:\ProgramData\~ofMZsqDhhCLj4Vr
[2012/01/18 14:52:15 | 000,000,607 | -H-- | C] () -- C:\Users\fran\Desktop\System Check.lnk
[2012/01/18 14:52:12 | 000,000,440 | -H-- | C] () -- C:\ProgramData\ofMZsqDhhCLj4V
[2012/01/16 16:06:09 | 000,008,754 | ---- | C] () -- C:\ProgramData\52423c85
[2012/01/16 16:04:43 | 000,062,459 | -H-- | C] () -- C:\Users\fran\Documents\The_Descendants_2011_REPACK_SCREENER_XviD_-_ZOMBiES.6959683.TPB.torrent
[2012/01/16 15:49:13 | 000,029,738 | -H-- | C] () -- C:\Users\fran\Documents\Moneyball_2011_BRRip_XviD-FTW.6892152.TPB.torrent
[2012/01/14 20:43:45 | 000,014,666 | -H-- | C] () -- C:\Users\fran\Documents\Person.of.Interest.S01E10.HDTV.XviD-ASAP [AGENT][1337x.org].torrent
[2012/01/13 17:58:32 | 000,007,476 | -H-- | C] () -- C:\Users\fran\Documents\The.Mentalist.S04E11.HDTV.XviD-ASAP.[VTV].avi.6951405.TPB.torrent
[2012/01/13 17:01:24 | 000,014,499 | -H-- | C] () -- C:\Users\fran\Documents\Person_of_Interest_S01E11_HDTV_XviD-ASAP_[eztv].6951579.TPB.torrent
[2012/01/12 14:19:43 | 000,014,593 | -H-- | C] () -- C:\Users\fran\Documents\Unforgettable_S01E12_HDTV_XviD-ASAP_[eztv][1337x.org].torrent
[2012/01/12 14:17:50 | 000,014,590 | -H-- | C] () -- C:\Users\fran\Documents\Unforgettable_S01E13_HDTV_XviD-2HD_[eztv][1337x.org].torrent
[2012/01/12 14:14:21 | 000,014,490 | -H-- | C] () -- C:\Users\fran\Documents\Harrys_Law_S02E11_HDTV_XviD-LOL_[eztv].6949132.TPB.torrent
[2012/01/12 14:11:42 | 000,014,479 | -H-- | C] () -- C:\Users\fran\Documents\Law.and.Order.SVU.S13E11.HDTV.XviD-LOL.[VTV].avi.6949230.TPB.torrent
[2012/01/09 17:14:25 | 017,364,199 | -H-- | C] () -- C:\Users\fran\Desktop\Excel 2010 For Dummies - (Maalestrom).pdf
[2012/01/09 17:12:20 | 000,006,337 | -H-- | C] () -- C:\Users\fran\Documents\Excel 2010 For Dummies - (Malestrom) [h33t].torrent
[2011/12/30 12:48:35 | 001,667,808 | -H-- | C] () -- C:\Users\fran\Desktop\Picture 102.jpg
[2011/12/29 17:11:41 | 000,002,045 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/12/26 13:13:52 | 000,008,105 | -H-- | C] () -- C:\Users\fran\Documents\Sibling.Rivalry.1990.DVDRip.x264.6384000.TPB.torrent
[2011/12/24 18:08:34 | 000,012,680 | -HS- | C] () -- C:\Users\fran\AppData\Local\16qb5285s67yesn24bxfk81p33a02r8x
[2011/12/24 18:08:34 | 000,012,680 | -HS- | C] () -- C:\ProgramData\16qb5285s67yesn24bxfk81p33a02r8x
[2011/12/20 13:10:54 | 000,004,348 | -HS- | C] () -- C:\Users\fran\AppData\Local\506881s3y808c713u857y1ysd5m6
[2011/12/20 13:10:54 | 000,003,930 | -HS- | C] () -- C:\ProgramData\506881s3y808c713u857y1ysd5m6
[2010/07/14 14:36:24 | 000,000,620 | ---- | C] () -- C:\Windows\RegGenie.ini
[2010/05/20 14:04:48 | 000,002,873 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate
[2010/03/27 20:06:36 | 000,100,000 | ---- | C] () -- C:\Windows\System32\xvidcore (2).dll
[2009/11/22 10:14:57 | 000,000,578 | ---- | C] () -- C:\Windows\M3JPEG.INI
[2009/09/16 20:58:33 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/16 20:58:33 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/15 12:22:41 | 000,169,341 | ---- | C] () -- C:\Windows\hpqins00.dat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/14 13:50:11 | 000,069,632 | ---- | C] () -- C:\Windows\System32\vzcontextmenu.dll
[2009/06/30 12:25:09 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Commands
[2009/06/30 12:25:09 | 000,000,268 | RH-- | C] () -- C:\Users\fran\AppData\Roaming\ColorTable
[2009/06/30 12:25:09 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdw.DAT
[2009/06/30 12:12:46 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Comedy Noises
[2009/06/30 12:12:46 | 000,000,268 | RH-- | C] () -- C:\Users\fran\AppData\Roaming\Cocoa
[2009/06/30 12:12:46 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2009/04/10 10:22:50 | 000,208,896 | ---- | C] () -- C:\Windows\LiveClient.dll
[2009/04/10 10:22:50 | 000,176,128 | ---- | C] () -- C:\Windows\GeoCodecLib.dll
[2009/01/12 18:06:56 | 000,005,055 | -H-- | C] () -- C:\ProgramData\ywasvxup.hvs
[2009/01/10 11:39:27 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\879bd249e38aa95
[2009/01/10 11:36:51 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\e2885dfed4432ad
[2009/01/10 11:30:31 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\f4b4078416895d5
[2009/01/10 11:30:11 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\5bd984c3690c592
[2009/01/10 11:27:06 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\e24b76a18275429
[2009/01/10 11:26:36 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\16a31fe427215df
[2009/01/10 11:23:25 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\8c381622b054eae
[2009/01/10 11:21:10 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\dfa409a166a6a13
[2009/01/10 11:19:15 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\32584a94ef4d92a
[2009/01/10 11:19:05 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\1a4687276c956c8
[2009/01/10 11:18:00 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\99ce21a2ae22606
[2009/01/10 11:17:30 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\c8c5499adc56da5
[2009/01/10 11:14:50 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\acbb6ef48b6dc68
[2009/01/10 11:14:14 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\c9104d4825b6261
[2009/01/10 11:07:59 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\4f8f8cf620a3077
[2009/01/10 10:23:30 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\65a00ff4fc8f1af
[2009/01/10 10:22:30 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\b06b03ba03bca22
[2009/01/09 18:10:36 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\491b74175c778c5
[2009/01/09 18:05:40 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\d4b5c41f8d74e6a
[2009/01/09 18:04:41 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\eb4387b7e66a85f
[2009/01/09 17:59:55 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\ff86e0b75094016
[2009/01/09 17:59:09 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\5b3cf438eb60b35
[2009/01/09 17:57:49 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\1c259bf20aab364
[2009/01/09 17:56:44 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\40beebab9c36ce0
[2009/01/09 17:53:34 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\b1b638edd446128
[2009/01/09 17:53:14 | 000,003,262 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\94800ada1706250
[2008/09/24 11:06:25 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/07/22 12:11:23 | 000,130,976 | ---- | C] () -- C:\Windows\hpoins18.dat.temp
[2008/07/22 12:11:23 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat.temp
[2008/06/18 19:51:06 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1504.dll
[2008/03/25 15:56:08 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1461.dll
[2008/02/27 16:04:58 | 000,000,153 | ---- | C] () -- C:\Windows\ACROREAD.INI
[2008/02/17 16:27:16 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2008/01/26 15:47:25 | 000,000,000 | ---- | C] () -- C:\Windows\Irremote.ini
[2008/01/19 12:15:12 | 000,001,028 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\AVIEncoder.wff
[2008/01/04 15:58:50 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2007/10/17 07:45:12 | 000,000,087 | ---- | C] () -- C:\Windows\UsnapPRO.INI
[2007/10/16 10:46:44 | 000,250,156 | -H-- | C] () -- C:\Users\fran\AppData\Local\rx_image.Cache
[2007/09/26 16:07:02 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2007/09/10 12:55:05 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2007/08/28 18:23:04 | 000,006,726 | -H-- | C] () -- C:\Users\fran\AppData\Roaming\wklnhst.dat
[2007/08/24 18:46:48 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1322.dll
[2007/08/23 18:35:04 | 000,210,944 | ---- | C] () -- C:\Windows\System32\MSVCRT10.DLL
[2007/08/23 18:35:04 | 000,000,165 | ---- | C] () -- C:\Windows\KPCMS.INI
[2007/08/23 18:35:03 | 000,100,864 | ---- | C] () -- C:\Windows\System32\Dc50ip32.dll
[2007/08/23 18:35:03 | 000,065,864 | ---- | C] () -- C:\Windows\System32\Digita.sys
[2007/08/23 18:35:03 | 000,006,144 | ---- | C] () -- C:\Windows\System32\ImgLibLead.dll
[2007/08/23 15:41:46 | 000,130,425 | ---- | C] () -- C:\Windows\hpoins18.dat
[2007/08/23 11:27:37 | 000,031,232 | -H-- | C] () -- C:\Users\fran\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/23 11:23:50 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
[2007/03/10 05:51:48 | 000,139,264 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2007/03/08 09:25:12 | 000,061,440 | ---- | C] () -- C:\Windows\System32\OsdRemove.exe
[2007/03/08 09:22:22 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom24.dll
[2007/03/08 09:22:22 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes24.dll
[2007/03/08 09:13:09 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1132.dll
[2007/03/06 12:49:42 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1227.dll
[2007/02/28 17:52:43 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2007/02/05 18:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2007/01/10 05:56:34 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2006/11/02 06:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 06:47:37 | 000,461,440 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 04:33:01 | 000,617,226 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,108,360 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 04:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/10/17 09:11:04 | 000,002,045 | -H-- | C] () -- C:\Windows\System32\whlpusp32.dll
[2006/08/11 01:00:40 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/08/11 01:00:40 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/06/23 12:09:34 | 000,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll
[2006/02/25 12:09:38 | 000,524,288 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
========== LOP Check ==========
[2007/12/05 12:49:48 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\AVSMedia
[2008/01/19 20:45:55 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Azureus
[2012/01/16 16:59:53 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\BitTorrent
[2008/03/13 10:28:13 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\BitTorrent DNA
[2012/01/24 14:28:25 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\DNA
[2009/01/12 12:17:50 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\DriverCure
[2010/06/20 19:06:43 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\FreeFLVConverter
[2008/11/13 16:58:15 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\FrostWire
[2008/11/05 11:05:30 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\GrabPro
[2011/11/01 18:13:35 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Image Zone Express
[2010/05/14 17:00:31 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Leadertech
[2008/11/22 12:06:01 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\LimeWire(56)
[2009/05/06 16:05:01 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\muvee Technologies
[2008/01/19 12:18:35 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\NCH Swift Sound
[2009/07/17 16:18:14 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Nikon
[2008/02/18 10:20:15 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Opera
[2011/06/17 13:56:28 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Orbit
[2007/12/29 17:52:47 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Pegasys Inc
[2007/08/23 16:25:44 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Printer Info Cache
[2008/01/19 20:45:56 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\SuperNZB
[2007/08/28 18:23:06 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Template
[2009/02/23 19:42:59 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\TomTom
[2010/07/14 14:56:53 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Uniblue
[2008/02/05 15:08:17 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\WinAVI
[2007/08/24 13:53:11 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\WinBatch
[2011/05/20 13:49:53 | 000,000,000 | -H-D | M] -- C:\Users\fran\AppData\Roaming\Windows Live Writer
[2012/01/23 19:52:30 | 000,032,586 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/01/24 14:09:59 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{F623431B-85FC-4B49-9266-D17D838F2373}.job
========== Purity Check ==========
========== Custom Scans ==========
< >
< >
< %SYSTEMDRIVE%\*.* >
[2009/05/05 12:32:01 | 000,000,174 | ---- | M] () -- C:\autoexec.bat
[2008/01/19 12:51:28 | 000,009,762 | ---- | M] () -- C:\avi_log.txt
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2007/03/08 09:12:49 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2008/01/19 17:50:41 | 000,024,219 | ---- | M] () -- C:\debug.log
[2009/11/17 17:28:04 | 000,000,064 | ---- | M] () -- C:\FINIS_IT.TXT
[2007/10/20 13:34:07 | 024,116,881 | ---- | M] () -- C:\HpWinVNC4.log
[2007/08/23 18:33:32 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/08/23 18:33:32 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2007/06/22 09:13:21 | 000,000,761 | ---- | M] () -- C:\net_save.dna
[2008/09/03 18:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\npbittorrent.dll
[2012/01/24 14:08:02 | 3525,066,752 | -HS- | M] () -- C:\pagefile.sys
[2007/07/18 23:29:40 | 003,405,312 | ---- | M] (Adobe Systems, Inc.) -- C:\PD4.exe
[2008/07/21 10:22:48 | 000,000,477 | ---- | M] () -- C:\RHDSetup.log
[2012/01/20 16:54:48 | 000,074,194 | ---- | M] () -- C:\TDSSKiller.2.7.6.0_20.01.2012_16.53.13_log.txt
[2012/01/23 16:29:17 | 000,071,858 | ---- | M] () -- C:\TDSSKiller.2.7.6.0_23.01.2012_16.20.12_log.txt
[2008/01/19 15:29:08 | 000,004,745 | ---- | M] () -- C:\unins000.dat
[2008/12/13 12:14:23 | 000,000,594 | ---- | M] () -- C:\updatedatfix.log
< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/23 14:55:57 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/02/02 10:26:36 | 000,273,920 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\hpzpp4v2.dll
[2006/11/02 06:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[1998/04/18 09:34:56 | 000,054,784 | ---- | M] (Storm Technology, Inc.) -- C:\Windows\EasyPhoto Slide Show.scr
[2010/11/10 01:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/07/19 10:37:32 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2008/03/15 06:10:09 | 023,454,528 | -H-- | M] ( ) -- C:\Users\fran\Desktop\AdbeRdr812_en_US.exe
[2012/01/20 15:37:23 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\fran\Desktop\aswMBR.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\fran\Desktop\boot_cleaner.exe
[2012/01/23 14:15:40 | 004,388,468 | R--- | M] (Swearware) -- C:\Users\fran\Desktop\Combofix.exe
[2010/12/24 16:22:34 | 007,734,240 | -H-- | M] (Malwarebytes Corporation ) -- C:\Users\fran\Desktop\explorer.exe.exe
[2012/01/20 16:52:00 | 002,054,448 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\fran\Desktop\MY APP.exe
[2012/01/24 14:18:25 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\fran\Desktop\OTL.exe
[2007/11/13 18:50:35 | 022,749,719 | -H-- | M] (Shark007) -- C:\Users\fran\Desktop\VistaCodecs_v452.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
[2009/07/30 09:56:55 | 000,061,224 | -H-- | M] () -- C:\Users\fran\GoToAssistDownloadHelper.exe
[1 C:\Users\fran\*.tmp files -> C:\Users\fran\*.tmp -> ]
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2009/09/23 15:16:56 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2009/09/23 15:16:26 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2009/09/23 15:16:26 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2009/09/23 15:16:26 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2009/09/23 15:16:26 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
[2009/09/23 15:16:26 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2007/08/29 08:38:58 | 000,000,402 | -HS- | M] () -- C:\Users\fran\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/01/19 16:15:47 | 000,448,768 | -H-- | M] () -- C:\ProgramData\123.exe
[2011/12/24 23:24:36 | 000,012,680 | -HS- | M] () -- C:\ProgramData\16qb5285s67yesn24bxfk81p33a02r8x
[2011/12/20 13:14:42 | 000,003,930 | -HS- | M] () -- C:\ProgramData\506881s3y808c713u857y1ysd5m6
[2012/01/16 19:37:38 | 000,008,754 | ---- | M] () -- C:\ProgramData\52423c85
[2009/06/30 12:12:46 | 000,000,268 | RH-- | M] () -- C:\ProgramData\Comedy Noises
[2009/06/30 12:25:09 | 000,000,268 | RH-- | M] () -- C:\ProgramData\Commands
[2009/08/15 12:24:20 | 000,005,167 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2012/01/19 17:21:33 | 000,000,448 | -H-- | M] () -- C:\ProgramData\k7vUREwXGlnIiC
[2010/05/20 14:05:03 | 000,002,873 | ---- | M] () -- C:\ProgramData\LUUnInstall.LiveUpdate
[2012/01/22 14:05:23 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/01/18 14:55:22 | 000,000,440 | -H-- | M] () -- C:\ProgramData\ofMZsqDhhCLj4V
[2012/01/19 16:26:03 | 000,000,456 | -H-- | M] () -- C:\ProgramData\q5Tf4nr63zhUx2
[2009/01/12 18:06:56 | 000,005,055 | -H-- | M] () -- C:\ProgramData\ywasvxup.hvs
[2012/01/19 17:19:53 | 000,000,296 | -H-- | M] () -- C:\ProgramData\~k7vUREwXGlnIiC
[2012/01/19 17:19:53 | 000,000,176 | -H-- | M] () -- C:\ProgramData\~k7vUREwXGlnIiCr
[2012/01/18 14:52:17 | 000,000,296 | -H-- | M] () -- C:\ProgramData\~ofMZsqDhhCLj4V
[2012/01/18 14:52:17 | 000,000,176 | -H-- | M] () -- C:\ProgramData\~ofMZsqDhhCLj4Vr
[2012/01/19 16:24:23 | 000,000,296 | -H-- | M] () -- C:\ProgramData\~q5Tf4nr63zhUx2
[2012/01/19 16:24:23 | 000,000,176 | -H-- | M] () -- C:\ProgramData\~q5Tf4nr63zhUx2r
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< >
========== Files - Unicode (All) ==========
[2011/04/08 16:31:33 | 000,000,000 | -H-D | M](C:\Users\fran\AppData\Roaming\???????sAppData) -- C:\Users\fran\AppData\Roaming\敎潲䍄敔灭慬整sAppData
[2011/04/08 16:31:33 | 000,000,000 | -H-D | M](C:\Users\fran\AppData\Roaming\???????sAppData) -- C:\Users\fran\AppData\Roaming\敎潲䍄敔灭慬整sAppData
(C:\Users\fran\AppData\Roaming\???????sAppData) -- C:\Users\fran\AppData\Roaming\敎潲䍄敔灭慬整sAppData
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB56286$] -> -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP
FC5A2B2
@Alternate Data Stream - 64 bytes -> C:\Users\fran\Documents\Romantics - Talking In Your Sleep.mp3:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\fran\Documents\MeatLoaf - Let Me Sleep On It.mp3:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\fran\Documents\jesse maccartney - Don't Go Breaking My Heart.mp3:TOC.WMV
@Alternate Data Stream - 3241 bytes -> C:\Users\fran\Documents\Girlfriends.eml:OECustomProperty
@Alternate Data Stream - 170 bytes -> C:\ProgramData\TEMP:F4CE9946
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:7F4E393D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:ECF54A0E
< End of report >