also @ TechSpot: Microsoft wants Xbox to be the entertainment hub for all your devices

TechSpot

[Inactive] Malware keeps infecting my PC

Discussion in 'Virus and Malware Removal' started by Paul881, Dec 27, 2011.

Thread Status:
Not open for further replies.
  1. Paul881 Newcomer, in training

    In spite of what it says above in the log, all the files in the F:\ partition are still there.
  2. Paul881 Newcomer, in training

    I won't run OTL until you come back to me with advice on OTMoveit issues.
  3. Bobbye Helper on the Fringe

    My apology Paul- I misplaced the thread.

    Please give me an update on how the system is doing now.
  4. Paul881 Newcomer, in training

    Bobbeye, thats okay, I have been busy travelling and working. The system is much better thanks you and performing very well and without the glitches it used to have.

    One thing I did do was copy the F drive to a spare external drive and then manually delete the files in the downloaded programs folder and this was done easily enough. I then wiped the drive by reformatting just to be on the safe side.

    So I could try manually deleting the files if it would help?
  5. Bobbye Helper on the Fringe

    Since you are having recurring malware, you should seriously consider removing those process know to bring malware. I see see Azureus/Vuze and eMule. Here are more to remove:

    OTL Custom Scan Fixes
    • Run OTL
    • Copy the contents of the Code box and paste in the Custom Scans/Fixes box at the bottom:
      Code:
      :OTL
      [2008/05/06 12:33:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Uniblue
      [2011/05/25 21:03:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Vso
      [2007/11/03 10:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
      [2011/08/01 21:18:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ask
      [2011/09/25 06:33:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
      [2008/02/17 03:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
      [2007/11/09 17:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
      [2009/03/12 22:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
      [2010/04/08 07:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
      [2009/09/19 12:47:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
      [2009/04/08 17:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
      [2010/03/23 17:09:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{BF329843-149E-4A5A-82A1-0250286442D0}
      [2010/03/23 17:11:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{E7D4E1BB-A8A8-4E3B-BEA6-38DD8E4522DF}
      [2009/09/19 12:45:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{EFBDC0EC-2698-4A44-8AAD-4113D6D8BB82}
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [emptyjava]
      [resethosts]
      [CreateRestorePoint]
      [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run uninterrupted, reboot the PC when it is done
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
  6. Paul881 Newcomer, in training

    OTL logfile created on: 23/02/2012 06:09:25 - Run 2
    OTL by OldTimer - Version 3.2.31.0 Folder = F:\Downloaded Programs\OTL
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    2.00 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.29% Memory free
    4.85 Gb Paging File | 4.41 Gb Available in Paging File | 90.89% Paging File free
    Paging file location(s): C:\pagefile.sys 3070 4096 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 146.48 Gb Total Space | 42.33 Gb Free Space | 28.90% Space Free | Partition Type: NTFS
    Drive F: | 247.94 Gb Total Space | 11.79 Gb Free Space | 4.76% Space Free | Partition Type: NTFS
    Drive G: | 116.51 Gb Total Space | 46.91 Gb Free Space | 40.27% Space Free | Partition Type: NTFS
    Drive H: | 101.31 Gb Total Space | 42.08 Gb Free Space | 41.54% Space Free | Partition Type: NTFS
    Drive I: | 164.33 Gb Total Space | 105.19 Gb Free Space | 64.01% Space Free | Partition Type: NTFS
    Drive J: | 154.95 Gb Total Space | 136.79 Gb Free Space | 88.28% Space Free | Partition Type: NTFS
    Drive N: | 14.90 Gb Total Space | 14.73 Gb Free Space | 98.85% Space Free | Partition Type: FAT32

    Computer Name: MUSIC-PC | User Name: Paul L. Smith | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - F:\Downloaded Programs\OTL\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
    PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
    PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
    PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
    PRC - C:\Program Files\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe (Panasonic Corporation)
    PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
    PRC - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
    PRC - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
    PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
    PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
    PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
    PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
    PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
    PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)


    ========== Modules (No Company Name) ==========

    MOD - C:\Program Files\AVAST Software\Avast\defs\12022201\algo.dll ()
    MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
    MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
    MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
    MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
    MOD - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()


    ========== Win32 Services (SafeList) ==========

    SRV - (AppMgmt) -- File not found
    SRV - (avast! Firewall) -- C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
    SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
    SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
    SRV - (ABBYY.Licensing.FineReader.Sprint.9.0) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
    SRV - (C-DillaCdaC11BA) -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
    SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
    SRV - (KService) -- C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
    SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
    SRV - (SoundMovieServer) -- C:\WINDOWS\System32\snmvtsvc.exe (SoundMovieServer)
    SRV - (AdobeActiveFileMonitor6.0) -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
    SRV - (bgsvcgen) -- C:\WINDOWS\System32\bgsvcgen.exe (B.H.A Corporation)
    SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
    SRV - (SoundMAX Agent Service (default)) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


    ========== Driver Services (SafeList) ==========

    DRV - (aswFW) -- C:\WINDOWS\System32\drivers\aswFW.sys (AVAST Software)
    DRV - (aswSnx) -- C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
    DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
    DRV - (aswNdis2) -- C:\WINDOWS\System32\drivers\aswNdis2.sys (AVAST Software)
    DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
    DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
    DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
    DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
    DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
    DRV - (aswNdis) -- C:\WINDOWS\system32\DRIVERS\aswNdis.sys (ALWIL Software)
    DRV - (pwdrvio) -- C:\WINDOWS\system32\pwdrvio.sys ()
    DRV - (pwdspio) -- C:\WINDOWS\system32\pwdspio.sys ()
    DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (SmartDefragDriver) -- C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
    DRV - (L6POD) -- C:\WINDOWS\system32\drivers\L6POD.sys (Line 6)
    DRV - (NCHSSVAD) SoundTap Recorder (32 Bit) -- C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
    DRV - (NPF) -- C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
    DRV - (KORGUMDS) -- C:\WINDOWS\system32\drivers\KORGUMDS.SYS (KORG INC.)
    DRV - (CdaC15BA) -- C:\WINDOWS\system32\drivers\CdaC15BA.SYS (Macrovision Europe Ltd)
    DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
    DRV - (tmcomm) -- C:\WINDOWS\System32\Drivers\tmcomm.sys (Trend Micro Inc.)
    DRV - (sensorsview32) -- C:\WINDOWS\system32\drivers\sensorsview32.sys (OpenLibSys.org)
    DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
    DRV - (Pcatip) -- C:\WINDOWS\system32\drivers\Pcatip.sys (VSO Software)
    DRV - (Fileprot) -- C:\WINDOWS\System32\drivers\fileprot.sys ()
    DRV - (SndTDriverV32) -- C:\WINDOWS\system32\drivers\SndTDriverV32.sys (Windows (R) 2000/XP)
    DRV - (MovRVDrv32) -- C:\WINDOWS\system32\drivers\MovRVDrv32.sys (Windows (R) 2000 DDK provider)
    DRV - (CrystalSysInfo) -- C:\Program Files\MediaCoder\SysInfo.sys ()
    DRV - (hotcore2) -- C:\WINDOWS\system32\drivers\hotcore2.sys (Paragon Software Group)
    DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
    DRV - (cdrbsdrv) -- C:\WINDOWS\System32\drivers\cdrbsdrv.sys (B.H.A Corporation)
    DRV - (MXOPSWD) -- C:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
    DRV - (MaxtorFrontPanel1) -- C:\WINDOWS\system32\drivers\mxofwfp.sys (Maxtor Corp.)
    DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
    DRV - (Aspi32) -- C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
    DRV - (MPD16USB) -- C:\WINDOWS\system32\drivers\MPD16USB.sys (AKAI professional M.I. Corp.)
    DRV - (Asapi) -- C:\WINDOWS\System32\drivers\asapi.sys (VOB Computersysteme GmbH)
    DRV - (FINEPIX_PCC) -- C:\WINDOWS\system32\drivers\V4CB0109.SYS (FUJI PHOTO FILM CO.,LTD.)
    DRV - (MASPINT) -- C:\WINDOWS\System32\drivers\MASPINT.SYS (MicroStaff Co.,Ltd.)
    DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========


    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
    FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin: C:\Program Files\Musicnotes\npsibelius.dll ()
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
    FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
    FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/12/18 02:37:15 | 000,000,000 | ---D | M]

    [2012/01/02 09:42:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Paul L. Smith\Application Data\Mozilla\Extensions
    [2012/01/02 09:42:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Paul L. Smith\Application Data\Mozilla\Extensions\uploadr@flickr.com

    ========== Chrome ==========

    CHR - default_search_provider: Yahoo! (Enabled)
    CHR - default_search_provider: search_url = http://uk.search.yahoo.com/search?fr=chr-greentree_gc&ei=utf-8&ilc=12&type=642886&p={searchTerms}
    CHR - default_search_provider: suggest_url =
    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\gcswf32.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
    CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
    CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
    CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
    CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
    CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
    CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\pdf.dll
    CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
    CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
    CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
    CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.71\npGoogleUpdate3.dll
    CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Musicnotes\npmusicn.dll
    CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Musicnotes\npsibelius.dll
    CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
    CHR - plugin: Veetle Broadcaster Plugin (Enabled) = C:\Program Files\Veetle\VLCBroadcast\npvbp.dll
    CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
    CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files\Yahoo!\Common\npyaxmpb.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    CHR - plugin: Default Plug-in (Enabled) = default_plugin
    CHR - Extension: YouTube = C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
    CHR - Extension: Google Search = C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
    CHR - Extension: avast! WebRep = C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\
    CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
    CHR - Extension: Gmail = C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

    O1 HOSTS File: ([2012/01/22 07:00:20 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\Drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
    O2 - BHO: (CmjBrowserHelperObject Object) - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:\Program Files\Mindjet\MindManager 7\Mm7InternetExplorer.dll (Mindjet)
    O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
    O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll (Yahoo! Inc)
    O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
    O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
    O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HD Writer.lnk = C:\Program Files\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe (Panasonic Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:\Program Files\Mindjet\MindManager 7\Mm7InternetExplorer.dll (Mindjet)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKCU\..Trusted Domains: line6.net ([]* in Trusted sites)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/downl...-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
    O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1198910439140 (MUWebControl Class)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/win/ActiveXPlugin.cab (Reg Error: Key error.)
    O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab (SysInfo Class)
    O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} https://www.plaxo.com/activex/plx_upldr-2k-xp.cab (Plaxo Auto-Import Utility)
    O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab (DownloadManager Control)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C6420938-3115-4CE0-8437-D6D31209BF94}: NameServer = 192.168.2.1,192.168.2.2
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
    O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2007/09/21 21:24:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/02/22 11:16:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
    [2012/02/12 07:04:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul L. Smith\Desktop\New Folder (2)
    [2012/02/12 07:04:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paul L. Smith\Desktop\New Folder
    [2012/02/08 19:45:16 | 000,523,264 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Paul L. Smith\Desktop\OTM.exe
    [2012/02/05 20:29:57 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2012/02/05 13:02:50 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
    [2012/01/27 07:08:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
    [2012/01/27 07:06:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2009/11/20 18:21:38 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Paul L. Smith\Application Data\pcouffin.sys
    [2008/03/21 07:29:03 | 719,174,560 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files\ADBEPPROCS3_ALP.exe
    [2004/10/06 11:39:57 | 028,676,096 | ---- | C] (Spectrasonics) -- C:\Program Files\StylusRMX.dll
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/02/23 06:19:00 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2012/02/23 06:05:34 | 000,073,308 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
    [2012/02/23 06:05:23 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2012/02/23 06:01:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/02/23 05:27:56 | 000,013,768 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/02/22 11:17:46 | 000,000,741 | ---- | M] () -- C:\Documents and Settings\Paul L. Smith\Desktop\VLC media player (2).lnk
    [2012/02/22 11:16:48 | 000,000,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
    [2012/02/21 15:57:33 | 000,001,364 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
    [2012/02/19 17:37:25 | 000,002,391 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ACDSee 4.0.lnk
    [2012/02/17 07:28:17 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\Paul L. Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
    [2012/02/17 03:18:49 | 001,542,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2012/02/17 03:11:08 | 000,444,392 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2012/02/17 03:11:08 | 000,072,524 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2012/02/17 03:04:27 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2012/02/16 21:22:27 | 000,001,823 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
    [2012/02/16 19:33:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2012/02/08 19:45:21 | 000,523,264 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Paul L. Smith\Desktop\OTM.exe
    [2012/02/07 21:41:47 | 000,000,588 | ---- | M] () -- C:\Documents and Settings\Paul L. Smith\Desktop\Shortcut to OTM.exe.lnk
    [2012/02/05 20:05:38 | 000,000,666 | ---- | M] () -- C:\Documents and Settings\Paul L. Smith\Desktop\Shortcut to SecurityCheck.exe.lnk
    [2012/02/05 04:12:54 | 000,000,564 | ---- | M] () -- C:\Documents and Settings\Paul L. Smith\Desktop\Shortcut to OTL.exe.lnk
    [2012/02/03 18:17:34 | 000,000,692 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2012/01/28 07:00:41 | 000,000,794 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/01/27 07:08:32 | 000,001,552 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/02/22 11:17:46 | 000,000,741 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Desktop\VLC media player (2).lnk
    [2012/02/22 11:16:48 | 000,000,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
    [2012/02/07 21:41:47 | 000,000,588 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Desktop\Shortcut to OTM.exe.lnk
    [2012/02/05 20:05:38 | 000,000,666 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Desktop\Shortcut to SecurityCheck.exe.lnk
    [2012/02/05 04:12:54 | 000,000,564 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Desktop\Shortcut to OTL.exe.lnk
    [2012/01/28 07:00:41 | 000,000,794 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/01/27 07:08:32 | 000,001,552 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
    [2012/01/22 06:09:24 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2012/01/22 06:09:24 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2012/01/22 06:09:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2012/01/22 06:09:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2012/01/22 06:09:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2011/08/15 11:32:49 | 000,029,520 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
    [2011/08/15 11:32:49 | 000,013,496 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
    [2011/06/16 17:29:03 | 000,910,920 | ---- | C] () -- C:\WINDOWS\System32\pwNative.exe
    [2011/06/16 17:29:03 | 000,016,472 | ---- | C] () -- C:\WINDOWS\System32\pwdrvio.sys
    [2011/06/16 17:29:02 | 000,011,104 | ---- | C] () -- C:\WINDOWS\System32\pwdspio.sys
    [2011/05/25 21:37:20 | 000,000,027 | ---- | C] () -- C:\WINDOWS\lang.ini
    [2011/04/21 16:43:50 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
    [2011/02/04 17:07:27 | 000,183,664 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2010/12/01 17:46:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
    [2010/02/07 10:22:45 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
    [2010/02/07 10:22:45 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
    [2010/02/07 10:22:45 | 000,015,670 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
    [2010/02/07 10:22:45 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
    [2010/01/09 11:44:53 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
    [2009/11/20 18:27:05 | 000,001,041 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Application Data\vso_ts_preview.xml
    [2009/11/20 18:21:38 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Application Data\inst.exe
    [2009/11/20 18:21:38 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Application Data\pcouffin.cat
    [2009/11/20 18:21:38 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Application Data\pcouffin.inf
    [2009/11/20 13:55:54 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
    [2009/11/20 13:55:54 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
    [2009/11/20 13:55:54 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
    [2009/11/20 13:55:54 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
    [2009/11/15 12:34:23 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2009/11/06 15:36:07 | 000,051,184 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2009/10/20 18:19:30 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
    [2009/08/08 10:05:44 | 000,008,330 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\Spectrasonicsml.html
    [2009/06/21 21:01:02 | 000,000,093 | ---- | C] () -- C:\WINDOWS\BBW_INFO.INI
    [2009/06/21 21:00:39 | 000,000,032 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\3336a8a31588d39509b23eff4c71869e_Paul L. Smith
    [2009/05/29 12:19:59 | 000,000,032 | ---- | C] () -- C:\WINDOWS\SpriteKt.ini
    [2009/05/29 12:19:42 | 000,007,184 | ---- | C] () -- C:\WINDOWS\sounder.ini
    [2009/05/21 16:48:40 | 001,657,376 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
    [2009/05/21 16:48:39 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
    [2009/05/21 16:48:38 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
    [2009/05/21 16:48:38 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
    [2009/05/21 16:48:37 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
    [2009/05/21 16:48:36 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
    [2009/05/21 16:48:36 | 001,346,080 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
    [2009/05/21 16:48:36 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
    [2009/05/21 16:48:33 | 000,449,056 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
    [2009/05/21 16:48:26 | 000,436,768 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
    [2009/05/15 13:37:00 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\fusioncache.dat
    [2009/05/04 09:01:23 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2009/01/25 08:19:13 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\minimp3.exe
    [2008/11/14 09:22:56 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
    [2008/11/14 09:22:55 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Application Data\PnkBstrK.sys
    [2008/11/14 09:22:39 | 000,103,736 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
    [2008/11/14 09:22:36 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
    [2008/11/14 09:22:34 | 000,000,319 | ---- | C] () -- C:\WINDOWS\game.ini
    [2008/10/25 13:36:05 | 000,000,112 | ---- | C] () -- C:\WINDOWS\System32\msvcsv60.dll
    [2008/10/25 13:36:05 | 000,000,112 | ---- | C] () -- C:\WINDOWS\msocreg32.dat
    [2008/10/06 17:35:09 | 000,000,379 | ---- | C] () -- C:\WINDOWS\GearBox.ini
    [2008/09/27 06:08:19 | 000,000,007 | ---- | C] () -- C:\WINDOWS\System32\ngxt.bin
    [2008/09/16 15:56:07 | 000,375,296 | ---- | C] () -- C:\WINDOWS\System32\tx32.dll
    [2008/09/16 15:56:07 | 000,000,202 | ---- | C] () -- C:\WINDOWS\System32\Ic32.ini
    [2008/09/03 06:21:55 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [2008/05/12 08:03:31 | 000,000,472 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2008/05/12 07:58:30 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
    [2008/04/05 06:13:44 | 000,000,370 | ---- | C] () -- C:\WINDOWS\msfsetup.ini
    [2008/03/20 14:40:29 | 000,000,395 | ---- | C] () -- C:\WINDOWS\videoimp.ini
    [2008/03/20 14:40:20 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
    [2008/03/12 06:40:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\graphedit.INI
    [2008/01/25 16:47:54 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2008/01/10 10:38:39 | 000,038,488 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Application Data\Comma Separated Values (Windows).ADR
    [2008/01/03 08:17:20 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
    [2008/01/03 08:17:19 | 000,073,220 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
    [2008/01/03 08:17:19 | 000,029,114 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
    [2008/01/03 08:17:19 | 000,021,021 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
    [2008/01/03 08:17:19 | 000,013,280 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
    [2008/01/03 08:17:19 | 000,010,673 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
    [2008/01/03 08:17:19 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
    [2008/01/03 08:17:19 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
    [2008/01/03 08:17:19 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
    [2008/01/03 08:17:19 | 000,001,137 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
    [2008/01/03 08:17:19 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
    [2008/01/03 08:17:19 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
    [2008/01/03 08:17:19 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
    [2008/01/03 08:17:19 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
    [2008/01/03 08:17:19 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
    [2008/01/03 08:15:32 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE RX700E.ini
    [2007/12/30 11:05:25 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
    [2007/12/30 11:03:05 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Soundtrack
    [2007/12/30 11:03:05 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Paul L. Smith\Application Data\Smooth Strings
    [2007/12/30 11:03:05 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
    [2007/12/30 11:03:05 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Speech Enhancer
    [2007/12/29 06:18:21 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/12/29 05:45:15 | 000,000,175 | ---- | C] () -- C:\WINDOWS\qwimp.ini
    [2007/12/29 05:38:45 | 000,001,364 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
    [2007/12/29 05:38:45 | 000,000,037 | ---- | C] () -- C:\WINDOWS\intuprof.ini
    [2007/11/03 11:17:23 | 000,000,043 | ---- | C] () -- C:\WINDOWS\gswin32.ini
    [2007/10/22 08:50:30 | 000,032,491 | ---- | C] () -- C:\WINDOWS\System32\drivers\fileprot.sys
    [2007/10/22 08:50:30 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\loadfp.exe
    [2007/10/20 09:43:31 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2007/10/20 09:43:28 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2007/10/20 09:43:28 | 000,579,602 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
    [2007/10/20 09:43:28 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2007/10/12 16:04:02 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
    [2007/10/12 14:39:20 | 000,002,240 | ---- | C] () -- C:\WINDOWS\LENDIG.sys
    [2007/10/05 18:29:57 | 000,029,184 | ---- | C] () -- C:\Documents and Settings\Paul L. Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/09/28 13:16:33 | 000,000,050 | ---- | C] () -- C:\WINDOWS\RKACCUBURN.INI
    [2007/09/28 13:14:02 | 004,239,360 | ---- | C] () -- C:\WINDOWS\System32\qtp-mt334.dll
    [2007/09/23 08:06:27 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\IWUninstall.exe
    [2007/09/23 06:18:36 | 000,331,263 | ---- | C] () -- C:\WINDOWS\LOOP.exe
    [2007/09/22 15:10:17 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
    [2007/09/22 13:41:17 | 000,118,784 | ---- | C] () -- C:\WINDOWS\dsdxirmv.exe
    [2007/09/22 09:19:44 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
    [2007/09/22 08:22:47 | 000,003,422 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
    [2007/09/22 08:22:46 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
    [2007/09/21 22:08:36 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2007/09/21 22:07:46 | 001,542,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2007/09/21 21:25:51 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2007/09/21 21:22:27 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2006/05/22 11:47:24 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2004/12/21 11:13:56 | 000,191,136 | ---- | C] () -- C:\WINDOWS\System32\plx_upldr.dll
    [2004/08/26 11:53:14 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\MXONmSpace.dll
    [2004/08/26 11:49:52 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\MXONmSpMFC.dll
    [2004/08/02 13:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [2003/03/31 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
    [2003/03/31 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [2003/03/31 12:00:00 | 000,444,392 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [2003/03/31 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [2003/03/31 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [2003/03/31 12:00:00 | 000,072,524 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [2003/03/31 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [2003/03/31 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [2003/03/31 12:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
    [2003/03/31 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
    [2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2002/03/21 13:51:52 | 000,503,808 | R--- | C] () -- C:\WINDOWS\System32\lt_xtrans.dll
    [2002/03/21 13:51:52 | 000,286,720 | R--- | C] () -- C:\WINDOWS\System32\MrSIDD.dll
    [2002/03/21 13:51:52 | 000,163,840 | R--- | C] () -- C:\WINDOWS\System32\lt_common.dll
    [2002/03/21 13:51:52 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\lt_trans.dll
    [2002/03/21 13:51:52 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\lt_meta.dll
    [2002/03/21 13:51:52 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\lt_encrypt.dll
    [2002/03/21 13:51:52 | 000,020,480 | R--- | C] () -- C:\WINDOWS\System32\lt_messagetext.dll
    [2002/03/20 22:01:06 | 000,006,688 | R--- | C] () -- C:\WINDOWS\System32\Digita.sys
    [2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportUSB.dll
    [2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportSerial.dll
    [2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrDA.dll
    [2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrCOMM.dll
    [1998/06/02 00:00:00 | 000,116,736 | ---- | C] () -- C:\WINDOWS\System32\PCDLIB32.DLL
    [1996/04/03 19:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
  7. Paul881 Newcomer, in training

    ========== LOP Check ==========

    [2007/11/03 10:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\ACD Systems
    [2008/09/11 16:06:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Anthropics
    [2011/12/27 01:51:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Azureus
    [2009/12/22 07:17:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Cakewalk
    [2011/12/18 02:38:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\DDMSettings
    [2010/12/01 06:32:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\EPSON
    [2012/01/02 09:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Flickr
    [2008/03/20 14:22:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\FUJIFILM
    [2009/12/31 07:18:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\ImgBurn
    [2009/12/30 04:56:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\JGoodies
    [2010/03/06 01:50:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\KORG
    [2010/02/20 08:27:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Lexicon PCM Native
    [2010/03/20 10:00:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Line 6
    [2008/01/10 08:28:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\LinkedIn
    [2011/06/02 06:39:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\NCH Swift Sound
    [2007/12/30 11:06:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Nikon
    [2008/04/25 07:32:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Nokia
    [2008/11/07 18:33:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Palo Alto Software
    [2008/10/04 18:01:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\PC Suite
    [2009/06/21 21:00:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Plogue
    [2011/12/29 16:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Propellerhead Software
    [2011/02/04 07:25:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Research In Motion
    [2010/01/13 07:30:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\SIR
    [2008/05/06 12:33:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Uniblue
    [2011/05/25 21:03:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paul L. Smith\Application Data\Vso
    [2007/11/03 10:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
    [2011/08/01 21:18:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ask
    [2011/09/25 06:33:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
    [2008/02/17 03:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
    [2007/11/09 17:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
    [2012/02/08 22:33:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cakewalk
    [2007/12/30 11:05:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
    [2010/11/30 20:55:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
    [2007/12/30 20:21:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
    [2008/02/17 03:02:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
    [2008/10/26 05:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IK Multimedia
    [2009/01/19 18:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
    [2011/08/22 05:20:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kontiki
    [2011/11/12 07:10:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KORG
    [2010/03/20 17:52:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Line 6
    [2008/10/07 18:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Line 6(2)
    [2007/10/12 16:04:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
    [2008/11/06 16:52:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mindjet
    [2010/02/07 11:33:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
    [2011/11/14 18:12:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Musicnotes
    [2009/10/04 10:13:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Native Instruments
    [2011/06/02 06:38:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
    [2007/12/30 11:03:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
    [2008/11/07 18:32:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Palo Alto Software
    [2011/03/19 07:35:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Panasonic
    [2008/11/07 18:30:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PAS
    [2008/02/29 08:04:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
    [2011/12/29 16:17:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
    [2011/02/04 07:23:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
    [2009/11/15 06:27:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SideKickReg
    [2009/08/03 05:49:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SIR
    [2009/04/10 09:37:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spectrasonics
    [2010/02/07 11:40:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
    [2010/11/30 20:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
    [2007/12/30 11:05:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
    [2009/11/20 18:35:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vso
    [2009/03/12 22:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
    [2010/04/08 07:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/09/19 12:47:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2009/04/08 17:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [2010/03/23 17:09:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{BF329843-149E-4A5A-82A1-0250286442D0}
    [2010/03/23 17:11:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{E7D4E1BB-A8A8-4E3B-BEA6-38DD8E4522DF}
    [2009/09/19 12:45:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{EFBDC0EC-2698-4A44-8AAD-4113D6D8BB82}
    [2011/06/12 09:44:00 | 000,000,314 | ---- | M] () -- C:\WINDOWS\Tasks\expressburnDowngrade.job
    [2011/06/18 09:44:04 | 000,000,314 | ---- | M] () -- C:\WINDOWS\Tasks\expressburnShakeIcon.job
    [2011/05/29 06:42:01 | 000,000,294 | ---- | M] () -- C:\WINDOWS\Tasks\switchShakeIcon.job
    [2011/06/09 05:58:02 | 000,000,298 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadShakeIcon.job

    ========== Purity Check ==========



    < End of report >
  8. Bobbye Helper on the Fringe

    Paul, there is a second log from OTL names Extras. Please find and post.
  9. Bobbye Helper on the Fringe

    Thread closed. No reply x 1week.
Thread Status:
Not open for further replies.