CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\kody\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\kody\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\kody\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\kody\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: avast! WebRep = C:\Users\kody\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\
O1 HOSTS File: ([2011/12/11 11:20:38 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:
64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll File not found
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll (Yontoo LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3:
64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe (Toshiba)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKU\S-1-5-21-522092188-2918335835-2023279602-1000..\Run: [Akamai NetSession Interface] C:\Users\kody\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKU\S-1-5-21-522092188-2918335835-2023279602-1000..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-522092188-2918335835-2023279602-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\kody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\##aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-522092188-2918335835-2023279602-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-522092188-2918335835-2023279602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.94.156.1 68.94.157.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0E20AB8E-9B98-433D-8D78-0094EAAC08AE}: DhcpNameServer = 68.94.156.1 68.94.157.1
O18:
64bit: - Protocol\Handler\avgsecuritytoolbar - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
O37 - HKLM\...exe [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3filter - C:\windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\windows\SysWow64\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\windows\SysWow64\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - C:\windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.xvid - C:\windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/12/11 11:30:18 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/12/11 11:27:31 | 000,000,000 | ---D | C] -- C:\windows\temp
[2011/12/11 11:06:23 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2011/12/11 11:06:23 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2011/12/11 11:06:23 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2011/12/11 11:06:17 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2011/12/11 11:06:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/11 08:18:22 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{CDC90EF2-F086-406F-8C0E-C2D2A4A80769}
[2011/12/11 08:16:48 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{19F92EE6-79AB-4663-9E92-BCC03012CDB9}
[2011/12/06 20:52:13 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{0EA2FEEA-7BD8-4C0F-80AB-8CA2BDACDC45}
[2011/12/06 20:51:31 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{4C55A154-5C1B-4567-A62B-878F9A4B78BD}
[2011/12/05 20:24:12 | 000,000,000 | ---D | C] -- C:\Users\kody\Documents\c++
[2011/12/05 20:11:25 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Roaming\Dev-Cpp
[2011/12/05 20:01:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
[2011/12/05 20:00:37 | 000,000,000 | ---D | C] -- C:\Dev-Cpp
[2011/12/05 18:35:54 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{7130B731-8407-4531-BDC9-40EFF9389D32}
[2011/11/30 15:40:40 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Roaming\OpenOffice.org
[2011/11/30 15:33:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2011/11/30 15:32:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2011/11/30 15:22:28 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
[2011/11/30 15:21:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice.org 3
[2011/11/30 15:19:52 | 000,000,000 | ---D | C] -- C:\Users\kody\Desktop\OpenOffice.org 3.3 (en-US) Installation Files
[2011/11/30 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\antiphishing-vmninternethelper1_1dn
[2011/11/30 15:16:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Anti-phishing Domain Advisor
[2011/11/30 15:15:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yontoo Layers Runtime
[2011/11/30 15:15:27 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\Babylon
[2011/11/30 15:15:26 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Roaming\Babylon
[2011/11/30 15:15:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2011/11/29 21:57:11 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{2572A233-6C1E-4424-B649-FC765DAE8E09}
[2011/11/29 21:56:59 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{E1BE36E5-2D63-4F73-AA58-4D059618D788}
[2011/11/26 23:10:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater
[2011/11/26 23:10:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Spigot
[2011/11/25 08:12:27 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Roaming\vlc
[2011/11/25 08:11:42 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\Ilivid Player
[2011/11/25 08:10:45 | 000,000,000 | -H-D | C] -- C:\ProgramData\{08E30618-5D06-461B-BBD3-4ADFB0810824}
[2011/11/25 08:10:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLivid
[2011/11/25 08:10:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iLivid
[2011/11/25 08:09:42 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\PackageAware
[2011/11/24 23:33:19 | 000,000,000 | ---D | C] -- C:\Users\kody\Documents\Art
[2011/11/23 20:27:32 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{EEF0F1EC-DEF2-4C9B-8446-60CC352C397D}
[2011/11/23 20:27:20 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{A13987DD-CC54-4EDF-8A6C-7D8594A24729}
[2011/11/20 10:33:56 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{B0493A9E-9CA9-41E7-A8E5-C33B9C87ADE2}
[2011/11/20 10:33:26 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{C5F39C18-F8A4-48CC-A4B8-8589152F4947}
[2011/11/18 22:49:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/13 20:10:49 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{B16A682E-6760-44DB-A80D-203C074171F3}
[2011/11/13 20:10:30 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{619AD7EE-2746-4934-B882-547668E7CF3F}
[2011/11/11 23:22:01 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{8B19F72E-9622-4A9E-9B52-C1006A5FDA98}
[2011/11/11 23:21:49 | 000,000,000 | ---D | C] -- C:\Users\kody\AppData\Local\{4A5309FE-301B-4C92-8101-8D58A2A530E5}
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/11 11:39:03 | 000,016,304 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/11 11:39:03 | 000,016,304 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/11 11:38:00 | 000,000,904 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-522092188-2918335835-2023279602-1000UA.job
[2011/12/11 11:31:36 | 000,000,890 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/11 11:29:49 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011/12/11 11:29:33 | 3016,503,296 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/11 11:29:00 | 000,000,894 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/11 11:23:58 | 000,726,316 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2011/12/11 11:23:58 | 000,624,178 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2011/12/11 11:23:58 | 000,106,522 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2011/12/11 11:20:38 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2011/12/11 11:16:22 | 000,004,720 | ---- | M] () -- C:\Users\kody\Documents\Document.rtf
[2011/12/11 10:56:04 | 000,000,512 | ---- | M] () -- C:\Users\kody\Desktop\MBR.dat
[2011/12/11 10:46:32 | 000,045,006 | ---- | M] () -- C:\Users\kody\.recently-used.xbel
[2011/12/10 22:29:54 | 000,000,852 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-522092188-2918335835-2023279602-1000Core.job
[2011/12/06 21:00:16 | 000,302,592 | ---- | M] () -- C:\Users\kody\Desktop\gmer.exe
[2011/12/06 20:47:20 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2011/12/05 20:01:08 | 000,000,620 | ---- | M] () -- C:\Users\kody\Application Data\Microsoft\Internet Explorer\Quick Launch\Dev-C++.lnk
[2011/12/05 18:41:35 | 000,000,220 | ---- | M] () -- C:\windows\tasks\SidebarExecute.job
[2011/12/05 00:31:42 | 004,922,280 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2011/12/04 20:27:59 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt
[2011/11/30 16:26:53 | 000,016,287 | ---- | M] () -- C:\Users\kody\Documents\Christmas List.odt
[2011/11/30 15:41:24 | 000,001,246 | ---- | M] () -- C:\Users\kody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/11/30 15:24:37 | 000,002,355 | ---- | M] () -- C:\Users\Public\Desktop\Toshiba Laptop Checkup.lnk
[2011/11/30 15:22:29 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2011/11/28 12:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\windows\avastSS.scr
[2011/11/28 12:01:23 | 000,199,816 | ---- | M] (AVAST Software) -- C:\windows\SysWow64\aswBoot.exe
[2011/11/28 12:01:14 | 000,256,960 | ---- | M] (AVAST Software) -- C:\windows\SysNative\aswBoot.exe
[2011/11/28 11:54:06 | 000,591,192 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswSnx.sys
[2011/11/28 11:53:58 | 000,304,472 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswSP.sys
[2011/11/28 11:52:22 | 000,042,328 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswRdr.sys
[2011/11/28 11:52:20 | 000,058,712 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswTdi.sys
[2011/11/28 11:52:11 | 000,066,904 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswMonFlt.sys
[2011/11/28 11:51:53 | 000,024,408 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswFsBlk.sys
[2011/11/28 00:21:43 | 000,002,006 | -H-- | M] () -- C:\Users\kody\Documents\Default.rdp
[2011/11/27 01:40:21 | 000,107,419 | ---- | M] () -- C:\Users\kody\Documents\chocolate rain.png
[2011/11/26 01:24:14 | 000,070,402 | ---- | M] () -- C:\Users\kody\Documents\Untitled.png
[2011/11/26 00:46:04 | 000,040,617 | ---- | M] () -- C:\Users\kody\Documents\Untitled.jpg
[2011/11/18 22:49:06 | 000,002,223 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/11 11:16:22 | 000,004,720 | ---- | C] () -- C:\Users\kody\Documents\Document.rtf
[2011/12/11 11:06:23 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2011/12/11 11:06:23 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2011/12/11 11:06:23 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2011/12/11 11:06:23 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2011/12/11 11:06:23 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2011/12/11 10:56:04 | 000,000,512 | ---- | C] () -- C:\Users\kody\Desktop\MBR.dat
[2011/12/11 10:46:32 | 000,045,006 | ---- | C] () -- C:\Users\kody\.recently-used.xbel
[2011/12/06 20:47:20 | 000,003,288 | ---- | C] () -- C:\bootsqm.dat
[2011/12/05 20:01:08 | 000,000,620 | ---- | C] () -- C:\Users\kody\Application Data\Microsoft\Internet Explorer\Quick Launch\Dev-C++.lnk
[2011/12/05 18:41:35 | 000,000,220 | ---- | C] () -- C:\windows\tasks\SidebarExecute.job
[2011/11/30 16:26:51 | 000,016,287 | ---- | C] () -- C:\Users\kody\Documents\Christmas List.odt
[2011/11/30 15:41:24 | 000,001,246 | ---- | C] () -- C:\Users\kody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/11/30 15:24:37 | 000,002,355 | ---- | C] () -- C:\Users\Public\Desktop\Toshiba Laptop Checkup.lnk
[2011/11/30 15:22:28 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2011/11/27 01:40:20 | 000,107,419 | ---- | C] () -- C:\Users\kody\Documents\chocolate rain.png
[2011/11/26 00:53:51 | 000,070,402 | ---- | C] () -- C:\Users\kody\Documents\Untitled.png
[2011/11/26 00:46:03 | 000,040,617 | ---- | C] () -- C:\Users\kody\Documents\Untitled.jpg
[2011/11/26 00:24:28 | 000,002,006 | -H-- | C] () -- C:\Users\kody\Documents\Default.rdp
[2011/11/18 22:49:06 | 000,002,223 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/09/22 11:08:56 | 003,902,976 | ---- | C] () -- C:\windows\SysWow64\ffmpeg.dll
[2011/08/22 13:07:48 | 000,074,752 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll
[2011/08/22 13:07:02 | 000,158,208 | ---- | C] () -- C:\windows\SysWow64\ff_unrar.dll
[2011/08/22 13:07:00 | 000,259,584 | ---- | C] () -- C:\windows\SysWow64\TomsMoComp_ff.dll
[2011/08/22 13:06:30 | 001,524,224 | ---- | C] () -- C:\windows\SysWow64\ff_samplerate.dll
[2011/08/22 13:06:30 | 000,211,456 | ---- | C] () -- C:\windows\SysWow64\ff_libdts.dll
[2011/08/22 13:06:30 | 000,097,280 | ---- | C] () -- C:\windows\SysWow64\ff_wmv9.dll
[2011/08/22 13:06:28 | 000,327,680 | ---- | C] () -- C:\windows\SysWow64\ff_libfaad2.dll
[2011/08/22 13:06:28 | 000,113,664 | ---- | C] () -- C:\windows\SysWow64\ff_liba52.dll
[2011/08/22 13:06:26 | 000,145,920 | ---- | C] () -- C:\windows\SysWow64\ff_libmad.dll
[2011/08/22 13:06:26 | 000,136,704 | ---- | C] () -- C:\windows\SysWow64\libmpeg2_ff.dll
[2011/05/30 07:42:50 | 000,240,640 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2011/05/23 01:46:30 | 000,645,632 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2011/03/14 19:11:39 | 000,000,738 | ---- | C] () -- C:\Users\kody\AppData\Roaming\wklnhst.dat
[2011/03/03 05:40:08 | 000,150,528 | ---- | C] () -- C:\windows\SysWow64\mkx.dll
[2011/03/03 05:39:56 | 000,109,568 | ---- | C] () -- C:\windows\SysWow64\avi.dll
[2011/03/03 05:39:46 | 000,141,824 | ---- | C] () -- C:\windows\SysWow64\mp4.dll
[2011/03/03 05:39:34 | 000,123,392 | ---- | C] () -- C:\windows\SysWow64\ogm.dll
[2011/03/03 05:39:02 | 000,113,152 | ---- | C] () -- C:\windows\SysWow64\dsmux.exe
[2011/03/03 05:38:54 | 000,154,112 | ---- | C] () -- C:\windows\SysWow64\ts.dll
[2011/03/03 05:38:40 | 000,249,856 | ---- | C] () -- C:\windows\SysWow64\dxr.dll
[2011/03/03 05:38:10 | 000,097,792 | ---- | C] () -- C:\windows\SysWow64\avs.dll
[2011/03/03 05:38:04 | 000,137,728 | ---- | C] () -- C:\windows\SysWow64\mkv2vfr.exe
[2011/03/03 05:37:50 | 000,093,184 | ---- | C] () -- C:\windows\SysWow64\avss.dll
[2011/03/03 05:37:40 | 000,358,400 | ---- | C] () -- C:\windows\SysWow64\gdsmux.exe
[2011/03/03 05:35:32 | 000,080,384 | ---- | C] () -- C:\windows\SysWow64\mkzlib.dll
[2011/03/03 05:35:26 | 000,024,576 | ---- | C] () -- C:\windows\SysWow64\mkunicode.dll
[2010/11/16 02:54:40 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2010/11/16 02:52:09 | 000,001,105 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2010/08/18 13:56:38 | 000,000,151 | ---- | C] () -- C:\windows\SysWow64\Registration.ini
[2009/08/11 15:21:26 | 000,087,552 | ---- | C] () -- C:\windows\SysWow64\ac3config.exe
[2009/08/11 15:21:20 | 001,021,440 | ---- | C] () -- C:\windows\SysWow64\ac3filter_intl.dll
[2009/07/13 23:38:36 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat
[2009/04/28 06:37:00 | 000,028,672 | ---- | C] () -- C:\windows\SysWow64\SPCtl.dll
[2006/03/03 22:52:00 | 000,088,576 | ---- | C] () -- C:\windows\SysWow64\OptimFROG.dll
========== LOP Check ==========
[2011/04/02 09:31:28 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\AVG10
[2011/11/30 15:15:26 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Babylon
[2011/04/02 10:50:29 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/05 20:41:58 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Dev-Cpp
[2011/12/11 10:46:32 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\gtk-2.0
[2011/10/08 15:30:52 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Notepad++
[2011/11/30 15:40:40 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\OpenOffice.org
[2011/10/07 18:31:20 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Opera
[2011/09/15 12:47:24 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Pokemon Online
[2011/03/14 19:11:40 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Template
[2011/03/03 18:39:14 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Tific
[2011/03/03 18:16:04 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\Toshiba
[2011/05/11 14:12:41 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\USMA
[2011/04/02 18:19:29 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\WildTangent
[2011/03/03 18:08:29 | 000,000,000 | ---D | M] -- C:\Users\kody\AppData\Roaming\WinBatch
[2009/07/13 23:08:49 | 000,012,416 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
[2011/12/05 18:41:35 | 000,000,220 | ---- | M] () -- C:\windows\Tasks\SidebarExecute.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/13 19:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2010/03/24 15:43:46 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011/12/06 20:47:20 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2011/12/11 11:27:29 | 000,028,114 | ---- | M] () -- C:\ComboFix.txt
[2011/12/11 11:29:33 | 3016,503,296 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/02 19:01:44 | 000,000,359 | -H-- | M] () -- C:\IPH.PH
[2011/12/11 11:29:38 | 4022,005,760 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | ---- | M] () -- C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | ---- | M] () -- C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | ---- | M] () -- C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | ---- | M] () -- C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | ---- | M] () -- C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 12:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\windows\avastSS.scr
[2011/05/13 14:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/31 20:24:27 | 000,000,221 | -HS- | M] () -- C:\Users\kody\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/12/06 21:00:16 | 000,302,592 | ---- | M] () -- C:\Users\kody\Desktop\gmer.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 15:20:04 | 000,000,802 | ---- | M] () -- C:\windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/11/05 19:22:53 | 000,008,192 | ---- | M] () -- C:\windows\SECURITY\Database\edb.chk
[2011/11/05 19:22:53 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edb.log
[2011/11/05 19:22:53 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00001.jrs
[2011/11/05 19:22:53 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00002.jrs
[2011/11/05 19:22:53 | 000,786,432 | ---- | M] () -- C:\windows\SECURITY\Database\edbtmp.log
[2011/11/05 19:22:53 | 001,056,768 | ---- | M] () -- C:\windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/11/05 19:24:34 | 000,000,402 | -HS- | M] () -- C:\Users\kody\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011/04/02 16:25:32 | 000,000,017 | ---- | M] ()(C:\windows\SysWow64\??) -- C:\windows\SysWow64\楰ȼ
[2011/04/02 16:25:32 | 000,000,017 | ---- | C] ()(C:\windows\SysWow64\??) -- C:\windows\SysWow64\楰ȼ
< End of report >