1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Drag & drop from Explorer to Audacity not working

Discussion in 'Malware and Virus Removal Archive' started by Frank D, 2012/01/04.

  1. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Continued from previous post

    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Quick Translator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
    [2010/07/24 21:57:28 | 000,000,000 | ---D | M] (SmoothWheel) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}(2)
    [2011/06/17 09:06:45 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    [2008/12/05 14:45:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{6c3a1de1-94ca-4ad6-acdf-c1324adc487b}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] ( "Inline Google Definitions ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{70171e70-9057-11da-9562-00e08161165f}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}(2)
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(3)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(4)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(5)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(6)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(7)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (Surf Canyon - Search Engine Assistant) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}(2)
    [2010/07/24 22:42:02 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{909409b9-2e3b-4682-a5d1-71ca80a76456}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Hyperwords) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9A752782-D706-479b-98F8-3F66BF921692}(2)
    [2010/07/24 22:25:35 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] ( "FfChrome ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9bc51d13-3849-4541-a69c-da418934ca05}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Sage) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}(2)
    [2010/07/28 15:39:29 | 000,000,000 | ---D | M] ( "DVDVideoSoft Menu ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Answers) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}(2)
    [2010/07/24 21:57:38 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}(2)
    [2010/07/24 21:57:40 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}-trash(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}(2)
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "CoolPreviews ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
    [2010/07/24 22:34:03 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Tweak Network) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] ( "Tab Mix Plus ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{dc572301-7619-498c-a57d-39143191b318}
    [2010/07/24 21:57:42 | 000,000,000 | ---D | M] ( "BitDefender QuickScanner ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] (Memory Fox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
    [2010/07/24 21:57:43 | 000,000,000 | ---D | M] (Disable Targets For Downloads) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{FF380879-E2AA-4E2D-A348-99B9CBD7D3C0}(2)
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (backword) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\backword@gneheix(2).com
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(2).org
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(4).org
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (InvisibleHand) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\canitbecheaper@trafficbroker.co.uk
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (StatusbarEx) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\doudehou@gmail.com
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Fasterfox Lite) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\FasterFox_Lite@BigRedBrent
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla(2).org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (FireDownload) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla.org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "Greasefire ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\greasefire@skrul.com
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\ietab@ip.cn
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (PriceBlink) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\info@priceblink.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(2).com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(3).com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Read It Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Flash Video Resources Downloader) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\max@subfighter(2).com
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] ( "Nice Translator ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\nt@tumbledesign.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "Print Context Menu ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\printcontextmenuoption@pp
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\qtl.co.il@gmail.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (QuoteURLText) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\quoteurltext@jay.palat
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "RAMBack ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\ramback@pavlov.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\SQLiteManager@mrinalkant.blogspot(2).com
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\staged-xpis(2)
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\temp
    [2010/07/24 22:00:39 | 000,000,000 | ---D | M] (Text to Voice) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\text2voice@vik.josh
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\tineye@ideeinc.com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (URL Tooltip) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\url-tooltip@timothytate.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] ( "Wayback machine toolbar button ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\Wayback-toolbar-button@robz
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (Viamatic foXpose) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\xpose@viamatic(2).com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho
    [2010/07/24 21:57:25 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho(2)
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\chrome
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\defaults
    [2011/12/14 11:34:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
    [2010/07/24 21:57:26 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}(2)
    [2010/07/24 21:57:26 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}(3)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Resurrect Pages) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] (MozTweak) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{155b68cd-2661-4d9a-8d0d-de336d6f9461}
    [2010/07/24 21:57:26 | 000,000,000 | ---D | M] (FlashGot) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Remove It Permanently) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{1dbc4a33-ea62-4330-966c-7bdad3455322}
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Flashblock) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
    [2010/07/24 21:57:27 | 000,000,000 | ---D | M] (ShowIP) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}(2)
    [2010/07/24 21:57:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{3eaacb33-878f-44fa-b4cd-6e67cbaf828b}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
    [2010/07/24 21:57:28 | 000,000,000 | ---D | M] (FEBE) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}(2)
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (RefreshBlocker) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{55ce2530-61df-4ddc-b287-feae64e70575}
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Quick Translator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
    [2010/07/24 21:57:28 | 000,000,000 | ---D | M] (SmoothWheel) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}(2)
    [2011/06/17 09:06:45 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    [2008/12/05 14:45:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{6c3a1de1-94ca-4ad6-acdf-c1324adc487b}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] ( "Inline Google Definitions ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{70171e70-9057-11da-9562-00e08161165f}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}(2)
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(3)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(4)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(5)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(6)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(7)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (Surf Canyon - Search Engine Assistant) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}(2)
    [2010/07/24 22:42:02 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{909409b9-2e3b-4682-a5d1-71ca80a76456}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Hyperwords) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9A752782-D706-479b-98F8-3F66BF921692}(2)
    [2010/07/24 22:25:35 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] ( "FfChrome ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9bc51d13-3849-4541-a69c-da418934ca05}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Sage) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Answers) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}(2)
    [2010/07/24 21:57:38 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}(2)
    [2010/07/24 21:57:40 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}-trash(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}(2)
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "CoolPreviews ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
    [2010/07/24 22:34:03 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Tweak Network) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] ( "Tab Mix Plus ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{dc572301-7619-498c-a57d-39143191b318}
    [2010/07/24 21:57:42 | 000,000,000 | ---D | M] ( "BitDefender QuickScanner ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] (Memory Fox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
    [2011/12/14 11:34:53 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
    [2010/07/24 21:57:43 | 000,000,000 | ---D | M] (Disable Targets For Downloads) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{FF380879-E2AA-4E2D-A348-99B9CBD7D3C0}(2)
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (backword) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\backword@gneheix(2).com
    [2011/12/15 10:43:37 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\bbrs_002@blabbers.com
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(2).org
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(4).org
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (InvisibleHand) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\canitbecheaper@trafficbroker.co.uk
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (StatusbarEx) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\doudehou@gmail.com
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Fasterfox Lite) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\FasterFox_Lite@BigRedBrent
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla(2).org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (FireDownload) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla.org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "Greasefire ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\greasefire@skrul.com
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\ietab@ip.cn
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (PriceBlink) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\info@priceblink.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(2).com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(3).com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Read It Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Flash Video Resources Downloader) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\max@subfighter(2).com
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] ( "Nice Translator ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\nt@tumbledesign.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "Print Context Menu ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\printcontextmenuoption@pp
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\qtl.co.il@gmail.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (QuoteURLText) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\quoteurltext@jay.palat
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "RAMBack ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\ramback@pavlov.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\SQLiteManager@mrinalkant.blogspot(2).com
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\staged-xpis(2)
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\temp
    [2010/07/24 22:00:39 | 000,000,000 | ---D | M] (Text to Voice) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\text2voice@vik.josh
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\tineye@ideeinc.com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (URL Tooltip) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\url-tooltip@timothytate.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] ( "Wayback machine toolbar button ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\Wayback-toolbar-button@robz
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (Viamatic foXpose) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\xpose@viamatic(2).com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho
    [2010/07/24 21:57:25 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho(2)
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\chrome
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\defaults
    [2011/12/27 08:47:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2011/12/25 12:02:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
    [2011/12/30 19:25:50 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2011/03/05 10:57:04 | 000,025,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider(3).dll
    [2011/03/05 10:57:04 | 000,140,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp(4).dll
    [2011/12/07 21:56:21 | 000,063,632 | ---- | M] (soft Xpansion) -- C:\Program Files (x86)\mozilla firefox\plugins\np-sxpdf.dll
    [2011/12/25 12:01:55 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2011/05/17 15:31:56 | 001,152,488 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\NPFxViewer.dll
    [2011/03/05 10:57:04 | 000,066,520 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32(54).dll
    [2011/12/30 19:25:46 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011/12/14 19:18:29 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
    [2011/12/30 19:25:46 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - default_search_provider: ()
    CHR - default_search_provider: search_url =
    CHR - default_search_provider: suggest_url =

    O1 HOSTS File: ([2012/01/04 23:33:55 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
    O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found
    O2 - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
    O2 - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
    O3:64bit: - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
    O3 - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (GOM Player + Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
    O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
    O4:64bit: - HKLM..\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe (IvoSoft)
    O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
    O4:64bit: - HKLM..\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe (PC-Doctor, Inc.)
    O4:64bit: - HKLM..\Run: [PretonClient] C:\Program Files\Preton\PretonSaver\PretonClient.exe File not found
    O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [Zentimo xStorage Manager] C:\Program Files (x86)\Zentimo\Zentimo.exe (Crystal Rich Ltd)
    O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
    O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
    O4 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001..\Run: [QTranslate] C:\Program Files (x86)\QTranslate\QTranslate.exe (QuestSoft)
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2011/09/20 19:11:54 | 000,000,000 | -H-D | M]
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ax.lnk = C:\Program Files (x86)\AX\AX.exe ()
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PopTray.lnk = C:\Program Files (x86)\PopTray\PopTray.exe (Renier Crause)
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QuickMonth Calendar.lnk = C:\Program Files (x86)\QuickMonth Calendar\qmc.exe ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 44
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinters = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeAnimation = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeKeyboardNavigationIndicators = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionName = Google Search
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionAction = http://www.google.com/search?q=%w
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSecCpl = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
    O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
    O8:64bit: - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files (x86)\Exif 2.3\IExifCom.htm ()
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files (x86)\Exif 2.3\IExifCom.htm ()
    O9:64bit: - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
    O9:64bit: - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe" File not found
    O9:64bit: - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe" File not found
    O9 - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: aol.com ([free] http in Trusted sites)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: esl.org ([]https in Trusted sites)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: esl.org ([www] https in Trusted sites)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: microsoft.com ([]https in Trusted sites)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.2.0)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.7.0_02)
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
    O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB (Hewlett-Packard Online Support Services)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?40435.6676851852 (Update Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BC77401-5212-4B2C-8238-2AF79A39494B}: DhcpNameServer = 209.18.47.61 209.18.47.62
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BC77401-5212-4B2C-8238-2AF79A39494B}: NameServer = 8.8.8.8,8.8.4.4
    O18:64bit: - Protocol\Handler\belarc - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\gopher - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - File not found
    O21:64bit: - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\Windows\SysNative\stobject.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2010/12/07 16:34:16 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2010/12/07 16:34:17 | 000,000,000 | R--D | M] - D:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2010/02/02 07:05:26 | 000,000,000 | R--D | M] - F:\autorun -- [ NTFS ]
    O32 - AutoRun File - [2011/08/21 14:25:13 | 000,000,000 | R--D | M] - F:\autorun.inf -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\...com [@ = ComFile] -- Reg Error: Key error. File not found


    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
    Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
    Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
    Drivers32: msacm.sl_anet - C:\Windows\SysWow64\SL_ANET.ACM (Sipro Lab Telecom Inc.)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
    Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
    Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
    Drivers32: VIDC.MP42 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
    Drivers32: VIDC.MPG4 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
    Drivers32: vidc.tscc - C:\Program Files (x86)\MpcStar\Codecs\tscc\tsccvid.dll (TechSmith Corporation)
    Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
    Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/01/05 09:21:14 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL.exe
    [2012/01/05 00:37:24 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\driveridentifier
    [2012/01/05 00:37:20 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\TempDIR
    [2012/01/05 00:37:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Identifier
    [2012/01/05 00:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver Identifier
    [2012/01/04 23:49:07 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2012/01/04 23:16:27 | 000,000,000 | ---D | C] -- C:\ProgramData\CDRWIN 8
    [2012/01/04 23:13:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 8
    [2012/01/04 23:13:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDRWIN 8
    [2012/01/04 23:06:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
    [2012/01/04 23:04:36 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
    [2012/01/04 23:02:13 | 002,604,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
    [2012/01/04 23:02:12 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
    [2012/01/04 23:02:11 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
    [2012/01/04 23:02:11 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
    [2012/01/04 23:02:11 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
    [2012/01/04 23:02:08 | 000,220,512 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFNHK64.dll
    [2012/01/04 23:02:08 | 000,180,048 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFProc64.dll
    [2012/01/04 23:02:08 | 000,083,792 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFSAPO64.dll
    [2012/01/04 23:02:07 | 000,086,352 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFComm64.dll
    [2012/01/04 23:02:07 | 000,082,768 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFHAPO64.dll
    [2012/01/04 23:02:07 | 000,082,768 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFDAPO64.dll
    [2012/01/04 23:02:07 | 000,081,248 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFCOM64.dll
    [2012/01/04 23:02:07 | 000,078,176 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFAPO64.dll
    [2012/01/04 23:02:07 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
    [2012/01/04 23:02:00 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
    [2012/01/04 23:02:00 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
    [2012/01/04 23:02:00 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
    [2012/01/04 23:01:59 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
    [2012/01/04 23:01:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
    [2012/01/04 23:01:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
    [2012/01/04 23:01:50 | 002,132,824 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
    [2012/01/04 23:01:49 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
    [2012/01/04 23:01:39 | 002,085,440 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
    [2012/01/04 22:23:03 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/01/04 19:14:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/01/04 19:14:41 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/01/04 19:14:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/01/04 19:14:28 | 000,000,000 | ---D | C] -- C:\Qoobox

    To Be Continued in next post
     
  2. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Continued from previous post

    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Quick Translator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
    [2010/07/24 21:57:28 | 000,000,000 | ---D | M] (SmoothWheel) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}(2)
    [2011/06/17 09:06:45 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    [2008/12/05 14:45:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{6c3a1de1-94ca-4ad6-acdf-c1324adc487b}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] ( "Inline Google Definitions ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{70171e70-9057-11da-9562-00e08161165f}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}(2)
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(3)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(4)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(5)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(6)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(7)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (Surf Canyon - Search Engine Assistant) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}(2)
    [2010/07/24 22:42:02 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{909409b9-2e3b-4682-a5d1-71ca80a76456}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Hyperwords) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9A752782-D706-479b-98F8-3F66BF921692}(2)
    [2010/07/24 22:25:35 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] ( "FfChrome ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{9bc51d13-3849-4541-a69c-da418934ca05}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Sage) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}(2)
    [2010/07/28 15:39:29 | 000,000,000 | ---D | M] ( "DVDVideoSoft Menu ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Answers) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}(2)
    [2010/07/24 21:57:38 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}(2)
    [2010/07/24 21:57:40 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}-trash(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}(2)
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "CoolPreviews ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
    [2010/07/24 22:34:03 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Tweak Network) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] ( "Tab Mix Plus ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{dc572301-7619-498c-a57d-39143191b318}
    [2010/07/24 21:57:42 | 000,000,000 | ---D | M] ( "BitDefender QuickScanner ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] (Memory Fox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
    [2010/07/24 21:57:43 | 000,000,000 | ---D | M] (Disable Targets For Downloads) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\{FF380879-E2AA-4E2D-A348-99B9CBD7D3C0}(2)
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (backword) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\backword@gneheix(2).com
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(2).org
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(4).org
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (InvisibleHand) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\canitbecheaper@trafficbroker.co.uk
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (StatusbarEx) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\doudehou@gmail.com
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Fasterfox Lite) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\FasterFox_Lite@BigRedBrent
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla(2).org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (FireDownload) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla.org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "Greasefire ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\greasefire@skrul.com
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\ietab@ip.cn
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (PriceBlink) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\info@priceblink.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(2).com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(3).com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Read It Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Flash Video Resources Downloader) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\max@subfighter(2).com
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] ( "Nice Translator ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\nt@tumbledesign.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "Print Context Menu ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\printcontextmenuoption@pp
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\qtl.co.il@gmail.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (QuoteURLText) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\quoteurltext@jay.palat
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "RAMBack ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\ramback@pavlov.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\SQLiteManager@mrinalkant.blogspot(2).com
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\staged-xpis(2)
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\temp
    [2010/07/24 22:00:39 | 000,000,000 | ---D | M] (Text to Voice) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\text2voice@vik.josh
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\tineye@ideeinc.com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (URL Tooltip) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\url-tooltip@timothytate.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] ( "Wayback machine toolbar button ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\Wayback-toolbar-button@robz
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (Viamatic foXpose) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\xpose@viamatic(2).com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho
    [2010/07/24 21:57:25 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho(2)
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\chrome
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\defaults
    [2011/12/14 11:34:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
    [2010/07/24 21:57:26 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}(2)
    [2010/07/24 21:57:26 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}(3)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Resurrect Pages) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] (MozTweak) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{155b68cd-2661-4d9a-8d0d-de336d6f9461}
    [2010/07/24 21:57:26 | 000,000,000 | ---D | M] (FlashGot) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Remove It Permanently) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{1dbc4a33-ea62-4330-966c-7bdad3455322}
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Flashblock) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
    [2010/07/24 21:57:27 | 000,000,000 | ---D | M] (ShowIP) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}(2)
    [2010/07/24 21:57:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{3eaacb33-878f-44fa-b4cd-6e67cbaf828b}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
    [2010/07/24 21:57:28 | 000,000,000 | ---D | M] (FEBE) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}(2)
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (RefreshBlocker) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{55ce2530-61df-4ddc-b287-feae64e70575}
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Quick Translator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
    [2010/07/24 21:57:28 | 000,000,000 | ---D | M] (SmoothWheel) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}(2)
    [2011/06/17 09:06:45 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    [2008/12/05 14:45:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{6c3a1de1-94ca-4ad6-acdf-c1324adc487b}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] ( "Inline Google Definitions ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{70171e70-9057-11da-9562-00e08161165f}
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (History Submenus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{7102aba3-045c-4ec2-b921-46d87636d84b}(2)
    [2010/07/24 21:57:29 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(3)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(4)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(5)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(6)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(7)
    [2010/07/24 21:57:30 | 000,000,000 | ---D | M] (Surf Canyon - Search Engine Assistant) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}(2)
    [2010/07/24 22:42:02 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{909409b9-2e3b-4682-a5d1-71ca80a76456}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Hyperwords) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9A752782-D706-479b-98F8-3F66BF921692}(2)
    [2010/07/24 22:25:35 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] ( "FfChrome ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{9bc51d13-3849-4541-a69c-da418934ca05}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Sage) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
    [2010/07/24 21:57:31 | 000,000,000 | ---D | M] (Answers) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}(2)
    [2010/07/24 21:57:38 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}(2)
    [2010/07/24 21:57:40 | 000,000,000 | ---D | M] (Interclue) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}-trash(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}(2)
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "CoolPreviews ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
    [2010/07/24 22:34:03 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2)
    [2010/07/24 21:57:41 | 000,000,000 | ---D | M] (Tweak Network) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}(2)
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] ( "Tab Mix Plus ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{dc572301-7619-498c-a57d-39143191b318}
    [2010/07/24 21:57:42 | 000,000,000 | ---D | M] ( "BitDefender QuickScanner ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] (Memory Fox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
    [2011/12/14 11:34:53 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
    [2010/07/24 21:57:43 | 000,000,000 | ---D | M] (Disable Targets For Downloads) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\{FF380879-E2AA-4E2D-A348-99B9CBD7D3C0}(2)
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (backword) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\backword@gneheix(2).com
    [2011/12/15 10:43:37 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\bbrs_002@blabbers.com
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(2).org
    [2010/07/24 21:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\brief@mozdev(4).org
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (InvisibleHand) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\canitbecheaper@trafficbroker.co.uk
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (StatusbarEx) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\doudehou@gmail.com
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (Fasterfox Lite) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\FasterFox_Lite@BigRedBrent
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla(2).org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] (FireDownload) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\firedownload@mozilla.org
    [2010/07/24 22:34:07 | 000,000,000 | ---D | M] ( "Greasefire ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\greasefire@skrul.com
    [2010/07/24 22:34:08 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\ietab@ip.cn
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (PriceBlink) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\info@priceblink.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(2).com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Read it Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower(3).com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (Read It Later) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\isreaditlater@ideashower.com
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (Flash Video Resources Downloader) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\max@subfighter(2).com
    [2010/07/24 22:34:09 | 000,000,000 | ---D | M] ( "Nice Translator ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\nt@tumbledesign.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "Print Context Menu ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\printcontextmenuoption@pp
    [2010/07/24 21:57:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\qtl.co.il@gmail.com
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] (QuoteURLText) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\quoteurltext@jay.palat
    [2010/07/24 22:34:10 | 000,000,000 | ---D | M] ( "RAMBack ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\ramback@pavlov.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\SQLiteManager@mrinalkant.blogspot(2).com
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\staged-xpis(2)
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\temp
    [2010/07/24 22:00:39 | 000,000,000 | ---D | M] (Text to Voice) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\text2voice@vik.josh
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\tineye@ideeinc.com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (URL Tooltip) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\url-tooltip@timothytate.net
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] ( "Wayback machine toolbar button ") -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\Wayback-toolbar-button@robz
    [2010/07/24 21:57:24 | 000,000,000 | ---D | M] (Viamatic foXpose) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\xpose@viamatic(2).com
    [2010/07/24 22:34:11 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho
    [2010/07/24 21:57:25 | 000,000,000 | ---D | M] (Yet Another Smooth Scrolling) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\yetanothersmoothscrolling@kataho(2)
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\chrome
    [2010/07/24 21:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\vkcqakp1.Test only\extensions\extensionlistdumper@sogame.cat\defaults
    [2011/12/27 08:47:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2011/12/25 12:02:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
    [2011/12/30 19:25:50 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2011/03/05 10:57:04 | 000,025,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider(3).dll
    [2011/03/05 10:57:04 | 000,140,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp(4).dll
    [2011/12/07 21:56:21 | 000,063,632 | ---- | M] (soft Xpansion) -- C:\Program Files (x86)\mozilla firefox\plugins\np-sxpdf.dll
    [2011/12/25 12:01:55 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2011/05/17 15:31:56 | 001,152,488 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\NPFxViewer.dll
    [2011/03/05 10:57:04 | 000,066,520 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32(54).dll
    [2011/12/30 19:25:46 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011/12/14 19:18:29 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
    [2011/12/30 19:25:46 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - default_search_provider: ()
    CHR - default_search_provider: search_url =
    CHR - default_search_provider: suggest_url =

    O1 HOSTS File: ([2012/01/04 23:33:55 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
    O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found
    O2 - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
    O2 - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
    O3:64bit: - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
    O3 - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No CLSID value found.
    O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (GOM Player + Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
    O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
    O4:64bit: - HKLM..\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe (IvoSoft)
    O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
    O4:64bit: - HKLM..\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe (PC-Doctor, Inc.)
    O4:64bit: - HKLM..\Run: [PretonClient] C:\Program Files\Preton\PretonSaver\PretonClient.exe File not found
    O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [Zentimo xStorage Manager] C:\Program Files (x86)\Zentimo\Zentimo.exe (Crystal Rich Ltd)
    O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
    O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
    O4 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001..\Run: [QTranslate] C:\Program Files (x86)\QTranslate\QTranslate.exe (QuestSoft)
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2011/09/20 19:11:54 | 000,000,000 | -H-D | M]
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ax.lnk = C:\Program Files (x86)\AX\AX.exe ()
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PopTray.lnk = C:\Program Files (x86)\PopTray\PopTray.exe (Renier Crause)
    O4 - Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QuickMonth Calendar.lnk = C:\Program Files (x86)\QuickMonth Calendar\qmc.exe ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 44
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinters = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeAnimation = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeKeyboardNavigationIndicators = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionName = Google Search
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionAction = http://www.google.com/search?q=%w
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSecCpl = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
    O7 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
    O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
    O8:64bit: - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files (x86)\Exif 2.3\IExifCom.htm ()
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files (x86)\Exif 2.3\IExifCom.htm ()
    O9:64bit: - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
    O9:64bit: - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe" File not found
    O9:64bit: - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe" File not found
    O9 - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: aol.com ([free] http in Trusted sites)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: esl.org ([]https in Trusted sites)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: esl.org ([www] https in Trusted sites)
    O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: microsoft.com ([]https in Trusted sites)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.2.0)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.7.0_02)
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
    O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB (Hewlett-Packard Online Support Services)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?40435.6676851852 (Update Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BC77401-5212-4B2C-8238-2AF79A39494B}: DhcpNameServer = 209.18.47.61 209.18.47.62
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BC77401-5212-4B2C-8238-2AF79A39494B}: NameServer = 8.8.8.8,8.8.4.4

    To Be Continued in next post
     

  3. to hide this advert.

  4. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Continued from previous post

    O18:64bit: - Protocol\Handler\belarc - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\gopher - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - File not found
    O21:64bit: - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\Windows\SysNative\stobject.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2010/12/07 16:34:16 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2010/12/07 16:34:17 | 000,000,000 | R--D | M] - D:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2010/02/02 07:05:26 | 000,000,000 | R--D | M] - F:\autorun -- [ NTFS ]
    O32 - AutoRun File - [2011/08/21 14:25:13 | 000,000,000 | R--D | M] - F:\autorun.inf -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\...com [@ = ComFile] -- Reg Error: Key error. File not found


    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
    Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
    Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
    Drivers32: msacm.sl_anet - C:\Windows\SysWow64\SL_ANET.ACM (Sipro Lab Telecom Inc.)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
    Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
    Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
    Drivers32: VIDC.MP42 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
    Drivers32: VIDC.MPG4 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
    Drivers32: vidc.tscc - C:\Program Files (x86)\MpcStar\Codecs\tscc\tsccvid.dll (TechSmith Corporation)
    Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
    Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/01/05 09:21:14 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL.exe
    [2012/01/05 00:37:24 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\driveridentifier
    [2012/01/05 00:37:20 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\TempDIR
    [2012/01/05 00:37:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Identifier
    [2012/01/05 00:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver Identifier
    [2012/01/04 23:49:07 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2012/01/04 23:16:27 | 000,000,000 | ---D | C] -- C:\ProgramData\CDRWIN 8
    [2012/01/04 23:13:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 8
    [2012/01/04 23:13:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDRWIN 8
    [2012/01/04 23:06:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
    [2012/01/04 23:04:36 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
    [2012/01/04 23:02:13 | 002,604,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
    [2012/01/04 23:02:12 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
    [2012/01/04 23:02:11 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
    [2012/01/04 23:02:11 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
    [2012/01/04 23:02:11 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
    [2012/01/04 23:02:08 | 000,220,512 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFNHK64.dll
    [2012/01/04 23:02:08 | 000,180,048 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFProc64.dll
    [2012/01/04 23:02:08 | 000,083,792 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFSAPO64.dll
    [2012/01/04 23:02:07 | 000,086,352 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFComm64.dll
    [2012/01/04 23:02:07 | 000,082,768 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFHAPO64.dll
    [2012/01/04 23:02:07 | 000,082,768 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFDAPO64.dll
    [2012/01/04 23:02:07 | 000,081,248 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFCOM64.dll
    [2012/01/04 23:02:07 | 000,078,176 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFAPO64.dll
    [2012/01/04 23:02:07 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
    [2012/01/04 23:02:00 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
    [2012/01/04 23:02:00 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
    [2012/01/04 23:02:00 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
    [2012/01/04 23:01:59 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
    [2012/01/04 23:01:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
    [2012/01/04 23:01:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
    [2012/01/04 23:01:50 | 002,132,824 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
    [2012/01/04 23:01:49 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
    [2012/01/04 23:01:39 | 002,085,440 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
    [2012/01/04 22:23:03 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/01/04 19:14:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/01/04 19:14:41 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/01/04 19:14:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/01/04 19:14:28 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/01/04 19:12:19 | 004,370,643 | R--- | C] (Swearware) -- C:\Users\Frank\Desktop\ComboFix.exe
    [2012/01/03 23:41:49 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Get from YouTube
    [2012/01/03 23:00:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd
    [2012/01/03 22:58:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logishrd
    [2012/01/03 22:58:49 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
    [2012/01/03 22:55:17 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
    [2012/01/03 22:55:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
    [2012/01/03 22:54:43 | 000,000,000 | ---D | C] -- C:\Intel
    [2012/01/02 11:22:19 | 000,027,968 | ---- | C] (COMODO Security Solutions Inc.) -- C:\Windows\SysNative\cpmnat.exe
    [2012/01/02 10:52:32 | 000,205,512 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\cumon.sys
    [2012/01/02 10:52:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
    [2012/01/02 10:32:09 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO Programs Manager
    [2012/01/01 20:13:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegShot Reverter
    [2012/01/01 20:10:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegShot
    [2012/01/01 19:09:54 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cleanse Uninstaller Pro
    [2012/01/01 19:09:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cleanse Uninstaller Pro
    [2012/01/01 18:46:01 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\iWisoft Free Video Converter
    [2011/12/31 20:09:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    [2011/12/31 20:08:30 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
    [2011/12/30 20:13:22 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\SpeedMP3Downloader
    [2011/12/30 20:13:22 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedMP3Downloader
    [2011/12/30 20:13:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speed MP3 Downloader
    [2011/12/30 20:13:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedMP3Downloader
    [2011/12/30 12:07:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WhatIsHang
    [2011/12/29 20:13:07 | 000,000,000 | ---D | C] -- C:\WINSSLog
    [2011/12/29 20:01:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
    [2011/12/29 19:28:19 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\PicaJet.Com
    [2011/12/28 20:28:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDFill
    [2011/12/28 19:54:31 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\PDF2Text Output
    [2011/12/28 19:54:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Simpo PDF to Text
    [2011/12/28 19:54:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Simpo PDF to Text
    [2011/12/28 16:22:06 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Canneverbe Limited
    [2011/12/28 16:22:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
    [2011/12/28 16:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDBurnerXP
    [2011/12/28 13:56:05 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\net.watype.puzzle.jigsawlite.59CF40312C069B2E5F3F9C70D453B8E2C77D2E60.1
    [2011/12/28 13:51:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puzzle.watype.net
    [2011/12/28 13:51:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\puzzle.watype.net
    [2011/12/28 13:15:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
    [2011/12/28 13:11:03 | 000,000,000 | ---D | C] -- C:\MATS
    [2011/12/27 12:00:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Goland
    [2011/12/27 12:00:43 | 000,000,000 | ---D | C] -- C:\AudioDVDCreator_Temp
    [2011/12/27 11:38:57 | 000,054,816 | ---- | C] (VSO Software) -- C:\Windows\SysNative\drivers\pcouffin64a.sys
    [2011/12/27 11:38:57 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\PcSetup
    [2011/12/27 08:28:44 | 000,000,000 | ---D | C] -- C:\d09372842ffb891599
    [2011/12/26 22:54:17 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\StarBurn
    [2011/12/26 22:54:17 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\StarBurn
    [2011/12/26 22:51:43 | 000,118,888 | ---- | C] (Rocket Division Software) -- C:\Windows\SysNative\drivers\StarPortLite.sys
    [2011/12/26 19:48:59 | 000,000,000 | ---D | C] -- C:\Program Files\Advanced Tokens Manager
    [2011/12/26 11:08:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BootSnooze
    [2011/12/26 10:53:16 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\Freemake
    [2011/12/25 13:48:42 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
    [2011/12/25 13:43:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2011/12/25 12:01:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
    [2011/12/25 11:57:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
    [2011/12/25 11:57:22 | 000,000,000 | ---D | C] -- C:\Program Files\Classic Shell
    [2011/12/25 11:44:46 | 000,000,000 | ---D | C] -- C:\Users\Frank\Application Data\Microsoft\Internet Explorer\Quick Launch\Q
    [2011/12/25 11:27:21 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Talk
    [2011/12/25 11:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Talk
    [2011/12/25 11:19:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3
    [2011/12/25 10:35:08 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\{8FCCB8D5-EA74-4EC1-885C-70F979C4866D}
    [2011/12/23 14:33:04 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\X-Setup Pro
    [2011/12/23 14:33:03 | 000,000,000 | ---D | C] -- C:\ProgramData\X-Setup Pro
    [2011/12/22 13:07:21 | 000,634,512 | ---- | C] (Gianpaolo Bottin) -- C:\Windows\gPhotoShow.scr
    [2011/12/22 13:07:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gPhotoShow
    [2011/12/22 13:07:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gPhotoShow
    [2011/12/22 12:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro
    [2011/12/22 10:06:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Password Security Scanner
    [2011/12/22 10:06:11 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Password Security Scanner
    [2011/12/21 14:22:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com Windows Repair (All in One)
    [2011/12/21 13:32:08 | 000,000,000 | ---D | C] -- C:\ProgramData\backup
    [2011/12/21 13:30:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon Backup & Recovery™ 2012 Free
    [2011/12/20 15:34:50 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
    [2011/12/20 15:34:49 | 000,000,000 | ---D | C] -- C:\Program Files\Image Composite Editor
    [2011/12/20 14:50:17 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\3D-Album
    [2011/12/20 14:50:16 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\visviva
    [2011/12/20 14:50:16 | 000,000,000 | ---D | C] -- C:\Windows\Temporary Internet Files
    [2011/12/20 14:29:43 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\Wondershare DVD Slideshow Builder Standard
    [2011/12/20 14:26:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare DVD Slideshow Builder Standard
    [2011/12/20 13:51:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UBCD4Win
    [2011/12/19 22:15:19 | 024,334,368 | ---- | C] (Amazon.com) -- C:\Windows\SysWow64\temp_%1%2
    [2011/12/19 19:59:39 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\Tipard Studio
    [2011/12/19 15:08:41 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Tipard Studio
    [2011/12/19 15:08:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tipard
    [2011/12/19 15:08:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Tipard Studio
    [2011/12/19 15:08:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tipard DVD Creator
    [2011/12/19 13:15:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Identity Finder
    [2011/12/19 13:14:02 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Identity Finder
    [2011/12/19 13:11:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Identity Finder
    [2011/12/19 13:11:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Identity Finder 5
    [2011/12/19 12:37:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JetBoost
    [2011/12/19 12:37:07 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueSprig
    [2011/12/19 12:37:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JetBoost
    [2011/12/18 14:55:10 | 000,544,768 | ---- | C] (Stardock Corporation) -- C:\Windows\SysWow64\wbocx.ocx
    [2011/12/18 14:55:09 | 000,056,496 | ---- | C] (Stardock.Net, Inc) -- C:\Windows\SysWow64\wbhelp2.dll
    [2011/12/18 14:55:09 | 000,033,968 | ---- | C] (Neil Banfield) -- C:\Windows\SysWow64\anim.dll
    [2011/12/18 14:49:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    [2011/12/18 14:09:26 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Windows Live
    [2011/12/18 14:09:00 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\{D5EBF2B8-5564-42B7-B1F5-B96892272E3C}
    [2011/12/18 10:15:49 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Wokhan
    [2011/12/18 10:13:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Firewall Notifier
    [2011/12/17 15:05:10 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\REAPER
    [2011/12/17 12:10:28 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Power Sound Editor Free
    [2011/12/17 12:10:20 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Power Sound Editor Free
    [2011/12/17 12:10:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Power Sound Editor Free
    [2011/12/15 17:04:49 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ArcSoft
    [2011/12/15 16:12:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    [2011/12/15 16:12:27 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2011/12/15 11:51:03 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek Equalizer
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\VST3
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\MTexturedStyles
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\ProgramData\MTexturedStyles
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\Program Files\MeldaProduction
    [2011/12/14 19:54:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRS Labs
    [2011/12/14 19:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\SRS HD Audio Lab
    [2011/12/14 17:39:45 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\ArcSoft
    [2011/12/14 13:43:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ArcSoft Perfect365
    [2011/12/14 12:56:01 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\WindowSlider
    [2011/12/14 12:55:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindowSlider
    [2011/12/14 11:36:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\RBSoft
    [2011/12/14 11:34:25 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Right Click Enhancer
    [2011/12/13 11:01:00 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\DiskBoss Pro
    [2011/12/13 11:00:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskBoss Pro
    [2011/12/13 11:00:45 | 000,000,000 | ---D | C] -- C:\Program Files\DiskBoss Pro
    [2011/12/12 09:36:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
    [2011/12/12 09:33:57 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\GomPlayer
    [2011/12/12 09:33:56 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\GRETECH
    [2011/12/12 09:27:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
    [2011/12/11 11:40:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    [2011/12/11 10:40:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 3
    [2011/12/11 10:35:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Advanced SystemCare 5
    [2011/12/10 23:08:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Engelmann Media VideoMizer.del
    [2011/12/09 10:59:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\USB Log View
    [2011/12/07 21:56:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\soft Xpansion
    [2011/12/07 21:56:16 | 000,000,000 | ---D | C] -- C:\ProgramData\soft Xpansion
    [2011/12/06 12:34:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rename Master 2.9.5
    [2011/10/06 15:34:11 | 000,018,944 | ---- | C] ( ) -- C:\Windows\SysWow64\Implode.dll
    [2011/07/03 18:48:42 | 000,147,456 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
    [2010/02/03 20:00:00 | 000,139,264 | ---- | C] ( ) -- C:\Windows\sipr3260.dll
    [4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [168 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
    [1 C:\Users\Frank\Desktop\*.tmp files -> C:\Users\Frank\Desktop\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/01/05 09:22:59 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA(243).DAT
    [2012/01/05 09:22:55 | 000,018,736 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/01/05 09:22:55 | 000,018,736 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/01/05 09:21:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL.exe
    [2012/01/05 09:17:24 | 000,000,031 | ---- | M] () -- C:\Windows\SysNative\bbcap.err
    [2012/01/05 09:17:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/01/05 09:17:14 | 3018,661,888 | -HS- | M] () -- C:\hiberfil.sys
    [2012/01/05 01:05:10 | 000,064,276 | ---- | M] () -- C:\Windows\CUAppUsage.Dat
    [2012/01/05 00:37:18 | 000,001,076 | ---- | M] () -- C:\Users\Public\Desktop\Driver Identifier.lnk
    [2012/01/04 23:33:55 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/01/04 23:13:20 | 000,000,892 | ---- | M] () -- C:\Users\Public\Desktop\CDRWIN 8.lnk
    [2012/01/04 21:28:25 | 000,016,907 | ---- | M] () -- C:\Users\Frank\Desktop\Worst Shoes for Your Feet.pdf
    [2012/01/04 21:27:01 | 000,012,981 | ---- | M] () -- C:\Users\Frank\Documents\Worst Shoes for Your Feet - WebMD.pdf
    [2012/01/04 20:05:34 | 001,008,141 | ---- | M] () -- C:\Users\Frank\Desktop\rkill.exe
    [2012/01/04 19:12:21 | 004,370,643 | R--- | M] (Swearware) -- C:\Users\Frank\Desktop\ComboFix.exe
    [2012/01/03 23:02:39 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LHidFilt_01005.Wdf
    [2012/01/03 23:02:38 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LMouFilt_01005.Wdf
    [2012/01/03 23:01:40 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
    [2012/01/02 10:35:56 | 629,145,600 | -H-- | M] () -- C:\fileimage.dat
    [2012/01/01 16:54:35 | 000,791,056 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/01/01 16:54:35 | 000,671,612 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/01/01 16:54:35 | 000,126,558 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/01/01 16:54:29 | 000,791,056 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2011/12/31 21:13:47 | 000,001,057 | ---- | M] () -- C:\Users\Frank\Application Data\Microsoft\Internet Explorer\Quick Launch\Waterfox.lnk
    [2011/12/29 22:23:26 | 000,037,888 | ---- | M] () -- C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/12/29 13:38:50 | 000,000,020 | ---- | M] () -- C:\Windows\¼Ã´4
    [2011/12/28 22:06:22 | 000,047,676 | ---- | M] () -- C:\Users\Frank\Documents\OC Foundation Hoarding Website.pdf
    [2011/12/28 22:03:31 | 000,000,162 | -H-- | M] () -- C:\Users\Frank\Documents\~$arding Survey.pdf
    [2011/12/28 21:03:27 | 031,137,792 | ---- | M] () -- C:\Users\Frank\Documents\New catalog.ccd
    [2011/12/28 20:30:20 | 000,002,998 | ---- | M] () -- C:\Users\Frank\Documents\Passwords.pdb
    [2011/12/28 20:08:56 | 000,003,298 | ---- | M] () -- C:\Windows\SysWow64\StyleVista.png
    [2011/12/28 20:08:56 | 000,003,137 | ---- | M] () -- C:\Windows\SysWow64\StyleVistaDown.png
    [2011/12/27 11:39:57 | 000,000,000 | ---- | M] () -- C:\Windows\AudioDVD.INI
    [2011/12/27 11:38:57 | 000,054,816 | ---- | M] (VSO Software) -- C:\Windows\SysNative\drivers\pcouffin64a.sys
    [2011/12/26 22:53:06 | 000,867,824 | ---- | M] () -- C:\Windows\SysNative\drivers\sptd.sys
    [2011/12/26 10:04:26 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/12/26 10:04:26 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/12/26 10:04:26 | 000,000,448 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
    [2011/12/23 11:31:50 | 000,118,888 | ---- | M] (Rocket Division Software) -- C:\Windows\SysNative\drivers\StarPortLite.sys
    [2011/12/22 11:55:27 | 013,893,632 | ---- | M] () -- C:\Users\Frank\ntuser.bak
    [2011/12/19 22:44:56 | 024,334,368 | ---- | M] (Amazon.com) -- C:\Windows\SysWow64\temp_%1%2
    [2011/12/18 15:41:05 | 000,000,676 | ---- | M] () -- C:\chksize.cmd
    [2011/12/18 15:32:41 | 000,000,551 | ---- | M] () -- C:\chksize.cmd.hold
    [2011/12/18 15:00:14 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\_WKERNEL.FRE
    [2011/12/16 13:07:40 | 000,000,230 | RH-- | M] () -- C:\Program Files (x86)\Mozilla Firefoxinstall.xml
    [2011/12/15 11:34:01 | 000,197,014 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MAnalyzerpresets.xml
    [2011/12/15 11:34:01 | 000,013,964 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MFlangerpresets.xml
    [2011/12/15 11:34:01 | 000,013,158 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MOscillatorpresets.xml
    [2011/12/15 11:34:01 | 000,009,119 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MFreqShifterpresets.xml
    [2011/12/15 11:34:01 | 000,007,130 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MEqualizerpresets.xml
    [2011/12/15 11:34:01 | 000,006,687 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\menvelopepresets.xml
    [2011/12/15 11:34:01 | 000,006,444 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MCompressorpresets.xml
    [2011/12/15 11:34:01 | 000,005,622 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MNoiseGeneratorpresets.xml
    [2011/12/15 11:34:01 | 000,005,138 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MWaveShaperpresets.xml
    [2011/12/15 11:34:01 | 000,004,362 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MPhaserpresets.xml
    [2011/12/15 11:34:01 | 000,003,771 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MRingModulatorpresets.xml
    [2011/12/15 11:34:01 | 000,002,820 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MEqualizerAreasEditorpresets.xml
    [2011/12/15 11:34:01 | 000,002,775 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MStereoExpanderpresets.xml
    [2011/12/15 11:34:01 | 000,002,666 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MVibratopresets.xml
    [2011/12/15 11:34:01 | 000,002,492 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MSpectralAnalyzerPrefilterpresets.xml
    [2011/12/15 11:34:01 | 000,002,366 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MTremolopresets.xml
    [2011/12/15 11:34:01 | 000,001,907 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MAutopanpresets.xml
    [2011/12/15 11:34:01 | 000,001,381 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MLimiterpresets.xml
    [2011/12/15 11:34:01 | 000,001,235 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\mbasestyleconfigurationpresets.xml
    [2011/12/15 11:34:01 | 000,001,011 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MValueToColor5presets.xml
    [2011/12/14 11:34:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\URL Parts Error
    [2011/12/14 11:34:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\OK
    [2011/12/13 11:01:00 | 000,000,105 | -HS- | M] () -- C:\Users\Frank\AppData\Local\00000021
    [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2011/12/09 12:15:03 | 000,308,003 | ---- | M] () -- C:\Users\Frank\Desktop\HP MS225 System Informaiton.pdf
    [2011/12/09 12:14:08 | 000,106,486 | ---- | M] () -- C:\Users\Frank\Documents\System Information.html
    [2011/12/09 12:13:32 | 000,027,059 | ---- | M] () -- C:\Users\Frank\Documents\Hardware Diagnostic Tools System Information Profiler.html
    [2011/12/07 21:56:23 | 000,008,608 | ---- | M] () -- C:\Windows\SysWow64\sx_p2d.tlb
    [4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [168 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
    [1 C:\Users\Frank\Desktop\*.tmp files -> C:\Users\Frank\Desktop\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/01/05 00:37:18 | 000,001,076 | ---- | C] () -- C:\Users\Public\Desktop\Driver Identifier.lnk
    [2012/01/04 23:13:20 | 000,000,892 | ---- | C] () -- C:\Users\Public\Desktop\CDRWIN 8.lnk
    [2012/01/04 21:28:25 | 000,016,907 | ---- | C] () -- C:\Users\Frank\Desktop\Worst Shoes for Your Feet.pdf
    [2012/01/04 21:27:01 | 000,012,981 | ---- | C] () -- C:\Users\Frank\Documents\Worst Shoes for Your Feet - WebMD.pdf
    [2012/01/04 20:04:50 | 001,008,141 | ---- | C] () -- C:\Users\Frank\Desktop\rkill.exe
    [2012/01/04 19:14:41 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/01/04 19:14:41 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/01/04 19:14:41 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/01/04 19:14:41 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/01/04 19:14:41 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/01/03 23:02:39 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LHidFilt_01005.Wdf
    [2012/01/03 23:02:38 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LMouFilt_01005.Wdf
    [2012/01/03 23:01:40 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
    [2012/01/03 11:12:09 | 000,001,805 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ax.lnk
    [2012/01/03 11:12:09 | 000,001,125 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QuickMonth Calendar.lnk
    [2012/01/03 11:12:09 | 000,001,033 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PopTray.lnk
    [2012/01/02 10:52:30 | 000,019,568 | ---- | C] () -- C:\Windows\SysNative\drivers\evdd.sys
    [2012/01/02 10:50:18 | 000,064,276 | ---- | C] () -- C:\Windows\CUAppUsage.Dat
    [2012/01/02 10:35:56 | 629,145,600 | -H-- | C] () -- C:\fileimage.dat
    [2011/12/31 21:13:47 | 000,001,057 | ---- | C] () -- C:\Users\Frank\Application Data\Microsoft\Internet Explorer\Quick Launch\Waterfox.lnk
    [2011/12/31 20:14:04 | 000,000,848 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox.lnk
    [2011/12/29 13:38:48 | 000,000,020 | ---- | C] () -- C:\Windows\¼Ã´4
    [2011/12/28 22:06:19 | 000,047,676 | ---- | C] () -- C:\Users\Frank\Documents\OC Foundation Hoarding Website.pdf
    [2011/12/28 22:03:31 | 000,000,162 | -H-- | C] () -- C:\Users\Frank\Documents\~$arding Survey.pdf
    [2011/12/28 16:21:58 | 000,001,867 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
    [2011/12/27 11:39:57 | 000,000,000 | ---- | C] () -- C:\Windows\AudioDVD.INI
    [2011/12/26 22:53:05 | 000,867,824 | ---- | C] () -- C:\Windows\SysNative\drivers\sptd.sys
    [2011/12/18 15:41:05 | 000,000,676 | ---- | C] () -- C:\chksize.cmd
    [2011/12/18 14:55:22 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\_WKERNEL.FRE
    [2011/12/18 14:55:09 | 000,000,439 | ---- | C] () -- C:\Windows\SysWow64\shfolder.inf
    [2011/12/16 13:07:40 | 000,000,230 | RH-- | C] () -- C:\Program Files (x86)\Mozilla Firefoxinstall.xml
    [2011/12/15 11:34:01 | 000,197,014 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MAnalyzerpresets.xml
    [2011/12/15 11:34:01 | 000,013,964 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MFlangerpresets.xml
    [2011/12/15 11:34:01 | 000,013,158 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MOscillatorpresets.xml
    [2011/12/15 11:34:01 | 000,009,119 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MFreqShifterpresets.xml
    [2011/12/15 11:34:01 | 000,007,130 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MEqualizerpresets.xml
    [2011/12/15 11:34:01 | 000,006,687 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\menvelopepresets.xml
    [2011/12/15 11:34:01 | 000,006,444 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MCompressorpresets.xml
    [2011/12/15 11:34:01 | 000,005,622 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MNoiseGeneratorpresets.xml
    [2011/12/15 11:34:01 | 000,005,138 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MWaveShaperpresets.xml
    [2011/12/15 11:34:01 | 000,004,362 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MPhaserpresets.xml
    [2011/12/15 11:34:01 | 000,003,771 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MRingModulatorpresets.xml
    [2011/12/15 11:34:01 | 000,002,820 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MEqualizerAreasEditorpresets.xml
    [2011/12/15 11:34:01 | 000,002,775 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MStereoExpanderpresets.xml
    [2011/12/15 11:34:01 | 000,002,666 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MVibratopresets.xml
    [2011/12/15 11:34:01 | 000,002,492 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MSpectralAnalyzerPrefilterpresets.xml
    [2011/12/15 11:34:01 | 000,002,366 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MTremolopresets.xml
    [2011/12/15 11:34:01 | 000,001,907 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MAutopanpresets.xml
    [2011/12/15 11:34:01 | 000,001,381 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MLimiterpresets.xml
    [2011/12/15 11:34:01 | 000,001,235 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\mbasestyleconfigurationpresets.xml
    [2011/12/15 11:34:01 | 000,001,011 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MValueToColor5presets.xml
    [2011/12/13 11:01:00 | 000,000,105 | -HS- | C] () -- C:\Users\Frank\AppData\Local\00000021
    [2011/12/09 12:15:02 | 000,308,003 | ---- | C] () -- C:\Users\Frank\Desktop\HP MS225 System Informaiton.pdf
    [2011/12/09 12:14:08 | 000,106,486 | ---- | C] () -- C:\Users\Frank\Documents\System Information.html
    [2011/12/09 12:13:31 | 000,027,059 | ---- | C] () -- C:\Users\Frank\Documents\Hardware Diagnostic Tools System Information Profiler.html
    [2011/12/07 21:56:23 | 000,008,608 | ---- | C] () -- C:\Windows\SysWow64\sx_p2d.tlb
    [2011/11/22 20:42:59 | 000,000,054 | ---- | C] () -- C:\Windows\Player.INI
    [2011/11/21 18:02:16 | 000,034,936 | ---- | C] () -- C:\Windows\SysWow64\uninstHelixYUV.exe
    [2011/11/16 10:03:52 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cd.dat
    [2011/11/04 09:54:42 | 000,065,536 | -H-- | C] () -- C:\Windows\SysWow64\WebCamLib.dll
    [2011/10/06 15:34:20 | 000,204,848 | ---- | C] () -- C:\Windows\SysWow64\gswin32c.exe
    [2011/10/06 15:34:12 | 000,054,272 | ---- | C] () -- C:\Windows\SysWow64\P2irdao.dll
    [2011/10/06 15:34:12 | 000,050,176 | ---- | C] () -- C:\Windows\SysWow64\P2ctdao.dll
    [2011/10/06 15:34:11 | 000,748,160 | ---- | C] () -- C:\Windows\SysWow64\Co2c40en.dll
    [2011/10/04 10:57:40 | 011,165,696 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Sandra.mdb
    [2011/09/22 12:08:56 | 003,902,976 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
    [2011/09/15 09:58:10 | 000,091,136 | ---- | C] () -- C:\Windows\SendToClip.exe
    [2011/09/11 09:26:18 | 000,000,292 | ---- | C] () -- C:\Users\Frank\AppData\Local\HamsterBookConverter.cfg
    [2011/09/08 19:49:01 | 000,000,548 | ---- | C] () -- C:\Program Files\Add_Restart_Explorer_Option.reg
    [2011/09/08 19:49:01 | 000,000,448 | ---- | C] () -- C:\Program Files\Restart_Explorer.bat
    [2011/08/31 13:29:00 | 004,023,808 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
    [2011/08/30 14:17:19 | 000,001,035 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2011/08/22 14:07:48 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
    [2011/08/22 14:07:02 | 000,158,208 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
    [2011/08/22 14:07:00 | 000,259,584 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
    [2011/08/22 14:06:30 | 001,524,224 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
    [2011/08/22 14:06:30 | 000,211,456 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
    [2011/08/22 14:06:30 | 000,097,280 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
    [2011/08/22 14:06:28 | 000,327,680 | ---- | C] () -- C:\Windows\SysWow64\ff_libfaad2.dll
    [2011/08/22 14:06:28 | 000,113,664 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
    [2011/08/22 14:06:26 | 000,145,920 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
    [2011/08/22 14:06:26 | 000,136,704 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
    [2011/07/28 18:24:42 | 000,156,160 | ---- | C] () -- C:\Windows\SysWow64\WS_ContextMenu.dll
    [2011/07/22 17:16:26 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\HPPLVS.dll
    [2011/07/17 22:54:02 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
    [2011/07/14 21:00:57 | 000,000,167 | ---- | C] () -- C:\Windows\topocr.INI
    [2011/07/06 13:21:42 | 000,311,296 | ---- | C] () -- C:\Windows\SysWow64\EMRegSys.dll
    [2011/06/01 19:05:51 | 000,000,000 | ---- | C] () -- C:\Windows\QuickInstall.INI
    [2011/05/30 09:49:08 | 000,000,525 | ---- | C] () -- C:\Users\Frank\AppData\Local\UserProducts.xml
    [2011/05/30 08:42:50 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2011/05/23 02:46:30 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2011/05/06 11:40:48 | 000,000,063 | -H-- | C] () -- C:\ProgramData\Ts_infos.ini
    [2011/04/29 12:36:29 | 000,000,354 | ---- | C] () -- C:\Windows\Ripper.INI
    [2011/04/28 19:05:28 | 000,164,112 | ---- | C] () -- C:\Windows\SysWow64\awmpi.dll
    [2011/04/28 15:54:16 | 000,016,096 | ---- | C] () -- C:\Users\Frank\AppData\Local\Schedule8.dat
    [2011/04/07 09:13:26 | 002,340,992 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
    [2011/04/07 09:13:26 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
    [2011/04/07 09:13:26 | 000,018,048 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
    [2011/04/07 09:13:26 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
    [2011/04/07 09:13:26 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
    [2011/03/03 06:40:08 | 000,150,528 | ---- | C] () -- C:\Windows\SysWow64\mkx.dll
    [2011/03/03 06:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\SysWow64\avi.dll
    [2011/03/03 06:39:46 | 000,141,824 | ---- | C] () -- C:\Windows\SysWow64\mp4.dll
    [2011/03/03 06:39:34 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\ogm.dll
    [2011/03/03 06:39:02 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\dsmux.exe
    [2011/03/03 06:38:54 | 000,154,112 | ---- | C] () -- C:\Windows\SysWow64\ts.dll
    [2011/03/03 06:38:40 | 000,249,856 | ---- | C] () -- C:\Windows\SysWow64\dxr.dll
    [2011/03/03 06:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\SysWow64\avs.dll
    [2011/03/03 06:38:04 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\mkv2vfr.exe
    [2011/03/03 06:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\avss.dll
    [2011/03/03 06:37:40 | 000,358,400 | ---- | C] () -- C:\Windows\SysWow64\gdsmux.exe
    [2011/03/03 06:35:32 | 000,080,384 | ---- | C] () -- C:\Windows\SysWow64\mkzlib.dll
    [2011/03/03 06:35:26 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\mkunicode.dll
    [2011/02/26 18:43:59 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
    [2011/02/26 18:29:09 | 000,000,059 | ---- | C] () -- C:\Windows\wpd99.drv
    [2011/02/26 18:29:08 | 000,047,616 | ---- | C] () -- C:\Windows\SysWow64\pdf995mon64.dll
    [2011/02/18 09:14:01 | 000,296,980 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
    [2011/02/09 23:03:48 | 000,000,326 | ---- | C] () -- C:\Windows\primopdf.ini
    [2011/02/09 19:54:58 | 003,973,120 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg2.exe
    [2011/01/27 17:06:52 | 000,791,056 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2011/01/18 10:28:23 | 000,014,336 | ---- | C] () -- C:\Windows\SysWow64\vsmon1.dll
    [2011/01/13 21:54:24 | 000,001,360 | ---- | C] () -- C:\Windows\ntbackup.ini
    [2011/01/10 19:23:42 | 000,000,186 | ---- | C] () -- C:\Windows\SysWow64\CleanMem.ini
    [2011/01/05 18:04:44 | 000,000,032 | ---- | C] () -- C:\Windows\SysWow64\EUOD.DAT
    [2011/01/04 15:33:38 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\RtlCPAPI.dll
    [2011/01/04 15:33:38 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\ChCfg.exe
    [2011/01/04 13:28:18 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010/12/19 16:59:26 | 000,000,029 | ---- | C] () -- C:\Windows\wordpad.ini
    [2010/12/09 21:06:00 | 000,040,963 | ---- | C] () -- C:\Program Files\NirCmd.chm
    [2010/10/29 15:11:12 | 000,017,189 | ---- | C] () -- C:\Windows\OCR.Ini
    [2010/10/23 09:08:51 | 000,153,600 | ---- | C] () -- C:\Windows\SysWow64\WSContextMenu.dll
    [2010/10/20 11:07:33 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
    [2010/10/10 15:49:51 | 000,000,354 | ---- | C] () -- C:\Windows\RMDownloader.INI
    [2010/10/04 12:19:12 | 000,037,888 | ---- | C] () -- C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/09/28 19:28:44 | 000,000,055 | ---- | C] () -- C:\Windows\CopyMessageBox.INI
    [2010/09/28 13:00:12 | 000,012,800 | ---- | C] () -- C:\Windows\LPRES.DLL
    [2010/09/11 12:58:15 | 000,075,776 | ---- | C] () -- C:\Windows\cadkasdeinst01e.exe
    [2010/08/18 14:56:38 | 000,000,151 | ---- | C] () -- C:\Windows\SysWow64\Registration.ini
    [2010/07/29 21:49:52 | 000,007,616 | ---- | C] () -- C:\Users\Frank\AppData\Local\resmon.resmoncfg
    [2010/07/29 08:06:00 | 000,110,602 | ---- | C] () -- C:\Windows\SysWow64\xcdsfx32.bin
    [2010/07/28 22:17:52 | 000,000,036 | ---- | C] () -- C:\Users\Frank\AppData\Local\housecall.guid.cache
    [2010/07/28 19:04:23 | 000,000,056 | ---- | C] () -- C:\ProgramData\claude.ini
    [2010/07/24 11:22:58 | 000,153,600 | ---- | C] () -- C:\Windows\SysWow64\AI_ContextMenu.dll
    [2010/07/21 12:52:51 | 000,000,057 | ---- | C] () -- C:\Windows\cdrLabel.ini
    [2010/07/21 10:51:59 | 000,454,656 | ---- | C] () -- C:\Windows\SysWow64\PaintX.dll
    [2010/07/21 10:51:59 | 000,094,208 | ---- | C] () -- C:\Windows\SysWow64\vbpng.dll
    [2010/07/21 10:51:59 | 000,072,192 | ---- | C] () -- C:\Windows\SysWow64\zlib.dll
    [2010/07/21 10:31:47 | 000,017,116 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\AllChars.xml
    [2010/07/21 10:31:47 | 000,016,555 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\AllChars-example.xml
    [2010/07/20 16:23:01 | 000,000,035 | ---- | C] () -- C:\Windows\Ulead32.INI
    [2010/07/20 15:32:40 | 000,285,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\Onsio.sys
    [2010/07/20 15:32:40 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\drivers\Onsreged.sys
    [2010/07/19 17:59:21 | 000,039,424 | ---- | C] () -- C:\Windows\SysWow64\rpiAccessProcess.dll
    [2010/07/18 21:33:22 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\VegaShEx.dll
    [2010/07/18 21:33:17 | 000,308,224 | ---- | C] () -- C:\Windows\SysWow64\Lffpx7.dll
    [2010/07/18 17:21:16 | 000,000,008 | RHS- | C] () -- C:\ProgramData\7C18212ACF.sys
    [2010/07/18 17:21:15 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
    [2010/07/18 17:02:41 | 000,157,696 | ---- | C] () -- C:\Windows\SysWow64\OggEnc.exe
    [2010/07/18 17:02:41 | 000,145,408 | ---- | C] () -- C:\Windows\SysWow64\Lame.exe
    [2010/07/18 17:02:41 | 000,076,800 | ---- | C] () -- C:\Windows\SysWow64\Faac.exe
    [2010/07/18 11:38:51 | 000,000,510 | ---- | C] () -- C:\Windows\ODBC.INI
    [2010/07/18 11:31:50 | 000,001,103 | ---- | C] () -- C:\Windows\ODBCINST.INI
    [2010/01/27 13:35:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2009/08/11 16:21:26 | 000,087,552 | ---- | C] () -- C:\Windows\SysWow64\ac3config.exe
    [2009/08/11 16:21:20 | 001,021,440 | ---- | C] () -- C:\Windows\SysWow64\ac3filter_intl.dll
    [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat(213).dat
    [2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2008/01/14 17:47:06 | 000,099,712 | ---- | C] () -- C:\Windows\HPBroker.dll
    [2007/04/27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
    [2007/02/05 16:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
    [2006/03/03 23:52:00 | 000,088,576 | ---- | C] () -- C:\Windows\SysWow64\OptimFROG.dll
    [2006/01/08 08:53:24 | 000,005,120 | ---- | C] () -- C:\Windows\SysWow64\hash2.dll
    [2005/08/26 15:28:34 | 000,143,360 | ---- | C] () -- C:\Windows\unzip.exe
    [2005/08/26 15:28:20 | 000,024,576 | ---- | C] () -- C:\Windows\shortcut.exe
    [2005/08/26 15:27:58 | 000,045,056 | ---- | C] () -- C:\Windows\devenum.exe
    [2004/06/12 14:55:32 | 000,274,432 | ---- | C] () -- C:\Windows\SysWow64\LAME_ENC.DLL
    [2004/06/12 14:55:32 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\LameEncShim.dll
    [2002/09/17 23:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe
    [1995/09/26 23:00:00 | 000,107,008 | ---- | C] () -- C:\Windows\SysWow64\TTEMB32.DLL
    [1995/09/26 23:00:00 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OPENENU.DLL
    [1995/09/26 23:00:00 | 000,006,352 | ---- | C] () -- C:\Windows\SysWow64\VISXUTIL.DLL
    [1995/09/26 23:00:00 | 000,002,041 | ---- | C] () -- C:\Windows\MSFNTMAP.INI
    [1995/09/26 23:00:00 | 000,000,586 | ---- | C] () -- C:\Windows\MSTXTCNV.INI
    [1995/09/26 23:00:00 | 000,000,280 | ---- | C] () -- C:\Windows\TTEMBED.INI

    ========== LOP Check ==========

    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Genie-Soft
    [2011/10/12 21:47:08 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ProcessLasso
    [2011/10/13 10:00:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\WinPatrol
    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Genie-Soft
    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Genie-Soft
    [2011/02/09 11:54:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\04AF0FFB-A69D-4A45-86C8-58ECAACE4096
    [2010/11/18 20:25:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Aaron Stewart
    [2010/07/21 10:09:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\abelhadigital.com
    [2011/10/06 18:33:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Abine
    [2011/09/07 20:42:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Acronis
    [2010/12/31 20:31:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\adma
    [2010/08/13 16:12:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\albumart
    [2011/10/24 09:48:47 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Amazon
    [2011/09/16 13:35:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Animal Software
    [2011/11/26 21:40:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\AnvSoft
    [2011/11/04 09:54:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Apowersoft
    [2010/08/31 08:31:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ArcticLine
    [2010/08/09 10:04:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ashampoo
    [2011/11/27 21:14:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ashampoo Slideshow Studio Elements
    [2012/01/05 00:33:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Audacity
    [2010/10/21 20:40:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Auslogics
    [2010/08/13 16:14:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\AV Soft
    [2011/02/05 18:21:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Avery
    [2011/06/18 10:30:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Babylon
    [2010/10/20 15:00:31 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Balabolka
    [2011/11/30 17:17:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\BDlot
    [2010/09/15 15:30:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\BioniX Wallpaper
    [2011/09/28 09:53:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bitmeter2
    [2011/11/30 14:19:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Blueberry
    [2010/11/12 11:48:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bluefive software
    [2010/07/18 14:08:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bullzip
    [2011/09/02 13:45:50 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\calibre
    [2011/12/28 16:22:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Canneverbe Limited
    [2011/09/15 20:05:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ChemTable Software
    [2011/06/14 09:23:21 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Clone2Go Audio Converter Free Version
    [2010/11/18 20:53:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\CometPlayer
    [2011/07/27 15:59:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Conversations Network
    [2010/12/03 10:21:04 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\CyberPower Audio Editing Lab
    [2011/05/09 15:25:45 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DeblurMyImage
    [2011/08/08 15:34:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Deskex
    [2011/04/23 09:03:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Digiarty
    [2011/09/07 19:12:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DirectoryListPrintPro
    [2011/10/21 16:48:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DirectoryMonitor
    [2012/01/05 00:37:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\driveridentifier
    [2011/11/28 15:34:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoft
    [2011/11/28 15:15:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers
    [2011/02/09 11:54:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\E294DE04-C792-4800-8F77-CC0A5B9E15E7

    To Be Continued in next post
     
  5. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Continued from previous post

    O18:64bit: - Protocol\Handler\belarc - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\gopher - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - File not found
    O21:64bit: - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\Windows\SysNative\stobject.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2010/12/07 16:34:16 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2010/12/07 16:34:17 | 000,000,000 | R--D | M] - D:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2010/02/02 07:05:26 | 000,000,000 | R--D | M] - F:\autorun -- [ NTFS ]
    O32 - AutoRun File - [2011/08/21 14:25:13 | 000,000,000 | R--D | M] - F:\autorun.inf -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\...com [@ = ComFile] -- Reg Error: Key error. File not found


    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
    Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
    Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
    Drivers32: msacm.sl_anet - C:\Windows\SysWow64\SL_ANET.ACM (Sipro Lab Telecom Inc.)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
    Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
    Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
    Drivers32: VIDC.MP42 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
    Drivers32: VIDC.MPG4 - C:\Windows\SysWow64\mpg4c32.dll (Microsoft Corporation)
    Drivers32: vidc.tscc - C:\Program Files (x86)\MpcStar\Codecs\tscc\tsccvid.dll (TechSmith Corporation)
    Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
    Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/01/05 09:21:14 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL.exe
    [2012/01/05 00:37:24 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\driveridentifier
    [2012/01/05 00:37:20 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\TempDIR
    [2012/01/05 00:37:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Identifier
    [2012/01/05 00:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver Identifier
    [2012/01/04 23:49:07 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2012/01/04 23:16:27 | 000,000,000 | ---D | C] -- C:\ProgramData\CDRWIN 8
    [2012/01/04 23:13:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 8
    [2012/01/04 23:13:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDRWIN 8
    [2012/01/04 23:06:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
    [2012/01/04 23:04:36 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
    [2012/01/04 23:02:13 | 002,604,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
    [2012/01/04 23:02:12 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
    [2012/01/04 23:02:11 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
    [2012/01/04 23:02:11 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
    [2012/01/04 23:02:11 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
    [2012/01/04 23:02:08 | 000,220,512 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFNHK64.dll
    [2012/01/04 23:02:08 | 000,180,048 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFProc64.dll
    [2012/01/04 23:02:08 | 000,083,792 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFSAPO64.dll
    [2012/01/04 23:02:07 | 000,086,352 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFComm64.dll
    [2012/01/04 23:02:07 | 000,082,768 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFHAPO64.dll
    [2012/01/04 23:02:07 | 000,082,768 | ---- | C] (Sonic Focus, Inc.) -- C:\Windows\SysNative\SFDAPO64.dll
    [2012/01/04 23:02:07 | 000,081,248 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFCOM64.dll
    [2012/01/04 23:02:07 | 000,078,176 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFAPO64.dll
    [2012/01/04 23:02:07 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
    [2012/01/04 23:02:00 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
    [2012/01/04 23:02:00 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
    [2012/01/04 23:02:00 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
    [2012/01/04 23:01:59 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
    [2012/01/04 23:01:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
    [2012/01/04 23:01:58 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
    [2012/01/04 23:01:50 | 002,132,824 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
    [2012/01/04 23:01:49 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
    [2012/01/04 23:01:39 | 002,085,440 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
    [2012/01/04 22:23:03 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/01/04 19:14:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/01/04 19:14:41 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/01/04 19:14:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/01/04 19:14:28 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/01/04 19:12:19 | 004,370,643 | R--- | C] (Swearware) -- C:\Users\Frank\Desktop\ComboFix.exe
    [2012/01/03 23:41:49 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Get from YouTube
    [2012/01/03 23:00:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd
    [2012/01/03 22:58:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logishrd
    [2012/01/03 22:58:49 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
    [2012/01/03 22:55:17 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
    [2012/01/03 22:55:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
    [2012/01/03 22:54:43 | 000,000,000 | ---D | C] -- C:\Intel
    [2012/01/02 11:22:19 | 000,027,968 | ---- | C] (COMODO Security Solutions Inc.) -- C:\Windows\SysNative\cpmnat.exe
    [2012/01/02 10:52:32 | 000,205,512 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\cumon.sys
    [2012/01/02 10:52:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
    [2012/01/02 10:32:09 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO Programs Manager
    [2012/01/01 20:13:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegShot Reverter
    [2012/01/01 20:10:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegShot
    [2012/01/01 19:09:54 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cleanse Uninstaller Pro
    [2012/01/01 19:09:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cleanse Uninstaller Pro
    [2012/01/01 18:46:01 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\iWisoft Free Video Converter
    [2011/12/31 20:09:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    [2011/12/31 20:08:30 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
    [2011/12/30 20:13:22 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\SpeedMP3Downloader
    [2011/12/30 20:13:22 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedMP3Downloader
    [2011/12/30 20:13:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speed MP3 Downloader
    [2011/12/30 20:13:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedMP3Downloader
    [2011/12/30 12:07:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WhatIsHang
    [2011/12/29 20:13:07 | 000,000,000 | ---D | C] -- C:\WINSSLog
    [2011/12/29 20:01:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
    [2011/12/29 19:28:19 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\PicaJet.Com
    [2011/12/28 20:28:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDFill
    [2011/12/28 19:54:31 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\PDF2Text Output
    [2011/12/28 19:54:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Simpo PDF to Text
    [2011/12/28 19:54:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Simpo PDF to Text
    [2011/12/28 16:22:06 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Canneverbe Limited
    [2011/12/28 16:22:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
    [2011/12/28 16:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDBurnerXP
    [2011/12/28 13:56:05 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\net.watype.puzzle.jigsawlite.59CF40312C069B2E5F3F9C70D453B8E2C77D2E60.1
    [2011/12/28 13:51:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puzzle.watype.net
    [2011/12/28 13:51:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\puzzle.watype.net
    [2011/12/28 13:15:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
    [2011/12/28 13:11:03 | 000,000,000 | ---D | C] -- C:\MATS
    [2011/12/27 12:00:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Goland
    [2011/12/27 12:00:43 | 000,000,000 | ---D | C] -- C:\AudioDVDCreator_Temp
    [2011/12/27 11:38:57 | 000,054,816 | ---- | C] (VSO Software) -- C:\Windows\SysNative\drivers\pcouffin64a.sys
    [2011/12/27 11:38:57 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\PcSetup
    [2011/12/27 08:28:44 | 000,000,000 | ---D | C] -- C:\d09372842ffb891599
    [2011/12/26 22:54:17 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\StarBurn
    [2011/12/26 22:54:17 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\StarBurn
    [2011/12/26 22:51:43 | 000,118,888 | ---- | C] (Rocket Division Software) -- C:\Windows\SysNative\drivers\StarPortLite.sys
    [2011/12/26 19:48:59 | 000,000,000 | ---D | C] -- C:\Program Files\Advanced Tokens Manager
    [2011/12/26 11:08:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BootSnooze
    [2011/12/26 10:53:16 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\Freemake
    [2011/12/25 13:48:42 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
    [2011/12/25 13:43:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2011/12/25 12:01:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
    [2011/12/25 11:57:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
    [2011/12/25 11:57:22 | 000,000,000 | ---D | C] -- C:\Program Files\Classic Shell
    [2011/12/25 11:44:46 | 000,000,000 | ---D | C] -- C:\Users\Frank\Application Data\Microsoft\Internet Explorer\Quick Launch\Q
    [2011/12/25 11:27:21 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Talk
    [2011/12/25 11:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Talk
    [2011/12/25 11:19:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3
    [2011/12/25 10:35:08 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\{8FCCB8D5-EA74-4EC1-885C-70F979C4866D}
    [2011/12/23 14:33:04 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\X-Setup Pro
    [2011/12/23 14:33:03 | 000,000,000 | ---D | C] -- C:\ProgramData\X-Setup Pro
    [2011/12/22 13:07:21 | 000,634,512 | ---- | C] (Gianpaolo Bottin) -- C:\Windows\gPhotoShow.scr
    [2011/12/22 13:07:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gPhotoShow
    [2011/12/22 13:07:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gPhotoShow
    [2011/12/22 12:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro
    [2011/12/22 10:06:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Password Security Scanner
    [2011/12/22 10:06:11 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Password Security Scanner
    [2011/12/21 14:22:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com Windows Repair (All in One)
    [2011/12/21 13:32:08 | 000,000,000 | ---D | C] -- C:\ProgramData\backup
    [2011/12/21 13:30:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon Backup & Recoveryâ„¢ 2012 Free
    [2011/12/20 15:34:50 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
    [2011/12/20 15:34:49 | 000,000,000 | ---D | C] -- C:\Program Files\Image Composite Editor
    [2011/12/20 14:50:17 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\3D-Album
    [2011/12/20 14:50:16 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\visviva
    [2011/12/20 14:50:16 | 000,000,000 | ---D | C] -- C:\Windows\Temporary Internet Files
    [2011/12/20 14:29:43 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\Wondershare DVD Slideshow Builder Standard
    [2011/12/20 14:26:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare DVD Slideshow Builder Standard
    [2011/12/20 13:51:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UBCD4Win
    [2011/12/19 22:15:19 | 024,334,368 | ---- | C] (Amazon.com) -- C:\Windows\SysWow64\temp_%1%2
    [2011/12/19 19:59:39 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\Tipard Studio
    [2011/12/19 15:08:41 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Tipard Studio
    [2011/12/19 15:08:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tipard
    [2011/12/19 15:08:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Tipard Studio
    [2011/12/19 15:08:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tipard DVD Creator
    [2011/12/19 13:15:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Identity Finder
    [2011/12/19 13:14:02 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Identity Finder
    [2011/12/19 13:11:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Identity Finder
    [2011/12/19 13:11:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Identity Finder 5
    [2011/12/19 12:37:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JetBoost
    [2011/12/19 12:37:07 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueSprig
    [2011/12/19 12:37:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JetBoost
    [2011/12/18 14:55:10 | 000,544,768 | ---- | C] (Stardock Corporation) -- C:\Windows\SysWow64\wbocx.ocx
    [2011/12/18 14:55:09 | 000,056,496 | ---- | C] (Stardock.Net, Inc) -- C:\Windows\SysWow64\wbhelp2.dll
    [2011/12/18 14:55:09 | 000,033,968 | ---- | C] (Neil Banfield) -- C:\Windows\SysWow64\anim.dll
    [2011/12/18 14:49:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    [2011/12/18 14:09:26 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Windows Live
    [2011/12/18 14:09:00 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\{D5EBF2B8-5564-42B7-B1F5-B96892272E3C}
    [2011/12/18 10:15:49 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Wokhan
    [2011/12/18 10:13:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Firewall Notifier
    [2011/12/17 15:05:10 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\REAPER
    [2011/12/17 12:10:28 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Power Sound Editor Free
    [2011/12/17 12:10:20 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Power Sound Editor Free
    [2011/12/17 12:10:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Power Sound Editor Free
    [2011/12/15 17:04:49 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ArcSoft
    [2011/12/15 16:12:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    [2011/12/15 16:12:27 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2011/12/15 11:51:03 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek Equalizer
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\VST3
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\MTexturedStyles
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\ProgramData\MTexturedStyles
    [2011/12/15 11:34:01 | 000,000,000 | ---D | C] -- C:\Program Files\MeldaProduction
    [2011/12/14 19:54:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRS Labs
    [2011/12/14 19:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\SRS HD Audio Lab
    [2011/12/14 17:39:45 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\ArcSoft
    [2011/12/14 13:43:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ArcSoft Perfect365
    [2011/12/14 12:56:01 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\WindowSlider
    [2011/12/14 12:55:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindowSlider
    [2011/12/14 11:36:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\RBSoft
    [2011/12/14 11:34:25 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Right Click Enhancer
    [2011/12/13 11:01:00 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\DiskBoss Pro
    [2011/12/13 11:00:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskBoss Pro
    [2011/12/13 11:00:45 | 000,000,000 | ---D | C] -- C:\Program Files\DiskBoss Pro
    [2011/12/12 09:36:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
    [2011/12/12 09:33:57 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\GomPlayer
    [2011/12/12 09:33:56 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\GRETECH
    [2011/12/12 09:27:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
    [2011/12/11 11:40:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    [2011/12/11 10:40:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 3
    [2011/12/11 10:35:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Advanced SystemCare 5
    [2011/12/10 23:08:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Engelmann Media VideoMizer.del
    [2011/12/09 10:59:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\USB Log View
    [2011/12/07 21:56:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\soft Xpansion
    [2011/12/07 21:56:16 | 000,000,000 | ---D | C] -- C:\ProgramData\soft Xpansion
    [2011/12/06 12:34:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rename Master 2.9.5
    [2011/10/06 15:34:11 | 000,018,944 | ---- | C] ( ) -- C:\Windows\SysWow64\Implode.dll
    [2011/07/03 18:48:42 | 000,147,456 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
    [2010/02/03 20:00:00 | 000,139,264 | ---- | C] ( ) -- C:\Windows\sipr3260.dll
    [4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [168 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
    [1 C:\Users\Frank\Desktop\*.tmp files -> C:\Users\Frank\Desktop\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/01/05 09:22:59 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA(243).DAT
    [2012/01/05 09:22:55 | 000,018,736 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/01/05 09:22:55 | 000,018,736 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/01/05 09:21:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL.exe
    [2012/01/05 09:17:24 | 000,000,031 | ---- | M] () -- C:\Windows\SysNative\bbcap.err
    [2012/01/05 09:17:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/01/05 09:17:14 | 3018,661,888 | -HS- | M] () -- C:\hiberfil.sys
    [2012/01/05 01:05:10 | 000,064,276 | ---- | M] () -- C:\Windows\CUAppUsage.Dat
    [2012/01/05 00:37:18 | 000,001,076 | ---- | M] () -- C:\Users\Public\Desktop\Driver Identifier.lnk
    [2012/01/04 23:33:55 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/01/04 23:13:20 | 000,000,892 | ---- | M] () -- C:\Users\Public\Desktop\CDRWIN 8.lnk
    [2012/01/04 21:28:25 | 000,016,907 | ---- | M] () -- C:\Users\Frank\Desktop\Worst Shoes for Your Feet.pdf
    [2012/01/04 21:27:01 | 000,012,981 | ---- | M] () -- C:\Users\Frank\Documents\Worst Shoes for Your Feet - WebMD.pdf
    [2012/01/04 20:05:34 | 001,008,141 | ---- | M] () -- C:\Users\Frank\Desktop\rkill.exe
    [2012/01/04 19:12:21 | 004,370,643 | R--- | M] (Swearware) -- C:\Users\Frank\Desktop\ComboFix.exe
    [2012/01/03 23:02:39 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LHidFilt_01005.Wdf
    [2012/01/03 23:02:38 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LMouFilt_01005.Wdf
    [2012/01/03 23:01:40 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
    [2012/01/02 10:35:56 | 629,145,600 | -H-- | M] () -- C:\fileimage.dat
    [2012/01/01 16:54:35 | 000,791,056 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/01/01 16:54:35 | 000,671,612 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/01/01 16:54:35 | 000,126,558 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/01/01 16:54:29 | 000,791,056 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2011/12/31 21:13:47 | 000,001,057 | ---- | M] () -- C:\Users\Frank\Application Data\Microsoft\Internet Explorer\Quick Launch\Waterfox.lnk
    [2011/12/29 22:23:26 | 000,037,888 | ---- | M] () -- C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/12/29 13:38:50 | 000,000,020 | ---- | M] () -- C:\Windows\¼Ã´4
    [2011/12/28 22:06:22 | 000,047,676 | ---- | M] () -- C:\Users\Frank\Documents\OC Foundation Hoarding Website.pdf
    [2011/12/28 22:03:31 | 000,000,162 | -H-- | M] () -- C:\Users\Frank\Documents\~$arding Survey.pdf
    [2011/12/28 21:03:27 | 031,137,792 | ---- | M] () -- C:\Users\Frank\Documents\New catalog.ccd
    [2011/12/28 20:30:20 | 000,002,998 | ---- | M] () -- C:\Users\Frank\Documents\Passwords.pdb
    [2011/12/28 20:08:56 | 000,003,298 | ---- | M] () -- C:\Windows\SysWow64\StyleVista.png
    [2011/12/28 20:08:56 | 000,003,137 | ---- | M] () -- C:\Windows\SysWow64\StyleVistaDown.png
    [2011/12/27 11:39:57 | 000,000,000 | ---- | M] () -- C:\Windows\AudioDVD.INI
    [2011/12/27 11:38:57 | 000,054,816 | ---- | M] (VSO Software) -- C:\Windows\SysNative\drivers\pcouffin64a.sys
    [2011/12/26 22:53:06 | 000,867,824 | ---- | M] () -- C:\Windows\SysNative\drivers\sptd.sys
    [2011/12/26 10:04:26 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/12/26 10:04:26 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/12/26 10:04:26 | 000,000,448 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
    [2011/12/23 11:31:50 | 000,118,888 | ---- | M] (Rocket Division Software) -- C:\Windows\SysNative\drivers\StarPortLite.sys
    [2011/12/22 11:55:27 | 013,893,632 | ---- | M] () -- C:\Users\Frank\ntuser.bak
    [2011/12/19 22:44:56 | 024,334,368 | ---- | M] (Amazon.com) -- C:\Windows\SysWow64\temp_%1%2
    [2011/12/18 15:41:05 | 000,000,676 | ---- | M] () -- C:\chksize.cmd
    [2011/12/18 15:32:41 | 000,000,551 | ---- | M] () -- C:\chksize.cmd.hold
    [2011/12/18 15:00:14 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\_WKERNEL.FRE
    [2011/12/16 13:07:40 | 000,000,230 | RH-- | M] () -- C:\Program Files (x86)\Mozilla Firefoxinstall.xml
    [2011/12/15 11:34:01 | 000,197,014 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MAnalyzerpresets.xml
    [2011/12/15 11:34:01 | 000,013,964 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MFlangerpresets.xml
    [2011/12/15 11:34:01 | 000,013,158 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MOscillatorpresets.xml
    [2011/12/15 11:34:01 | 000,009,119 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MFreqShifterpresets.xml
    [2011/12/15 11:34:01 | 000,007,130 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MEqualizerpresets.xml
    [2011/12/15 11:34:01 | 000,006,687 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\menvelopepresets.xml
    [2011/12/15 11:34:01 | 000,006,444 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MCompressorpresets.xml
    [2011/12/15 11:34:01 | 000,005,622 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MNoiseGeneratorpresets.xml
    [2011/12/15 11:34:01 | 000,005,138 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MWaveShaperpresets.xml
    [2011/12/15 11:34:01 | 000,004,362 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MPhaserpresets.xml
    [2011/12/15 11:34:01 | 000,003,771 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MRingModulatorpresets.xml
    [2011/12/15 11:34:01 | 000,002,820 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MEqualizerAreasEditorpresets.xml
    [2011/12/15 11:34:01 | 000,002,775 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MStereoExpanderpresets.xml
    [2011/12/15 11:34:01 | 000,002,666 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MVibratopresets.xml
    [2011/12/15 11:34:01 | 000,002,492 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MSpectralAnalyzerPrefilterpresets.xml
    [2011/12/15 11:34:01 | 000,002,366 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MTremolopresets.xml
    [2011/12/15 11:34:01 | 000,001,907 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MAutopanpresets.xml
    [2011/12/15 11:34:01 | 000,001,381 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MLimiterpresets.xml
    [2011/12/15 11:34:01 | 000,001,235 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\mbasestyleconfigurationpresets.xml
    [2011/12/15 11:34:01 | 000,001,011 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\MValueToColor5presets.xml
    [2011/12/14 11:34:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\URL Parts Error
    [2011/12/14 11:34:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\OK
    [2011/12/13 11:01:00 | 000,000,105 | -HS- | M] () -- C:\Users\Frank\AppData\Local\00000021
    [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2011/12/09 12:15:03 | 000,308,003 | ---- | M] () -- C:\Users\Frank\Desktop\HP MS225 System Informaiton.pdf
    [2011/12/09 12:14:08 | 000,106,486 | ---- | M] () -- C:\Users\Frank\Documents\System Information.html
    [2011/12/09 12:13:32 | 000,027,059 | ---- | M] () -- C:\Users\Frank\Documents\Hardware Diagnostic Tools System Information Profiler.html
    [2011/12/07 21:56:23 | 000,008,608 | ---- | M] () -- C:\Windows\SysWow64\sx_p2d.tlb
    [4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [168 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
    [1 C:\Users\Frank\Desktop\*.tmp files -> C:\Users\Frank\Desktop\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/01/05 00:37:18 | 000,001,076 | ---- | C] () -- C:\Users\Public\Desktop\Driver Identifier.lnk
    [2012/01/04 23:13:20 | 000,000,892 | ---- | C] () -- C:\Users\Public\Desktop\CDRWIN 8.lnk
    [2012/01/04 21:28:25 | 000,016,907 | ---- | C] () -- C:\Users\Frank\Desktop\Worst Shoes for Your Feet.pdf
    [2012/01/04 21:27:01 | 000,012,981 | ---- | C] () -- C:\Users\Frank\Documents\Worst Shoes for Your Feet - WebMD.pdf
    [2012/01/04 20:04:50 | 001,008,141 | ---- | C] () -- C:\Users\Frank\Desktop\rkill.exe
    [2012/01/04 19:14:41 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/01/04 19:14:41 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/01/04 19:14:41 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/01/04 19:14:41 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/01/04 19:14:41 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/01/03 23:02:39 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LHidFilt_01005.Wdf
    [2012/01/03 23:02:38 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LMouFilt_01005.Wdf
    [2012/01/03 23:01:40 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
    [2012/01/03 11:12:09 | 000,001,805 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ax.lnk
    [2012/01/03 11:12:09 | 000,001,125 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QuickMonth Calendar.lnk
    [2012/01/03 11:12:09 | 000,001,033 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PopTray.lnk
    [2012/01/02 10:52:30 | 000,019,568 | ---- | C] () -- C:\Windows\SysNative\drivers\evdd.sys
    [2012/01/02 10:50:18 | 000,064,276 | ---- | C] () -- C:\Windows\CUAppUsage.Dat
    [2012/01/02 10:35:56 | 629,145,600 | -H-- | C] () -- C:\fileimage.dat
    [2011/12/31 21:13:47 | 000,001,057 | ---- | C] () -- C:\Users\Frank\Application Data\Microsoft\Internet Explorer\Quick Launch\Waterfox.lnk
    [2011/12/31 20:14:04 | 000,000,848 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox.lnk
    [2011/12/29 13:38:48 | 000,000,020 | ---- | C] () -- C:\Windows\¼Ã´4
    [2011/12/28 22:06:19 | 000,047,676 | ---- | C] () -- C:\Users\Frank\Documents\OC Foundation Hoarding Website.pdf
    [2011/12/28 22:03:31 | 000,000,162 | -H-- | C] () -- C:\Users\Frank\Documents\~$arding Survey.pdf
    [2011/12/28 16:21:58 | 000,001,867 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
    [2011/12/27 11:39:57 | 000,000,000 | ---- | C] () -- C:\Windows\AudioDVD.INI
    [2011/12/26 22:53:05 | 000,867,824 | ---- | C] () -- C:\Windows\SysNative\drivers\sptd.sys
    [2011/12/18 15:41:05 | 000,000,676 | ---- | C] () -- C:\chksize.cmd
    [2011/12/18 14:55:22 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\_WKERNEL.FRE
    [2011/12/18 14:55:09 | 000,000,439 | ---- | C] () -- C:\Windows\SysWow64\shfolder.inf
    [2011/12/16 13:07:40 | 000,000,230 | RH-- | C] () -- C:\Program Files (x86)\Mozilla Firefoxinstall.xml
    [2011/12/15 11:34:01 | 000,197,014 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MAnalyzerpresets.xml
    [2011/12/15 11:34:01 | 000,013,964 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MFlangerpresets.xml
    [2011/12/15 11:34:01 | 000,013,158 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MOscillatorpresets.xml
    [2011/12/15 11:34:01 | 000,009,119 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MFreqShifterpresets.xml
    [2011/12/15 11:34:01 | 000,007,130 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MEqualizerpresets.xml
    [2011/12/15 11:34:01 | 000,006,687 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\menvelopepresets.xml
    [2011/12/15 11:34:01 | 000,006,444 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MCompressorpresets.xml
    [2011/12/15 11:34:01 | 000,005,622 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MNoiseGeneratorpresets.xml
    [2011/12/15 11:34:01 | 000,005,138 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MWaveShaperpresets.xml
    [2011/12/15 11:34:01 | 000,004,362 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MPhaserpresets.xml
    [2011/12/15 11:34:01 | 000,003,771 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MRingModulatorpresets.xml
    [2011/12/15 11:34:01 | 000,002,820 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MEqualizerAreasEditorpresets.xml
    [2011/12/15 11:34:01 | 000,002,775 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MStereoExpanderpresets.xml
    [2011/12/15 11:34:01 | 000,002,666 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MVibratopresets.xml
    [2011/12/15 11:34:01 | 000,002,492 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MSpectralAnalyzerPrefilterpresets.xml
    [2011/12/15 11:34:01 | 000,002,366 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MTremolopresets.xml
    [2011/12/15 11:34:01 | 000,001,907 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MAutopanpresets.xml
    [2011/12/15 11:34:01 | 000,001,381 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MLimiterpresets.xml
    [2011/12/15 11:34:01 | 000,001,235 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\mbasestyleconfigurationpresets.xml
    [2011/12/15 11:34:01 | 000,001,011 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\MValueToColor5presets.xml
    [2011/12/13 11:01:00 | 000,000,105 | -HS- | C] () -- C:\Users\Frank\AppData\Local\00000021
    [2011/12/09 12:15:02 | 000,308,003 | ---- | C] () -- C:\Users\Frank\Desktop\HP MS225 System Informaiton.pdf
    [2011/12/09 12:14:08 | 000,106,486 | ---- | C] () -- C:\Users\Frank\Documents\System Information.html
    [2011/12/09 12:13:31 | 000,027,059 | ---- | C] () -- C:\Users\Frank\Documents\Hardware Diagnostic Tools System Information Profiler.html
    [2011/12/07 21:56:23 | 000,008,608 | ---- | C] () -- C:\Windows\SysWow64\sx_p2d.tlb
    [2011/11/22 20:42:59 | 000,000,054 | ---- | C] () -- C:\Windows\Player.INI
    [2011/11/21 18:02:16 | 000,034,936 | ---- | C] () -- C:\Windows\SysWow64\uninstHelixYUV.exe
    [2011/11/16 10:03:52 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cd.dat
    [2011/11/04 09:54:42 | 000,065,536 | -H-- | C] () -- C:\Windows\SysWow64\WebCamLib.dll
    [2011/10/06 15:34:20 | 000,204,848 | ---- | C] () -- C:\Windows\SysWow64\gswin32c.exe
    [2011/10/06 15:34:12 | 000,054,272 | ---- | C] () -- C:\Windows\SysWow64\P2irdao.dll
    [2011/10/06 15:34:12 | 000,050,176 | ---- | C] () -- C:\Windows\SysWow64\P2ctdao.dll
    [2011/10/06 15:34:11 | 000,748,160 | ---- | C] () -- C:\Windows\SysWow64\Co2c40en.dll
    [2011/10/04 10:57:40 | 011,165,696 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\Sandra.mdb
    [2011/09/22 12:08:56 | 003,902,976 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
    [2011/09/15 09:58:10 | 000,091,136 | ---- | C] () -- C:\Windows\SendToClip.exe
    [2011/09/11 09:26:18 | 000,000,292 | ---- | C] () -- C:\Users\Frank\AppData\Local\HamsterBookConverter.cfg
    [2011/09/08 19:49:01 | 000,000,548 | ---- | C] () -- C:\Program Files\Add_Restart_Explorer_Option.reg
    [2011/09/08 19:49:01 | 000,000,448 | ---- | C] () -- C:\Program Files\Restart_Explorer.bat
    [2011/08/31 13:29:00 | 004,023,808 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
    [2011/08/30 14:17:19 | 000,001,035 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2011/08/22 14:07:48 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
    [2011/08/22 14:07:02 | 000,158,208 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
    [2011/08/22 14:07:00 | 000,259,584 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
    [2011/08/22 14:06:30 | 001,524,224 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
    [2011/08/22 14:06:30 | 000,211,456 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
    [2011/08/22 14:06:30 | 000,097,280 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
    [2011/08/22 14:06:28 | 000,327,680 | ---- | C] () -- C:\Windows\SysWow64\ff_libfaad2.dll
    [2011/08/22 14:06:28 | 000,113,664 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
    [2011/08/22 14:06:26 | 000,145,920 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
    [2011/08/22 14:06:26 | 000,136,704 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
    [2011/07/28 18:24:42 | 000,156,160 | ---- | C] () -- C:\Windows\SysWow64\WS_ContextMenu.dll
    [2011/07/22 17:16:26 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\HPPLVS.dll
    [2011/07/17 22:54:02 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
    [2011/07/14 21:00:57 | 000,000,167 | ---- | C] () -- C:\Windows\topocr.INI
    [2011/07/06 13:21:42 | 000,311,296 | ---- | C] () -- C:\Windows\SysWow64\EMRegSys.dll
    [2011/06/01 19:05:51 | 000,000,000 | ---- | C] () -- C:\Windows\QuickInstall.INI
    [2011/05/30 09:49:08 | 000,000,525 | ---- | C] () -- C:\Users\Frank\AppData\Local\UserProducts.xml
    [2011/05/30 08:42:50 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2011/05/23 02:46:30 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2011/05/06 11:40:48 | 000,000,063 | -H-- | C] () -- C:\ProgramData\Ts_infos.ini
    [2011/04/29 12:36:29 | 000,000,354 | ---- | C] () -- C:\Windows\Ripper.INI
    [2011/04/28 19:05:28 | 000,164,112 | ---- | C] () -- C:\Windows\SysWow64\awmpi.dll
    [2011/04/28 15:54:16 | 000,016,096 | ---- | C] () -- C:\Users\Frank\AppData\Local\Schedule8.dat
    [2011/04/07 09:13:26 | 002,340,992 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
    [2011/04/07 09:13:26 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
    [2011/04/07 09:13:26 | 000,018,048 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
    [2011/04/07 09:13:26 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
    [2011/04/07 09:13:26 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
    [2011/03/03 06:40:08 | 000,150,528 | ---- | C] () -- C:\Windows\SysWow64\mkx.dll
    [2011/03/03 06:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\SysWow64\avi.dll
    [2011/03/03 06:39:46 | 000,141,824 | ---- | C] () -- C:\Windows\SysWow64\mp4.dll
    [2011/03/03 06:39:34 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\ogm.dll
    [2011/03/03 06:39:02 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\dsmux.exe
    [2011/03/03 06:38:54 | 000,154,112 | ---- | C] () -- C:\Windows\SysWow64\ts.dll
    [2011/03/03 06:38:40 | 000,249,856 | ---- | C] () -- C:\Windows\SysWow64\dxr.dll
    [2011/03/03 06:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\SysWow64\avs.dll
    [2011/03/03 06:38:04 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\mkv2vfr.exe
    [2011/03/03 06:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\avss.dll
    [2011/03/03 06:37:40 | 000,358,400 | ---- | C] () -- C:\Windows\SysWow64\gdsmux.exe
    [2011/03/03 06:35:32 | 000,080,384 | ---- | C] () -- C:\Windows\SysWow64\mkzlib.dll
    [2011/03/03 06:35:26 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\mkunicode.dll
    [2011/02/26 18:43:59 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
    [2011/02/26 18:29:09 | 000,000,059 | ---- | C] () -- C:\Windows\wpd99.drv
    [2011/02/26 18:29:08 | 000,047,616 | ---- | C] () -- C:\Windows\SysWow64\pdf995mon64.dll
    [2011/02/18 09:14:01 | 000,296,980 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
    [2011/02/09 23:03:48 | 000,000,326 | ---- | C] () -- C:\Windows\primopdf.ini
    [2011/02/09 19:54:58 | 003,973,120 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg2.exe
    [2011/01/27 17:06:52 | 000,791,056 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2011/01/18 10:28:23 | 000,014,336 | ---- | C] () -- C:\Windows\SysWow64\vsmon1.dll
    [2011/01/13 21:54:24 | 000,001,360 | ---- | C] () -- C:\Windows\ntbackup.ini
    [2011/01/10 19:23:42 | 000,000,186 | ---- | C] () -- C:\Windows\SysWow64\CleanMem.ini
    [2011/01/05 18:04:44 | 000,000,032 | ---- | C] () -- C:\Windows\SysWow64\EUOD.DAT
    [2011/01/04 15:33:38 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\RtlCPAPI.dll
    [2011/01/04 15:33:38 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\ChCfg.exe
    [2011/01/04 13:28:18 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010/12/19 16:59:26 | 000,000,029 | ---- | C] () -- C:\Windows\wordpad.ini
    [2010/12/09 21:06:00 | 000,040,963 | ---- | C] () -- C:\Program Files\NirCmd.chm
    [2010/10/29 15:11:12 | 000,017,189 | ---- | C] () -- C:\Windows\OCR.Ini
    [2010/10/23 09:08:51 | 000,153,600 | ---- | C] () -- C:\Windows\SysWow64\WSContextMenu.dll
    [2010/10/20 11:07:33 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
    [2010/10/10 15:49:51 | 000,000,354 | ---- | C] () -- C:\Windows\RMDownloader.INI
    [2010/10/04 12:19:12 | 000,037,888 | ---- | C] () -- C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    To Be Continued in next post
     
  6. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Continued from previous post

    [2010/09/28 19:28:44 | 000,000,055 | ---- | C] () -- C:\Windows\CopyMessageBox.INI
    [2010/09/28 13:00:12 | 000,012,800 | ---- | C] () -- C:\Windows\LPRES.DLL
    [2010/09/11 12:58:15 | 000,075,776 | ---- | C] () -- C:\Windows\cadkasdeinst01e.exe
    [2010/08/18 14:56:38 | 000,000,151 | ---- | C] () -- C:\Windows\SysWow64\Registration.ini
    [2010/07/29 21:49:52 | 000,007,616 | ---- | C] () -- C:\Users\Frank\AppData\Local\resmon.resmoncfg
    [2010/07/29 08:06:00 | 000,110,602 | ---- | C] () -- C:\Windows\SysWow64\xcdsfx32.bin
    [2010/07/28 22:17:52 | 000,000,036 | ---- | C] () -- C:\Users\Frank\AppData\Local\housecall.guid.cache
    [2010/07/28 19:04:23 | 000,000,056 | ---- | C] () -- C:\ProgramData\claude.ini
    [2010/07/24 11:22:58 | 000,153,600 | ---- | C] () -- C:\Windows\SysWow64\AI_ContextMenu.dll
    [2010/07/21 12:52:51 | 000,000,057 | ---- | C] () -- C:\Windows\cdrLabel.ini
    [2010/07/21 10:51:59 | 000,454,656 | ---- | C] () -- C:\Windows\SysWow64\PaintX.dll
    [2010/07/21 10:51:59 | 000,094,208 | ---- | C] () -- C:\Windows\SysWow64\vbpng.dll
    [2010/07/21 10:51:59 | 000,072,192 | ---- | C] () -- C:\Windows\SysWow64\zlib.dll
    [2010/07/21 10:31:47 | 000,017,116 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\AllChars.xml
    [2010/07/21 10:31:47 | 000,016,555 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\AllChars-example.xml
    [2010/07/20 16:23:01 | 000,000,035 | ---- | C] () -- C:\Windows\Ulead32.INI
    [2010/07/20 15:32:40 | 000,285,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\Onsio.sys
    [2010/07/20 15:32:40 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\drivers\Onsreged.sys
    [2010/07/19 17:59:21 | 000,039,424 | ---- | C] () -- C:\Windows\SysWow64\rpiAccessProcess.dll
    [2010/07/18 21:33:22 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\VegaShEx.dll
    [2010/07/18 21:33:17 | 000,308,224 | ---- | C] () -- C:\Windows\SysWow64\Lffpx7.dll
    [2010/07/18 17:21:16 | 000,000,008 | RHS- | C] () -- C:\ProgramData\7C18212ACF.sys
    [2010/07/18 17:21:15 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
    [2010/07/18 17:02:41 | 000,157,696 | ---- | C] () -- C:\Windows\SysWow64\OggEnc.exe
    [2010/07/18 17:02:41 | 000,145,408 | ---- | C] () -- C:\Windows\SysWow64\Lame.exe
    [2010/07/18 17:02:41 | 000,076,800 | ---- | C] () -- C:\Windows\SysWow64\Faac.exe
    [2010/07/18 11:38:51 | 000,000,510 | ---- | C] () -- C:\Windows\ODBC.INI
    [2010/07/18 11:31:50 | 000,001,103 | ---- | C] () -- C:\Windows\ODBCINST.INI
    [2010/01/27 13:35:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2009/08/11 16:21:26 | 000,087,552 | ---- | C] () -- C:\Windows\SysWow64\ac3config.exe
    [2009/08/11 16:21:20 | 001,021,440 | ---- | C] () -- C:\Windows\SysWow64\ac3filter_intl.dll
    [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat(213).dat
    [2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2008/01/14 17:47:06 | 000,099,712 | ---- | C] () -- C:\Windows\HPBroker.dll
    [2007/04/27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
    [2007/02/05 16:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
    [2006/03/03 23:52:00 | 000,088,576 | ---- | C] () -- C:\Windows\SysWow64\OptimFROG.dll
    [2006/01/08 08:53:24 | 000,005,120 | ---- | C] () -- C:\Windows\SysWow64\hash2.dll
    [2005/08/26 15:28:34 | 000,143,360 | ---- | C] () -- C:\Windows\unzip.exe
    [2005/08/26 15:28:20 | 000,024,576 | ---- | C] () -- C:\Windows\shortcut.exe
    [2005/08/26 15:27:58 | 000,045,056 | ---- | C] () -- C:\Windows\devenum.exe
    [2004/06/12 14:55:32 | 000,274,432 | ---- | C] () -- C:\Windows\SysWow64\LAME_ENC.DLL
    [2004/06/12 14:55:32 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\LameEncShim.dll
    [2002/09/17 23:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe
    [1995/09/26 23:00:00 | 000,107,008 | ---- | C] () -- C:\Windows\SysWow64\TTEMB32.DLL
    [1995/09/26 23:00:00 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OPENENU.DLL
    [1995/09/26 23:00:00 | 000,006,352 | ---- | C] () -- C:\Windows\SysWow64\VISXUTIL.DLL
    [1995/09/26 23:00:00 | 000,002,041 | ---- | C] () -- C:\Windows\MSFNTMAP.INI
    [1995/09/26 23:00:00 | 000,000,586 | ---- | C] () -- C:\Windows\MSTXTCNV.INI
    [1995/09/26 23:00:00 | 000,000,280 | ---- | C] () -- C:\Windows\TTEMBED.INI

    ========== LOP Check ==========

    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Genie-Soft
    [2011/10/12 21:47:08 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ProcessLasso
    [2011/10/13 10:00:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\WinPatrol
    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Genie-Soft
    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Genie-Soft
    [2011/02/09 11:54:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\04AF0FFB-A69D-4A45-86C8-58ECAACE4096
    [2010/11/18 20:25:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Aaron Stewart
    [2010/07/21 10:09:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\abelhadigital.com
    [2011/10/06 18:33:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Abine
    [2011/09/07 20:42:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Acronis
    [2010/12/31 20:31:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\adma
    [2010/08/13 16:12:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\albumart
    [2011/10/24 09:48:47 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Amazon
    [2011/09/16 13:35:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Animal Software
    [2011/11/26 21:40:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\AnvSoft
    [2011/11/04 09:54:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Apowersoft
    [2010/08/31 08:31:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ArcticLine
    [2010/08/09 10:04:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ashampoo
    [2011/11/27 21:14:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ashampoo Slideshow Studio Elements
    [2012/01/05 00:33:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Audacity
    [2010/10/21 20:40:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Auslogics
    [2010/08/13 16:14:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\AV Soft
    [2011/02/05 18:21:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Avery
    [2011/06/18 10:30:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Babylon
    [2010/10/20 15:00:31 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Balabolka
    [2011/11/30 17:17:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\BDlot
    [2010/09/15 15:30:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\BioniX Wallpaper
    [2011/09/28 09:53:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bitmeter2
    [2011/11/30 14:19:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Blueberry
    [2010/11/12 11:48:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bluefive software
    [2010/07/18 14:08:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bullzip
    [2011/09/02 13:45:50 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\calibre
    [2011/12/28 16:22:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Canneverbe Limited
    [2011/09/15 20:05:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ChemTable Software
    [2011/06/14 09:23:21 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Clone2Go Audio Converter Free Version
    [2010/11/18 20:53:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\CometPlayer
    [2011/07/27 15:59:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Conversations Network
    [2010/12/03 10:21:04 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\CyberPower Audio Editing Lab
    [2011/05/09 15:25:45 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DeblurMyImage
    [2011/08/08 15:34:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Deskex
    [2011/04/23 09:03:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Digiarty
    [2011/09/07 19:12:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DirectoryListPrintPro
    [2011/10/21 16:48:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DirectoryMonitor
    [2012/01/05 00:37:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\driveridentifier
    [2011/11/28 15:34:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoft
    [2011/11/28 15:15:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers
    [2011/02/09 11:54:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\E294DE04-C792-4800-8F77-CC0A5B9E15E7
    [2011/04/18 15:19:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\EAC
    [2011/08/17 18:45:47 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\EAST Technologies
    [2011/03/15 08:48:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\eComic
    [2011/03/29 20:54:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Engelmann Media
    [2011/01/13 12:47:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ethervane
    [2011/01/18 10:16:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Expert PDF 7
    [2011/11/27 20:49:05 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ffDiaporama
    [2011/03/02 19:55:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FILEminimizerPictures
    [2011/10/23 21:36:46 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FileQuery
    [2011/11/22 21:59:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Foxit Software
    [2011/02/01 21:47:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\freac
    [2010/12/19 19:56:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Free Sound Recorder
    [2011/04/24 17:35:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FreeLanguageTranslator
    [2011/10/18 15:28:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FreeScreenToVideo
    [2011/08/31 09:33:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Frieger
    [2010/11/16 19:04:53 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Genie-Soft
    [2012/01/03 23:41:49 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Get from YouTube
    [2011/11/23 10:17:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\GetRightToGo
    [2011/01/12 12:10:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\gimagereader
    [2011/09/19 11:58:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\GlarySoft
    [2010/08/18 18:12:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\gnupg
    [2010/12/07 15:18:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Godlike
    [2011/05/02 18:05:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Goodsol
    [2011/01/12 12:19:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\gtk-2.0
    [2011/01/31 11:54:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Gyazo
    [2011/02/02 11:21:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HandBrake
    [2010/08/20 13:48:56 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HandyCDRipper
    [2011/09/16 11:06:32 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HotSync
    [2011/10/10 08:57:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Hulubulu
    [2010/10/20 18:33:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Hunspell
    [2011/09/29 14:29:32 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ICE Book Reader Professional
    [2011/08/08 11:25:39 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ImgBurn
    [2011/09/15 10:50:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Inventivio
    [2011/12/11 10:35:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\IObit
    [2011/12/15 10:43:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\IrfanView
    [2011/03/18 10:35:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\iSpring Solutions
    [2010/12/02 13:35:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\JAM Software
    [2011/08/22 12:28:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\JGsoft
    [2010/11/14 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\johnsadventures.com
    [2011/01/19 11:05:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\JPEGsnoop
    [2010/08/16 10:48:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Kana Solution
    [2011/11/05 13:31:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\kingsoft
    [2010/07/20 09:47:52 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\KO Approach Items
    [2011/04/10 10:09:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Leawo
    [2011/08/21 09:06:11 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LibrariIcon
    [2011/10/22 11:48:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LibreOffice
    [2010/12/30 11:18:53 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Lightscape
    [2010/07/28 19:22:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Lingoes
    [2011/08/23 06:29:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Listary
    [2011/08/08 11:10:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LiveBoot
    [2011/01/19 11:14:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LockHunter
    [2011/10/18 13:20:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LogSys
    [2011/10/23 08:59:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mael
    [2011/11/08 21:14:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MAGIX
    [2010/07/18 16:13:21 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MakeitOne
    [2011/12/30 20:47:52 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MediaMonkey
    [2011/07/06 09:54:01 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\mediAvatar
    [2011/05/11 10:06:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\minus
    [2011/07/05 11:12:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mobipocket
    [2011/09/02 16:01:56 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mouse Recorder Pro
    [2010/09/09 17:05:50 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Moyea
    [2011/09/08 10:37:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MP3 Speed
    [2011/12/28 19:49:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mp3tag
    [2011/12/15 11:34:01 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MTexturedStyles
    [2011/11/24 22:22:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MusE
    [2010/08/27 08:40:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Musereo
    [2011/09/20 18:20:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\NCH Swift Sound
    [2011/07/27 06:27:26 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\nemo
    [2011/12/28 13:56:05 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\net.watype.puzzle.jigsawlite.59CF40312C069B2E5F3F9C70D453B8E2C77D2E60.1
    [2010/09/23 09:34:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Notepad++
    [2011/07/19 19:14:28 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nullsoft
    [2011/01/25 15:55:21 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Opera
    [2011/09/23 11:17:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\OverDrive
    [2011/08/09 10:08:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDF
    [2011/01/06 16:22:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDF Experte 7
    [2011/09/12 15:32:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDF Reader
    [2011/10/11 12:55:28 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\pdfforge
    [2011/05/05 14:28:56 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDM
    [2011/06/02 09:17:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PhotoScape
    [2011/12/29 19:28:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PicaJet.Com
    [2011/12/12 15:29:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PotPlayerMini
    [2011/12/17 12:11:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Power Sound Editor Free
    [2011/04/10 10:09:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PPT2DVD
    [2011/10/11 13:00:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PrimoPDF
    [2011/03/29 21:02:05 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Prish
    [2010/07/22 11:18:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Process Hacker 2
    [2011/06/08 08:26:28 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ProcessLasso
    [2010/12/31 20:48:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\qliner
    [2010/12/02 11:25:53 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\QMC
    [2011/11/01 21:20:39 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\QTranslate
    [2011/01/23 14:28:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\QuickScan
    [2011/12/17 15:08:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\REAPER
    [2010/11/22 16:38:40 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Recordpad
    [2011/07/26 18:15:31 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\RegGenie
    [2011/11/07 19:23:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\rockbox.org
    [2011/09/12 13:54:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Roni Music
    [2010/07/21 09:17:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SecurityHeroes
    [2010/10/24 21:36:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ShellFolderFix
    [2011/06/12 18:44:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SlickRun
    [2011/10/06 17:17:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Smart PDF Creator Pro
    [2011/08/08 10:44:44 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Snippage.B28FB424FD6880E47B18D7D649F6CC93BDE9B29B.1
    [2011/07/17 13:45:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Softi Software
    [2011/10/11 12:41:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Softland
    [2012/01/04 19:14:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Software Informer
    [2010/12/31 20:55:02 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Soluto
    [2011/10/22 11:01:31 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Songbird2
    [2012/01/03 23:42:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Sound Editor Deluxe
    [2011/08/14 09:44:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Sound Editor Pro
    [2011/09/15 10:53:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Speak-A-Message
    [2011/12/30 20:13:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SpeedMP3Downloader
    [2011/12/26 22:54:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\StarBurn
    [2011/09/27 10:30:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Stegisoft
    [2011/09/26 12:38:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\StepShot
    [2011/03/19 12:01:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SuperUtils.com
    [2010/07/17 18:57:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SupportSoft
    [2011/09/20 15:47:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\T-App
    [2011/08/09 10:38:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TeamViewer
    [2011/09/13 17:30:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TeraCopy
    [2011/08/22 12:28:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TheSage
    [2010/07/16 21:05:32 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Thunderbird
    [2011/11/18 10:59:49 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\tigerplayer
    [2011/03/29 20:00:44 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TIPP10
    [2010/07/18 15:52:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TreeCardGames
    [2010/12/02 12:06:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TrueCrypt
    [2011/09/13 09:21:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Tweak-7
    [2010/07/29 22:01:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Uniblue
    [2011/06/01 21:50:52 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\uTorrent
    [2010/10/18 17:07:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Video DVD Maker FREE
    [2011/12/20 14:50:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\visviva
    [2011/08/10 14:06:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Volume2
    [2010/12/21 15:30:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\VOS
    [2011/08/18 10:09:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WallpaperSS
    [2011/03/22 09:19:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WaveMax Sound Editor
    [2011/09/22 11:45:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Win7codecs
    [2010/07/17 20:18:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WinBatch
    [2011/12/14 12:56:01 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WindowSlider
    [2010/07/20 15:01:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WinPatrol
    [2011/10/24 12:26:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Wordcycler
    [2011/10/20 11:21:46 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\www.shadowexplorer.com
    [2011/02/24 13:12:26 | 000,000,000 | -HSD | M] -- C:\Users\Frank\AppData\Roaming\wyUpdate AU
    [2011/12/23 14:33:04 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\X-Setup Pro
    [2011/10/10 14:42:40 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\YoWindow
    [2010/12/02 10:46:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Zentimo
    [2011/01/07 11:02:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Zoner
    [2011/10/14 10:53:52 | 000,000,324 | ---- | M] () -- C:\Windows\Tasks\GlaryInitialize.job
    [2011/12/26 10:04:26 | 000,000,448 | ---- | M] () -- C:\Windows\Tasks\PCDRScheduledMaintenance.job
    [2012/01/05 09:22:59 | 000,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA(243).DAT
    [2012/01/05 09:21:57 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU(244).TXT
    [2012/01/05 09:21:57 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < >

    < %SYSTEMDRIVE%\*.* >
    [2011/11/28 21:50:45 | 000,001,024 | ---- | M] () -- C:\.rnd
    [2010/10/05 20:43:38 | 000,003,890 | ---- | M] () -- C:\AddToSendTo.vbs
    [2011/11/11 22:28:02 | 000,003,408 | ---- | M] () -- C:\bootsqm.dat
    [2011/12/18 15:41:05 | 000,000,676 | ---- | M] () -- C:\chksize.cmd
    [2011/12/18 15:32:41 | 000,000,551 | ---- | M] () -- C:\chksize.cmd.hold
    [2011/10/22 18:21:00 | 000,000,370 | ---- | M] () -- C:\chksize.cmd.old
    [2012/01/04 23:45:45 | 000,052,608 | ---- | M] () -- C:\ComboFix.txt
    [2012/01/02 10:35:56 | 629,145,600 | -H-- | M] () -- C:\fileimage.dat
    [2011/12/09 11:39:56 | 000,001,875 | ---- | M] () -- C:\FINIS_IT.TXT
    [2012/01/05 09:17:14 | 3018,661,888 | -HS- | M] () -- C:\hiberfil.sys
    [2011/09/16 10:25:06 | 004,918,812 | ---- | M] () -- C:\HuskyInstallerLog.txt
    [2006/12/02 02:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
    [2010/11/28 17:02:10 | 000,040,963 | ---- | M] () -- C:\NirCmd.chm
    [2011/10/12 22:12:09 | 000,038,752 | ---- | M] () -- C:\P1005.log
    [2012/01/05 09:17:15 | 4024,885,248 | -HS- | M] () -- C:\pagefile.sys
    [2011/10/08 12:45:07 | 000,001,620 | ---- | M] () -- C:\RHDSetup.log
    [2012/01/04 20:10:28 | 000,000,493 | ---- | M] () -- C:\rkill.log
    [2011/09/16 09:54:11 | 000,000,136 | ---- | M] () -- C:\SerialSync.txt
    [2011/08/15 21:16:51 | 000,044,718 | ---- | M] () -- C:\sfcdetails.txt
    [2012/01/04 12:23:10 | 000,000,000 | ---- | M] () -- C:\sniffer.log
    [2006/03/06 07:10:34 | 000,000,132 | ---- | M] () -- C:\StopPrint.bat
    [2004/06/11 18:33:28 | 000,290,304 | ---- | M] (Microsoft Corporation) -- C:\subinacl.exe
    [2006/11/01 13:05:48 | 000,150,328 | ---- | M] (Sysinternals) -- C:\sync.exe
    [2011/12/22 12:35:54 | 000,067,610 | ---- | M] () -- C:\TDSSKiller.2.4.12.0_22.12.2011_12.35.04_log.txt
    [2011/09/20 18:20:10 | 000,000,266 | ---- | M] () -- C:\test.ini
    [2010/08/10 11:47:01 | 000,451,792 | ---- | M] () -- C:\vcredist_x86.log

    < %systemroot%\Fonts\*.com >
    [2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2011/11/28 13:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
    [2009/01/12 13:23:54 | 000,634,512 | ---- | M] (Gianpaolo Bottin) -- C:\Windows\gPhotoShow.scr
    [2011/08/13 08:53:06 | 000,692,736 | ---- | M] (repkasoft) -- C:\Windows\yowindow.scr
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
    [2011/12/16 13:07:40 | 000,000,230 | RH-- | M] () -- C:\Program Files (x86)\Mozilla Firefoxinstall.xml

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >

    < %PROGRAMFILES%\bak. /s >
    [2011/12/11 10:57:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Advanced SystemCare 3\Bak

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2011/03/21 14:24:05 | 000,000,487 | -HS- | M] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2012/01/04 19:12:21 | 004,370,643 | R--- | M] (Swearware) -- C:\Users\Frank\Desktop\ComboFix.exe
    [2012/01/05 09:21:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL.exe
    [2012/01/04 20:05:34 | 001,008,141 | ---- | M] () -- C:\Users\Frank\Desktop\rkill.exe
    [1 C:\Users\Frank\Desktop\*.tmp files -> C:\Users\Frank\Desktop\*.tmp -> ]

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >
    [2011/03/18 21:00:58 | 000,000,878 | ---- | M] () -- C:\Windows\AppPatch\Custom\{00a8ce68-cb2e-4652-aecd-c05c0d9d53a7}.sdb
    [2010/10/20 22:23:26 | 000,000,698 | ---- | M] () -- C:\Windows\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >
    [2010/09/13 13:09:56 | 000,000,000 | ---- | M] () -- C:\Users\Frank\emet_conf.exe
    [2011/02/23 15:33:36 | 000,000,000 | ---- | M] () -- C:\Users\Frank\ngen.exe

    < %systemroot%\ADDINS\*.* >
    [2009/06/10 16:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2011/02/23 13:35:55 | 000,000,402 | -HS- | M] () -- C:\Users\Frank\Favorites\desktop.ini
    [2012/01/04 23:14:02 | 000,000,912 | ---- | M] () -- C:\Users\Frank\Favorites\My Documents.lnk
    [2012/01/04 23:14:02 | 000,000,286 | ---- | M] () -- C:\Users\Frank\Favorites\NCH Audio and Telephony Software.lnk

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2010/07/18 17:21:16 | 000,000,008 | RHS- | M] () -- C:\ProgramData\7C18212ACF.sys
    [2010/07/28 19:04:40 | 000,000,056 | ---- | M] () -- C:\ProgramData\claude.ini
    [2010/07/28 19:04:23 | 000,000,006 | ---- | M] () -- C:\ProgramData\claude.log
    [2010/08/10 11:53:00 | 000,002,828 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys
    [2011/05/20 09:45:35 | 000,000,193 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
    [2011/05/17 16:07:59 | 000,000,063 | -H-- | M] () -- C:\ProgramData\Ts_infos.ini

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Files - Unicode (All) ==========
    [2010/07/29 12:59:44 | 000,000,000 | ---D | M](C:\Windows\SysNative\?N) -- C:\Windows\SysNative\?N
    [2010/07/29 12:59:44 | 000,000,000 | ---D | C](C:\Windows\SysNative\?N) -- C:\Windows\SysNative\?N
    [2010/07/23 20:15:48 | 000,000,000 | ---D | M](C:\Users\Frank\Favorites\?£sorted Bookmarks) -- C:\Users\Frank\Favorites\?£sorted Bookmarks

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 191 bytes -> C:\ProgramData\Temp:B1CD2545
    @Alternate Data Stream - 187 bytes -> C:\ProgramData\Temp:63CD0333
    @Alternate Data Stream - 182 bytes -> C:\ProgramData\Temp:C97C8631
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:84098FD3
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:5C321E34

    < End of report >


    ====================================================

    OTL Extras logfile created on: 1/5/2012 10:04:49 AM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Frank\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.75 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 59.90% Memory free
    7.50 Gb Paging File | 5.89 Gb Available in Paging File | 78.53% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 287.57 Gb Total Space | 195.42 Gb Free Space | 67.96% Space Free | Partition Type: NTFS
    Drive D: | 10.42 Gb Total Space | 1.52 Gb Free Space | 14.61% Space Free | Partition Type: NTFS
    Drive F: | 465.76 Gb Total Space | 102.39 Gb Free Space | 21.98% Space Free | Partition Type: NTFS

    Computer Name: FRANKS-PC | User Name: Frank | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .html[@ = FirefoxHTML] -- C:\Program Files\Waterfox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
    .html [@ = FirefoxHTML] -- C:\Program Files\Waterfox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Classes\<extension>]
    .bat [@ = batfile] -- Reg Error: Key error. File not found
    .chm [@ = chm.file] -- Reg Error: Key error. File not found
    .cmd [@ = cmdfile] -- Reg Error: Key error. File not found
    .com [@ = ComFile] -- Reg Error: Key error. File not found
    .html [@ = FirefoxHTML] -- C:\Program Files\Waterfox\firefox.exe (Mozilla Corporation)
    .pif [@ = piffile] -- Reg Error: Key error. File not found
    .reg [@ = regfile] -- Reg Error: Key error. File not found
    .txt [@ = txtfile] -- C:\Program Files (x86)\EditPadLite\EditPadLite.exe (Just Great Software)
    .vbs [@ = VBSFile] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll ",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Add To ControlPanel] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "ControlPanel" "Folder "
    Directory [Add To MyComputer] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "MyComputer" "Folder "
    Directory [Add To Right Click] -- "C:\Program Files\Common Files\RBSoft\Right Click Shortcuts Creator\RCSC.exe" "%1" "folder "
    Directory [Add To SendTo] -- wscript "C:\Program Files\Common Files\RBSoft\Send To Manager\SendToAdd.vbs" "%1 "
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
    Directory [cdTree] -- Reg Error: Value error.
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
    Directory [NIYoW] -- "C:\Program Files (x86)\NIYoW\niyow.exe" "/folder %1" (MC Software)
    Directory [NIYoW.QuickRename] -- "C:\Program Files (x86)\NIYoW\niyow.exe" /quickrename folder= "%1" rules= "$choose_task$" (MC Software)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [PotPlayer.Enqueue] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" /Add ()
    Directory [PotPlayer.Play] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" ()
    Directory [RenameMaster] -- C:\Users\Frank\Rename Master 2.9.4\RenameMaster.exe "%1" (www.joejoesoft.com)
    Directory [runas] -- cmd.exe /k "pushd %L && title Command Prompt" (Microsoft Corporation)
    Directory [TakeOwnership] -- wscript "C:\Program Files\Common Files\RBSoft\Right Click Tweaker\TakeOwnership.vbs" "%1" "Folder "
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1 ",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Add To ControlPanel] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "ControlPanel" "Folder "
    Directory [Add To MyComputer] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "MyComputer" "Folder "
    Directory [Add To Right Click] -- "C:\Program Files\Common Files\RBSoft\Right Click Shortcuts Creator\RCSC.exe" "%1" "folder "
    Directory [Add To SendTo] -- wscript "C:\Program Files\Common Files\RBSoft\Send To Manager\SendToAdd.vbs" "%1 "
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
    Directory [cdTree] -- Reg Error: Value error.
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
    Directory [NIYoW] -- "C:\Program Files (x86)\NIYoW\niyow.exe" "/folder %1" (MC Software)
    Directory [NIYoW.QuickRename] -- "C:\Program Files (x86)\NIYoW\niyow.exe" /quickrename folder= "%1" rules= "$choose_task$" (MC Software)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [PotPlayer.Enqueue] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" /Add ()
    Directory [PotPlayer.Play] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" ()
    Directory [RenameMaster] -- C:\Users\Frank\Rename Master 2.9.4\RenameMaster.exe "%1" (www.joejoesoft.com)
    Directory [runas] -- cmd.exe /k "pushd %L && title Command Prompt" (Microsoft Corporation)
    Directory [TakeOwnership] -- wscript "C:\Program Files\Common Files\RBSoft\Right Click Tweaker\TakeOwnership.vbs" "%1" "Folder "
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
    "DefaultOutboundAction" = 1
    "DefaultInboundAction" = 1
    "DisableUnicastResponsesToMulticastBroadcast" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
    "DefaultInboundAction" = 1
    "DefaultOutboundAction" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
    "DefaultInboundAction" = 1
    "DefaultOutboundAction" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()

    To Be Continued in next post
     
  7. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Continued from previous post

    [2010/09/28 19:28:44 | 000,000,055 | ---- | C] () -- C:\Windows\CopyMessageBox.INI
    [2010/09/28 13:00:12 | 000,012,800 | ---- | C] () -- C:\Windows\LPRES.DLL
    [2010/09/11 12:58:15 | 000,075,776 | ---- | C] () -- C:\Windows\cadkasdeinst01e.exe
    [2010/08/18 14:56:38 | 000,000,151 | ---- | C] () -- C:\Windows\SysWow64\Registration.ini
    [2010/07/29 21:49:52 | 000,007,616 | ---- | C] () -- C:\Users\Frank\AppData\Local\resmon.resmoncfg
    [2010/07/29 08:06:00 | 000,110,602 | ---- | C] () -- C:\Windows\SysWow64\xcdsfx32.bin
    [2010/07/28 22:17:52 | 000,000,036 | ---- | C] () -- C:\Users\Frank\AppData\Local\housecall.guid.cache
    [2010/07/28 19:04:23 | 000,000,056 | ---- | C] () -- C:\ProgramData\claude.ini
    [2010/07/24 11:22:58 | 000,153,600 | ---- | C] () -- C:\Windows\SysWow64\AI_ContextMenu.dll
    [2010/07/21 12:52:51 | 000,000,057 | ---- | C] () -- C:\Windows\cdrLabel.ini
    [2010/07/21 10:51:59 | 000,454,656 | ---- | C] () -- C:\Windows\SysWow64\PaintX.dll
    [2010/07/21 10:51:59 | 000,094,208 | ---- | C] () -- C:\Windows\SysWow64\vbpng.dll
    [2010/07/21 10:51:59 | 000,072,192 | ---- | C] () -- C:\Windows\SysWow64\zlib.dll
    [2010/07/21 10:31:47 | 000,017,116 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\AllChars.xml
    [2010/07/21 10:31:47 | 000,016,555 | ---- | C] () -- C:\Users\Frank\AppData\Roaming\AllChars-example.xml
    [2010/07/20 16:23:01 | 000,000,035 | ---- | C] () -- C:\Windows\Ulead32.INI
    [2010/07/20 15:32:40 | 000,285,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\Onsio.sys
    [2010/07/20 15:32:40 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\drivers\Onsreged.sys
    [2010/07/19 17:59:21 | 000,039,424 | ---- | C] () -- C:\Windows\SysWow64\rpiAccessProcess.dll
    [2010/07/18 21:33:22 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\VegaShEx.dll
    [2010/07/18 21:33:17 | 000,308,224 | ---- | C] () -- C:\Windows\SysWow64\Lffpx7.dll
    [2010/07/18 17:21:16 | 000,000,008 | RHS- | C] () -- C:\ProgramData\7C18212ACF.sys
    [2010/07/18 17:21:15 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
    [2010/07/18 17:02:41 | 000,157,696 | ---- | C] () -- C:\Windows\SysWow64\OggEnc.exe
    [2010/07/18 17:02:41 | 000,145,408 | ---- | C] () -- C:\Windows\SysWow64\Lame.exe
    [2010/07/18 17:02:41 | 000,076,800 | ---- | C] () -- C:\Windows\SysWow64\Faac.exe
    [2010/07/18 11:38:51 | 000,000,510 | ---- | C] () -- C:\Windows\ODBC.INI
    [2010/07/18 11:31:50 | 000,001,103 | ---- | C] () -- C:\Windows\ODBCINST.INI
    [2010/01/27 13:35:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2009/08/11 16:21:26 | 000,087,552 | ---- | C] () -- C:\Windows\SysWow64\ac3config.exe
    [2009/08/11 16:21:20 | 001,021,440 | ---- | C] () -- C:\Windows\SysWow64\ac3filter_intl.dll
    [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat(213).dat
    [2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2008/01/14 17:47:06 | 000,099,712 | ---- | C] () -- C:\Windows\HPBroker.dll
    [2007/04/27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
    [2007/02/05 16:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
    [2006/03/03 23:52:00 | 000,088,576 | ---- | C] () -- C:\Windows\SysWow64\OptimFROG.dll
    [2006/01/08 08:53:24 | 000,005,120 | ---- | C] () -- C:\Windows\SysWow64\hash2.dll
    [2005/08/26 15:28:34 | 000,143,360 | ---- | C] () -- C:\Windows\unzip.exe
    [2005/08/26 15:28:20 | 000,024,576 | ---- | C] () -- C:\Windows\shortcut.exe
    [2005/08/26 15:27:58 | 000,045,056 | ---- | C] () -- C:\Windows\devenum.exe
    [2004/06/12 14:55:32 | 000,274,432 | ---- | C] () -- C:\Windows\SysWow64\LAME_ENC.DLL
    [2004/06/12 14:55:32 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\LameEncShim.dll
    [2002/09/17 23:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe
    [1995/09/26 23:00:00 | 000,107,008 | ---- | C] () -- C:\Windows\SysWow64\TTEMB32.DLL
    [1995/09/26 23:00:00 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OPENENU.DLL
    [1995/09/26 23:00:00 | 000,006,352 | ---- | C] () -- C:\Windows\SysWow64\VISXUTIL.DLL
    [1995/09/26 23:00:00 | 000,002,041 | ---- | C] () -- C:\Windows\MSFNTMAP.INI
    [1995/09/26 23:00:00 | 000,000,586 | ---- | C] () -- C:\Windows\MSTXTCNV.INI
    [1995/09/26 23:00:00 | 000,000,280 | ---- | C] () -- C:\Windows\TTEMBED.INI

    ========== LOP Check ==========

    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Genie-Soft
    [2011/10/12 21:47:08 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ProcessLasso
    [2011/10/13 10:00:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\WinPatrol
    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Genie-Soft
    [2010/11/16 19:04:19 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Genie-Soft
    [2011/02/09 11:54:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\04AF0FFB-A69D-4A45-86C8-58ECAACE4096
    [2010/11/18 20:25:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Aaron Stewart
    [2010/07/21 10:09:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\abelhadigital.com
    [2011/10/06 18:33:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Abine
    [2011/09/07 20:42:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Acronis
    [2010/12/31 20:31:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\adma
    [2010/08/13 16:12:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\albumart
    [2011/10/24 09:48:47 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Amazon
    [2011/09/16 13:35:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Animal Software
    [2011/11/26 21:40:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\AnvSoft
    [2011/11/04 09:54:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Apowersoft
    [2010/08/31 08:31:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ArcticLine
    [2010/08/09 10:04:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ashampoo
    [2011/11/27 21:14:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ashampoo Slideshow Studio Elements
    [2012/01/05 00:33:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Audacity
    [2010/10/21 20:40:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Auslogics
    [2010/08/13 16:14:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\AV Soft
    [2011/02/05 18:21:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Avery
    [2011/06/18 10:30:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Babylon
    [2010/10/20 15:00:31 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Balabolka
    [2011/11/30 17:17:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\BDlot
    [2010/09/15 15:30:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\BioniX Wallpaper
    [2011/09/28 09:53:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bitmeter2
    [2011/11/30 14:19:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Blueberry
    [2010/11/12 11:48:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bluefive software
    [2010/07/18 14:08:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Bullzip
    [2011/09/02 13:45:50 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\calibre
    [2011/12/28 16:22:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Canneverbe Limited
    [2011/09/15 20:05:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ChemTable Software
    [2011/06/14 09:23:21 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Clone2Go Audio Converter Free Version
    [2010/11/18 20:53:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\CometPlayer
    [2011/07/27 15:59:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Conversations Network
    [2010/12/03 10:21:04 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\CyberPower Audio Editing Lab
    [2011/05/09 15:25:45 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DeblurMyImage
    [2011/08/08 15:34:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Deskex
    [2011/04/23 09:03:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Digiarty
    [2011/09/07 19:12:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DirectoryListPrintPro
    [2011/10/21 16:48:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DirectoryMonitor
    [2012/01/05 00:37:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\driveridentifier
    [2011/11/28 15:34:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoft
    [2011/11/28 15:15:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers
    [2011/02/09 11:54:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\E294DE04-C792-4800-8F77-CC0A5B9E15E7
    [2011/04/18 15:19:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\EAC
    [2011/08/17 18:45:47 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\EAST Technologies
    [2011/03/15 08:48:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\eComic
    [2011/03/29 20:54:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Engelmann Media
    [2011/01/13 12:47:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ethervane
    [2011/01/18 10:16:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Expert PDF 7
    [2011/11/27 20:49:05 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ffDiaporama
    [2011/03/02 19:55:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FILEminimizerPictures
    [2011/10/23 21:36:46 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FileQuery
    [2011/11/22 21:59:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Foxit Software
    [2011/02/01 21:47:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\freac
    [2010/12/19 19:56:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Free Sound Recorder
    [2011/04/24 17:35:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FreeLanguageTranslator
    [2011/10/18 15:28:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\FreeScreenToVideo
    [2011/08/31 09:33:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Frieger
    [2010/11/16 19:04:53 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Genie-Soft
    [2012/01/03 23:41:49 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Get from YouTube
    [2011/11/23 10:17:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\GetRightToGo
    [2011/01/12 12:10:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\gimagereader
    [2011/09/19 11:58:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\GlarySoft
    [2010/08/18 18:12:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\gnupg
    [2010/12/07 15:18:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Godlike
    [2011/05/02 18:05:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Goodsol
    [2011/01/12 12:19:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\gtk-2.0
    [2011/01/31 11:54:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Gyazo
    [2011/02/02 11:21:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HandBrake
    [2010/08/20 13:48:56 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HandyCDRipper
    [2011/09/16 11:06:32 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HotSync
    [2011/10/10 08:57:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Hulubulu
    [2010/10/20 18:33:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Hunspell
    [2011/09/29 14:29:32 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ICE Book Reader Professional
    [2011/08/08 11:25:39 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ImgBurn
    [2011/09/15 10:50:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Inventivio
    [2011/12/11 10:35:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\IObit
    [2011/12/15 10:43:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\IrfanView
    [2011/03/18 10:35:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\iSpring Solutions
    [2010/12/02 13:35:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\JAM Software
    [2011/08/22 12:28:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\JGsoft
    [2010/11/14 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\johnsadventures.com
    [2011/01/19 11:05:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\JPEGsnoop
    [2010/08/16 10:48:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Kana Solution
    [2011/11/05 13:31:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\kingsoft
    [2010/07/20 09:47:52 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\KO Approach Items
    [2011/04/10 10:09:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Leawo
    [2011/08/21 09:06:11 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LibrariIcon
    [2011/10/22 11:48:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LibreOffice
    [2010/12/30 11:18:53 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Lightscape
    [2010/07/28 19:22:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Lingoes
    [2011/08/23 06:29:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Listary
    [2011/08/08 11:10:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LiveBoot
    [2011/01/19 11:14:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LockHunter
    [2011/10/18 13:20:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\LogSys
    [2011/10/23 08:59:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mael
    [2011/11/08 21:14:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MAGIX
    [2010/07/18 16:13:21 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MakeitOne
    [2011/12/30 20:47:52 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MediaMonkey
    [2011/07/06 09:54:01 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\mediAvatar
    [2011/05/11 10:06:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\minus
    [2011/07/05 11:12:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mobipocket
    [2011/09/02 16:01:56 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mouse Recorder Pro
    [2010/09/09 17:05:50 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Moyea
    [2011/09/08 10:37:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MP3 Speed
    [2011/12/28 19:49:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mp3tag
    [2011/12/15 11:34:01 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MTexturedStyles
    [2011/11/24 22:22:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MusE
    [2010/08/27 08:40:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Musereo
    [2011/09/20 18:20:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\NCH Swift Sound
    [2011/07/27 06:27:26 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\nemo
    [2011/12/28 13:56:05 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\net.watype.puzzle.jigsawlite.59CF40312C069B2E5F3F9C70D453B8E2C77D2E60.1
    [2010/09/23 09:34:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Notepad++
    [2011/07/19 19:14:28 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nullsoft
    [2011/01/25 15:55:21 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Opera
    [2011/09/23 11:17:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\OverDrive
    [2011/08/09 10:08:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDF
    [2011/01/06 16:22:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDF Experte 7
    [2011/09/12 15:32:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDF Reader
    [2011/10/11 12:55:28 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\pdfforge
    [2011/05/05 14:28:56 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PDM
    [2011/06/02 09:17:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PhotoScape
    [2011/12/29 19:28:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PicaJet.Com
    [2011/12/12 15:29:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PotPlayerMini
    [2011/12/17 12:11:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Power Sound Editor Free
    [2011/04/10 10:09:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PPT2DVD
    [2011/10/11 13:00:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PrimoPDF
    [2011/03/29 21:02:05 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Prish
    [2010/07/22 11:18:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Process Hacker 2
    [2011/06/08 08:26:28 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ProcessLasso
    [2010/12/31 20:48:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\qliner
    [2010/12/02 11:25:53 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\QMC
    [2011/11/01 21:20:39 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\QTranslate
    [2011/01/23 14:28:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\QuickScan
    [2011/12/17 15:08:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\REAPER
    [2010/11/22 16:38:40 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Recordpad
    [2011/07/26 18:15:31 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\RegGenie
    [2011/11/07 19:23:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\rockbox.org
    [2011/09/12 13:54:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Roni Music
    [2010/07/21 09:17:24 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SecurityHeroes
    [2010/10/24 21:36:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ShellFolderFix
    [2011/06/12 18:44:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SlickRun
    [2011/10/06 17:17:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Smart PDF Creator Pro
    [2011/08/08 10:44:44 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Snippage.B28FB424FD6880E47B18D7D649F6CC93BDE9B29B.1
    [2011/07/17 13:45:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Softi Software
    [2011/10/11 12:41:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Softland
    [2012/01/04 19:14:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Software Informer
    [2010/12/31 20:55:02 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Soluto
    [2011/10/22 11:01:31 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Songbird2
    [2012/01/03 23:42:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Sound Editor Deluxe
    [2011/08/14 09:44:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Sound Editor Pro
    [2011/09/15 10:53:09 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Speak-A-Message
    [2011/12/30 20:13:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SpeedMP3Downloader
    [2011/12/26 22:54:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\StarBurn
    [2011/09/27 10:30:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Stegisoft
    [2011/09/26 12:38:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\StepShot
    [2011/03/19 12:01:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SuperUtils.com
    [2010/07/17 18:57:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\SupportSoft
    [2011/09/20 15:47:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\T-App
    [2011/08/09 10:38:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TeamViewer
    [2011/09/13 17:30:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TeraCopy
    [2011/08/22 12:28:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TheSage
    [2010/07/16 21:05:32 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Thunderbird
    [2011/11/18 10:59:49 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\tigerplayer
    [2011/03/29 20:00:44 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TIPP10
    [2010/07/18 15:52:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TreeCardGames
    [2010/12/02 12:06:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TrueCrypt
    [2011/09/13 09:21:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Tweak-7
    [2010/07/29 22:01:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Uniblue
    [2011/06/01 21:50:52 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\uTorrent
    [2010/10/18 17:07:08 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Video DVD Maker FREE
    [2011/12/20 14:50:16 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\visviva
    [2011/08/10 14:06:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Volume2
    [2010/12/21 15:30:27 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\VOS
    [2011/08/18 10:09:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WallpaperSS
    [2011/03/22 09:19:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WaveMax Sound Editor
    [2011/09/22 11:45:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Win7codecs
    [2010/07/17 20:18:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WinBatch
    [2011/12/14 12:56:01 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WindowSlider
    [2010/07/20 15:01:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\WinPatrol
    [2011/10/24 12:26:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Wordcycler
    [2011/10/20 11:21:46 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\www.shadowexplorer.com
    [2011/02/24 13:12:26 | 000,000,000 | -HSD | M] -- C:\Users\Frank\AppData\Roaming\wyUpdate AU
    [2011/12/23 14:33:04 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\X-Setup Pro
    [2011/10/10 14:42:40 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\YoWindow
    [2010/12/02 10:46:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Zentimo
    [2011/01/07 11:02:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Zoner
    [2011/10/14 10:53:52 | 000,000,324 | ---- | M] () -- C:\Windows\Tasks\GlaryInitialize.job
    [2011/12/26 10:04:26 | 000,000,448 | ---- | M] () -- C:\Windows\Tasks\PCDRScheduledMaintenance.job
    [2012/01/05 09:22:59 | 000,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA(243).DAT
    [2012/01/05 09:21:57 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU(244).TXT
    [2012/01/05 09:21:57 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < >

    < %SYSTEMDRIVE%\*.* >
    [2011/11/28 21:50:45 | 000,001,024 | ---- | M] () -- C:\.rnd
    [2010/10/05 20:43:38 | 000,003,890 | ---- | M] () -- C:\AddToSendTo.vbs
    [2011/11/11 22:28:02 | 000,003,408 | ---- | M] () -- C:\bootsqm.dat
    [2011/12/18 15:41:05 | 000,000,676 | ---- | M] () -- C:\chksize.cmd
    [2011/12/18 15:32:41 | 000,000,551 | ---- | M] () -- C:\chksize.cmd.hold
    [2011/10/22 18:21:00 | 000,000,370 | ---- | M] () -- C:\chksize.cmd.old
    [2012/01/04 23:45:45 | 000,052,608 | ---- | M] () -- C:\ComboFix.txt
    [2012/01/02 10:35:56 | 629,145,600 | -H-- | M] () -- C:\fileimage.dat
    [2011/12/09 11:39:56 | 000,001,875 | ---- | M] () -- C:\FINIS_IT.TXT
    [2012/01/05 09:17:14 | 3018,661,888 | -HS- | M] () -- C:\hiberfil.sys
    [2011/09/16 10:25:06 | 004,918,812 | ---- | M] () -- C:\HuskyInstallerLog.txt
    [2006/12/02 02:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
    [2010/11/28 17:02:10 | 000,040,963 | ---- | M] () -- C:\NirCmd.chm
    [2011/10/12 22:12:09 | 000,038,752 | ---- | M] () -- C:\P1005.log
    [2012/01/05 09:17:15 | 4024,885,248 | -HS- | M] () -- C:\pagefile.sys
    [2011/10/08 12:45:07 | 000,001,620 | ---- | M] () -- C:\RHDSetup.log
    [2012/01/04 20:10:28 | 000,000,493 | ---- | M] () -- C:\rkill.log
    [2011/09/16 09:54:11 | 000,000,136 | ---- | M] () -- C:\SerialSync.txt
    [2011/08/15 21:16:51 | 000,044,718 | ---- | M] () -- C:\sfcdetails.txt
    [2012/01/04 12:23:10 | 000,000,000 | ---- | M] () -- C:\sniffer.log
    [2006/03/06 07:10:34 | 000,000,132 | ---- | M] () -- C:\StopPrint.bat
    [2004/06/11 18:33:28 | 000,290,304 | ---- | M] (Microsoft Corporation) -- C:\subinacl.exe
    [2006/11/01 13:05:48 | 000,150,328 | ---- | M] (Sysinternals) -- C:\sync.exe
    [2011/12/22 12:35:54 | 000,067,610 | ---- | M] () -- C:\TDSSKiller.2.4.12.0_22.12.2011_12.35.04_log.txt
    [2011/09/20 18:20:10 | 000,000,266 | ---- | M] () -- C:\test.ini
    [2010/08/10 11:47:01 | 000,451,792 | ---- | M] () -- C:\vcredist_x86.log

    < %systemroot%\Fonts\*.com >
    [2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2011/11/28 13:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
    [2009/01/12 13:23:54 | 000,634,512 | ---- | M] (Gianpaolo Bottin) -- C:\Windows\gPhotoShow.scr
    [2011/08/13 08:53:06 | 000,692,736 | ---- | M] (repkasoft) -- C:\Windows\yowindow.scr
    [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
    [2011/12/16 13:07:40 | 000,000,230 | RH-- | M] () -- C:\Program Files (x86)\Mozilla Firefoxinstall.xml

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >

    < %PROGRAMFILES%\bak. /s >
    [2011/12/11 10:57:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Advanced SystemCare 3\Bak

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2011/03/21 14:24:05 | 000,000,487 | -HS- | M] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2012/01/04 19:12:21 | 004,370,643 | R--- | M] (Swearware) -- C:\Users\Frank\Desktop\ComboFix.exe
    [2012/01/05 09:21:28 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL.exe
    [2012/01/04 20:05:34 | 001,008,141 | ---- | M] () -- C:\Users\Frank\Desktop\rkill.exe
    [1 C:\Users\Frank\Desktop\*.tmp files -> C:\Users\Frank\Desktop\*.tmp -> ]

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >
    [2011/03/18 21:00:58 | 000,000,878 | ---- | M] () -- C:\Windows\AppPatch\Custom\{00a8ce68-cb2e-4652-aecd-c05c0d9d53a7}.sdb
    [2010/10/20 22:23:26 | 000,000,698 | ---- | M] () -- C:\Windows\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >
    [2010/09/13 13:09:56 | 000,000,000 | ---- | M] () -- C:\Users\Frank\emet_conf.exe
    [2011/02/23 15:33:36 | 000,000,000 | ---- | M] () -- C:\Users\Frank\ngen.exe

    < %systemroot%\ADDINS\*.* >
    [2009/06/10 16:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2011/02/23 13:35:55 | 000,000,402 | -HS- | M] () -- C:\Users\Frank\Favorites\desktop.ini
    [2012/01/04 23:14:02 | 000,000,912 | ---- | M] () -- C:\Users\Frank\Favorites\My Documents.lnk
    [2012/01/04 23:14:02 | 000,000,286 | ---- | M] () -- C:\Users\Frank\Favorites\NCH Audio and Telephony Software.lnk

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2010/07/18 17:21:16 | 000,000,008 | RHS- | M] () -- C:\ProgramData\7C18212ACF.sys
    [2010/07/28 19:04:40 | 000,000,056 | ---- | M] () -- C:\ProgramData\claude.ini
    [2010/07/28 19:04:23 | 000,000,006 | ---- | M] () -- C:\ProgramData\claude.log
    [2010/08/10 11:53:00 | 000,002,828 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys
    [2011/05/20 09:45:35 | 000,000,193 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
    [2011/05/17 16:07:59 | 000,000,063 | -H-- | M] () -- C:\ProgramData\Ts_infos.ini

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Files - Unicode (All) ==========
    [2010/07/29 12:59:44 | 000,000,000 | ---D | M](C:\Windows\SysNative\?N) -- C:\Windows\SysNative\?N
    [2010/07/29 12:59:44 | 000,000,000 | ---D | C](C:\Windows\SysNative\?N) -- C:\Windows\SysNative\?N
    [2010/07/23 20:15:48 | 000,000,000 | ---D | M](C:\Users\Frank\Favorites\?£sorted Bookmarks) -- C:\Users\Frank\Favorites\?£sorted Bookmarks

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 191 bytes -> C:\ProgramData\Temp:B1CD2545
    @Alternate Data Stream - 187 bytes -> C:\ProgramData\Temp:63CD0333
    @Alternate Data Stream - 182 bytes -> C:\ProgramData\Temp:C97C8631
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:84098FD3
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:5C321E34

    < End of report >


    ====================================================

    OTL Extras logfile created on: 1/5/2012 10:04:49 AM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Frank\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.75 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 59.90% Memory free
    7.50 Gb Paging File | 5.89 Gb Available in Paging File | 78.53% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 287.57 Gb Total Space | 195.42 Gb Free Space | 67.96% Space Free | Partition Type: NTFS
    Drive D: | 10.42 Gb Total Space | 1.52 Gb Free Space | 14.61% Space Free | Partition Type: NTFS
    Drive F: | 465.76 Gb Total Space | 102.39 Gb Free Space | 21.98% Space Free | Partition Type: NTFS

    Computer Name: FRANKS-PC | User Name: Frank | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .html[@ = FirefoxHTML] -- C:\Program Files\Waterfox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
    .html [@ = FirefoxHTML] -- C:\Program Files\Waterfox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Classes\<extension>]
    .bat [@ = batfile] -- Reg Error: Key error. File not found
    .chm [@ = chm.file] -- Reg Error: Key error. File not found
    .cmd [@ = cmdfile] -- Reg Error: Key error. File not found
    .com [@ = ComFile] -- Reg Error: Key error. File not found
    .html [@ = FirefoxHTML] -- C:\Program Files\Waterfox\firefox.exe (Mozilla Corporation)
    .pif [@ = piffile] -- Reg Error: Key error. File not found
    .reg [@ = regfile] -- Reg Error: Key error. File not found
    .txt [@ = txtfile] -- C:\Program Files (x86)\EditPadLite\EditPadLite.exe (Just Great Software)
    .vbs [@ = VBSFile] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll ",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Add To ControlPanel] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "ControlPanel" "Folder "
    Directory [Add To MyComputer] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "MyComputer" "Folder "
    Directory [Add To Right Click] -- "C:\Program Files\Common Files\RBSoft\Right Click Shortcuts Creator\RCSC.exe" "%1" "folder "
    Directory [Add To SendTo] -- wscript "C:\Program Files\Common Files\RBSoft\Send To Manager\SendToAdd.vbs" "%1 "
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
    Directory [cdTree] -- Reg Error: Value error.
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
    Directory [NIYoW] -- "C:\Program Files (x86)\NIYoW\niyow.exe" "/folder %1" (MC Software)
    Directory [NIYoW.QuickRename] -- "C:\Program Files (x86)\NIYoW\niyow.exe" /quickrename folder= "%1" rules= "$choose_task$" (MC Software)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [PotPlayer.Enqueue] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" /Add ()
    Directory [PotPlayer.Play] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" ()
    Directory [RenameMaster] -- C:\Users\Frank\Rename Master 2.9.4\RenameMaster.exe "%1" (www.joejoesoft.com)
    Directory [runas] -- cmd.exe /k "pushd %L && title Command Prompt" (Microsoft Corporation)
    Directory [TakeOwnership] -- wscript "C:\Program Files\Common Files\RBSoft\Right Click Tweaker\TakeOwnership.vbs" "%1" "Folder "
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1 ",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Add To ControlPanel] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "ControlPanel" "Folder "
    Directory [Add To MyComputer] -- wscript "C:\Program Files\Common Files\RBSoft\My Computer Manager\MyComputerManager.vbs" "%1" "MyComputer" "Folder "
    Directory [Add To Right Click] -- "C:\Program Files\Common Files\RBSoft\Right Click Shortcuts Creator\RCSC.exe" "%1" "folder "
    Directory [Add To SendTo] -- wscript "C:\Program Files\Common Files\RBSoft\Send To Manager\SendToAdd.vbs" "%1 "
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
    Directory [cdTree] -- Reg Error: Value error.
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
    Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
    Directory [NIYoW] -- "C:\Program Files (x86)\NIYoW\niyow.exe" "/folder %1" (MC Software)
    Directory [NIYoW.QuickRename] -- "C:\Program Files (x86)\NIYoW\niyow.exe" /quickrename folder= "%1" rules= "$choose_task$" (MC Software)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [PotPlayer.Enqueue] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" /Add ()
    Directory [PotPlayer.Play] -- "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" "%1" ()
    Directory [RenameMaster] -- C:\Users\Frank\Rename Master 2.9.4\RenameMaster.exe "%1" (www.joejoesoft.com)
    Directory [runas] -- cmd.exe /k "pushd %L && title Command Prompt" (Microsoft Corporation)
    Directory [TakeOwnership] -- wscript "C:\Program Files\Common Files\RBSoft\Right Click Tweaker\TakeOwnership.vbs" "%1" "Folder "
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
    "DefaultOutboundAction" = 1
    "DefaultInboundAction" = 1
    "DisableUnicastResponsesToMulticastBroadcast" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
    "DefaultInboundAction" = 1
    "DefaultOutboundAction" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
    "DefaultInboundAction" = 1
    "DefaultOutboundAction" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()
    "C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe" = C:\Program Files (x86)\PotPlayer\PotPlayerMini.exe:*:Enabled:potPlayer -- ()

    To Be Continued in next post
     
  8. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Continued from previous post

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
    "{00a8ce68-cb2e-4652-aecd-c05c0d9d53a7}.sdb" = Windows Media Player 64-bit Plug-in Fix
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.7
    "{08C3441C-4FAF-48D3-A551-70DD6031734F}" = Microsoft Baseline Security Analyzer 2.2
    "{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
    "{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
    "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
    "{1EEF5C7E-C371-431D-A507-8C5B46EED7B4}" = Classic Shell
    "{23170F69-40C1-2702-0916-000001000000}" = 7-Zip 9.16 (x64 edition)
    "{26A24AE4-039D-4CA4-87B4-2F86416030FF}" = Java(TM) 6 Update 30 (64-bit)
    "{26A24AE4-039D-4CA4-87B4-2F86417002FF}" = Java(TM) 7 Update 2 (64-bit)
    "{3DD823AB-145A-4522-B9F6-A9566121F837}_is1" = ShellFolderFix 1.1.4
    "{48B23888-B23F-8F40-9A79-DD5A9134EBFE}" = ATI Catalyst Install Manager
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{4C4A1499-1381-4174-9DB5-F6DE9249D23E}" = UAC Trust Shortcut 1.0
    "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{636B3A2D-50EC-4DFA-82A5-D5F3C7D43284}" = User Profile Helper Cleanup Service
    "{751CDC69-9B11-63A4-CCF8-452D8638AA70}" = ccc-utility64
    "{80A620C1-B22C-4781-A351-B14B8A37BFE3}" = Image Resizer Powertoy Clone for Windows (64 bit)
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
    "{85C76689-536B-4CD4-AD94-2F5D259C084B}" = Free Launch Bar 64-bit Edition
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{9CF6A157-F0E8-4216-B229-C0CA8204BE2C}_is1" = Copy Handler 1.32Final
    "{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
    "{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
    "{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
    "{B821CDAA-34DE-46FD-87C9-E6EE7158DB5D}" = Microsoft Image Composite Editor
    "{B860298B-CE03-4DE2-B92E-422F2C20A2D8}_is1" = PDF-XChange Lite 4
    "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
    "{C6F34AE0-0576-11d4-82FE-4491FCC00000}" = IconViewer
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{D79C2CD4-7BCC-60AC-76C9-834CEEF1CDBE}" = ccc-utility64
    "{D968E920-3A49-48EB-BA1D-8964DCDF0CA9}" = COMODO Programs Manager
    "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
    "{DBCF0030-9149-11DE-B8B6-005056C00008}" = Paragon Drive Copy™ 10 Personal SE
    "{E47A6052-382E-420B-9397-F1B04E39F612}" = MOBZHunt
    "{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD1}" = Paint.NET v3.5.5
    "{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
    "Agent Ransack (64-bit)_is1" = Agent Ransack 2010 (64-bit)
    "AntiFreeze_is1" = AntiFreeze 1.01
    "BDlot DVD Clone Ultimate_is1" = BDlot DVD Clone Ultimate 3.1.0
    "Bulk Rename Utility_is1" = Bulk Rename Utility 2.7.1.2
    "Bullzip PDF Printer_is1" = Bullzip PDF Printer 6.0.0.865
    "CCleaner" = CCleaner
    "Default Programs Editor" = Default Programs Editor
    "Defraggler" = Defraggler
    "FileMenu Tools_is1" = FileMenu Tools
    "FrRefEng" = French Spelling Settings
    "GPL Ghostscript 8.56" = GPL Ghostscript 8.56
    "GPL Ghostscript Fonts" = GPL Ghostscript Fonts
    "KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v4.1.0
    "Listary_is1" = Listary 2.00
    "LockHunter_is1" = LockHunter version 1.0 beta 3, 64 bit edition
    "MediaInfo" = MediaInfo 0.7.51
    "MediaTab" = MediaTab
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "PC-Doctor for Windows" = Hardware Diagnostic Tools
    "Recuva" = Recuva
    "Waterfox 9.0 (x64 en-US)" = Waterfox 9.0 (x64 en-US)
    "WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 3.0.0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
    "{02FCAA8F-59D3-4198-822E-135C61EE4F0B}" = NeroKwikMedia Help (CHM)
    "{07A02221-CF5A-B902-A02E-21E2439FBECC}" = CCC Help Portuguese
    "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0CD8A170-E470-11DB-3D6C-00D529464AE1}" = Notation Musician 2.6.3 (Trial Version)
    "{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
    "{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}" = Windows Media Center Add-in for Silverlight
    "{132C5FA3-75F3-93C8-4371-EC93F7208EAC}" = CCC Help French
    "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
    "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    "{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
    "{1D1C53BF-AADF-8589-AA93-7966B71822C4}" = CCC Help Thai
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{2081036F-986D-EF5A-9992-6F5C53E8DFF1}" = Catalyst Control Center InstallProxy
    "{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
    "{23D4A873-14FF-474E-0001-6529DDC11226}" = CDRWIN 8
    "{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
    "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
    "{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java(TM) 6 Update 30
    "{272C8DEE-F54F-406C-9AA6-B4DE2985A47C}" = Flash Drive Tester v1.14
    "{28B406AA-8B04-02F4-3B8D-E47DC53155D7}" = CCC Help Dutch
    "{29205904-A7A8-4545-0001-697935602C90}" = SimplyGoodPictures
    "{2A9E937C-D3E3-49FA-9766-A3174B88CE35}" = MinusShare
    "{2AEDC172-479F-47AE-8A48-A0524D4AED5B}_is1" = Inpaint 3.0
    "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
    "{31991C00-3C71-A920-4B80-02A155ACBC5A}" = Catalyst Control Center Graphics Light
    "{330D5210-3C4F-E632-2714-BE23C7C10B9F}" = Catalyst Control Center Graphics Previews Common
    "{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
    "{345C90FB-FA10-11D5-9C2A-0080C85A0C2D}" = ABBYY FineReader OCR Engine for Microtek
    "{3C6F60BD-EDBF-4D45-A063-59261E6FD540}" = Media Add-ons for Acronis True Image Home 2010
    "{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1" = DriverIdentifier 3.5
    "{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1" = YouTube Song Downloader
    "{42A8860C-323D-D7E4-9922-D19482115C1B}" = CCC Help Finnish
    "{43002AE2-4093-49E0-A03D-990EE184C568}" = Lyrics Plugin for Windows Media Player
    "{43460E60-E2B7-45e4-8567-9069C08A5DD7}_is1" = Tipard DVD Creator 3.1.18
    "{43544FB5-BC1D-939A-7FDA-F7F3E5AEC35B}" = AMD VISION Engine Control Center
    "{44390616-015F-4BFB-90F4-341217FC3949}" = Identity Finder
    "{44A69352-33DD-405E-ADB8-2D768643BBAE}_is1" = AnyBizSoft PDF to Word (Build 3.0.0)
    "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
    "{453C9E55-80DF-4BD2-9885-52A1FB0D9382}" = eReader
    "{49FEEC97-8F99-6D8E-7E78-E3D840C290F9}" = CCC Help Chinese Traditional
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
    "{4F762B0F-8613-BC6F-B631-798067B6F5D6}" = CCC Help Japanese
    "{55393517-DB95-4E82-884E-EDFA2C519458}" = WildVoice Studio 1.0
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{58A49B80-2595-4C9D-B3EB-261E68A2C4D1}_is1" = Wallpaper SlideShow LT 1.4.5
    "{58CB9A9A-1EFB-4EA8-B50C-3097E754AC21}" = High-Definition Video Playback
    "{58ECE031-9AAD-4011-B34A-BC78E77527E2}" = hppMSRedist
    "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
    "{5B5E949E-3924-45E3-9229-84E8270BED68}" = ArcSoft Perfect365
    "{61150C85-DC0A-4976-922F-5575F388ADA6}" = Notation Player 2.6.3
    "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
    "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
    "{6788AB8A-4D71-42E0-8125-B95A9C47D51D}" = System Restore Explorer
    "{67DCE9A2-94DA-CEC0-8981-89A620165773}" = CCC Help Swedish
    "{67E4EF06-E0D6-42E0-A2BA-67199B0143FB}_is1" = Windows Media Player Plus! 2.1
    "{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{6A060A85-6297-EFED-2478-A5FDF1C9757E}" = CCC Help Danish
    "{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1" = Gyazo 1.0
    "{6ED53E0C-EAC0-4F0F-947D-6BA817E4C8C3}" = HostsMan 3.2.73
    "{6EEDB8C7-1B5B-DA4C-B144-64AA1A35F2F4}" = CCC Help Italian
    "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.1.0
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{769DAD15-B198-7DB5-3DB0-B11589B2BD06}" = puzzle.watype.net/jigsawlite
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7821C7B2-7E21-4CF3-925B-58B6A8BC6311}" = LibreOffice 3.4
    "{78D2854E-5DBF-11E7-B41F-47D203C8ED66}" = CCC Help English
    "{7902E313-FF0F-4493-ACB1-A8147B78DCD0}" = HPSSupply
    "{7CDC26F7-D6BF-442A-B599-0075A48310F7}" = SA32xx Device Manager
    "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
    "{82809116-D1EE-443C-AE31-F19E709DDF7A}" = AMD USB Filter Driver
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{85031FD7-4B7B-4769-A2DF-75F8046ED626}_is1" = PDF/ePUB to Kindle Tool version 2.4.0
    "{85BF0E64-6ABB-4EA1-A026-A3DEA6554A60}" = Do It Again
    "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    "{87E60394-2E62-400D-99C0-C1BEA2F9A439}" = SlimDrivers
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
    "{889E44CE-435C-4D37-B302-A7E43339E5FA}_is1" = Mouse Recorder Pro 2.0.5.0
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{8FA1794F-F38A-430B-A9DB-9B0DBAA05012}" = Alissa's MobiHandler
    "{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
    "{93A2E3C5-5F01-C261-DA21-E3FEF9B7B097}" = CCC Help Chinese Standard
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 4.1.2
    "{9889A710-7060-079C-FD40-4E2E438A4150}" = Snippage
    "{998C9435-DAF8-4BDF-B9A5-F844B01D524C}_is1" = TCPEye 1.0
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9CD59439-960B-40AC-4DC2-21BC8AEB9361}" = ccc-core-static
    "{9FAB5EAB-5D79-499C-864D-858CBD1E4AB6}_is1" = 4.02
    "{A0C8D249-8E3C-263E-49C0-810EAB06CD81}" = Catalyst Control Center Core Implementation
    "{A453B3CD-64C4-A6CE-9E28-EDFD1E55D829}" = Catalyst Control Center Graphics Full New
    "{A61EBA6E-B44A-48B4-B57B-0BAE80DA97CE}_is1" = Stalled Printer Repair 1.2
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AA51FEDE-9F5F-8782-3B56-FB14DA5B698A}" = Catalyst Control Center Graphics Full Existing
    "{AAB49CB7-FE7C-44CE-A19B-E0602945F8A2}" = Catalyst Control Center - Branding
    "{AAE4A005-1ABC-4F3E-B568-B5EE0CA7D1F1}" = AV Album Art Fixer
    "{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
    "{ABCC90CD-A89E-4E84-B57D-7538936C2E85}" = CCC Help Spanish
    "{AC76BA86-0000-7EC8-7489-000000000603}" = Adobe Acrobat and Reader 6.0.3 Update
    "{AC76BA86-0000-7EC8-7489-000000000604}" = Adobe Acrobat and Reader 6.0.4 Update
    "{AC76BA86-0000-7EC8-7489-000000000605}" = Adobe Acrobat and Reader 6.0.5 Update
    "{AC76BA86-0000-7EC8-7489-000000000606}" = Adobe Acrobat and Reader 6.0.6 Update
    "{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0.1 Professional
    "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
    "{AF772E70-3CD2-0F4B-F252-B8EA7C0BE726}" = CCC Help Polish
    "{AFE499B5-FCC4-45E6-A1A5-3C51AE0E539B}" = Mobipocket Creator 4.2
    "{B08D262E-D902-11D5-9C28-0080C85A0C2D}" = ScanWizard 5
    "{B36E2A06-D0BF-F084-7B7A-8908495B07FC}" = CCC Help German
    "{B38D3AAC-D3C1-BE01-6DB3-D8A328B890CC}" = CCC Help English
    "{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
    "{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
    "{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
    "{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
    "{BCD2FF98-7DF2-4FE2-B7E3-9593C5D66A4E}_is1" = Iconoid version 3.8.6
    "{BDEE7660-E08C-4824-8577-6CE12F8C3492}_is1" = gPhotoShow v1.6.3
    "{BF06BEBB-2C47-4D9F-AB6F-07C07EB54F09}_is1" = Wondershare PDF to Word (Build 3.0.0)
    "{C01AE05C-3C8C-75B3-C9F0-1B525DD3697C}" = Catalyst Control Center InstallProxy
    "{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Audio Pack 1
    "{C39EBDD4-6765-08FC-69C5-8CBB8B248939}" = CCC Help Hungarian
    "{C6758EBF-FD04-C4FF-1C05-B3CAB63287DB}" = CCC Help Czech
    "{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}" = HP Support Assistant
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{D220A72F-C99C-809B-56D1-8E1D0A694AF6}" = CCC Help Norwegian
    "{D4481AFF-4218-4CF0-A68C-87E9EBAE3B86}" = WordTalkInstall
    "{D647F06F-2908-487E-9CDA-DE52148CBF49}" = OverDrive Media Console
    "{D9417F6D-48D1-B954-06B8-C56E115ABC3C}" = Catalyst Control Center Localization All
    "{D9696ED1-09D1-EF62-EF01-5F3552800D91}" = CCC Help Russian
    "{D9E9549E-AE65-3918-4BD3-0639CAAE808A}" = CCC Help Korean
    "{DD6FA976-3F0A-4C6C-A30F-6E75DFC39DE9}" = MakeitOne - MP3AlbumMaker
    "{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
    "{DFC86EF1-C609-468A-95E9-75C2E026A081}" = AportisDoc Converter
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}" = LightScribe System Software
    "{E2C2FA27-5B9E-E9C4-D6E6-25994314BB1A}" = CCC Help Turkish
    "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
    "{E623BB3F-F7ED-4148-BEB5-A0D1DB28B4DE}" = Media Converter for Philips
    "{E69A76AA-71D9-4939-8EBB-8FC8BE22428D}" = Files Compare Tool
    "{E7C6D565-2E48-4303-A114-AFE7B2E561AF}_is1" = FotoSketcher 2.10
    "{E89D78B8-28F7-412F-8B26-C684739CBBDC}" = Palm Desktop
    "{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
    "{EB9F3F92-4857-4121-AA6F-1C424AC6C266}_is1" = Screen Recording Suite V2.2.0
    "{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
    "{ED1D3C27-EFE7-43D9-AFE9-14281CD6AE65}" = GooReader
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F1AC923B-2A52-4C5D-8011-5FC83CD58CF4}" = hppusgP1000
    "{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
    "{F83FD7EE-65D6-726C-B2CE-828738ECA738}" = CCC Help Greek
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "123 Free Solitaire_is1" = 123 Free Solitaire 2009 v7.2
    "ABC Amber LIT Converter" = ABC Amber LIT Converter
    "abc2score" = abc2score
    "Adobe AIR" = Adobe AIR
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.6
    "Adolix Wallpaper Changer_is1" = Adolix Wallpaper Changer 2.2
    "Advanced SystemCare 3_is1" = Advanced SystemCare 3
    "Aimersoft Video Converter Std_is1" = Aimersoft Video Converter Std(Build 4.0.0.0)
    "Aiseesoft DVD Ripper_is1" = Aiseesoft DVD Ripper 6.1.10
    "Aiseesoft Total Media Converter_is1" = Aiseesoft Total Media Converter 5.2.30
    "All Sound Recorder Vista_is1" = All Sound Recorder Vista 1.30
    "Any Audio Converter_is1" = Any Audio Converter 3.2.7
    "Any Video Converter_is1" = Any Video Converter 3.1.2
    "A-PDF Text Extractor_is1" = A-PDF Text Extractor 1.4
    "Artensoft Photo Mosaic Wizard_is1" = Artensoft Photo Mosaic Wizard
    "Ashampoo Burning Studio 2010 Advanced_is1" = Ashampoo Burning Studio 2010 Advanced
    "Ashampoo Internet Accelerator 3_is1" = Ashampoo Internet Accelerator 3 v.3.20
    "Ashampoo Photo Commander 7_is1" = Ashampoo Photo Commander 7.40
    "Ashampoo Slideshow Studio Elements_is1" = Ashampoo Slideshow Studio Elements 2.0.1
    "Ashampoo Snap 4_is1" = Ashampoo Snap 4 v.4.3.0
    "Ashampoo Undeleter_is1" = Ashampoo Undeleter v.1.00
    "asterisk key" = Asterisk Key 10.0
    "Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
    "Audio Speed Changer Pro" = Audio Speed Changer Pro 1.3
    "Audiograbber" = Audiograbber 1.83 SE
    "Audiograbber-Lame" = Audiograbber MP3 Plugin
    "avast" = avast! Free Antivirus
    "Awesome Duplicate Photo Finder_is1" = Awesome Duplicate Photo Finder v. 1.0
    "Axence NetTools Pro_is1" = Axence NetTools Pro 4.0
    "Balabolka" = Balabolka
    "BB FlashBack Express" = BB FlashBack Express
    "BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1" = 0.9.4.6
    "Belarc Advisor" = Belarc Advisor 8.2
    "BestPractice" = BestPractice (remove only)
    "Boxoft Free OCR (freeware)_is1" = Boxoft Free OCR (freeware)
    "Boxoft PDF to HTML (freeware)_is1" = Boxoft PDF to HTML (freeware)
    "Boxoft PDF to JPG (freeware)_is1" = Boxoft PDF to JPG (freeware)
    "Boxoft PDF to PowerPoint (freeware)_is1" = Boxoft PDF to PowerPoint (freeware)
    "Boxoft PDF to Text (freeware)_is1" = Boxoft PDF to Text (freeware)
    "Boxoft PDF to WORD (freeware)_is1" = Boxoft PDF to WORD (freeware)
    "Burlington's CD Design Creator" = Burlington's CD Design Creator
    "CD Recovery Toolbox Free_is1" = CD Recovery Toolbox Free 1.1
    "CDisplay_is1" = CDisplay 1.8
    "cdTree 3 Standard Edition" = cdTree 3 Standard Edition 3.1.4 Std
    "CleanMem" = CleanMem
    "Cleanse Uninstaller Pro 8.0" = Cleanse Uninstaller Pro 8.0
    "Clone2Go Audio Converter Free Version_is1" = Clone2Go Audio Converter Free Version 1.9.7
    "ConvertLIT Graphical User Interface" = ConvertLIT Graphical User Interface 2.0
    "Daniusoft MOD Converter_is1" = Daniusoft MOD Converter(Build 2.1.0.1)
    "DiskBoss Pro" = DiskBoss Pro 2.0.16
    "Disketch" = Disketch CD Label Software
    "DoremiSoft RM to MP3 Converter" = DoremiSoft RM to MP3 Converter 1.0
    "Driver Magician_is1" = Driver Magician 3.61
    "DVD Flick_is1" = DVD Flick 1.3.0.7
    "DVD Shrink_is1" = DVD Shrink 3.2
    "EASEUS Data Recovery Wizard 5.5.1_is1" = EASEUS Data Recovery Wizard 5.5.1
    "EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 8.0.1 Professional
    "Easy File Joiner_is1" = Easy File Joiner
    "EditPad Lite" = Just Great Software EditPad Lite 6.7.1
    "ERUNT_is1" = ERUNT 1.1j
    "eSpeak_is1" = eSpeak version 1.45.04
    "EULAlyzer_is1" = EULAlyzer 2.0
    "Exact Audio Copy" = Exact Audio Copy 1.0beta1
    "ExamDiff_is1" = ExamDiff 1.8 (Build 1.8.0.7)
    "FFmpeg for Audacity on Windows_is1" = FFmpeg for Audacity on Windows
    "FFmpeg for Audacity_is1" = FFmpeg v0.6.2 for Audacity
    "File Repair_is1" = File Repair
    "FILEminimizer Pictures_is1" = FILEminimizer Pictures
    "FormatFactory" = FormatFactory 2.70
    "Free DVD Creator (by minidvdsoft)_is1" = Free DVD Creator version 2.0
    "Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
    "Free Video to DVD Converter_is1" = Free Video to DVD Converter version 5.0.2.1125
    "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.11.923
    "Freecorder Toolbar" = Freecorder Toolbar
    "Freecorder5.01" = Freecorder 5
    "Freemake Video Converter_is1" = Freemake Video Converter version 2.1.0
    "Freemake Video Downloader_is1" = Freemake Video Downloader
    "FrRefEng" = French Spelling Settings
    "Gadwin PrintScreen" = Gadwin PrintScreen
    "Game Booster_is1" = Game Booster 3
    "Gentibus CD_is1" = Gentibus CD 1.49
    "GhostMouse_is1" = GhostMouse
    "Goodsol Solitaire 101_is1" = Goodsol Solitaire 101 Version 2.01
    "GPL Ghostscript 8.71" = GPL Ghostscript 8.71
    "GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
    "Graph paper printer" = Graph paper printer
    "GUI for dvdauthor" = GUI for dvdauthor 1.07
    "HaaliMkx" = Haali Media Splitter
    "HandBrake" = HandBrake 0.9.5
    "Handy CD Ripper_is1" = Handy CD Ripper version 2.5.5
    "HDVideoConverterFactoryPro" = HD Video Converter Factory Pro
    "HelixYUVCodecs" = Helix YUV Codecs (remove only)
    "HP LaserJet P1000 series" = HP LaserJet P1000 series
    "HP Remote Solution" = HP Remote Solution
    "HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
    "ImageConverter Plus_is1" = ImageConverter Plus 8.0
    "ImgBurn" = ImgBurn
    "IrfanView" = IrfanView (remove only)
    "ISpell_is1" = ISpell 1.1.1
    "iWisoft Free Video Converter_is1" = iWisoft Free Video Converter 1.2
    "Jet Screenshot_is1" = Jet Screenshot v 2.3
    "JetBoost_is1" = JetBoost
    "Karen's Directory Printer" = Karen's Directory Printer
    "Karen's Version Browser" = Karen's Version Browser
    "Kindle Auto eBook Converter" = Kindle Auto eBook Converter 0.4.50
    "KLiteCodecPack_is1" = K-Lite Codec Pack 6.0.4 (Basic)
    "LAME for Audacity_is1" = LAME v3.98.2 for Audacity
    "LHTTSDUN" = L&H TTS3000 Nederlands
    "LHTTSENG" = L&H TTS3000 British English
    "LHTTSFRF" = L&H TTS3000 Français
    "LHTTSGED" = L&H TTS3000 Deutsch
    "LHTTSITI" = L&H TTS3000 Italiano
    "LHTTSSPE" = L&H TTS3000 Español
    "MacX HD Video Converter Pro For Windows_is1" = MacX HD Video Converter Pro For Windows 3.10.2
    "MagicScore_is1" = MagicScore
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
    "MediaMonkey_is1" = MediaMonkey 4.0
    "mediAvatar PowerPoint to Video Converter Personal" = mediAvatar PowerPoint to Video Converter Personal
    "mediAvatar Video to DVD Converter" = mediAvatar Video to DVD Converter
    "midi2abc " = midi2abc
    "MidimergeSetup" = MidimergeSetup
    "Minus_is1" = Minus Desktop Tool 1.4
    "Moo0 Mp3InfoEditor" = Moo0 Mp3InfoEditor 1.17
    "MozBackup" = MozBackup 1.5.1
    "Mozilla Firefox 8.0.1 (x86 en-US)" = Mozilla Firefox 8.0.1 (x86 en-US)
    "Mozilla Thunderbird (3.1.16)" = Mozilla Thunderbird (3.1.16)
    "Mp3tag" = Mp3tag v2.46a
    "MpcStar" = MpcStar 5.1
    "MSOffice" = Microsoft Office Professional
    "MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
    "mtt12" = Mp3 Tag Tools v1.2
    "MuseScore" = MuseScore 1.1 MuseScore score typesetter
    "Name It Your Way (NIYoW)_is1" = Name It Your Way (NIYoW) v1.7.6
    "net.watype.puzzle.jigsawlite.59CF40312C069B2E5F3F9C70D453B8E2C77D2E60.1" = puzzle.watype.net/jigsawlite
    "NetworkIndicator_is1" = Network Activity Indicator for Windows 7
    "NirSoft BlueScreenView" = NirSoft BlueScreenView
    "NirSoft Wireless Network Watcher" = NirSoft Wireless Network Watcher
    "Opanda IExif_is1" = Opanda IExif 2.3
    "OpenWith Enhanced" = OpenWith (Enhanced)
    "PC Wizard 2010_is1" = PC Wizard 2010.1.96
    "Photocopier_is1" = Photocopier 3.05
    "PhotoFilmStrip_is1" = PhotoFilmStrip 1.5.0
    "PhotoToolkit_is1" = Photo! Editor 1.1
    "PhotoWipe_is1" = PhotoWipe 1.0
    "Picasa 3" = Picasa 3
    "PopTray" = PopTray 3.20
    "PrintFolder_is1" = PrintFolder 1.3
    "ProcessLasso" = Process Lasso
    "QTranslate" = QTranslate 3.0.1
    "QuickMonth Calendar_is1" = QuickMonth Calendar 2.1
    "RealAlt_is1" = Real Alternative 2.0.2
    "Rename Master_is1" = Rename Master
    "ResetDRM" = Windows Media DRM Reset
    "Revo Uninstaller" = Revo Uninstaller 1.93
    "Right Click Enhancer" = Right Click Enhancer 2.4
    "SetFileDate_is1" = SetFileDate 2.0
    "setup.exe_is1" = setup.exe
    "Shortcuts Map" = Shortcuts Map 2.3
    "Simpo PDF to PowerPoint_is1" = Simpo PDF to PowerPoint 1.0.0.1
    "Simpo PDF to Text_is1" = Simpo PDF to Text 2.2.0.0
    "Simpo PDF to Word_is1" = Simpo PDF to Word 2.1.1.0
    "Sketch It!" = Sketch It! 3.1
    "Slice" = Slice Audio File Splitter
    "SMPlayer" = SMPlayer 0.6.9
    "SnapDraw Free" = SnapDraw Free
    "Snippage.B28FB424FD6880E47B18D7D649F6CC93BDE9B29B.1" = Snippage
    "SnowFox Total Video Converter_is1" = SnowFox Total Video Converter 2.8.1.1
    "Software Informer_is1" = Software Informer 1.1
    "Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.20
    "SpeedFan" = SpeedFan (remove only)
    "SpeedMP3Downloader" = Speed MP3 Downloader
    "SpywareBlaster_is1" = SpywareBlaster 4.5
    "ST6UNST #1" = JS Text File Merger
    "System Explorer_is1" = System Explorer 2.3.7
    "TeamViewer 7" = TeamViewer 7
    "TeleKast" = TeleKast 1.0.0.14
    "The KMPlayer" = The KMPlayer (remove only)
    "TIPP10_is1" = TIPP10 Version 2.1.0
    "TrueCrypt" = TrueCrypt
    "Tunatic" = Tunatic
    "tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
    "Tweaking.com - Windows Repair (All in One)" = Tweaking.com - Windows Repair (All in One)
    "TXTcollector_is1" = TXTcollector
    "Unlocker" = Unlocker 1.9.1
    "VisiPics_is1" = VisiPics V1.30
    "VLC media player" = VLC media player 1.1.11
    "WavePad" = WavePad Sound Editor
    "Windows 7 - Codec Pack" = Windows 7 Codec Pack 3.4.0
    "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
    "Windows Media Encoder 9" = Windows Media Encoder 9 Series
    "WinHotKey_is1" = WinHotKey 0.70
    "WinLiveSuite" = Windows Live Essentials
    "WinMend Auto Shutdown_is1" = WinMend Auto Shutdown 1.2.7
    "WinMend Folder Hidden_is1" = WinMend Folder Hidden 1.4.3
    "WinMerge_is1" = WinMerge 2.12.4
    "WinPcapInst" = WinPcap 4.1.2
    "WinScraper Utility" = WinScraper Utility 1.0
    "WinX DVD Author_is1" = WinX DVD Author 5.9
    "WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 2.0.0
    "WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 6.0.2
    "WinX HD Video Converter Deluxe_is1" = WinX HD Video Converter Deluxe 3.10.3
    "WonderFoxDVDRipper" = WonderFox DVD Ripper
    "Wondershare DVD Slideshow Builder Standard_is1" = Wondershare DVD Slideshow Builder Standard(Build 6.1.6.55)
    "Wondershare Video Converter Ultimate_is1" = Wondershare Video Converter Ultimate(Build 5.6.0.1)
    "Yahoo! Desktop Search" = Yahoo! Desktop Search
    "yowindow" = YoWindow
    "Zebra Screen Recorder_is1" = Zebra Screen Recorder version 1.2
    "Zentimo PRO_is1" = Zentimo PRO 1.4
    "Zentimo_is1" = Zentimo 1.0
    "Zero Assumption Recovery_is1" = Zero Assumption Recovery Version 9

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
    "Amazon Kindle" = Amazon Kindle
    "Depeche View" = Depeche View
    "HuluDesktop" = Hulu Desktop

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 1/1/2012 5:16:43 PM | Computer Name = Franks-PC | Source = Application Hang | ID = 1002
    Description = The program firefox.exe version 9.0.0.4371 stopped interacting with
    Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Action Center control panel. Process ID: 634 Start
    Time: 01ccc8c731feedb5 Termination Time: 12 Application Path: C:\Program Files\Waterfox\firefox.exe

    Report
    Id: dcc9fbf9-34bd-11e1-9721-c80aa928c58a

    Error - 1/1/2012 7:41:57 PM | Computer Name = Franks-PC | Source = Application Hang | ID = 1002
    Description = The program AudioConverter.exe version 3.2.2.1 stopped interacting
    with Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Action Center control panel. Process ID: 1100 Start
    Time: 01ccc8dea81881d6 Termination Time: 31 Application Path: C:\Program Files (x86)\AnvSoft
    Any Audio Converter\AudioConverter.exe Report Id: 2ce69105-34d2-11e1-ac56-c80aa928c58a


    Error - 1/2/2012 12:24:41 PM | Computer Name = Franks-PC | Source = Application Error | ID = 1000
    Description = Faulting application name: CPM.exe, version: 1.3.0.86, time stamp:
    0x4e8ac23f Faulting module name: UninstallAppNotMon_DLL.DLL, version: 1.0.0.1, time
    stamp: 0x4e8ac0ff Exception code: 0xc0000417 Fault offset: 0x000000000003a328 Faulting
    process id: 0xc40 Faulting application start time: 0x01ccc967ecd2d237 Faulting application
    path: C:\Program Files\COMODO Programs Manager\CPM.exe Faulting module path: C:\Program
    Files\COMODO Programs Manager\UninstallAppNotMon_DLL.DLL Report Id: 4582cfdd-355e-11e1-a43c-c80aa928c58a

    Error - 1/2/2012 12:26:39 PM | Computer Name = Franks-PC | Source = Application Error | ID = 1000
    Description = Faulting application name: CPM.exe, version: 1.3.0.86, time stamp:
    0x4e8ac23f Faulting module name: UninstallAppNotMon_DLL.DLL, version: 1.0.0.1, time
    stamp: 0x4e8ac0ff Exception code: 0xc0000417 Fault offset: 0x000000000003a328 Faulting
    process id: 0x173c Faulting application start time: 0x01ccc96b299e8260 Faulting application
    path: C:\Program Files\COMODO Programs Manager\CPM.exe Faulting module path: C:\Program
    Files\COMODO Programs Manager\UninstallAppNotMon_DLL.DLL Report Id: 8bff8f0a-355e-11e1-a43c-c80aa928c58a

    Error - 1/2/2012 12:29:49 PM | Computer Name = Franks-PC | Source = Application Error | ID = 1000
    Description = Faulting application name: CPM.exe, version: 1.3.0.86, time stamp:
    0x4e8ac23f Faulting module name: UninstallAppNotMon_DLL.DLL, version: 1.0.0.1, time
    stamp: 0x4e8ac0ff Exception code: 0xc0000417 Fault offset: 0x000000000003a328 Faulting
    process id: 0xd6c Faulting application start time: 0x01ccc96b691b3f77 Faulting application
    path: C:\Program Files\COMODO Programs Manager\CPM.exe Faulting module path: C:\Program
    Files\COMODO Programs Manager\UninstallAppNotMon_DLL.DLL Report Id: fd005813-355e-11e1-a43c-c80aa928c58a

    Error - 1/2/2012 11:26:41 PM | Computer Name = Franks-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
    Description = Cryptographic Services failed while processing the OnIdentity() call
    in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
    of service PretonSaver since QueryServiceConfig API failed System Error: The system
    cannot find the file specified. .

    Error - 1/4/2012 12:04:10 AM | Computer Name = Franks-PC | Source = MsiInstaller | ID = 11935
    Description = Product: Microsoft Visual C++ 2005 Redistributable -- Error 1935.An
    error occurred during the installation of assembly 'Microsoft.VC80.OpenMP,type= "win32 ",version= "8.0.50727.762 ",publicKeyToken= "1fc8b3b9a1e18e3b ",processorArchitecture= "x86 "'.
    Please refer to Help and Support for more information. HRESULT: 0x80070422. assembly
    interface: IAssemblyCacheItem, function: Commit, component: {1E507087-0819-45E0-A01F-C8B3B9A1E18E}

    Error - 1/4/2012 12:24:04 AM | Computer Name = Franks-PC | Source = Application Error | ID = 1000
    Description = Faulting application name: CPM.exe, version: 1.3.0.86, time stamp:
    0x4e8ac23f Faulting module name: UninstallAppNotMon_DLL.DLL, version: 1.0.0.1, time
    stamp: 0x4e8ac0ff Exception code: 0xc0000417 Fault offset: 0x000000000003a328 Faulting
    process id: 0xd68 Faulting application start time: 0x01ccca9860749724 Faulting application
    path: C:\Program Files\COMODO Programs Manager\CPM.exe Faulting module path: C:\Program
    Files\COMODO Programs Manager\UninstallAppNotMon_DLL.DLL Report Id: ef02ff13-368b-11e1-ba81-c80aa928c58a

    Error - 1/4/2012 12:36:28 AM | Computer Name = Franks-PC | Source = Application Hang | ID = 1002
    Description = The program wmplayer.exe version 12.0.7601.17514 stopped interacting
    with Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Action Center control panel. Process ID: 650 Start
    Time: 01ccca9a5a8cc87f Termination Time: 60 Application Path: C:\Program Files (x86)\Windows
    Media Player\wmplayer.exe Report Id: a715e76c-368d-11e1-ba81-c80aa928c58a

    Error - 1/4/2012 11:45:57 PM | Computer Name = Franks-PC | Source = Service1 | ID = 0
    Description = Failed to stop service. System.NullReferenceException: Object reference
    not set to an instance of an object. at CaptureLibService.CaptureLibService.OnStop()

    at System.ServiceProcess.ServiceBase.DeferredStop()

    [ Hewlett-Packard Events ]
    Error - 12/28/2011 11:37:18 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    Error - 12/29/2011 9:22:21 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    Error - 12/29/2011 10:38:24 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    Error - 12/30/2011 2:27:29 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    Error - 12/30/2011 2:32:46 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 2000
    Description =

    Error - 12/31/2011 6:44:38 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description = HP Error ID: -2146233087 Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
    action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
    outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
    action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
    outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage
    methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
    message) Exception rethrown at [0] Message: The server did not provide a meaningful
    reply; this might be caused by a contract mismatch, a premature session shutdown
    or an internal server error. StackTrace: Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
    action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
    outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
    action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
    outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage
    methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
    message) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
    reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
    msgData, Int32 type) at HP.SupportFramework.Communicator.MessengerComm.IMessengerCommunicator.UpdateTimer()

    at HP.SupportAssistant.UI.MessengerCommunication.sendTimerUpdate() Source: mscorlib

    Name:
    HPSF.exe Version: 06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support
    Framework\HPSF.exe Format: en-US RAM: 3838 Ram Utilization: 30 TargetSite: Void HandleReturnMessage(System.Runtime.Remoting.Messaging.IMessage,
    System.Runtime.Remoting.Messaging.IMessage)

    Error - 12/31/2011 6:44:55 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    Error - 12/31/2011 6:44:57 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    Error - 12/31/2011 6:44:58 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    Error - 12/31/2011 6:45:07 PM | Computer Name = Franks-PC | Source = HPSF.exe | ID = 4000
    Description =

    [ System Events ]
    Error - 1/5/2012 10:21:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7031
    Description = The Secondary Logon service terminated unexpectedly. It has done
    this 1 time(s). The following corrective action will be taken in 120000 milliseconds:
    Restart the service.

    Error - 1/5/2012 10:21:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7031
    Description = The System Event Notification Service service terminated unexpectedly.
    It has done this 1 time(s). The following corrective action will be taken in
    120000 milliseconds: Restart the service.

    Error - 1/5/2012 10:21:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7031
    Description = The Shell Hardware Detection service terminated unexpectedly. It
    has done this 1 time(s). The following corrective action will be taken in 60000
    milliseconds: Restart the service.

    Error - 1/5/2012 10:21:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7031
    Description = The Themes service terminated unexpectedly. It has done this 1 time(s).
    The following corrective action will be taken in 60000 milliseconds: Restart the
    service.

    Error - 1/5/2012 10:21:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7031
    Description = The Windows Management Instrumentation service terminated unexpectedly.
    It has done this 1 time(s). The following corrective action will be taken in
    60000 milliseconds: Restart the service.

    Error - 1/5/2012 10:21:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7031
    Description = The Windows Update service terminated unexpectedly. It has done this
    1 time(s). The following corrective action will be taken in 60000 milliseconds:
    Restart the service.

    Error - 1/5/2012 10:22:27 AM | Computer Name = Franks-PC | Source = DCOM | ID = 10010
    Description =

    Error - 1/5/2012 10:22:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7032
    Description = The Service Control Manager tried to take a corrective action (Restart
    the service) after the unexpected termination of the Server service, but this action
    failed with the following error: %%1056

    Error - 1/5/2012 10:23:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7032
    Description = The Service Control Manager tried to take a corrective action (Restart
    the service) after the unexpected termination of the User Profile Service service,
    but this action failed with the following error: %%1056

    Error - 1/5/2012 10:23:57 AM | Computer Name = Franks-PC | Source = Service Control Manager | ID = 7032
    Description = The Service Control Manager tried to take a corrective action (Restart
    the service) after the unexpected termination of the Computer Browser service,
    but this action failed with the following error: %%1056


    < End of report >


    Frank
     
  9. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Broni,

    You asked, "How is computer doing?" It's doing well in all respects except two:

    1. I can't run sfc /scannow. The error message I get is:
    ========================================
    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>sfc /scannow

    Windows Resource Protection could not start the repair service.

    C:\Windows\system32>

    I brought this subject up on this BBS before, but it was unresolved.
    ========================================

    2. I can't drag and drop .mp3 and .wav files from Windows Explorer into an Audacity or Windows Media Player window. Before about a week ago, I could do that all the time. Now what I get is the "no-go" icon (the circle with the diagonal crossbar). Instead of dragging and dropping, I have to use the File > Import or File > Open commands. I can drag and drop other files anywhere and how I want, and I can drag and drop .mp3 and .wav files to other windows and to the desktop, but not into those programs. I can drag and drop to my heart's content in Safe Mode, but not in Normal mode.

    I know these are not related to each other, but that's the summary of how my computer is. The tests that you and I have been running haven't changed the way it works in any way that I can detect. I can live with the current problems if they can't be fixed. If all else fails, or if more things "go south" I can run an in-place upgrade and see if that fixes things. Would you have anything else to add? Thanks! :)

    Frank
     
  10. 2012/01/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    As for the first issue see here: http://www.winhelponline.com/blog/f...the-repair-service-when-running-sfc-in-vista/

    As for the second one...
    In this forum we'll make sure your computer is clean.

    =============================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found
      O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
      O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
      O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (no name) - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No CLSID value found.
      O3 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..\Toolbar\WebBrowser: (GOM Player + Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
      O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
      O9:64bit: - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} -  "C:\Program Files (x86)\Fiddler2\Fiddler.exe" File not found
      O9:64bit: - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} -  "C:\Program Files (x86)\Fiddler2\Fiddler.exe" File not found
      O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: aol.com ([free] http in Trusted sites)
      O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: esl.org ([]https in Trusted sites)
      O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: esl.org ([www] https in Trusted sites)
      O15 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\..Trusted Domains: microsoft.com ([]https in Trusted sites)
      O37 - HKU\S-1-5-21-1554658206-2804524318-1847147138-1001\...com [@ = ComFile] -- Reg Error: Key error. File not found
      [2011/12/13 11:01:00 | 000,000,105 | -HS- | M] () -- C:\Users\Frank\AppData\Local\00000021
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ================================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  11. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Broni,

    Thanks for that link! It addresses the problem, but unfortunately it doesn't solve it.

    I now get a slightly different message:
    =================================================
    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>sfc /scannow

    Beginning system scan. This process will take some time.

    Windows Resource Protection could not perform the requested operation.

    C:\Windows\system32>
    =================================================

    But I don't see this as a being a problem to pose to you on this thread. It's most likely not due to malware.

    Frank
     
  12. 2012/01/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Make sure you run "sfc" as administrator.

    Click Start and in "Start search" type in:
    cmd
    Hold SHIFT and CTRL keys, press Enter.

    Now in command prompt window type:
    sfc /scannow
    Press Enter.
     
  13. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Here is the contents of the OTL.exe file:

    =============================================
    All processes killed
    ========== OTL ==========
    64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    Registry value HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612}\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612}\ deleted successfully.
    Registry value HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
    Registry value HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C2DB4FE6-8409-45CE-8010-189A7B5CCE86} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C2DB4FE6-8409-45CE-8010-189A7B5CCE86}\ not found.
    Registry value HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
    64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}\ not found.
    Registry key HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\aol.com\free\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\esl.org\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\esl.org\www\ not found.
    Registry key HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\microsoft.com\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001_Classes\.com\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-1554658206-2804524318-1847147138-1001_Classes\ComFile\ not found.
    HKEY_LOCAL_MACHINE\Software\Classes\.com\\|comfile /E : value set successfully!
    C:\Users\Frank\AppData\Local\00000021 moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Flash cache emptied: 168 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Flash cache emptied: 56475 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Frank
    ->Temp folder emptied: 2003146 bytes
    ->Temporary Internet Files folder emptied: 5903075 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 169482508 bytes
    ->Google Chrome cache emptied: 6099312 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Opera cache emptied: 36623 bytes
    ->Flash cache emptied: 57696 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: TEMP
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 24576 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 844 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84014 bytes
    RecycleBin emptied: 701324 bytes

    Total Files Cleaned = 176.00 mb


    [EMPTYFLASH]

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Frank
    ->Flash cache emptied: 0 bytes

    User: Public

    User: TEMP

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.31.0 log created on 01052012_192343

    Files\Folders moved on Reboot...
    C:\Users\Frank\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Frank\AppData\Local\Mozilla\Firefox\Profiles\maz74s9a.Default\startupCache\startupCache.8.little moved successfully.
    C:\Users\Frank\AppData\Local\Mozilla\Firefox\Profiles\maz74s9a.Default\Cache\_CACHE_001_ moved successfully.
    C:\Users\Frank\AppData\Local\Mozilla\Firefox\Profiles\maz74s9a.Default\Cache\_CACHE_002_ moved successfully.
    C:\Users\Frank\AppData\Local\Mozilla\Firefox\Profiles\maz74s9a.Default\Cache\_CACHE_003_ moved successfully.
    C:\Users\Frank\AppData\Local\Mozilla\Firefox\Profiles\maz74s9a.Default\Cache\_CACHE_MAP_ moved successfully.
    C:\Users\Frank\AppData\Local\Mozilla\Firefox\Profiles\maz74s9a.Default\urlclassifier3.sqlite moved successfully.

    Registry entries deleted on Reboot...
    =============================================

    Frank
     
  14. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Broni,

    I followed your instructions precisely, but got the same results as before:
    ==============================================
    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>sfc /scannow

    Beginning system scan. This process will take some time.

    Windows Resource Protection could not perform the requested operation.

    C:\Windows\system32>
    ==============================================

    Frank
     
  15. 2012/01/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Well, I think it'll be a subject to a different forum when we're done here.
     
  16. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Here are the contents of the checkup.txt file:

    Results of screen317's Security Check version 0.99.24
    Windows 7 x64 (UAC is enabled)
    Internet Explorer 9
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    avast! Free Antivirus
    MidimergeSetup
    MuseScore 1.1 MuseScore score typesetter
    Windows Media DRM Reset
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    SpywareBlaster 4.5
    HostsMan 3.2.73
    Sophos Anti-Rootkit 1.5.20
    Java(TM) 6 Update 30
    Mozilla Thunderbird (3.1.16) Thunderbird Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    WinPatrol winpatrol.exe
    Alwil Software Avast5 AvastSvc.exe
    Alwil Software Avast5 AvastUI.exe
    BillP Studios WinPatrol WinPatrol.exe
    ``````````End of Log````````````
     
  17. 2012/01/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good. Go on....
     
  18. 2012/01/05
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Broni,

    Here is the contents of ESETScan:

    C:\Program Files (x86)\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
    C:\Users\Frank\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\XP Desktop Icons\eBay.lnk Win32/Adware.ADON application cleaned by deleting - quarantined
    C:\Users\Frank\Downloads\asc 3.8-setup.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
    C:\Users\Frank\Downloads\asc-setup(1).exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
    C:\Users\Frank\Downloads\cnet2_64bit_Vista_Win7_R265_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
    C:\Users\Frank\Downloads\fsSetup132.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
    C:\Users\Frank\Downloads\gb3-setup.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
    C:\Users\Frank\Downloads\PDFCreator-1_2_3_setup.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
    C:\Users\Frank\Downloads\SoftonicDownloader_for_windows-7-service-pack-1.exe a variant of Win32/SoftonicDownloader.A application cleaned by deleting - quarantined
    C:\Users\Frank\Downloads\unlocker-setup.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
    C:\Users\Frank\Downloads\Unlocker1.9.1.exe Win32/Adware.ADON application deleted - quarantined
    C:\Users\Frank\Downloads\windows.7.codec.pack.v3.4.0.setup.exe probably a variant of Win32/Toolbar.Widgi application deleted - quarantined

    Minor note: ESet runs only in Internet Explorer.

    Would you say that I should not be using the services of the programs or websites from which these "bad actors" came from? Should I avoid them in the future?

    Frank
     
    Last edited: 2012/01/06
  19. 2012/01/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No problem :)
     
  20. 2012/01/07
    Frank D

    Frank D Inactive Thread Starter

    Joined:
    2004/07/15
    Messages:
    553
    Likes Received:
    6
    Broni, are you still there?
     
  21. 2012/01/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If you're sure it came from there obviously yes.

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.