1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Resolved Cant unistall ask & record toolbar

Discussion in 'Other PC Software' started by DPI Graphics, 2010/06/05.

  1. 2010/06/05
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    Has anybody tried to unistall this tool bar. I have tried the uninstall program, add and remove, and manually deleting it. Nothing seems to work. HELP!!!!
    thx DPI
     
  2. 2010/06/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download OTL to your Desktop.

    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * Under the Custom Scan box paste this in:



    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    userinit.exe
    explorer.exe
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT



    * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     

  3. to hide this advert.

  4. 2010/06/05
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    Here ya go:
    Had to break it apate this is OTL 1st 1/2

    OTL logfile created on: 6/5/2010 5:14:02 PM - Run 1
    OTL by OldTimer - Version 3.2.5.3 Folder = C:\Documents and Settings\Ed Day.DPI01\Desktop\My Downloads
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1,023.00 Mb Total Physical Memory | 623.00 Mb Available Physical Memory | 61.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 76.34 Gb Total Space | 50.05 Gb Free Space | 65.56% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    Drive E: | 76.33 Gb Total Space | 71.70 Gb Free Space | 93.94% Space Free | Partition Type: NTFS
    Drive F: | 72.72 Gb Total Space | 54.20 Gb Free Space | 74.54% Space Free | Partition Type: NTFS
    Drive G: | 76.32 Gb Total Space | 62.25 Gb Free Space | 81.57% Space Free | Partition Type: NTFS
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: DPI01
    Current User Name: Ed Day
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2010/06/05 17:13:06 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My Downloads\OTL.exe
    PRC - [2010/02/25 17:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\ccsvchst.exe
    PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2005/03/14 12:05:02 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
    PRC - [1998/07/23 00:06:26 | 000,067,584 | ---- | M] (IntelliQuest Communications, Inc.) -- C:\Program Files\Corel\Graphics9\Register\Remind32.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/06/05 17:13:06 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My Downloads\OTL.exe
    MOD - [2010/05/13 22:35:01 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\asoehook.dll
    MOD - [2009/07/12 01:02:02 | 000,653,120 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\microsoft.vc90.crt\msvcr90.dll
    MOD - [2009/07/12 01:02:00 | 000,569,664 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\microsoft.vc90.crt\msvcp90.dll
    MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


    ========== Win32 Services (SafeList) ==========

    SRV - [2010/02/25 17:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe -- (N360)
    SRV - [2008/01/29 16:09:02 | 000,394,704 | ---- | M] (Symantec, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe -- (Symantec RemoteAssist)
    SRV - [2005/03/14 12:05:02 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


    ========== Driver Services (SafeList) ==========

    DRV - [2010/06/01 21:35:18 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
    DRV - [2010/05/31 01:00:00 | 001,347,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100605.003\NAVEX15.SYS -- (NAVEX15)
    DRV - [2010/05/31 01:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
    DRV - [2010/05/31 01:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
    DRV - [2010/05/31 01:00:00 | 000,085,552 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100605.003\NAVENG.SYS -- (NAVENG)
    DRV - [2010/05/28 12:33:19 | 000,331,640 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100528.003\IDSXpx86.sys -- (IDSxpx86)
    DRV - [2010/05/05 21:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0402000.00C\SYMTDI.SYS -- (SYMTDI)
    DRV - [2010/04/29 10:44:04 | 000,537,136 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100429.001\BHDrvx86.sys -- (BHDrvx86)
    DRV - [2010/04/28 22:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\Ironx86.SYS -- (SymIRON)
    DRV - [2010/04/21 20:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\SYMEFA.SYS -- (SymEFA)
    DRV - [2010/04/21 19:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\N360\0402000.00C\SRTSP.SYS -- (SRTSP)
    DRV - [2010/04/21 19:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
    DRV - [2010/02/25 17:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\ccHPx86.sys -- (ccHP)
    DRV - [2009/10/14 20:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\SYMDS.SYS -- (SymDS)
    DRV - [2003/10/06 14:16:00 | 001,550,043 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
    DRV - [2003/03/05 12:19:28 | 000,015,840 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PFMODNT.SYS -- (PfModNT)
    DRV - [2002/03/11 10:34:32 | 000,005,376 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\DELL\drivers\R60303\TVTGAA01\BIN\atiicdxx.sys -- (ATICDSDr)
    DRV - [2001/08/17 05:12:20 | 000,032,840 | ---- | M] (NETGEAR Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Ngrpci.sys -- (ngrpci)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hei.net/
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/06/02 13:50:29 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/06/01 21:36:37 | 000,000,000 | ---D | M]

    [2010/03/30 17:38:38 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2007/07/26 12:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml

    O1 HOSTS File: ([2006/02/28 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
    O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
    O2 - BHO: (Ask and Record Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
    O3 - HKLM\..\Toolbar: (Ask and Record Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (Ask and Record Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
    O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
    O4 - HKCU..\Run: [NvMediaCenter] C:\WINDOWS\System32\NVMCTRAY.DLL (NVIDIA Corporation)
    O4 - Startup: C:\Documents and Settings\Ed Day.DPI01\Start Menu\Programs\Startup\Corel Registration.lnk = C:\Program Files\Corel\Graphics9\Register\Remind32.exe (IntelliQuest Communications, Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.69.150 68.87.85.102
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/03/11 17:13:16 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2009/03/11 17:13:16 | 000,000,000 | ---- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/04/06 23:40:06 | 000,000,000 | ---D | M]
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
    NetSvcs: WmdmPmSp - File not found

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (56308606093492224)

    ========== Files/Folders - Created Within 90 Days ==========

    [2010/06/05 12:10:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\Ask & Record Toolbar
    [2010/06/05 11:53:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\AskToolbar
    [2010/06/04 23:57:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Printer Info Cache
    [2010/06/04 23:57:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Image Zone Express
    [2010/06/04 23:43:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\HP
    [2010/06/04 23:35:05 | 000,098,304 | ---- | C] (Hewlett Packard Company) -- C:\WINDOWS\System32\hpzjsn01.dll
    [2010/06/04 23:11:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\FFOutput
    [2010/06/04 23:11:31 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
    [2010/06/04 22:12:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Corel
    [2010/06/04 22:11:02 | 000,607,744 | ---- | C] (Digital Equipment Corp.) -- C:\WINDOWS\System32\Decslib.dll
    [2010/06/04 22:09:23 | 000,909,312 | ---- | C] (Apple Computer Inc.) -- C:\WINDOWS\System32\qd3d.dll
    [2010/06/04 22:09:13 | 000,168,448 | ---- | C] (WexTech Systems, Inc.) -- C:\WINDOWS\System32\Awrtl30.dll
    [2010/06/04 22:09:13 | 000,100,864 | ---- | C] (Corel Corporation Limited) -- C:\WINDOWS\System32\awpe.dll
    [2010/06/04 22:09:02 | 000,245,760 | ---- | C] (Corel Corporation) -- C:\WINDOWS\System32\Sccomp91.dll
    [2010/06/04 22:09:02 | 000,225,280 | ---- | C] (Corel Corporation) -- C:\WINDOWS\System32\Scint91.dll
    [2010/06/04 22:09:02 | 000,110,592 | ---- | C] (Corel Corporation) -- C:\WINDOWS\System32\Sccres91.dll
    [2010/06/04 15:12:40 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Resource Kits
    [2010/06/04 14:49:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop\LookInMyPC
    [2010/06/03 00:01:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NCH Software
    [2010/06/02 18:08:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\FLVService
    [2010/06/02 17:02:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader 9 Installer
    [2010/06/02 16:55:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\nos
    [2010/06/02 16:54:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Google
    [2010/06/02 16:54:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Google
    [2010/06/02 16:46:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
    [2010/06/02 16:45:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Google
    [2010/06/02 16:45:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Adobe
    [2010/06/02 16:45:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NOS
    [2010/06/02 14:54:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
    [2010/06/02 14:29:00 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
    [2010/06/02 09:27:51 | 000,361,904 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdi.sys
    [2010/06/02 09:27:51 | 000,339,504 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdiv.sys
    [2010/06/02 09:27:50 | 000,328,752 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.sys
    [2010/06/02 09:27:50 | 000,325,680 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.sys
    [2010/06/02 09:27:50 | 000,173,104 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.sys
    [2010/06/02 09:27:50 | 000,116,784 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\ironx86.sys
    [2010/06/02 09:27:50 | 000,043,696 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.sys
    [2010/06/02 09:27:49 | 000,501,888 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.sys
    [2010/06/02 09:27:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360\0402000.00C
    [2010/06/02 09:19:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\GlarySoft
    [2010/06/01 21:35:19 | 000,124,976 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
    [2010/06/01 21:35:19 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
    [2010/06/01 21:31:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
    [2010/06/01 21:31:18 | 000,408,088 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton_Download_Manager.exe
    [2010/06/01 20:13:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
    [2010/06/01 19:27:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Symantec
    [2010/06/01 13:49:34 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
    [2010/06/01 12:18:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Tific
    [2010/05/31 23:48:05 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
    [2010/05/31 22:34:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8(3)
    [2010/05/31 13:16:12 | 000,000,000 | R-SD | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\My Stationery
    [2010/05/31 13:16:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\microsoft
    [2010/05/31 13:10:03 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
    [2010/05/31 13:02:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\Symantec
    [2010/05/31 13:01:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\Norton
    [2010/05/31 12:16:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton
    [2010/05/31 12:16:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NortonInstaller
    [2010/05/31 12:11:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
    [2010/05/31 11:56:50 | 000,098,304 | ---- | C] (NVIDIA) -- C:\WINDOWS\System32\nvudisp.exe
    [2010/05/31 11:47:51 | 000,000,000 | ---D | C] -- C:\Program Files\W3i
    [2010/05/31 11:47:20 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
    [2010/05/31 11:47:19 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
    [2010/05/31 11:46:12 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Suite
    [2010/05/31 11:35:22 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\IECompatCache
    [2010/05/31 11:34:40 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\PrivacIE
    [2010/05/31 11:33:14 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\IETldCache
    [2010/05/13 21:14:10 | 000,000,000 | -H-D | C] -- C:\msdownld.tmp
    [2010/04/29 17:22:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Identities
    [2010/04/11 16:35:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop\HP
    [2010/04/11 16:32:35 | 000,000,000 | ---D | C] -- C:\Program Files\Creative
    [2010/04/11 16:09:40 | 000,045,056 | ---- | C] (adi) -- C:\WINDOWS\System32\CleanUp.exe
    [2010/04/11 16:09:40 | 000,036,864 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\DSndUp.exe
    [2010/04/11 16:00:52 | 000,000,000 | ---D | C] -- C:\drvrtmp
    [2010/04/11 15:41:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Drivers
    [2010/04/07 10:20:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\UserData
    [2010/04/07 00:32:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Macromedia
    [2010/04/07 00:32:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Adobe
    [2010/04/06 23:47:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Identities
    [2010/04/06 23:47:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\My Pictures
    [2010/04/06 23:47:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\My Music
    [2010/04/06 23:47:43 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Microsoft
    [2010/04/06 23:47:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ed Day.DPI01\SendTo
    [2010/04/06 23:47:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Recent
    [2010/04/06 23:47:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data
    [2010/04/06 23:47:43 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\Start Menu
    [2010/04/06 23:47:43 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents
    [2010/04/06 23:47:43 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\Favorites
    [2010/04/06 23:47:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\Cookies
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Templates
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\PrintHood
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\NetHood
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings
    [2010/04/06 23:47:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Microsoft
    [2010/04/06 23:47:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop
    [2010/04/06 23:42:40 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
    [2010/04/06 23:42:40 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
    [2010/04/06 23:41:29 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
    [2010/04/06 23:39:48 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users.WINDOWS\DRM
    [2010/04/06 23:38:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\My Pictures
    [2010/04/06 23:38:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
    [2010/04/06 23:37:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\My Music
    [2010/04/06 16:30:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu
    [2010/04/06 16:30:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents
    [2010/04/06 16:30:16 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Templates
    [2010/04/06 16:30:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Favorites
    [2010/04/06 16:30:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Desktop
    [2010/04/06 16:29:46 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
    [2010/04/06 16:29:46 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data
    [2010/04/06 15:58:35 | 000,032,840 | ---- | C] (NETGEAR Corporation.) -- C:\WINDOWS\System32\drivers\Ngrpci.sys
    [2010/04/06 05:01:30 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
    [2010/04/06 03:00:48 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
    [2010/04/02 12:21:09 | 000,000,000 | ---D | C] -- C:\bootable
    [2010/04/01 16:49:48 | 000,000,000 | ---D | C] -- C:\68b152f709b480b484
    [2010/04/01 16:44:04 | 000,000,000 | ---D | C] -- C:\ee22816f5bfeabddc659d8bf50207b
    [2010/04/01 12:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\Runtime Software
    [2010/04/01 12:32:22 | 000,000,000 | ---D | C] -- C:\Program Files\Cobian Backup 10
    [2010/03/31 22:10:28 | 000,000,000 | ---D | C] -- C:\Program Files\Crawler
    [2010/03/31 21:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Terminator
    [2010/03/31 16:32:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\DVDVideoSoft
    [2010/03/31 16:32:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple
    [2010/03/31 15:53:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
    [2010/03/30 18:20:48 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
    [2010/03/30 18:18:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
    [2010/03/30 18:18:08 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
    [2010/03/30 17:38:34 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
    [2010/03/30 15:12:22 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/03/30 15:12:19 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft
    [2010/03/29 21:13:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
    [2010/03/29 21:12:06 | 000,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
    [2010/03/29 21:04:29 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
    [2010/03/29 14:51:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
    [2010/03/29 14:35:14 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/03/27 07:36:48 | 000,000,000 | ---D | C] -- C:\Program Files\Pure Networks
    [2010/03/27 07:33:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Pure Networks Shared
    [2010/03/26 18:29:32 | 000,000,000 | ---D | C] -- C:\Program Files\Linksys
    [2010/03/26 18:15:07 | 000,000,000 | ---D | C] -- C:\Program Files\WebEx
    [2010/03/26 16:56:06 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
    [2010/03/26 16:43:32 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic
    [2010/03/25 09:43:34 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Repair
    [2010/03/24 19:00:58 | 000,000,000 | ---D | C] -- C:\Program Files\EMCO
    [2010/03/24 16:01:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8(2)
    [2010/03/17 17:18:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
    [2010/03/17 17:18:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2010/03/15 10:31:52 | 004,032,840 | ---- | C] (CYBERsitter LLC/Solid Oak Software) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\LookInMyPC.exe
    [2010/03/13 21:31:53 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
    [2010/03/13 21:27:09 | 000,000,000 | ---D | C] -- C:\Manual-PCProgram
    [2010/03/12 23:03:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
    [2010/03/10 20:32:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
    [2010/03/10 20:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
    [2010/03/10 20:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
    [220 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]

    ========== Files - Modified Within 90 Days ==========

    [2010/06/05 17:07:32 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/06/05 17:07:32 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/06/05 17:07:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/06/05 17:07:28 | 1072,766,976 | -HS- | M] () -- C:\hiberfil.sys
    [2010/06/05 17:01:57 | 001,835,008 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.dat
    [2010/06/05 17:01:57 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.ini
    [2010/06/05 14:02:52 | 000,002,329 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\SeaTools for Windows.lnk
    [2010/06/05 13:54:22 | 000,456,276 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/06/05 13:54:22 | 000,431,772 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/06/05 13:54:22 | 000,069,962 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/06/05 13:25:27 | 001,976,698 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\Cat.DB
    [2010/06/04 23:44:15 | 000,110,076 | ---- | M] () -- C:\WINDOWS\hpoins08.dat
    [2010/06/04 23:43:01 | 000,000,532 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/06/04 23:42:34 | 000,000,733 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\HP Photosmart Essential.lnk
    [2010/06/04 23:38:38 | 000,000,710 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Scanner and Camera Wizard.lnk
    [2010/06/04 23:35:20 | 000,014,992 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/06/04 23:31:52 | 000,099,048 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/06/04 22:12:00 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Start Menu\Programs\Startup\Corel Registration.lnk
    [2010/06/04 22:11:31 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\CorelDRAW 9.LNK
    [2010/06/04 22:11:30 | 000,001,783 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\COREL.COM.LNK
    [2010/06/04 14:49:20 | 004,032,840 | ---- | M] (CYBERsitter LLC/Solid Oak Software) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\LookInMyPC.exe
    [2010/06/03 23:18:47 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/06/03 20:46:33 | 000,001,843 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Resume your download.lnk
    [2010/06/02 17:17:57 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader 9.lnk
    [2010/06/02 17:04:43 | 000,000,732 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Acrobat_com.lnk
    [2010/06/02 14:56:28 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
    [2010/06/02 13:19:00 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
    [2010/06/02 09:18:49 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Glarysoft Registry Repair.lnk
    [2010/06/01 21:35:18 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
    [2010/06/01 21:35:18 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
    [2010/06/01 21:35:18 | 000,007,443 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
    [2010/06/01 21:35:18 | 000,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
    [2010/06/01 21:31:24 | 000,000,849 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton Installation Files.lnk
    [2010/06/01 21:31:22 | 000,408,088 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton_Download_Manager.exe
    [2010/06/01 13:58:52 | 005,858,960 | -H-- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\IconCache.db
    [2010/05/31 23:56:46 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\E-mail.lnk
    [2010/05/31 15:13:52 | 000,000,659 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\siw_init.xml
    [2010/05/14 12:44:16 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\isolate.ini
    [2010/05/05 21:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdi.sys
    [2010/05/05 21:01:59 | 000,339,504 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdiv.sys
    [2010/05/05 21:01:43 | 000,001,473 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.inf
    [2010/05/05 21:01:43 | 000,001,445 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.inf
    [2010/04/28 22:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\ironx86.sys
    [2010/04/28 22:03:51 | 000,007,438 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.cat
    [2010/04/28 22:03:51 | 000,000,741 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.inf
    [2010/04/26 01:18:40 | 000,007,873 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.cat
    [2010/04/24 04:31:04 | 000,003,373 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.inf
    [2010/04/21 20:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.sys
    [2010/04/21 19:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.sys
    [2010/04/21 19:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.sys
    [2010/04/21 19:29:50 | 000,007,442 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.cat
    [2010/04/21 19:29:50 | 000,007,438 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.cat
    [2010/04/21 19:29:50 | 000,001,388 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.inf
    [2010/04/21 19:29:50 | 000,001,382 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.inf
    [2010/04/11 16:26:16 | 000,000,523 | ---- | M] () -- C:\WINDOWS\ATICIM.INI
    [2010/04/10 09:46:02 | 000,000,328 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My eBay Summary.url
    [2010/04/08 22:46:25 | 000,000,697 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My Scans.lnk
    [2010/04/07 00:16:46 | 000,000,433 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\FTP Commander.lnk
    [2010/04/06 23:55:48 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Shortcut to Internet.lnk
    [2010/04/06 23:47:05 | 000,013,588 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
    [2010/04/06 23:45:20 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
    [2010/04/06 23:43:17 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
    [2010/04/06 23:40:46 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
    [2010/04/06 23:40:46 | 000,000,000 | ---- | M] () -- C:\WINDOWS\control.ini
    [2010/04/06 23:40:36 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
    [2010/04/06 23:40:36 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
    [2010/04/06 23:40:21 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
    [2010/04/06 23:39:34 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest
    [2010/04/06 23:39:34 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
    [2010/04/06 23:38:46 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2010/04/06 23:36:04 | 000,000,321 | -HS- | M] () -- C:\boot.ini
    [2010/04/06 23:06:25 | 000,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
    [2010/04/06 23:06:25 | 000,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini
    [2010/04/06 16:30:28 | 000,000,231 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/03/30 17:41:09 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Mozilla Firefox.lnk
    [2010/03/29 14:35:19 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/03/26 16:56:17 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Spybot - Search & Destroy.lnk
    [2010/03/25 10:59:32 | 000,000,862 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malware Destroyer.lnk
    [220 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]
     
  5. 2010/06/05
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    Here is OTL 2nd 1/2;

    ========== Files Created - No Company Name ==========

    [2010/06/05 13:57:27 | 000,002,329 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\SeaTools for Windows.lnk
    [2010/06/04 23:56:32 | 000,000,710 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Scanner and Camera Wizard.lnk
    [2010/06/04 23:42:33 | 000,000,733 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\HP Photosmart Essential.lnk
    [2010/06/04 23:35:32 | 000,000,734 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\hpzinstall.log
    [2010/06/04 23:35:29 | 000,110,076 | ---- | C] () -- C:\WINDOWS\hpoins08.dat
    [2010/06/04 23:35:29 | 000,007,577 | ---- | C] () -- C:\WINDOWS\hpomdl08.dat
    [2010/06/04 22:12:00 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Start Menu\Programs\Startup\Corel Registration.lnk
    [2010/06/04 22:11:30 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\COREL.COM.LNK
    [2010/06/04 22:09:47 | 000,028,252 | ---- | C] () -- C:\WINDOWS\corelpf.lrs
    [2010/06/04 22:09:27 | 000,039,095 | ---- | C] () -- C:\WINDOWS\iccsigs.dat
    [2010/06/04 22:09:26 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
    [2010/06/03 20:46:33 | 000,001,843 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Resume your download.lnk
    [2010/06/03 15:47:55 | 000,000,328 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My eBay Summary.url
    [2010/06/02 17:04:42 | 000,000,732 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Acrobat_com.lnk
    [2010/06/02 17:03:57 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader 9.lnk
    [2010/06/02 13:18:21 | 001,976,698 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\Cat.DB
    [2010/06/02 09:27:51 | 000,007,787 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.cat
    [2010/06/02 09:27:51 | 000,007,368 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.cat
    [2010/06/02 09:27:51 | 000,001,473 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.inf
    [2010/06/02 09:27:51 | 000,001,445 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.inf
    [2010/06/02 09:27:50 | 000,007,873 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.cat
    [2010/06/02 09:27:50 | 000,007,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.cat
    [2010/06/02 09:27:50 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.cat
    [2010/06/02 09:27:50 | 000,007,425 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.cat
    [2010/06/02 09:27:50 | 000,003,373 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.inf
    [2010/06/02 09:27:50 | 000,002,793 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.inf
    [2010/06/02 09:27:50 | 000,001,388 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.inf
    [2010/06/02 09:27:50 | 000,001,382 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.inf
    [2010/06/02 09:27:49 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.cat
    [2010/06/02 09:27:49 | 000,007,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.cat
    [2010/06/02 09:27:49 | 000,001,754 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.inf
    [2010/06/02 09:27:49 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.inf
    [2010/06/02 09:27:05 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\isolate.ini
    [2010/06/01 21:35:19 | 000,007,443 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
    [2010/06/01 21:35:19 | 000,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
    [2010/06/01 21:35:01 | 000,002,265 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
    [2010/06/01 12:25:18 | 001,835,008 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.dat
    [2010/05/31 23:56:46 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\E-mail.lnk
    [2010/05/31 22:00:22 | 1072,766,976 | -HS- | C] () -- C:\hiberfil.sys
    [2010/05/31 15:13:52 | 000,000,659 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\siw_init.xml
    [2010/05/31 13:01:24 | 000,000,849 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton Installation Files.lnk
    [2010/05/31 11:56:51 | 000,009,801 | ---- | C] () -- C:\WINDOWS\System32\nvdisp.nvu
    [2010/05/31 09:58:57 | 000,613,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm
    [2010/05/31 09:58:57 | 000,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav
    [2010/05/31 09:58:57 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav
    [2010/05/31 09:58:57 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav
    [2010/05/31 09:58:57 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav
    [2010/05/31 09:58:57 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav
    [2010/05/31 09:58:57 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav
    [2010/05/31 09:58:57 | 000,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav
    [2010/05/31 09:58:57 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav
    [2010/05/31 09:58:57 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav
    [2010/05/31 09:58:57 | 000,010,457 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.hta
    [2010/05/31 09:58:57 | 000,006,769 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf
    [2010/05/31 09:58:57 | 000,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css
    [2010/05/31 09:58:57 | 000,000,855 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf
    [2010/05/31 09:58:57 | 000,000,420 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmploc.js
    [2010/05/31 09:58:56 | 000,017,272 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf
    [2010/05/31 09:58:56 | 000,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif
    [2010/05/31 09:58:56 | 000,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif
    [2010/05/31 09:58:56 | 000,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif
    [2010/05/31 09:58:56 | 000,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif
    [2010/05/31 09:58:56 | 000,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif
    [2010/05/31 09:58:56 | 000,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif
    [2010/05/31 09:58:56 | 000,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif
    [2010/05/31 09:58:56 | 000,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif
    [2010/05/31 09:58:56 | 000,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif
    [2010/05/31 09:58:54 | 000,300,969 | ---- | C] () -- C:\WINDOWS\System32\dllcache\viz.wmv
    [2010/05/31 09:58:54 | 000,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif
    [2010/05/31 09:58:54 | 000,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif
    [2010/05/31 09:58:54 | 000,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif
    [2010/05/31 09:58:54 | 000,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif
    [2010/05/31 09:58:54 | 000,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif
    [2010/05/31 09:58:54 | 000,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif
    [2010/05/31 09:58:54 | 000,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif
    [2010/05/31 09:58:53 | 000,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js
    [2010/05/31 09:58:53 | 000,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif
    [2010/05/31 09:58:53 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif
    [2010/05/31 09:58:53 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif
    [2010/05/31 09:58:53 | 000,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif
    [2010/05/31 09:58:51 | 000,572,557 | ---- | C] () -- C:\WINDOWS\System32\dllcache\rtuner.wmv
    [2010/05/31 09:58:51 | 000,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm
    [2010/05/31 09:58:51 | 000,000,908 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf
    [2010/05/31 09:58:50 | 000,077,307 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm
    [2010/05/31 09:58:49 | 000,375,519 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nuskin.wmv
    [2010/05/31 09:58:49 | 000,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip
    [2010/05/31 09:58:49 | 000,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip
    [2010/05/31 09:58:48 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
    [2010/05/31 09:58:45 | 000,097,117 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.hlp
    [2010/05/31 09:58:45 | 000,018,286 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf
    [2010/05/31 09:58:45 | 000,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif
    [2010/05/31 09:58:45 | 000,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif
    [2010/05/31 09:58:45 | 000,001,885 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.cnt
    [2010/05/31 09:58:44 | 000,457,607 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mdlib.wmv
    [2010/05/31 09:58:41 | 000,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js
    [2010/05/31 09:58:36 | 000,381,425 | ---- | C] () -- C:\WINDOWS\System32\dllcache\copycd.wmv
    [2010/05/31 09:58:36 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
    [2010/05/31 09:58:35 | 000,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css
    [2010/05/31 09:58:35 | 000,008,298 | ---- | C] () -- C:\WINDOWS\System32\dllcache\contents.htm
    [2010/05/31 09:58:35 | 000,006,878 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.js
    [2010/05/31 09:58:35 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif
    [2010/05/31 09:58:35 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif
    [2010/05/31 09:58:35 | 000,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif
    [2010/05/31 09:58:35 | 000,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif
    [2010/05/31 09:58:35 | 000,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif
    [2010/05/31 09:58:34 | 000,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif
    [2010/05/31 09:57:16 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
    [2010/04/11 16:25:43 | 000,000,523 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
    [2010/04/11 16:01:07 | 000,002,983 | R--- | C] () -- C:\WINDOWS\System32\net82557.din
    [2010/04/07 00:16:46 | 000,000,433 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\FTP Commander.lnk
    [2010/04/06 23:55:48 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Shortcut to Internet.lnk
    [2010/04/06 23:49:57 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My Computer.lnk
    [2010/04/06 23:47:45 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.ini
    [2010/04/06 23:47:43 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Ed Day.DPI01\NTUSER.DAT.LOG
    [2010/04/06 23:47:06 | 000,013,588 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
    [2010/04/06 23:45:20 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
    [2010/04/06 23:43:17 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2010/04/06 23:43:10 | 000,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
    [2010/04/06 23:42:35 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
    [2010/04/06 23:42:35 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
    [2010/04/06 23:42:31 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
    [2010/04/06 23:42:11 | 000,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
    [2010/04/06 23:42:10 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
    [2010/04/06 23:42:03 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
    [2010/04/06 23:42:01 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
    [2010/04/06 23:42:00 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
    [2010/04/06 23:41:51 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
    [2010/04/06 23:41:47 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
    [2010/04/06 23:41:32 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
    [2010/04/06 23:41:29 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_864.nls
    [2010/04/06 23:41:29 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_862.nls
    [2010/04/06 23:41:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_870.nls
    [2010/04/06 23:41:28 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20949.nls
    [2010/04/06 23:41:28 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_858.nls
    [2010/04/06 23:41:28 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_708.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28596.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21027.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21025.nls
    [2010/04/06 23:41:27 | 000,180,770 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20932.nls
    [2010/04/06 23:41:27 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20936.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20924.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20880.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20871.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20838.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20833.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20424.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20423.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20420.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20297.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20290.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20285.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20284.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20280.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20278.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20277.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20273.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20269.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20108.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20107.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20106.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20105.nls
    [2010/04/06 23:41:25 | 000,189,986 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1361.nls
    [2010/04/06 23:41:25 | 000,187,938 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20005.nls
    [2010/04/06 23:41:25 | 000,186,402 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20001.nls
    [2010/04/06 23:41:25 | 000,185,378 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20003.nls
    [2010/04/06 23:41:25 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20004.nls
    [2010/04/06 23:41:25 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20000.nls
    [2010/04/06 23:41:25 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20002.nls
    [2010/04/06 23:41:25 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1149.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1148.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1147.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1146.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1145.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1144.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1143.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1142.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1141.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1140.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1047.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10021.nls
    [2010/04/06 23:41:23 | 000,195,618 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10002.nls
    [2010/04/06 23:41:23 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10003.nls
    [2010/04/06 23:41:23 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10008.nls
    [2010/04/06 23:41:23 | 000,162,850 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10001.nls
    [2010/04/06 23:41:23 | 000,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
    [2010/04/06 23:41:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10005.nls
    [2010/04/06 23:41:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10004.nls
    [2010/04/06 23:41:22 | 000,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
    [2010/04/06 23:40:46 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
    [2010/04/06 23:40:36 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
    [2010/04/06 23:40:36 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
    [2010/04/06 23:40:34 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
    [2010/04/06 23:08:05 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
    [2010/04/06 23:08:05 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
    [2010/04/06 23:07:32 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
    [2010/04/06 23:07:10 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
    [2010/04/06 23:07:10 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
    [2010/04/06 23:07:05 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
    [2010/04/06 23:06:40 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2010/04/06 23:05:28 | 000,227,840 | ---- | C] () -- C:\WINDOWS\System32\avtapi.dll
    [2010/04/06 23:05:25 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
    [2010/04/06 23:05:24 | 000,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
    [2010/04/06 23:05:24 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
    [2010/04/06 23:05:24 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
    [2010/04/06 23:05:24 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
    [2010/04/06 23:05:24 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
    [2010/04/06 23:05:24 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
    [2010/04/06 23:05:24 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
    [2010/04/06 23:05:24 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
    [2010/04/06 23:05:24 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
    [2010/04/06 23:05:24 | 000,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
    [2010/04/06 23:05:24 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
    [2010/04/06 23:05:24 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
    [2010/04/06 23:05:23 | 000,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
    [2010/04/06 23:05:23 | 000,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
    [2010/04/06 23:05:23 | 000,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
    [2010/04/06 23:05:23 | 000,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
    [2010/04/06 23:05:23 | 000,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
    [2010/04/06 23:05:23 | 000,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
    [2010/04/06 23:05:22 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
    [2010/04/06 23:05:22 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
    [2010/04/06 23:05:21 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
    [2010/04/06 23:05:17 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
    [2010/04/06 15:56:00 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
    [2010/04/06 15:55:52 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
    [2010/04/06 15:55:52 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
    [2010/04/06 15:55:50 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
    [2010/04/06 15:55:50 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
    [2010/04/06 15:55:46 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls
    [2010/04/06 15:55:46 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS
    [2010/04/06 15:55:45 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_852.nls
    [2010/04/06 15:55:45 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
    [2010/04/06 15:55:43 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20127.nls
    [2010/04/06 15:55:43 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls
    [2010/04/06 15:55:40 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
    [2010/04/06 15:55:27 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
    [2010/04/06 15:55:27 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
    [2010/04/06 15:55:27 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
    [2010/04/06 15:55:27 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
    [2010/04/06 15:55:27 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
    [2010/04/06 15:55:27 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
    [2010/04/06 15:55:27 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
    [2010/04/06 15:55:27 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
    [2010/04/06 15:54:42 | 000,099,048 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/04/06 15:52:02 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
    [2010/03/30 17:38:42 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Mozilla Firefox.lnk
    [2010/03/29 14:35:19 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/03/26 16:56:17 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Spybot - Search & Destroy.lnk
    [2010/03/25 10:59:32 | 000,000,862 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malware Destroyer.lnk
    [2010/03/25 09:43:35 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Glarysoft Registry Repair.lnk
    [2010/03/24 14:05:27 | 000,000,980 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\20xYJkS83BHk4
    [2009/09/22 09:54:08 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2006/02/28 05:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
    [2006/02/28 05:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
    [2006/02/28 05:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
    [2006/02/28 05:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
    [2006/02/28 05:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
    [2003/10/06 14:16:00 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\nvcod.dll
    [2001/07/06 16:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

    ========== LOP Check ==========

    [2010/06/02 09:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\GlarySoft
    [2010/06/04 23:57:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Image Zone Express
    [2010/06/04 23:57:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Printer Info Cache
    [2010/06/01 12:18:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Tific

    ========== Purity Check ==========


    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.exe >


    < MD5 for: AGP440.SYS >
    [2006/02/28 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
    [2010/05/31 17:36:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
    [2010/05/31 17:36:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
    [2010/05/31 17:36:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sp3.cab:AGP440.sys
    [2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
    [2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
    [2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
    [2004/08/03 16:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
    [2004/08/03 16:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\ReinstallBackups\0017\DriverFiles\i386\AGP440.SYS

    < MD5 for: ATAPI.SYS >
    [2006/02/28 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
    [2010/05/31 17:36:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
    [2010/05/31 17:36:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
    [2010/05/31 17:36:23 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sp3.cab:atapi.sys
    [2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
    [2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
    [2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
    [2006/02/28 05:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

    < MD5 for: EVENTLOG.DLL >
    [2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
    [2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
    [2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
    [2006/02/28 05:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

    < MD5 for: EXPLORER.EXE >
    [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
    [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
    [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
    [2006/02/28 05:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

    < MD5 for: NETLOGON.DLL >
    [2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
    [2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
    [2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
    [2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
    [2009/02/06 11:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
    [2006/02/28 05:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

    < MD5 for: SCECLI.DLL >
    [2006/02/28 05:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
    [2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
    [2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
    [2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

    < MD5 for: USERINIT.EXE >
    [2006/02/28 05:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
    [2008/04/13 17:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
    [2008/04/13 17:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\userinit.exe
    [2008/04/13 17:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

    < %systemroot%\*. /mp /s >

    < %systemroot%\system32\*.dll /lockedfiles >
    [220 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\system32\drivers\*.sys /lockedfiles >

    < %systemroot%\System32\config\*.sav >
    [2010/04/06 15:52:07 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
    [2010/04/06 15:52:07 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
    [2010/04/06 15:52:07 | 000,901,120 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
    < End of report >
     
    Last edited: 2010/06/05
  6. 2010/06/05
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    And now Extra:

    OTL Extras logfile created on: 6/5/2010 5:14:02 PM - Run 1
    OTL by OldTimer - Version 3.2.5.3 Folder = C:\Documents and Settings\Ed Day.DPI01\Desktop\My Downloads
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1,023.00 Mb Total Physical Memory | 623.00 Mb Available Physical Memory | 61.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 76.34 Gb Total Space | 50.05 Gb Free Space | 65.56% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    Drive E: | 76.33 Gb Total Space | 71.70 Gb Free Space | 93.94% Space Free | Partition Type: NTFS
    Drive F: | 72.72 Gb Total Space | 54.20 Gb Free Space | 74.54% Space Free | Partition Type: NTFS
    Drive G: | 76.32 Gb Total Space | 62.25 Gb Free Space | 81.57% Space Free | Partition Type: NTFS
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: DPI01
    Current User Name: Ed Day
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 1
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "E:\FTP\ftpcomm.exe" = E:\FTP\ftpcomm.exe:*:Enabled:ftpcomm -- (Internetsoft)
    "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
    "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- ()
    "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
    "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Development Company, L.P.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{05C56753-F144-44BC-BA67-83CC5DBF395C}" = F300
    "{0BF5FBE7-3907-4A1F-9E48-8B66E52850D6}" = TrayApp
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{1E1F1E70-14D8-4380-8652-BD1A895A7D65}" = Status
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{20C53FA2-4307-4671-A93F-9463B29DFCF1}" = Symantec Technical Support Web Controls
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
    "{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
    "{31263605-FC84-4787-B847-BA445B147E24}" = ScannerCopy
    "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
    "{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
    "{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
    "{4BE53DB2-C1F2-44D1-A9AB-1630BA7F2AF1}" = SolutionCenter
    "{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
    "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
    "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
    "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
    "{71D9B000-CD43-4DE9-9729-49434415B8F7}" = F300Trb
    "{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
    "{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{98613C99-1399-416C-A07C-1EE1C585D872}" = SeaTools for Windows
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
    "{AAA11090-6E99-4655-AAF5-57EB5F677D0C}" = MarketResearch
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
    "{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
    "{BF4E9ED0-EF26-4A4C-A123-6A6A1ABEE411}" = DocProc
    "{C6812939-B117-48E6-A3BA-1709C14A3C8C}" = Scan
    "{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
    "{C98E8D9D-21DE-4F87-A9B7-142BB89840FC}" = Toolbox
    "{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}" = HP Photosmart Essential
    "{DEBB2986-15B0-4D28-95FA-5C966A396589}" = HPProductAssistant
    "{E5966E4C-0A93-4F59-A981-BD3173D4799F}" = F300_Help
    "{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}" = HP PSC & OfficeJet 6.1.A
    "{EC2715CE-C182-483C-84CC-81D7D914CF14}" = WebReg
    "{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
    "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
    "{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
    "{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}" = Windows Resource Kit Tools
    "{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "Corel Applications" = Corel Applications
    "HP Imaging Device Functions" = HP Imaging Device Functions 6.1
    "HP Solution Center & Imaging Support Tools" = HP Solution Center and Imaging Support Tools 6.1
    "HPExtendedCapabilities" = HP Extended Capabilities 6.1
    "ie8" = Windows Internet Explorer 8
    "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
    "N360" = Norton Security Suite
    "NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
    "NVIDIA Display Driver" = NVIDIA Display Driver
    "PROSet" = Intel(R) PRO Ethernet Adapter and Software
    "Registry Repair_is1" = Glarysoft Registry Repair 2.7
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinLiveSuite_Wave3" = Windows Live Essentials

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 4/6/2010 7:30:33 PM | Computer Name = MACHINENAME | Source = LoadPerf | ID = 3001
    Description = The performance counter name string value in the registry is incorrectly
    formatted.
    The bogus string is 1848, the bogus index value is the first DWORD in Data section
    while the last valid index values are the second and third DWORD in Data section.

    Error - 4/6/2010 7:30:33 PM | Computer Name = MACHINENAME | Source = LoadPerf | ID = 3001
    Description = The performance counter name string value in the registry is incorrectly
    formatted.
    The bogus string is 1848, the bogus index value is the first DWORD in Data section
    while the last valid index values are the second and third DWORD in Data section.

    Error - 4/7/2010 2:36:23 AM | Computer Name = DPI01 | Source = LoadPerf | ID = 3001
    Description = The performance counter name string value in the registry is incorrectly
    formatted.
    The bogus string is 1848, the bogus index value is the first DWORD in Data section
    while the last valid index values are the second and third DWORD in Data section.

    Error - 5/31/2010 2:10:22 PM | Computer Name = DPI01 | Source = MsiInstaller | ID = 10005
    Description = Product: Windows Live Sign-in Assistant -- The installer has encountered
    an unexpected error installing this package. This may indicate a problem with this
    package. The error code is 2753. The arguments are: SDKCOMPONENTS_PPCRL_WLLOGINPROXY.EXE,
    ,

    Error - 5/31/2010 4:10:25 PM | Computer Name = DPI01 | Source = Application Error | ID = 1005
    Description = Windows cannot access the file C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\7190B588\4.0.0.127\ccL90U.dll
    for one of the following reasons: there is a problem with the network connection,
    the disk that the file is stored on, or the storage drivers installed on this computer;
    or the disk is missing. Windows closed the program Symantec Library because of
    this error. Program: Symantec Library File: C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\7190B588\4.0.0.127\ccL90U.dll

    The
    error value is listed in the Additional Data section. User Action 1. Open the file
    again. This situation might be a temporary problem that corrects itself when the
    program runs again. 2. If the file still cannot be accessed and - It is on the network,
    your network administrator should verify that there is not a problem with the network
    and that the server can be contacted. - It is on a removable disk, for example,
    a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
    3.
    Check and repair the file system by running CHKDSK. To run CHKDSK, click Start,
    click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F,
    and then press ENTER. 4. If the problem persists, restore the file from a backup
    copy. 5. Determine whether other files on the same disk can be opened. If not, the
    disk might be damaged. If it is a hard disk, contact your administrator or computer
    hardware vendor for further assistance. Additional Data Error value: C0000015 Disk
    type: 3

    Error - 5/31/2010 4:10:28 PM | Computer Name = DPI01 | Source = Application Error | ID = 1000
    Description = Faulting application NC4.exe, version 4.0.0.127, faulting module ccL90U.dll,
    version 109.0.2.14, fault address 0x00071dbb.

    Error - 6/5/2010 2:57:33 AM | Computer Name = DPI01 | Source = Application Error | ID = 1000
    Description = Faulting application hp_ize.exe, version 1.12.0.46, faulting module
    hp_ize.exe, version 1.12.0.46, fault address 0x00037265.

    Error - 6/5/2010 2:57:46 AM | Computer Name = DPI01 | Source = Application Error | ID = 1000
    Description = Faulting application hp_ize.exe, version 1.12.0.46, faulting module
    hp_ize.exe, version 1.12.0.46, fault address 0x00037265.

    Error - 6/5/2010 8:00:28 PM | Computer Name = DPI01 | Source = Application Hang | ID = 1002
    Description = Hanging application OTL.exe, version 3.2.5.3, hang module hungapp,
    version 0.0.0.0, hang address 0x00000000.

    [ System Events ]
    Error - 6/5/2010 3:07:02 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 3:07:02 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 3:07:03 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 3:07:03 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 3:07:03 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 3:07:03 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 3:07:03 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 3:07:03 AM | Computer Name = DPI01 | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 6/5/2010 5:58:08 PM | Computer Name = DPI01 | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.

    Error - 6/5/2010 5:58:41 PM | Computer Name = DPI01 | Source = Disk | ID = 262151
    Description = The device, \Device\Harddisk0\D, has a bad block.


    < End of report >
     
  7. 2010/06/05
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    Geeze, I guess you know everything about my computer now. But that's just fine if you can help me fix it. heeheehee.DPI.
     
  8. 2010/06/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    First part, OTL.txt seems to be cutoff at the bottom. It should end with:
    Reopen your OTL.txt file, then look at the end of your reply #4 and post whatever follows this:
     
  9. 2010/06/05
    retiredlearner

    retiredlearner SuperGeek WindowsBBS Team Member

    Joined:
    2004/06/25
    Messages:
    7,214
    Likes Received:
    514
    Hi DPI Graphics, Do you want to completely uninstall the Tool bar or just not have it display. If you go to View > Toolbars > then uncheck Ask (or whatever it comes packaged in) and you won't have it on the screen. I have it and use it when I want to and uncheck it when I don't. Neil.:D
     
  10. 2010/06/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Ask toolbar is considered as so called foistware - a program, which installs itself without your knowledge, or approval, often bundled with some other legit program.
    As such, it belongs gray area of security/privacy.
    That's officially.

    Personally speaking, it's a piece of garbage, which shouldn't be present on any clean computer.
     
  11. 2010/06/05
    retiredlearner

    retiredlearner SuperGeek WindowsBBS Team Member

    Joined:
    2004/06/25
    Messages:
    7,214
    Likes Received:
    514
    Hi Broni, I had it come with a Nero Package and thought I would try it out. Hence my Post about using Toolbar to uncheck it. I have no problems - so far. Neil.:cool:
     
  12. 2010/06/05
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    Did you see where I corrected post#4? Since it was so big, I just edited it with the new data. I really don't know where to go from here. DPI.
     
    Last edited: 2010/06/05
  13. 2010/06/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I understand what you're saying, however to me it's about principals. If some application must use "drive-by-install" to get on your computer, it's a big NO-NO to me.
    I never said, Ask was any kind of malicious program.
    However, it's not always easy to remove the sucker, which definitely adds to my opinion about it.
     
  14. 2010/06/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    DPI Graphics
    Let me see....
     
  15. 2010/06/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK. Cool :)


    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      O2 - BHO: (Ask  and Record Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
      O3 - HKLM\..\Toolbar: (Ask and Record Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
      O3 - HKCU\..\Toolbar\WebBrowser: (Ask and Record Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
      [2010/06/05 12:10:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\Ask & Record Toolbar
      [2010/06/05 11:53:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\AskToolbar
      
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [resethosts]
      [Reboot]
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
     
  16. 2010/06/05
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    Here is the results log from the fix.

    All processes killed
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
    C:\WINDOWS\Ask & Record Toolbar folder moved successfully.
    C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\AskToolbar folder moved successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Administrator.DPI01
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 373952 bytes

    User: All Users

    User: All Users.WINDOWS

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User.WINDOWS
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 41620 bytes

    User: Desktop

    User: Documents

    User: Ed Day
    ->Temp folder emptied: 4506861 bytes
    ->Temporary Internet Files folder emptied: 29634006 bytes
    ->Java cache emptied: 17801213 bytes

    User: Ed Day.DPI01
    ->Temp folder emptied: 1128162482 bytes
    ->Temporary Internet Files folder emptied: 78708917 bytes
    ->Flash cache emptied: 47556 bytes

    User: EDDAY~1~DPI

    User: LocalService
    ->Temp folder emptied: 66016 bytes
    ->Temporary Internet Files folder emptied: 47146683 bytes
    ->Flash cache emptied: 15683 bytes

    User: LocalService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Marci

    User: NetworkService
    ->Temp folder emptied: 701818 bytes
    ->Temporary Internet Files folder emptied: 17958704 bytes
    ->Java cache emptied: 927 bytes
    ->Flash cache emptied: 33296 bytes

    User: NetworkService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Owner
    ->Temp folder emptied: 744515507 bytes
    ->Temporary Internet Files folder emptied: 86266837 bytes
    ->Java cache emptied: 109706333 bytes
    ->FireFox cache emptied: 62757612 bytes
    ->Flash cache emptied: 127765 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 5485744 bytes
    %systemroot%\System32 .tmp files removed: 62386001 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1894217 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 13233733 bytes

    Total Files Cleaned = 2,300.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: Administrator.DPI01

    User: All Users

    User: All Users.WINDOWS

    User: Default User

    User: Default User.WINDOWS
    ->Flash cache emptied: 0 bytes

    User: Desktop

    User: Documents

    User: Ed Day

    User: Ed Day.DPI01
    ->Flash cache emptied: 0 bytes

    User: EDDAY~1~DPI

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: LocalService.NT AUTHORITY

    User: Marci

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: NetworkService.NT AUTHORITY

    User: Owner
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
    HOSTS file reset successfully

    OTL by OldTimer - Version 3.2.5.3 log created on 06052010_213014

    Files\Folders moved on Reboot...
    File\Folder C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temp\~DF543C.tmp not found!
    File\Folder C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temp\~DF5462.tmp not found!
    File\Folder C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temp\~DF5B35.tmp not found!
    File\Folder C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temp\~DF5B6E.tmp not found!
    C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temporary Internet Files\Content.IE5\W50G9BHM\93378-cant-unistall-ask-record-toolbar[1].html moved successfully.
    C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temporary Internet Files\Content.IE5\SQD5Z98A\ads[10].htm moved successfully.
    C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temporary Internet Files\Content.IE5\SQD5Z98A\WV-GunShop[1].htm moved successfully.
    C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temporary Internet Files\Content.IE5\N43UOMLC\windowsbbs_com[1].htm moved successfully.
    C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temporary Internet Files\Content.IE5\LX5R88UL\iframescript[2].htm moved successfully.
    C:\Documents and Settings\Ed Day.DPI01\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
    File\Folder C:\WINDOWS\temp\Perflib_Perfdata_7d8.dat not found!

    Registry entries deleted on Reboot...
     
  17. 2010/06/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Is Ask bar still bothering you?
     
  18. 2010/06/06
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    I still need to run the OTL scan after the fix. Do I need any parameters for this scan?DPI.
     
  19. 2010/06/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No, just click on Quick Scan button.
     
  20. 2010/06/06
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    Here it is. The whole report this time(I hope).
    Part 1:

    OTL logfile created on: 6/5/2010 10:41:25 PM - Run 2
    OTL by OldTimer - Version 3.2.5.3 Folder = C:\Documents and Settings\Ed Day.DPI01\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1,023.00 Mb Total Physical Memory | 640.00 Mb Available Physical Memory | 63.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 90.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 76.34 Gb Total Space | 52.28 Gb Free Space | 68.49% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    Drive E: | 76.33 Gb Total Space | 71.70 Gb Free Space | 93.94% Space Free | Partition Type: NTFS
    Drive F: | 72.72 Gb Total Space | 54.20 Gb Free Space | 74.54% Space Free | Partition Type: NTFS
    Drive G: | 76.32 Gb Total Space | 62.25 Gb Free Space | 81.57% Space Free | Partition Type: NTFS
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: DPI01
    Current User Name: Ed Day
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2010/06/05 17:13:06 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\OTL.exe
    PRC - [2010/02/25 17:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\ccsvchst.exe
    PRC - [2008/04/13 17:12:30 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntvdm.exe
    PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2005/03/14 12:05:02 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
    PRC - [1998/07/23 00:06:26 | 000,067,584 | ---- | M] (IntelliQuest Communications, Inc.) -- C:\Program Files\Corel\Graphics9\Register\Remind32.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/06/05 17:13:06 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\OTL.exe
    MOD - [2010/05/13 22:35:01 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\asoehook.dll
    MOD - [2009/07/12 01:02:02 | 000,653,120 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\microsoft.vc90.crt\msvcr90.dll
    MOD - [2009/07/12 01:02:00 | 000,569,664 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\microsoft.vc90.crt\msvcp90.dll
    MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


    ========== Win32 Services (SafeList) ==========

    SRV - [2010/02/25 17:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe -- (N360)
    SRV - [2008/01/29 16:09:02 | 000,394,704 | ---- | M] (Symantec, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe -- (Symantec RemoteAssist)
    SRV - [2005/03/14 12:05:02 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


    ========== Driver Services (SafeList) ==========

    DRV - [2010/06/01 21:35:18 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
    DRV - [2010/05/31 01:00:00 | 001,347,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100605.003\NAVEX15.SYS -- (NAVEX15)
    DRV - [2010/05/31 01:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
    DRV - [2010/05/31 01:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
    DRV - [2010/05/31 01:00:00 | 000,085,552 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100605.003\NAVENG.SYS -- (NAVENG)
    DRV - [2010/05/28 12:33:19 | 000,331,640 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100528.003\IDSXpx86.sys -- (IDSxpx86)
    DRV - [2010/05/05 21:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0402000.00C\SYMTDI.SYS -- (SYMTDI)
    DRV - [2010/04/29 10:44:04 | 000,537,136 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100429.001\BHDrvx86.sys -- (BHDrvx86)
    DRV - [2010/04/28 22:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\Ironx86.SYS -- (SymIRON)
    DRV - [2010/04/21 20:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\SYMEFA.SYS -- (SymEFA)
    DRV - [2010/04/21 19:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\N360\0402000.00C\SRTSP.SYS -- (SRTSP)
    DRV - [2010/04/21 19:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
    DRV - [2010/02/25 17:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\ccHPx86.sys -- (ccHP)
    DRV - [2009/10/14 20:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0402000.00C\SYMDS.SYS -- (SymDS)
    DRV - [2003/10/06 14:16:00 | 001,550,043 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
    DRV - [2003/03/05 12:19:28 | 000,015,840 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PFMODNT.SYS -- (PfModNT)
    DRV - [2002/03/11 10:34:32 | 000,005,376 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\DELL\drivers\R60303\TVTGAA01\BIN\atiicdxx.sys -- (ATICDSDr)
    DRV - [2001/08/17 05:12:20 | 000,032,840 | ---- | M] (NETGEAR Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Ngrpci.sys -- (ngrpci)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hei.net/
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/06/02 13:50:29 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/06/01 21:36:37 | 000,000,000 | ---D | M]

    [2010/03/30 17:38:38 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2007/07/26 12:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml

    O1 HOSTS File: ([2010/06/05 21:33:53 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: ::1 localhost
    O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
    O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
    O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
    O4 - HKCU..\Run: [NvMediaCenter] C:\WINDOWS\System32\NVMCTRAY.DLL (NVIDIA Corporation)
    O4 - Startup: C:\Documents and Settings\Ed Day.DPI01\Start Menu\Programs\Startup\Corel Registration.lnk = C:\Program Files\Corel\Graphics9\Register\Remind32.exe (IntelliQuest Communications, Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.69.150 68.87.85.102
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/03/11 17:13:16 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2009/03/11 17:13:16 | 000,000,000 | ---- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 90 Days ==========

    [2010/06/05 21:30:14 | 000,000,000 | ---D | C] -- C:\_OTL
    [2010/06/05 16:45:40 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\OTL.exe
    [2010/06/04 23:57:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Printer Info Cache
    [2010/06/04 23:57:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Image Zone Express
    [2010/06/04 23:43:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\HP
    [2010/06/04 23:35:05 | 000,098,304 | ---- | C] (Hewlett Packard Company) -- C:\WINDOWS\System32\hpzjsn01.dll
    [2010/06/04 23:11:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\FFOutput
    [2010/06/04 23:11:31 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
    [2010/06/04 22:12:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Corel
    [2010/06/04 22:11:02 | 000,607,744 | ---- | C] (Digital Equipment Corp.) -- C:\WINDOWS\System32\Decslib.dll
    [2010/06/04 22:09:23 | 000,909,312 | ---- | C] (Apple Computer Inc.) -- C:\WINDOWS\System32\qd3d.dll
    [2010/06/04 22:09:13 | 000,168,448 | ---- | C] (WexTech Systems, Inc.) -- C:\WINDOWS\System32\Awrtl30.dll
    [2010/06/04 22:09:13 | 000,100,864 | ---- | C] (Corel Corporation Limited) -- C:\WINDOWS\System32\awpe.dll
    [2010/06/04 22:09:02 | 000,245,760 | ---- | C] (Corel Corporation) -- C:\WINDOWS\System32\Sccomp91.dll
    [2010/06/04 22:09:02 | 000,225,280 | ---- | C] (Corel Corporation) -- C:\WINDOWS\System32\Scint91.dll
    [2010/06/04 22:09:02 | 000,110,592 | ---- | C] (Corel Corporation) -- C:\WINDOWS\System32\Sccres91.dll
    [2010/06/04 15:12:40 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Resource Kits
    [2010/06/04 14:49:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop\LookInMyPC
    [2010/06/03 00:01:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NCH Software
    [2010/06/02 18:08:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\FLVService
    [2010/06/02 17:02:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader 9 Installer
    [2010/06/02 16:55:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\nos
    [2010/06/02 16:54:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Google
    [2010/06/02 16:54:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Google
    [2010/06/02 16:46:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
    [2010/06/02 16:45:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Google
    [2010/06/02 16:45:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Adobe
    [2010/06/02 16:45:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NOS
    [2010/06/02 14:54:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
    [2010/06/02 14:29:00 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
    [2010/06/02 09:27:51 | 000,361,904 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdi.sys
    [2010/06/02 09:27:51 | 000,339,504 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdiv.sys
    [2010/06/02 09:27:50 | 000,328,752 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.sys
    [2010/06/02 09:27:50 | 000,325,680 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.sys
    [2010/06/02 09:27:50 | 000,173,104 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.sys
    [2010/06/02 09:27:50 | 000,116,784 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\ironx86.sys
    [2010/06/02 09:27:50 | 000,043,696 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.sys
    [2010/06/02 09:27:49 | 000,501,888 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.sys
    [2010/06/02 09:27:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360\0402000.00C
    [2010/06/02 09:19:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\GlarySoft
    [2010/06/01 21:35:19 | 000,124,976 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
    [2010/06/01 21:35:19 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
    [2010/06/01 21:31:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
    [2010/06/01 21:31:18 | 000,408,088 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton_Download_Manager.exe
    [2010/06/01 20:13:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
    [2010/06/01 19:27:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Symantec
    [2010/06/01 13:49:34 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
    [2010/06/01 12:18:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Tific
    [2010/05/31 23:48:05 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
    [2010/05/31 22:34:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8(3)
    [2010/05/31 13:16:12 | 000,000,000 | R-SD | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\My Stationery
    [2010/05/31 13:16:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\microsoft
    [2010/05/31 13:10:03 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
    [2010/05/31 13:02:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\Symantec
    [2010/05/31 13:01:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\Norton
    [2010/05/31 12:16:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton
    [2010/05/31 12:16:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NortonInstaller
    [2010/05/31 12:11:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
    [2010/05/31 11:56:50 | 000,098,304 | ---- | C] (NVIDIA) -- C:\WINDOWS\System32\nvudisp.exe
    [2010/05/31 11:47:51 | 000,000,000 | ---D | C] -- C:\Program Files\W3i
    [2010/05/31 11:47:20 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
    [2010/05/31 11:47:19 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
    [2010/05/31 11:46:12 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Suite
    [2010/05/31 11:35:22 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\IECompatCache
    [2010/05/31 11:34:40 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\PrivacIE
    [2010/05/31 11:33:14 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\IETldCache
    [2010/04/29 17:22:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Identities
    [2010/04/11 16:35:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop\HP
    [2010/04/11 16:32:35 | 000,000,000 | ---D | C] -- C:\Program Files\Creative
    [2010/04/11 16:09:40 | 000,045,056 | ---- | C] (adi) -- C:\WINDOWS\System32\CleanUp.exe
    [2010/04/11 16:09:40 | 000,036,864 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\DSndUp.exe
    [2010/04/11 16:00:52 | 000,000,000 | ---D | C] -- C:\drvrtmp
    [2010/04/11 15:41:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Drivers
    [2010/04/07 10:20:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\UserData
    [2010/04/07 00:32:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Macromedia
    [2010/04/07 00:32:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Adobe
    [2010/04/06 23:47:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Identities
    [2010/04/06 23:47:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\My Pictures
    [2010/04/06 23:47:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents\My Music
    [2010/04/06 23:47:43 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Microsoft
    [2010/04/06 23:47:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ed Day.DPI01\SendTo
    [2010/04/06 23:47:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Recent
    [2010/04/06 23:47:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Application Data
    [2010/04/06 23:47:43 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\Start Menu
    [2010/04/06 23:47:43 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\My Documents
    [2010/04/06 23:47:43 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ed Day.DPI01\Favorites
    [2010/04/06 23:47:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Ed Day.DPI01\Cookies
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Templates
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\PrintHood
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\NetHood
    [2010/04/06 23:47:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings
    [2010/04/06 23:47:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\Microsoft
    [2010/04/06 23:47:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ed Day.DPI01\Desktop
    [2010/04/06 23:42:40 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
    [2010/04/06 23:42:40 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
    [2010/04/06 23:41:29 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
    [2010/04/06 23:39:48 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users.WINDOWS\DRM
    [2010/04/06 23:38:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\My Pictures
    [2010/04/06 23:38:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
    [2010/04/06 23:37:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents\My Music
    [2010/04/06 16:30:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu
    [2010/04/06 16:30:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documents
    [2010/04/06 16:30:16 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Templates
    [2010/04/06 16:30:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Favorites
    [2010/04/06 16:30:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Desktop
    [2010/04/06 16:29:46 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
    [2010/04/06 16:29:46 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data
    [2010/04/06 15:58:35 | 000,032,840 | ---- | C] (NETGEAR Corporation.) -- C:\WINDOWS\System32\drivers\Ngrpci.sys
    [2010/04/06 05:01:30 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
    [2010/04/06 03:00:48 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
    [2010/04/02 12:21:09 | 000,000,000 | ---D | C] -- C:\bootable
    [2010/04/01 16:49:48 | 000,000,000 | ---D | C] -- C:\68b152f709b480b484
    [2010/04/01 16:44:04 | 000,000,000 | ---D | C] -- C:\ee22816f5bfeabddc659d8bf50207b
    [2010/04/01 12:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\Runtime Software
    [2010/04/01 12:32:22 | 000,000,000 | ---D | C] -- C:\Program Files\Cobian Backup 10
    [2010/03/31 22:10:28 | 000,000,000 | ---D | C] -- C:\Program Files\Crawler
    [2010/03/31 21:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Terminator
    [2010/03/31 16:32:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\DVDVideoSoft
    [2010/03/31 16:32:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple
    [2010/03/31 15:53:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
    [2010/03/30 18:20:48 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
    [2010/03/30 18:18:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
    [2010/03/30 18:18:08 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
    [2010/03/30 17:38:34 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
    [2010/03/30 15:12:22 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/03/30 15:12:19 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft
    [2010/03/29 21:13:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
    [2010/03/29 21:04:29 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
    [2010/03/29 14:51:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
    [2010/03/29 14:35:14 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/03/27 07:36:48 | 000,000,000 | ---D | C] -- C:\Program Files\Pure Networks
    [2010/03/27 07:33:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Pure Networks Shared
    [2010/03/26 18:29:32 | 000,000,000 | ---D | C] -- C:\Program Files\Linksys
    [2010/03/26 18:15:07 | 000,000,000 | ---D | C] -- C:\Program Files\WebEx
    [2010/03/26 16:56:06 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
    [2010/03/26 16:43:32 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic
    [2010/03/25 09:43:34 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Repair
    [2010/03/24 19:00:58 | 000,000,000 | ---D | C] -- C:\Program Files\EMCO
    [2010/03/24 16:01:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8(2)
    [2010/03/17 17:18:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
    [2010/03/17 17:18:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2010/03/15 10:31:52 | 004,032,840 | ---- | C] (CYBERsitter LLC/Solid Oak Software) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\LookInMyPC.exe
    [2010/03/13 21:31:53 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
    [2010/03/13 21:27:09 | 000,000,000 | ---D | C] -- C:\Manual-PCProgram
    [2010/03/12 23:03:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
    [2010/03/10 20:32:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
    [2010/03/10 20:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
    [2010/03/10 20:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe

    ========== Files - Modified Within 90 Days ==========

    [2010/06/05 22:10:51 | 001,835,008 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.dat
    [2010/06/05 21:36:47 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/06/05 21:36:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/06/05 21:36:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/06/05 21:36:43 | 1072,766,976 | -HS- | M] () -- C:\hiberfil.sys
    [2010/06/05 21:35:06 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.ini
    [2010/06/05 21:33:53 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
    [2010/06/05 17:13:06 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\OTL.exe
    [2010/06/05 14:02:52 | 000,002,329 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\SeaTools for Windows.lnk
    [2010/06/05 13:54:22 | 000,456,276 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/06/05 13:54:22 | 000,431,772 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/06/05 13:54:22 | 000,069,962 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/06/05 13:25:27 | 001,976,698 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\Cat.DB
    [2010/06/04 23:44:15 | 000,110,076 | ---- | M] () -- C:\WINDOWS\hpoins08.dat
    [2010/06/04 23:43:01 | 000,000,532 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/06/04 23:42:34 | 000,000,733 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\HP Photosmart Essential.lnk
    [2010/06/04 23:38:38 | 000,000,710 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Scanner and Camera Wizard.lnk
    [2010/06/04 23:35:20 | 000,014,992 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/06/04 23:31:52 | 000,099,048 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/06/04 22:12:00 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Start Menu\Programs\Startup\Corel Registration.lnk
    [2010/06/04 22:11:31 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\CorelDRAW 9.LNK
    [2010/06/04 22:11:30 | 000,001,783 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\COREL.COM.LNK
    [2010/06/04 14:49:20 | 004,032,840 | ---- | M] (CYBERsitter LLC/Solid Oak Software) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\LookInMyPC.exe
    [2010/06/03 23:18:47 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/06/03 20:46:33 | 000,001,843 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Resume your download.lnk
    [2010/06/02 17:17:57 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader 9.lnk
    [2010/06/02 17:04:43 | 000,000,732 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Acrobat_com.lnk
    [2010/06/02 14:56:28 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
    [2010/06/02 13:19:00 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
    [2010/06/02 09:18:49 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Glarysoft Registry Repair.lnk
    [2010/06/01 21:35:18 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
    [2010/06/01 21:35:18 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
    [2010/06/01 21:35:18 | 000,007,443 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
    [2010/06/01 21:35:18 | 000,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
    [2010/06/01 21:31:24 | 000,000,849 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton Installation Files.lnk
    [2010/06/01 21:31:22 | 000,408,088 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton_Download_Manager.exe
    [2010/06/01 13:58:52 | 005,858,960 | -H-- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Local Settings\Application Data\IconCache.db
    [2010/05/31 23:56:46 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\E-mail.lnk
    [2010/05/31 15:13:52 | 000,000,659 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\siw_init.xml
    [2010/05/14 12:44:16 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\isolate.ini
    [2010/05/05 21:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdi.sys
    [2010/05/05 21:01:59 | 000,339,504 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symtdiv.sys
    [2010/05/05 21:01:43 | 000,001,473 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.inf
    [2010/05/05 21:01:43 | 000,001,445 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.inf
    [2010/04/28 22:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\ironx86.sys
    [2010/04/28 22:03:51 | 000,007,438 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.cat
    [2010/04/28 22:03:51 | 000,000,741 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.inf
    [2010/04/26 01:18:40 | 000,007,873 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.cat
    [2010/04/24 04:31:04 | 000,003,373 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.inf
    [2010/04/21 20:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.sys
    [2010/04/21 19:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.sys
    [2010/04/21 19:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.sys
    [2010/04/21 19:29:50 | 000,007,442 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.cat
    [2010/04/21 19:29:50 | 000,007,438 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.cat
    [2010/04/21 19:29:50 | 000,001,388 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.inf
    [2010/04/21 19:29:50 | 000,001,382 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.inf
    [2010/04/11 16:26:16 | 000,000,523 | ---- | M] () -- C:\WINDOWS\ATICIM.INI
    [2010/04/10 09:46:02 | 000,000,328 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My eBay Summary.url
    [2010/04/08 22:46:25 | 000,000,697 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My Scans.lnk
    [2010/04/07 00:16:46 | 000,000,433 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\FTP Commander.lnk
    [2010/04/06 23:55:48 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Shortcut to Internet.lnk
    [2010/04/06 23:47:05 | 000,013,588 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
    [2010/04/06 23:45:20 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
    [2010/04/06 23:43:17 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
    [2010/04/06 23:40:46 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
    [2010/04/06 23:40:46 | 000,000,000 | ---- | M] () -- C:\WINDOWS\control.ini
    [2010/04/06 23:40:36 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
    [2010/04/06 23:40:36 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
    [2010/04/06 23:40:21 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
    [2010/04/06 23:39:34 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest
    [2010/04/06 23:39:34 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
    [2010/04/06 23:39:26 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
    [2010/04/06 23:38:46 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2010/04/06 23:36:04 | 000,000,321 | -HS- | M] () -- C:\boot.ini
    [2010/04/06 23:06:25 | 000,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
    [2010/04/06 23:06:25 | 000,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini
    [2010/04/06 16:30:28 | 000,000,231 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/03/30 17:41:09 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Mozilla Firefox.lnk
    [2010/03/29 14:35:19 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/03/26 16:56:17 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Spybot - Search & Destroy.lnk
    [2010/03/25 10:59:32 | 000,000,862 | ---- | M] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malware Destroyer.lnk
     
  21. 2010/06/06
    DPI Graphics

    DPI Graphics Well-Known Member Thread Starter

    Joined:
    2009/06/12
    Messages:
    283
    Likes Received:
    0
    And here is part 2;

    ========== Files Created - No Company Name ==========

    [2010/06/05 13:57:27 | 000,002,329 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\SeaTools for Windows.lnk
    [2010/06/04 23:56:32 | 000,000,710 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Scanner and Camera Wizard.lnk
    [2010/06/04 23:42:33 | 000,000,733 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\HP Photosmart Essential.lnk
    [2010/06/04 23:35:32 | 000,000,734 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\hpzinstall.log
    [2010/06/04 23:35:29 | 000,110,076 | ---- | C] () -- C:\WINDOWS\hpoins08.dat
    [2010/06/04 23:35:29 | 000,007,577 | ---- | C] () -- C:\WINDOWS\hpomdl08.dat
    [2010/06/04 22:12:00 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Start Menu\Programs\Startup\Corel Registration.lnk
    [2010/06/04 22:11:30 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\COREL.COM.LNK
    [2010/06/04 22:09:47 | 000,028,252 | ---- | C] () -- C:\WINDOWS\corelpf.lrs
    [2010/06/04 22:09:27 | 000,039,095 | ---- | C] () -- C:\WINDOWS\iccsigs.dat
    [2010/06/04 22:09:26 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
    [2010/06/03 20:46:33 | 000,001,843 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Resume your download.lnk
    [2010/06/03 15:47:55 | 000,000,328 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My eBay Summary.url
    [2010/06/02 17:04:42 | 000,000,732 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Acrobat_com.lnk
    [2010/06/02 17:03:57 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader 9.lnk
    [2010/06/02 13:18:21 | 001,976,698 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\Cat.DB
    [2010/06/02 09:27:51 | 000,007,787 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.cat
    [2010/06/02 09:27:51 | 000,007,368 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.cat
    [2010/06/02 09:27:51 | 000,001,473 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnetv.inf
    [2010/06/02 09:27:51 | 000,001,445 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symnet.inf
    [2010/06/02 09:27:50 | 000,007,873 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.cat
    [2010/06/02 09:27:50 | 000,007,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.cat
    [2010/06/02 09:27:50 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.cat
    [2010/06/02 09:27:50 | 000,007,425 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.cat
    [2010/06/02 09:27:50 | 000,003,373 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symefa.inf
    [2010/06/02 09:27:50 | 000,002,793 | R--- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\symds.inf
    [2010/06/02 09:27:50 | 000,001,388 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtspx.inf
    [2010/06/02 09:27:50 | 000,001,382 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\srtsp.inf
    [2010/06/02 09:27:49 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.cat
    [2010/06/02 09:27:49 | 000,007,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.cat
    [2010/06/02 09:27:49 | 000,001,754 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\cchpx86.inf
    [2010/06/02 09:27:49 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\iron.inf
    [2010/06/02 09:27:05 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\N360\0402000.00C\isolate.ini
    [2010/06/01 21:35:19 | 000,007,443 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
    [2010/06/01 21:35:19 | 000,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
    [2010/06/01 21:35:01 | 000,002,265 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
    [2010/06/01 12:25:18 | 001,835,008 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.dat
    [2010/05/31 23:56:46 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\E-mail.lnk
    [2010/05/31 22:00:22 | 1072,766,976 | -HS- | C] () -- C:\hiberfil.sys
    [2010/05/31 15:13:52 | 000,000,659 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\siw_init.xml
    [2010/05/31 13:01:24 | 000,000,849 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Norton Installation Files.lnk
    [2010/05/31 11:56:51 | 000,009,801 | ---- | C] () -- C:\WINDOWS\System32\nvdisp.nvu
    [2010/05/31 09:58:57 | 000,613,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm
    [2010/05/31 09:58:57 | 000,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav
    [2010/05/31 09:58:57 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav
    [2010/05/31 09:58:57 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav
    [2010/05/31 09:58:57 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav
    [2010/05/31 09:58:57 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav
    [2010/05/31 09:58:57 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav
    [2010/05/31 09:58:57 | 000,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav
    [2010/05/31 09:58:57 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav
    [2010/05/31 09:58:57 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav
    [2010/05/31 09:58:57 | 000,010,457 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.hta
    [2010/05/31 09:58:57 | 000,006,769 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf
    [2010/05/31 09:58:57 | 000,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css
    [2010/05/31 09:58:57 | 000,000,855 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf
    [2010/05/31 09:58:57 | 000,000,420 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmploc.js
    [2010/05/31 09:58:56 | 000,017,272 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf
    [2010/05/31 09:58:56 | 000,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif
    [2010/05/31 09:58:56 | 000,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif
    [2010/05/31 09:58:56 | 000,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif
    [2010/05/31 09:58:56 | 000,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif
    [2010/05/31 09:58:56 | 000,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif
    [2010/05/31 09:58:56 | 000,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif
    [2010/05/31 09:58:56 | 000,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif
    [2010/05/31 09:58:56 | 000,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif
    [2010/05/31 09:58:56 | 000,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif
    [2010/05/31 09:58:54 | 000,300,969 | ---- | C] () -- C:\WINDOWS\System32\dllcache\viz.wmv
    [2010/05/31 09:58:54 | 000,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif
    [2010/05/31 09:58:54 | 000,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif
    [2010/05/31 09:58:54 | 000,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif
    [2010/05/31 09:58:54 | 000,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif
    [2010/05/31 09:58:54 | 000,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif
    [2010/05/31 09:58:54 | 000,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif
    [2010/05/31 09:58:54 | 000,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif
    [2010/05/31 09:58:53 | 000,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js
    [2010/05/31 09:58:53 | 000,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif
    [2010/05/31 09:58:53 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif
    [2010/05/31 09:58:53 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif
    [2010/05/31 09:58:53 | 000,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif
    [2010/05/31 09:58:51 | 000,572,557 | ---- | C] () -- C:\WINDOWS\System32\dllcache\rtuner.wmv
    [2010/05/31 09:58:51 | 000,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm
    [2010/05/31 09:58:51 | 000,000,908 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf
    [2010/05/31 09:58:50 | 000,077,307 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm
    [2010/05/31 09:58:49 | 000,375,519 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nuskin.wmv
    [2010/05/31 09:58:49 | 000,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip
    [2010/05/31 09:58:49 | 000,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip
    [2010/05/31 09:58:48 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
    [2010/05/31 09:58:45 | 000,097,117 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.hlp
    [2010/05/31 09:58:45 | 000,018,286 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf
    [2010/05/31 09:58:45 | 000,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif
    [2010/05/31 09:58:45 | 000,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif
    [2010/05/31 09:58:45 | 000,001,885 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.cnt
    [2010/05/31 09:58:44 | 000,457,607 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mdlib.wmv
    [2010/05/31 09:58:41 | 000,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js
    [2010/05/31 09:58:36 | 000,381,425 | ---- | C] () -- C:\WINDOWS\System32\dllcache\copycd.wmv
    [2010/05/31 09:58:36 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
    [2010/05/31 09:58:35 | 000,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css
    [2010/05/31 09:58:35 | 000,008,298 | ---- | C] () -- C:\WINDOWS\System32\dllcache\contents.htm
    [2010/05/31 09:58:35 | 000,006,878 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.js
    [2010/05/31 09:58:35 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif
    [2010/05/31 09:58:35 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif
    [2010/05/31 09:58:35 | 000,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif
    [2010/05/31 09:58:35 | 000,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif
    [2010/05/31 09:58:35 | 000,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif
    [2010/05/31 09:58:34 | 000,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif
    [2010/05/31 09:57:16 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
    [2010/04/11 16:25:43 | 000,000,523 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
    [2010/04/11 16:01:07 | 000,002,983 | R--- | C] () -- C:\WINDOWS\System32\net82557.din
    [2010/04/07 00:16:46 | 000,000,433 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\FTP Commander.lnk
    [2010/04/06 23:55:48 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Shortcut to Internet.lnk
    [2010/04/06 23:49:57 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\My Computer.lnk
    [2010/04/06 23:47:45 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Ed Day.DPI01\ntuser.ini
    [2010/04/06 23:47:43 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Ed Day.DPI01\NTUSER.DAT.LOG
    [2010/04/06 23:47:06 | 000,013,588 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
    [2010/04/06 23:45:20 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
    [2010/04/06 23:43:17 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2010/04/06 23:43:10 | 000,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
    [2010/04/06 23:42:35 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
    [2010/04/06 23:42:35 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
    [2010/04/06 23:42:31 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
    [2010/04/06 23:42:11 | 000,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
    [2010/04/06 23:42:10 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
    [2010/04/06 23:42:03 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
    [2010/04/06 23:42:01 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
    [2010/04/06 23:42:00 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
    [2010/04/06 23:41:51 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
    [2010/04/06 23:41:47 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
    [2010/04/06 23:41:32 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
    [2010/04/06 23:41:29 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_864.nls
    [2010/04/06 23:41:29 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_862.nls
    [2010/04/06 23:41:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_870.nls
    [2010/04/06 23:41:28 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20949.nls
    [2010/04/06 23:41:28 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_858.nls
    [2010/04/06 23:41:28 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_708.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28596.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21027.nls
    [2010/04/06 23:41:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21025.nls
    [2010/04/06 23:41:27 | 000,180,770 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20932.nls
    [2010/04/06 23:41:27 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20936.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20924.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20880.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20871.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20838.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20833.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20424.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20423.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20420.nls
    [2010/04/06 23:41:27 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20297.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20290.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20285.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20284.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20280.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20278.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20277.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20273.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20269.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20108.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20107.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20106.nls
    [2010/04/06 23:41:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20105.nls
    [2010/04/06 23:41:25 | 000,189,986 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1361.nls
    [2010/04/06 23:41:25 | 000,187,938 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20005.nls
    [2010/04/06 23:41:25 | 000,186,402 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20001.nls
    [2010/04/06 23:41:25 | 000,185,378 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20003.nls
    [2010/04/06 23:41:25 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20004.nls
    [2010/04/06 23:41:25 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20000.nls
    [2010/04/06 23:41:25 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20002.nls
    [2010/04/06 23:41:25 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1149.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1148.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1147.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1146.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1145.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1144.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1143.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1142.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1141.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1140.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1047.nls
    [2010/04/06 23:41:24 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10021.nls
    [2010/04/06 23:41:23 | 000,195,618 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10002.nls
    [2010/04/06 23:41:23 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10003.nls
    [2010/04/06 23:41:23 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10008.nls
    [2010/04/06 23:41:23 | 000,162,850 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10001.nls
    [2010/04/06 23:41:23 | 000,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
    [2010/04/06 23:41:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10005.nls
    [2010/04/06 23:41:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10004.nls
    [2010/04/06 23:41:22 | 000,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
    [2010/04/06 23:40:46 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
    [2010/04/06 23:40:36 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
    [2010/04/06 23:40:36 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
    [2010/04/06 23:40:34 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
    [2010/04/06 23:08:05 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
    [2010/04/06 23:08:05 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
    [2010/04/06 23:07:56 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
    [2010/04/06 23:07:32 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
    [2010/04/06 23:07:10 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
    [2010/04/06 23:07:10 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
    [2010/04/06 23:07:05 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
    [2010/04/06 23:06:40 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2010/04/06 23:05:28 | 000,227,840 | ---- | C] () -- C:\WINDOWS\System32\avtapi.dll
    [2010/04/06 23:05:25 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
    [2010/04/06 23:05:24 | 000,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
    [2010/04/06 23:05:24 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
    [2010/04/06 23:05:24 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
    [2010/04/06 23:05:24 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
    [2010/04/06 23:05:24 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
    [2010/04/06 23:05:24 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
    [2010/04/06 23:05:24 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
    [2010/04/06 23:05:24 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
    [2010/04/06 23:05:24 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
    [2010/04/06 23:05:24 | 000,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
    [2010/04/06 23:05:24 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
    [2010/04/06 23:05:24 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
    [2010/04/06 23:05:23 | 000,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
    [2010/04/06 23:05:23 | 000,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
    [2010/04/06 23:05:23 | 000,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
    [2010/04/06 23:05:23 | 000,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
    [2010/04/06 23:05:23 | 000,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
    [2010/04/06 23:05:23 | 000,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
    [2010/04/06 23:05:22 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
    [2010/04/06 23:05:22 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
    [2010/04/06 23:05:21 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
    [2010/04/06 23:05:17 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
    [2010/04/06 15:56:00 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
    [2010/04/06 15:55:52 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
    [2010/04/06 15:55:52 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
    [2010/04/06 15:55:50 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
    [2010/04/06 15:55:50 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
    [2010/04/06 15:55:50 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
    [2010/04/06 15:55:49 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
    [2010/04/06 15:55:47 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
    [2010/04/06 15:55:47 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
    [2010/04/06 15:55:46 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
    [2010/04/06 15:55:46 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls
    [2010/04/06 15:55:46 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS
    [2010/04/06 15:55:45 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_852.nls
    [2010/04/06 15:55:45 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
    [2010/04/06 15:55:45 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
    [2010/04/06 15:55:43 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20127.nls
    [2010/04/06 15:55:43 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls
    [2010/04/06 15:55:40 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
    [2010/04/06 15:55:27 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
    [2010/04/06 15:55:27 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
    [2010/04/06 15:55:27 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
    [2010/04/06 15:55:27 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
    [2010/04/06 15:55:27 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
    [2010/04/06 15:55:27 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
    [2010/04/06 15:55:27 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
    [2010/04/06 15:55:27 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
    [2010/04/06 15:54:42 | 000,099,048 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/04/06 15:52:02 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
    [2010/03/30 17:38:42 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Mozilla Firefox.lnk
    [2010/03/29 14:35:19 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/03/26 16:56:17 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Spybot - Search & Destroy.lnk
    [2010/03/25 10:59:32 | 000,000,862 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Malware Destroyer.lnk
    [2010/03/25 09:43:35 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\Ed Day.DPI01\Desktop\Glarysoft Registry Repair.lnk
    [2010/03/24 14:05:27 | 000,000,980 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\20xYJkS83BHk4
    [2009/09/22 09:54:08 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2003/10/06 14:16:00 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\nvcod.dll
    [2001/07/06 16:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

    ========== LOP Check ==========

    [2010/06/02 09:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\GlarySoft
    [2010/06/04 23:57:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Image Zone Express
    [2010/06/04 23:57:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Printer Info Cache
    [2010/06/01 12:18:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ed Day.DPI01\Application Data\Tific

    ========== Purity Check ==========


    < End of report >
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.