1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Host Process Problems + MBAM logs

Discussion in 'Malware and Virus Removal Archive' started by keithy397, 2014/05/10.

  1. 2014/05/15
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    OTL.txt Part 1

    OTL logfile created on: 15/05/2014 19:38:31 - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = F:\Documents and Settings\Paul\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    1022.48 Mb Total Physical Memory | 341.93 Mb Available Physical Memory | 33.44% Memory free
    2.13 Gb Paging File | 1.57 Gb Available in Paging File | 73.72% Paging File free
    Paging file location(s): F:\pagefile.sys 1250 2304 [binary data]

    %SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
    Drive C: | 37.27 Gb Total Space | 31.30 Gb Free Space | 84.00% Space Free | Partition Type: NTFS
    Drive F: | 76.32 Gb Total Space | 7.93 Gb Free Space | 10.38% Space Free | Partition Type: NTFS

    Computer Name: PC | User Name: Paul | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2014/05/15 18:43:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Paul\Desktop\OTL.exe
    PRC - [2014/05/13 16:37:03 | 000,182,696 | ---- | M] (Oracle Corporation) -- F:\Program Files\Java\jre7\bin\jqs.exe
    PRC - [2014/04/25 10:56:12 | 012,971,328 | ---- | M] (TeamViewer GmbH) -- F:\Program Files\TeamViewer\Version9\TeamViewer.exe
    PRC - [2014/04/25 10:56:12 | 005,024,576 | ---- | M] (TeamViewer GmbH) -- F:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
    PRC - [2014/04/25 10:42:00 | 000,238,400 | ---- | M] (TeamViewer GmbH) -- F:\Program Files\TeamViewer\Version9\tv_w32.exe
    PRC - [2014/04/25 10:03:52 | 022,415,552 | ---- | M] (Google) -- F:\Program Files\Google\Drive\googledrivesync.exe
    PRC - [2014/04/24 10:09:28 | 021,858,600 | ---- | M] (Bartels Media GmbH) -- F:\Program Files\PhraseExpress\phraseexpress.exe
    PRC - [2014/04/20 10:32:00 | 003,873,704 | ---- | M] (AVAST Software) -- F:\Program Files\AVAST Software\Avast\AvastUI.exe
    PRC - [2014/04/20 10:31:58 | 000,050,344 | ---- | M] (AVAST Software) -- F:\Program Files\AVAST Software\Avast\AvastSvc.exe
    PRC - [2014/04/10 09:50:10 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- F:\Program Files\Real\Update\realsched.exe
    PRC - [2014/03/23 11:53:52 | 000,050,504 | ---- | M] (Google Inc.) -- F:\Program Files\Google\Chrome Remote Desktop\34.0.1847.86\remoting_host.exe
    PRC - [2013/08/14 15:19:22 | 000,039,056 | ---- | M] () -- F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
    PRC - [2012/10/31 08:18:49 | 001,006,080 | ---- | M] () -- F:\Program Files\MedalFolders\MedalFolders.exe
    PRC - [2012/08/13 11:57:02 | 010,376,704 | ---- | M] (OpenOffice.org) -- F:\Program Files\OpenOffice.org 3\program\soffice.exe
    PRC - [2012/08/13 11:57:02 | 010,368,512 | ---- | M] (OpenOffice.org) -- F:\Program Files\OpenOffice.org 3\program\soffice.bin
    PRC - [2012/07/11 19:54:49 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- F:\Program Files\SUPERAntiSpyware\SASCore.exe
    PRC - [2012/05/30 07:08:28 | 001,842,384 | ---- | M] (Gadwin Systems, Inc) -- F:\Documents and Settings\Paul\My Documents\Other Programs\PrintScreen\PrintScreen.exe
    PRC - [2011/07/10 19:40:14 | 001,555,456 | ---- | M] () -- F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\locate32.exe
    PRC - [2009/10/20 15:21:26 | 000,551,784 | ---- | M] (Sysinternals - www.sysinternals.com) -- F:\Documents and Settings\Paul\My Documents\Other Programs\Zoomit\ZoomIt.exe
    PRC - [2009/09/13 00:09:10 | 000,103,768 | ---- | M] (Citrix Systems, Inc.) -- F:\Program Files\Citrix\ICA Client\concentr.exe
    PRC - [2009/09/13 00:09:04 | 000,550,232 | ---- | M] (Citrix Systems, Inc.) -- F:\Program Files\Citrix\ICA Client\wfcrun32.exe
    PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- F:\WINDOWS\explorer.exe
    PRC - [2007/05/22 18:34:26 | 000,208,896 | ---- | M] () -- F:\Program Files\Clipdiary\ClipDiary.exe
    PRC - [2006/07/14 09:48:16 | 000,136,704 | ---- | M] (Royal Philips Electronics Inc) -- F:\Program Files\Philips\Media Manager\Philips Media Manager.exe
    PRC - [2004/03/18 09:33:26 | 000,892,928 | ---- | M] (Logitech Inc.) -- F:\Program Files\Logitech\iTouch\iTouch.exe


    ========== Modules (No Company Name) ==========

    MOD - [2014/05/15 18:55:27 | 000,805,888 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._gdi_.pyd
    MOD - [2014/05/15 18:55:27 | 000,027,136 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\_multiprocessing.pyd
    MOD - [2014/05/15 18:55:26 | 001,159,680 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\_ssl.pyd
    MOD - [2014/05/15 18:55:26 | 000,811,008 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._windows_.pyd
    MOD - [2014/05/15 18:55:26 | 000,713,216 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\_hashlib.pyd
    MOD - [2014/05/15 18:55:26 | 000,110,080 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\PyWinTypes27.dll
    MOD - [2014/05/15 18:55:25 | 001,062,400 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._controls_.pyd
    MOD - [2014/05/15 18:55:25 | 000,070,656 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._html2.pyd
    MOD - [2014/05/15 18:55:25 | 000,038,912 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32inet.pyd
    MOD - [2014/05/15 18:55:25 | 000,035,840 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32process.pyd
    MOD - [2014/05/15 18:55:25 | 000,025,600 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32pdh.pyd
    MOD - [2014/05/15 18:55:25 | 000,024,064 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32pipe.pyd
    MOD - [2014/05/15 18:55:24 | 000,686,080 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\unicodedata.pyd
    MOD - [2014/05/15 18:55:24 | 000,127,488 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\pyexpat.pyd
    MOD - [2014/05/15 18:55:24 | 000,018,432 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32event.pyd
    MOD - [2014/05/15 18:55:24 | 000,010,240 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\select.pyd
    MOD - [2014/05/15 18:55:23 | 000,525,640 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\windows._lib_cacheinvalidation.pyd
    MOD - [2014/05/15 18:55:23 | 000,167,936 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32gui.pyd
    MOD - [2014/05/15 18:55:23 | 000,128,512 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\_elementtree.pyd
    MOD - [2014/05/15 18:55:23 | 000,119,808 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32file.pyd
    MOD - [2014/05/15 18:55:23 | 000,108,544 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32security.pyd
    MOD - [2014/05/15 18:55:23 | 000,087,552 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\_ctypes.pyd
    MOD - [2014/05/15 18:55:23 | 000,045,568 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\_socket.pyd
    MOD - [2014/05/15 18:55:23 | 000,017,408 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32profile.pyd
    MOD - [2014/05/15 18:55:22 | 001,175,040 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._core_.pyd
    MOD - [2014/05/15 18:55:22 | 000,735,232 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._misc_.pyd
    MOD - [2014/05/15 18:55:22 | 000,557,056 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\pysqlite2._sqlite.pyd
    MOD - [2014/05/15 18:55:22 | 000,364,544 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\pythoncom27.dll
    MOD - [2014/05/15 18:55:22 | 000,320,512 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32com.shell.shell.pyd
    MOD - [2014/05/15 18:55:22 | 000,098,816 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32api.pyd
    MOD - [2014/05/15 18:55:22 | 000,078,336 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._animate.pyd
    MOD - [2014/05/15 18:55:22 | 000,022,528 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32ts.pyd
    MOD - [2014/05/15 18:55:21 | 000,122,368 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\wx._wizard.pyd
    MOD - [2014/05/15 18:55:21 | 000,011,264 | ---- | M] () -- F:\Documents and Settings\Paul\Local Settings\Temp\_MEI8322\win32crypt.pyd
    MOD - [2014/05/15 18:46:17 | 002,253,312 | ---- | M] () -- F:\Program Files\AVAST Software\Avast\defs\14051501\algo.dll
    MOD - [2014/04/24 10:09:24 | 000,460,072 | ---- | M] () -- F:\Program Files\PhraseExpress\pexlang.dll
    MOD - [2014/04/02 21:58:56 | 019,336,120 | ---- | M] () -- F:\Program Files\AVAST Software\Avast\libcef.dll
    MOD - [2014/02/12 20:58:32 | 000,073,544 | ---- | M] () -- F:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2014/02/12 20:58:10 | 001,044,808 | ---- | M] () -- F:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2013/08/14 15:19:22 | 000,039,056 | ---- | M] () -- F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
    MOD - [2013/01/02 07:49:10 | 001,292,288 | ---- | M] () -- F:\WINDOWS\system32\quartz.dll
    MOD - [2012/10/31 15:43:51 | 000,985,088 | ---- | M] () -- F:\Program Files\OpenOffice.org 3\program\libxml2.dll
    MOD - [2012/10/31 08:18:49 | 001,006,080 | ---- | M] () -- F:\Program Files\MedalFolders\MedalFolders.exe
    MOD - [2011/07/10 19:40:14 | 001,555,456 | ---- | M] () -- F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\locate32.exe
    MOD - [2011/07/10 19:39:24 | 000,124,416 | ---- | M] () -- F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\lan_en.dll
    MOD - [2011/07/10 19:38:52 | 000,045,568 | ---- | M] () -- F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\keyhelper.dll
    MOD - [2008/04/14 01:11:59 | 000,014,336 | ---- | M] () -- F:\WINDOWS\system32\msdmo.dll
    MOD - [2008/04/14 01:11:51 | 000,059,904 | ---- | M] () -- F:\WINDOWS\system32\devenum.dll
    MOD - [2007/05/22 18:34:26 | 000,208,896 | ---- | M] () -- F:\Program Files\Clipdiary\ClipDiary.exe
    MOD - [2007/05/22 17:44:02 | 000,350,711 | ---- | M] () -- F:\Program Files\Clipdiary\sqlite3.dll
    MOD - [2006/07/14 09:48:16 | 000,045,056 | ---- | M] () -- F:\Program Files\Philips\Media Manager\bin\win\usbnotify.dll
    MOD - [2006/07/14 09:48:16 | 000,045,056 | ---- | M] () -- F:\Program Files\Philips\Media Manager\bin\win\cdnotify.dll


    ========== Services (SafeList) ==========

    SRV - File not found [Disabled | Stopped] -- -- (ServiceLayer)
    SRV - File not found [Auto | Stopped] -- -- (RP_FWS)
    SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
    SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
    SRV - [2014/05/14 12:18:25 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- F:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2014/05/13 16:37:03 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- F:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
    SRV - [2014/05/10 06:59:31 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- F:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2014/04/25 10:56:12 | 005,024,576 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- F:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
    SRV - [2014/04/20 10:31:58 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- F:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2014/03/23 11:53:52 | 000,050,504 | ---- | M] (Google Inc.) [Auto | Running] -- F:\Program Files\Google\Chrome Remote Desktop\34.0.1847.86\remoting_host.exe -- (chromoting)
    SRV - [2013/08/14 15:19:22 | 000,039,056 | ---- | M] () [Auto | Running] -- F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
    SRV - [2012/07/11 19:54:49 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- F:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)
    SRV - [2009/06/08 13:07:50 | 001,033,480 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- F:\Program Files\Raxco\PerfectDisk10\PDEngine.exe -- (PDEngine)
    SRV - [2009/06/08 13:07:48 | 000,931,080 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- F:\Program Files\Raxco\PerfectDisk10\PDAgent.exe -- (PDAgent)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev)
    DRV - File not found [Kernel | On_Demand | Stopped] -- F:\Program Files\Virgin Media\Security\BitDefender\trufos.sys -- (Trufos)
    DRV - File not found [Kernel | On_Demand | Stopped] -- F:\Program Files\Virgin Media\Security\BitDefender\profos.sys -- (Profos)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- F:\ComboFix\catchme.sys -- (catchme)
    DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\AFGSp50.sys -- (AFGSp50)
    DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\AFGMp50.sys -- (AFGMp50)
    DRV - [2014/05/15 10:56:54 | 000,777,488 | ---- | M] (AVAST Software) [File_System | System | Running] -- F:\WINDOWS\system32\drivers\aswsnx.sys -- (aswSnx)
    DRV - [2014/05/15 10:56:52 | 000,054,832 | ---- | M] (AVAST Software) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\aswrdr.sys -- (AswRdr)
    DRV - [2014/05/15 10:56:50 | 000,411,680 | ---- | M] (AVAST Software) [File_System | System | Running] -- F:\WINDOWS\system32\drivers\aswsp.sys -- (aswSP)
    DRV - [2014/04/20 10:32:10 | 000,180,632 | ---- | M] () [Kernel | Boot | Running] -- F:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
    DRV - [2014/04/20 10:32:10 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- F:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
    DRV - [2014/04/20 10:32:10 | 000,057,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2014/04/20 10:32:10 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- F:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
    DRV - [2014/04/20 10:32:10 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\aswHwid.sys -- (aswHwid)
    DRV - [2011/07/22 17:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- F:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
    DRV - [2011/07/12 22:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
    DRV - [2010/11/11 12:03:25 | 000,053,192 | ---- | M] (Radialpoint Inc.) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\rp_skt32.sys -- (RPSKT)
    DRV - [2009/11/02 16:27:02 | 000,025,608 | ---- | M] (AVG Technologies ) [Kernel | Boot | Running] -- F:\WINDOWS\system32\drivers\AVGIDSEH.sys -- (RadialpointIDSEH)
    DRV - [2009/10/23 14:25:54 | 000,285,704 | ---- | M] (BitDefender S.R.L. Bucharest, ROMANIA) [File_System | Boot | Running] -- F:\WINDOWS\system32\drivers\bdfsfltr.sys -- (bdfsfltr)
    DRV - [2009/09/08 19:13:16 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\ctxusbm.sys -- (ctxusbm)
    DRV - [2009/06/08 11:00:56 | 000,071,696 | ---- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- F:\WINDOWS\System32\drivers\DefragFs.sys -- (DefragFS)
    DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
    DRV - [2006/07/09 21:45:24 | 000,642,560 | ---- | M] () [Kernel | Boot | Running] -- F:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
    DRV - [2005/11/25 14:39:06 | 000,203,776 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio)
    DRV - [2005/01/05 22:43:06 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | System | Running] -- F:\WINDOWS\system32\npptNT2.sys -- (NPPTNT2)
    DRV - [2004/03/10 13:42:24 | 000,012,953 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\itchfltr.sys -- (itchfltr)
    DRV - [2003/09/05 18:37:16 | 000,183,040 | ---- | M] () [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\snpt513.sys -- (SNPT513)
    DRV - [2002/12/27 04:41:00 | 000,026,880 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- F:\WINDOWS\system32\drivers\VIAAGP1.SYS -- (viaagp1)
    DRV - [2001/06/15 08:18:28 | 000,005,006 | ---- | M] (Winbond Electronics Corp.) [Kernel | Auto | Running] -- F:\WINDOWS\System32\drivers\Wbhwdoct.sys -- (WBHWDOCT)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7


    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 18 86 44 1C E2 1A CB 01 [binary data]
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\..\SearchScopes\{68CF1381-B856-4965-ADC3-4166F97CE48C}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_en-GB
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co.uk/search?sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&q={searchTerms}&rlz=1I7GGLL_en-GB
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-448539723-2139871995-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..browser.search.openintab: true
    FF - prefs.js..browser.startup.homepage: "google.co.uk "
    FF - prefs.js..extensions.enabledAddons: firefox-autofill%40googlegroups.com:3.6
    FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.4
    FF - prefs.js..extensions.enabledAddons: savefileto%40mozdev.org:2.5.1
    FF - prefs.js..extensions.enabledAddons: secureLogin%40blueimp.net:1.0.3
    FF - prefs.js..extensions.enabledAddons: Stylish-Custom%40choggi.dyndns.org:0.7.7
    FF - prefs.js..extensions.enabledAddons: %7B3e0e7d2a-070f-4a47-b019-91fe5385ba79%7D:3.5.9
    FF - prefs.js..extensions.enabledAddons: %7B9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC%7D:6.0.4.9000
    FF - prefs.js..extensions.enabledAddons: %7Bc72c0c73-4eb0-4fb3-af0f-074e97326cfd%7D:1.4
    FF - prefs.js..extensions.enabledAddons: %7BEDA7B1D7-F793-4e03-B074-E6F303317FB0%7D:1.2.7
    FF - prefs.js..extensions.enabledAddons: savedpasswordeditor%40daniel.dawson:2.7.2
    FF - prefs.js..extensions.enabledAddons: UKTVGuide%40mozilla.org:1.3.14
    FF - prefs.js..extensions.enabledAddons: facebook_notification%40wips.com:1.0.1
    FF - prefs.js..extensions.enabledAddons: verticaltoolbar%40xuldev.org:1.0.7
    FF - prefs.js..extensions.enabledAddons: %7B1cff04ef-0c75-4621-ba2a-2efb77346996%7D:3.0.0b1
    FF - prefs.js..extensions.enabledAddons: showParentFolder%40alice:2.1
    FF - prefs.js..extensions.enabledAddons: %7Bada4b710-8346-4b82-8199-5de2b400a6ae%7D:2.1.5
    FF - prefs.js..extensions.enabledAddons: %7Bdc572301-7619-498c-a57d-39143191b318%7D:0.4.1.4pre.140414a1
    FF - prefs.js..extensions.enabledAddons: %7B46551EC9-40F0-4e47-8E18-8E5CF550CFB8%7D:1.4.3
    FF - prefs.js..extensions.enabledAddons: abhere2%40moztw.org:29.0.20140506
    FF - prefs.js..extensions.enabledAddons: %7B37fa1426-b82d-11db-8314-0800200c9a66%7D:3.4
    FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: F:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: F:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: F:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: F:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: F:\Program Files\Real\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: F:\Program Files\Real\Netscape6\nprpplugin.dll (RealPlayer)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: F:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: F:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: F:\Documents and Settings\Paul\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
    FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: F:\Documents and Settings\Paul\Application Data\Facebook\npfbplugin_1_0_3.dll ( )

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2014/04/10 09:51:56 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: F:\Program Files\Mozilla Firefox\components [2014/05/10 06:58:09 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: F:\Program Files\Mozilla Firefox\plugins

    [2010/08/13 20:13:33 | 000,000,000 | ---D | M] (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Extensions
    [2014/05/15 19:34:42 | 000,000,000 | ---D | M] (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions
    [2012/12/01 10:05:28 | 000,000,000 | ---D | M] (AddThis) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
    [2012/10/30 12:15:45 | 000,000,000 | ---D | M] (MR Tech Toolkit) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}
    [2014/04/18 09:18:57 | 000,000,000 | ---D | M] (ReminderFox) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
    [2013/06/14 07:46:27 | 000,000,000 | ---D | M] (eCleaner) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}
    [2014/04/03 17:34:03 | 000,000,000 | ---D | M] (Facebook Notification) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\facebook_notification@wips.com
    [2014/04/11 19:57:21 | 000,000,000 | ---D | M] (Ginger - Grammar and Spell Checker) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\firefox@gingersoftware.com
    [2013/06/14 07:46:28 | 000,000,000 | ---D | M] (Autofill) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\firefox-autofill@googlegroups.com
    [2012/11/28 15:22:54 | 000,000,000 | ---D | M] (Secure Login) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\secureLogin@blueimp.net
    [2012/10/30 12:37:56 | 000,000,000 | ---D | M] (Stylish-Custom) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\Stylish-Custom@choggi.dyndns.org
    [2014/05/07 07:31:49 | 000,066,000 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\abhere2@moztw.org.xpi
    [2013/06/14 07:46:26 | 000,067,503 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\firefox-autofill@googlegroups.com.xpi
    [2014/03/03 12:32:51 | 000,062,226 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\HighlightedTextToFile@bobbyrne01.org.xpi
    [2014/05/06 08:30:28 | 000,400,514 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\jid0-105eGBfutA8RahNXKJRXP7CPNs0@jetpack.xpi
    [2014/05/11 13:24:35 | 000,667,234 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\jid1-cwbvBTE216jjpg@jetpack.xpi
    [2014/05/06 07:56:07 | 000,207,726 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\oldnewsfeed@jetpack.xpi
    [2014/03/03 12:59:57 | 000,215,649 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\savedpasswordeditor@daniel.dawson.xpi
    [2012/11/27 07:33:02 | 000,083,379 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\secureLogin@blueimp.net.xpi
    [2014/04/17 10:11:44 | 000,009,489 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\showParentFolder@alice.xpi
    [2014/03/03 13:00:38 | 000,046,663 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\UKTVGuide@mozilla.org.xpi
    [2014/04/15 08:35:22 | 000,161,083 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\verticaltoolbar@xuldev.org.xpi
    [2014/04/03 08:44:10 | 000,024,423 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{0e3fc079-afbb-4a00-87e5-9486062d0f9c}.xpi
    [2014/05/14 22:49:41 | 000,013,704 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    [2014/04/15 08:58:26 | 000,101,397 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{1cff04ef-0c75-4621-ba2a-2efb77346996}.xpi
    [2012/10/30 19:23:24 | 000,024,701 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2c}.xpi
    [2014/05/10 07:02:16 | 000,220,072 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi
    [2014/05/06 07:56:36 | 000,293,729 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
    [2013/06/14 07:46:26 | 000,016,921 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    [2014/04/29 09:07:31 | 000,837,038 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
    [2012/10/30 19:23:24 | 000,091,557 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi
    [2009/12/04 02:20:54 | 000,006,110 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\content\local_install\local_XPInstall.xul
    [2006/04/28 13:58:16 | 000,000,050 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\content\local_install\XPInstall.css
    [2008/01/17 06:02:40 | 000,001,756 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\content\local_install\xpinstall.js
    [2006/12/28 04:19:00 | 000,000,313 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\content\local_install\locale\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,545 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\be-BY\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,459 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\bg-BG\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,326 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\cs-CZ\local_install\disable_xpi_delay.properties
    [2008/10/31 00:32:26 | 000,000,343 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\da-DK\local_install\disable_xpi_delay.properties
    [2008/10/31 14:11:58 | 000,000,462 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\de-DE\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,557 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\el-GR\local_install\disable_xpi_delay.properties
    [2006/12/28 04:19:00 | 000,000,313 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\en-US\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,312 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\es-AR\local_install\disable_xpi_delay.properties
    [2008/10/31 03:11:50 | 000,000,325 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\es-ES\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,493 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\fa-IR\local_install\disable_xpi_delay.properties
    [2008/11/04 03:32:32 | 000,000,312 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\fi-FI\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,390 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\fr-FR\local_install\disable_xpi_delay.properties
    [2008/10/31 01:47:38 | 000,000,315 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\fy-NL\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,406 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\he-IL\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,334 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\hr-HR\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,367 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\hu-HU\local_install\disable_xpi_delay.properties
    [2008/10/31 00:45:14 | 000,000,330 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\it-IT\local_install\disable_xpi_delay.properties
    [2009/11/21 18:13:26 | 000,000,390 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\ja\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,349 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\ko-KR\local_install\disable_xpi_delay.properties
    [2008/11/02 00:23:42 | 000,000,328 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\lt-LT\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,352 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\mk-MK\local_install\disable_xpi_delay.properties
    [2008/10/31 00:31:36 | 000,000,325 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\nb-NO\local_install\disable_xpi_delay.properties
    [2008/10/31 06:16:58 | 000,000,302 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\nl-NL\local_install\disable_xpi_delay.properties
    [2008/10/31 11:20:38 | 000,000,311 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\pl-PL\local_install\disable_xpi_delay.properties
    [2008/10/31 02:29:58 | 000,000,331 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\pt-BR\local_install\disable_xpi_delay.properties
    [2008/11/02 00:47:32 | 000,000,349 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\pt-PT\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,399 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\ro-RO\local_install\disable_xpi_delay.properties
    [2008/10/31 11:13:06 | 000,000,537 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\ru-RU\local_install\disable_xpi_delay.properties
    [2008/10/31 03:11:10 | 000,000,358 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\sk\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,471 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\sr-YU\local_install\disable_xpi_delay.properties
    [2008/10/31 22:22:14 | 000,000,353 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\sv-SE\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,343 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\tr-TR\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,543 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\uk-UA\local_install\disable_xpi_delay.properties
    [2008/11/04 01:48:58 | 000,000,430 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\vi-VN\local_install\disable_xpi_delay.properties
    [2007/07/18 04:38:16 | 000,000,270 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\zh-CN\local_install\disable_xpi_delay.properties
    [2008/10/31 02:30:38 | 000,000,292 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}\chrome\local_install\locale\zh-TW\local_install\disable_xpi_delay.properties
    [2014/04/18 09:17:24 | 000,004,398 | ---- | M] () (No name found) -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}\chrome\content\reminderfox\utils\rmFxUpdateXPI.xul
    [2014/05/10 06:58:07 | 000,000,000 | ---D | M] (No name found) -- F:\Program Files\Mozilla Firefox\browser\extensions
    [2014/05/10 06:59:53 | 000,000,000 | ---D | M] (Default) -- F:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    File not found (No name found) -- F:\DOCUMENTS AND SETTINGS\PAUL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\JF2V1CJF.DEFAULT\EXTENSIONS\ISREADITLATER@IDEASHOWER.COM
    File not found (No name found) -- F:\DOCUMENTS AND SETTINGS\PAUL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\JF2V1CJF.DEFAULT\EXTENSIONS\SAVEFILETO@MOZDEV.ORG.XPI
     
  2. 2014/05/15
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    OTL.txt Part 2

    O1 HOSTS File: ([2014/05/15 10:52:07 | 000,000,027 | ---- | M]) - F:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - F:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O3 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\..\Toolbar\WebBrowser: (MSN Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Program Files\MSN Toolbar\01.01.2607.0\msgr.en-us.en-gb\msntb.dll (Microsoft Corporation)
    O4 - HKLM..\Run: [APSDaemon] F:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [AvastUI.exe] F:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [ConnectionCenter] F:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
    O4 - HKLM..\Run: [NvCplDaemon] F:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [TkBellExe] F:\Program Files\Real\update\realsched.exe (RealNetworks, Inc.)
    O4 - HKLM..\Run: [zBrowser Launcher] F:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
    O4 - HKLM..\Run: [ZoomIt] F:\Documents and Settings\Paul\My Documents\Other Programs\Zoomit\ZoomIt.exe (Sysinternals - www.sysinternals.com)
    O4 - HKU\S-1-5-21-448539723-2139871995-725345543-1004..\Run: [clipdiary] F:\Program Files\Clipdiary\ClipDiary.exe ()
    O4 - HKU\S-1-5-21-448539723-2139871995-725345543-1004..\Run: [Gadwin PrintScreen] F:\Documents and Settings\Paul\My Documents\Other Programs\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
    O4 - HKU\S-1-5-21-448539723-2139871995-725345543-1004..\Run: [GoogleDriveSync] F:\Program Files\Google\Drive\googledrivesync.exe (Google)
    O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\PhraseExpress.lnk = F:\Program Files\PhraseExpress\phraseexpress.exe (Bartels Media GmbH)
    O4 - Startup: F:\Documents and Settings\Paul\Start Menu\Programs\Startup\Locate32 Autorun.lnk = F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\locate32.exe ()
    O4 - Startup: F:\Documents and Settings\Paul\Start Menu\Programs\Startup\MedalFolders.lnk = F:\Program Files\MedalFolders\MedalFolders.exe ()
    O4 - Startup: F:\Documents and Settings\Paul\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = F:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
    O4 - Startup: F:\Documents and Settings\Paul\Start Menu\Programs\Startup\Philips Media Manager.lnk = F:\Program Files\Philips\Media Manager\Philips Media Manager.exe (Royal Philips Electronics Inc)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 1
    O7 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\..Trusted Domains: ([]msn in My Computer)
    O16 - DPF: {00000161-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaud.cab (Reg Error: Key error.)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/C/8/0C8EDFAB-30BC-4792-898E-2DABE27B2C4D/mp43dmo.CAB (Reg Error: Key error.)
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
    O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab (Reg Error: Key error.)
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
    O16 - DPF: {84818113-96C5-11D2-BE39-006008BF4DD5} http://www.scotlandspeople.gov.uk/Viewers/ActiveXControl/viewdw32.ocx (ViewDirector Object)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.55.2)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.55.2)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.virginmedia.com/CST/ver1/xp_mail.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F508AB4A-234B-4593-8068-9E880E91A931}: DhcpNameServer = 192.168.0.1
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
    O20 - HKLM Winlogon: UserInit - (F:\WINDOWS\system32\userinit.exe) - F:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: F:\Documents and Settings\Paul\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: F:\Documents and Settings\Paul\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/05/07 22:13:52 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (PDBoot.exe)
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    ========== Files/Folders - Created Within 30 Days ==========

    [2014/05/15 19:23:20 | 000,000,000 | ---D | C] -- F:\WINDOWS\ERUNT
    [2014/05/15 18:46:37 | 000,000,000 | ---D | C] -- F:\AdwCleaner
    [2014/05/15 18:43:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- F:\Documents and Settings\Paul\Desktop\OTL.exe
    [2014/05/15 18:42:32 | 001,016,261 | ---- | C] (Thisisu) -- F:\Documents and Settings\Paul\Desktop\JRT.exe
    [2014/05/15 12:30:44 | 000,000,000 | -HSD | C] -- F:\RECYCLER
    [2014/05/14 07:18:40 | 000,000,000 | RHSD | C] -- F:\cmdcons
    [2014/05/14 07:16:02 | 000,518,144 | ---- | C] (SteelWerX) -- F:\WINDOWS\SWREG.exe
    [2014/05/14 07:16:02 | 000,406,528 | ---- | C] (SteelWerX) -- F:\WINDOWS\SWSC.exe
    [2014/05/14 07:16:02 | 000,212,480 | ---- | C] (SteelWerX) -- F:\WINDOWS\SWXCACLS.exe
    [2014/05/14 07:16:02 | 000,060,416 | ---- | C] (NirSoft) -- F:\WINDOWS\NIRCMD.exe
    [2014/05/14 07:15:23 | 000,000,000 | ---D | C] -- F:\Qoobox
    [2014/05/14 07:14:35 | 000,000,000 | ---D | C] -- F:\WINDOWS\erdnt
    [2014/05/13 22:47:57 | 005,200,050 | R--- | C] (Swearware) -- F:\Documents and Settings\Paul\Desktop\ComboFix.exe
    [2014/05/13 16:37:54 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Start Menu\Programs\Java
    [2014/05/13 08:56:12 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
    [2014/05/11 09:15:46 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- F:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
    [2014/05/11 09:15:18 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
    [2014/05/11 09:15:06 | 000,053,208 | ---- | C] (Malwarebytes Corporation) -- F:\WINDOWS\System32\drivers\mbamchameleon.sys
    [2014/05/11 09:15:06 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- F:\WINDOWS\System32\drivers\mbam.sys
    [2014/05/11 09:15:05 | 000,000,000 | ---D | C] -- F:\Program Files\Malwarebytes Anti-Malware
    [2014/05/11 09:08:52 | 000,688,992 | ---- | C] (Swearware) -- F:\Documents and Settings\Paul\My Documents\dds.com
    [2014/05/10 06:58:05 | 000,000,000 | ---D | C] -- F:\Program Files\Mozilla Firefox
    [2014/05/07 07:42:22 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
    [2014/05/07 07:42:20 | 000,000,000 | ---D | C] -- F:\Program Files\7-Zip
    [2014/04/30 14:56:44 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Paul\Local Settings\Application Data\Opera Software
    [2014/04/30 14:56:43 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Paul\Application Data\Opera Software
    [2014/04/30 14:56:00 | 000,000,000 | ---D | C] -- F:\Program Files\Opera
    [2014/04/29 12:19:14 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 9
    [2014/04/29 07:21:34 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Application Data\BoostSoftware
    [2014/04/28 15:44:02 | 000,000,000 | ---D | C] -- F:\WINDOWS\pss
    [2014/04/22 11:03:57 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Paul\Application Data\addpcs
    [2014/04/22 10:52:54 | 000,000,000 | ---D | C] -- F:\Program Files\Temp File Cleaner
    [2014/04/22 09:04:09 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Paul\Start Menu\Programs\Clipdiary
    [2014/04/22 09:04:08 | 000,000,000 | ---D | C] -- F:\Program Files\Clipdiary
    [2014/04/22 08:19:01 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Paul\Application Data\Clipdiary
    [2014/04/20 10:32:08 | 000,043,152 | ---- | C] (AVAST Software) -- F:\WINDOWS\avastSS.scr
    [1 F:\WINDOWS\System32\dllcache\*.tmp files -> F:\WINDOWS\System32\dllcache\*.tmp -> ]
    [1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2014/05/15 19:18:15 | 000,000,830 | ---- | M] () -- F:\WINDOWS\tasks\Adobe Flash Player Updater.job
    [2014/05/15 18:58:27 | 000,000,364 | -H-- | M] () -- F:\WINDOWS\tasks\avast! Emergency Update.job
    [2014/05/15 18:55:30 | 000,000,882 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc5518eebf6b00.job
    [2014/05/15 18:55:14 | 000,000,220 | ---- | M] () -- F:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
    [2014/05/15 18:55:02 | 000,002,048 | --S- | M] () -- F:\WINDOWS\bootstat.dat
    [2014/05/15 18:54:59 | 1072,222,208 | -HS- | M] () -- F:\hiberfil.sys
    [2014/05/15 18:49:00 | 000,000,882 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2014/05/15 18:43:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Paul\Desktop\OTL.exe
    [2014/05/15 18:42:33 | 001,016,261 | ---- | M] (Thisisu) -- F:\Documents and Settings\Paul\Desktop\JRT.exe
    [2014/05/15 18:41:32 | 001,325,827 | ---- | M] () -- F:\Documents and Settings\Paul\Desktop\adwcleaner_3.208.exe
    [2014/05/15 12:31:15 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- F:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
    [2014/05/15 12:30:26 | 000,000,782 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    [2014/05/15 10:56:54 | 000,777,488 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\drivers\aswsnx.sys
    [2014/05/15 10:56:52 | 000,054,832 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\drivers\aswrdr.sys
    [2014/05/15 10:56:50 | 000,411,680 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\drivers\aswsp.sys
    [2014/05/15 10:52:07 | 000,000,027 | ---- | M] () -- F:\WINDOWS\System32\drivers\etc\hosts
    [2014/05/15 10:51:33 | 000,002,422 | ---- | M] () -- F:\WINDOWS\System32\wpa.dbl
    [2014/05/14 09:52:00 | 000,000,284 | ---- | M] () -- F:\WINDOWS\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-448539723-2139871995-725345543-1004.job
    [2014/05/14 07:18:52 | 000,000,327 | RHS- | M] () -- F:\boot.ini
    [2014/05/13 22:48:21 | 005,200,050 | R--- | M] (Swearware) -- F:\Documents and Settings\Paul\Desktop\ComboFix.exe
    [2014/05/12 07:26:02 | 000,053,208 | ---- | M] (Malwarebytes Corporation) -- F:\WINDOWS\System32\drivers\mbamchameleon.sys
    [2014/05/12 07:25:54 | 000,023,256 | ---- | M] (Malwarebytes Corporation) -- F:\WINDOWS\System32\drivers\mbam.sys
    [2014/05/11 08:37:01 | 000,688,992 | ---- | M] (Swearware) -- F:\Documents and Settings\Paul\My Documents\dds.com
    [2014/05/09 23:16:01 | 000,000,284 | ---- | M] () -- F:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2014/05/08 19:49:53 | 000,000,214 | ---- | M] () -- F:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
    [2014/05/08 07:03:05 | 000,000,759 | ---- | M] () -- F:\Documents and Settings\All Users\Start Menu\Programs\Startup\PhraseExpress.lnk
    [2014/04/30 14:56:12 | 000,000,674 | ---- | M] () -- F:\Documents and Settings\Paul\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
    [2014/04/30 14:56:12 | 000,000,674 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\Opera.lnk
    [2014/04/29 12:19:13 | 000,000,820 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\TeamViewer 9.lnk
    [2014/04/23 09:20:05 | 000,527,930 | ---- | M] () -- F:\WINDOWS\System32\perfh009.dat
    [2014/04/23 09:20:05 | 000,097,320 | ---- | M] () -- F:\WINDOWS\System32\perfc009.dat
    [2014/04/22 11:03:27 | 000,000,715 | ---- | M] () -- F:\Documents and Settings\Paul\Desktop\Temp File Cleaner.lnk
    [2014/04/22 10:45:08 | 000,000,687 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2014/04/22 09:04:09 | 000,000,699 | ---- | M] () -- F:\Documents and Settings\Paul\Desktop\clipdiary.lnk
    [2014/04/20 10:33:47 | 000,001,738 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
    [2014/04/20 10:32:10 | 000,776,976 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\drivers\aswsnx.sys.1400147803375
    [2014/04/20 10:32:10 | 000,180,632 | ---- | M] () -- F:\WINDOWS\System32\drivers\aswVmm.sys
    [2014/04/20 10:32:10 | 000,067,824 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\drivers\aswMonFlt.sys
    [2014/04/20 10:32:10 | 000,057,672 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\drivers\aswTdi.sys
    [2014/04/20 10:32:10 | 000,054,832 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\drivers\aswrdr.sys.1400147803375
    [2014/04/20 10:32:10 | 000,049,944 | ---- | M] () -- F:\WINDOWS\System32\drivers\aswRvrt.sys
    [2014/04/20 10:32:10 | 000,024,184 | ---- | M] () -- F:\WINDOWS\System32\drivers\aswHwid.sys
    [2014/04/20 10:32:08 | 000,271,264 | ---- | M] (AVAST Software) -- F:\WINDOWS\System32\aswBoot.exe
    [2014/04/20 10:32:08 | 000,043,152 | ---- | M] (AVAST Software) -- F:\WINDOWS\avastSS.scr
    [1 F:\WINDOWS\System32\dllcache\*.tmp files -> F:\WINDOWS\System32\dllcache\*.tmp -> ]
    [1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2014/05/15 18:41:31 | 001,325,827 | ---- | C] () -- F:\Documents and Settings\Paul\Desktop\adwcleaner_3.208.exe
    [2014/05/14 07:18:51 | 000,000,210 | ---- | C] () -- F:\Boot.bak
    [2014/05/14 07:18:43 | 000,260,272 | RHS- | C] () -- F:\cmldr
    [2014/05/14 07:16:02 | 000,256,000 | ---- | C] () -- F:\WINDOWS\PEV.exe
    [2014/05/14 07:16:02 | 000,208,896 | ---- | C] () -- F:\WINDOWS\MBR.exe
    [2014/05/14 07:16:02 | 000,098,816 | ---- | C] () -- F:\WINDOWS\sed.exe
    [2014/05/14 07:16:02 | 000,080,412 | ---- | C] () -- F:\WINDOWS\grep.exe
    [2014/05/14 07:16:02 | 000,068,096 | ---- | C] () -- F:\WINDOWS\zip.exe
    [2014/05/11 09:15:18 | 000,000,782 | ---- | C] () -- F:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    [2014/04/30 14:56:12 | 000,000,674 | ---- | C] () -- F:\Documents and Settings\Paul\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
    [2014/04/30 14:56:12 | 000,000,674 | ---- | C] () -- F:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk
    [2014/04/30 14:56:12 | 000,000,674 | ---- | C] () -- F:\Documents and Settings\All Users\Desktop\Opera.lnk
    [2014/04/22 13:06:38 | 000,301,338 | ---- | C] () -- F:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
    [2014/04/22 11:03:27 | 000,000,721 | ---- | C] () -- F:\Documents and Settings\Paul\Start Menu\Programs\Temp File Cleaner.lnk
    [2014/04/22 11:03:27 | 000,000,715 | ---- | C] () -- F:\Documents and Settings\Paul\Desktop\Temp File Cleaner.lnk
    [2014/04/22 10:45:08 | 000,000,687 | ---- | C] () -- F:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2014/04/22 09:04:09 | 000,000,699 | ---- | C] () -- F:\Documents and Settings\Paul\Desktop\clipdiary.lnk
    [2014/04/20 10:32:18 | 000,024,184 | ---- | C] () -- F:\WINDOWS\System32\drivers\aswHwid.sys
    [2013/04/05 21:27:13 | 000,180,632 | ---- | C] () -- F:\WINDOWS\System32\drivers\aswVmm.sys
    [2013/04/05 21:27:10 | 000,049,944 | ---- | C] () -- F:\WINDOWS\System32\drivers\aswRvrt.sys
    [2012/09/26 21:57:16 | 000,030,568 | ---- | C] () -- F:\WINDOWS\MusiccityDownload.exe
    [2012/09/26 21:57:14 | 000,974,848 | ---- | C] () -- F:\WINDOWS\System32\cis-2.4.dll
    [2012/09/26 21:57:14 | 000,081,920 | ---- | C] () -- F:\WINDOWS\System32\issacapi_bs-2.3.dll
    [2012/09/26 21:57:14 | 000,065,536 | ---- | C] () -- F:\WINDOWS\System32\issacapi_pe-2.3.dll
    [2012/09/26 21:57:14 | 000,057,344 | ---- | C] () -- F:\WINDOWS\System32\issacapi_se-2.3.dll
    [2010/04/07 20:26:34 | 000,014,532 | -HS- | C] () -- F:\Documents and Settings\Paul\Local Settings\Application Data\GbW53PfLB
    [2010/04/07 20:26:34 | 000,014,532 | -HS- | C] () -- F:\Documents and Settings\All Users\Application Data\GbW53PfLB
    [2008/12/17 17:38:59 | 000,000,127 | ---- | C] () -- F:\Documents and Settings\Paul\Local Settings\Application Data\fusioncache.dat
    [2008/03/02 09:58:37 | 000,002,528 | ---- | C] () -- F:\Documents and Settings\Paul\Application Data\$_hpcst$.hpc
    [2006/05/13 20:04:43 | 000,001,356 | ---- | C] () -- F:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2006/05/08 23:00:42 | 000,224,256 | ---- | C] () -- F:\Documents and Settings\Paul\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    ========== ZeroAccess Check ==========

    [2014/04/18 09:17:29 | 000,000,596 | ---- | M] () -- F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}\defaults\printing\icons\@.png
    [2008/01/25 02:31:49 | 000,000,227 | RHS- | M] () -- F:\WINDOWS\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    " " = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 01:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    " " = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
    " " = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 01:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    ========== LOP Check ==========

    [2014/04/05 06:40:03 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
    [2014/04/02 21:48:45 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\AVAST Software
    [2014/04/30 10:24:38 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\BoostSoftware
    [2011/12/23 18:37:52 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\Citrix
    [2010/09/22 11:24:50 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\Nokia
    [2009/08/17 20:06:26 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\NokiaMusic
    [2009/08/17 20:16:03 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\PC Suite
    [2012/12/01 19:06:59 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\PhraseExpress
    [2012/10/29 17:32:40 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\Radialpoint
    [2008/12/28 19:09:34 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\Sports Interactive
    [2008/12/17 17:33:02 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\ViaMichelin
    [2011/05/04 22:13:16 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/09/10 12:12:56 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2008/03/30 18:39:18 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\.BitTornado
    [2014/04/22 11:03:57 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\addpcs
    [2014/04/02 22:13:43 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\AVAST Software
    [2014/05/15 11:14:08 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Clipdiary
    [2010/03/22 18:30:53 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Facebook
    [2012/10/31 14:51:58 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\FreeBurner
    [2011/12/23 19:05:42 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\ICAClient
    [2006/05/13 18:10:24 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Kazaa Lite
    [2012/10/10 08:34:19 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Locate32
    [2012/10/31 15:45:22 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\OpenOffice.org
    [2014/04/30 14:56:43 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Opera Software
    [2009/08/17 20:15:59 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\PC Suite
    [2012/12/01 19:06:59 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\PhraseExpress
    [2012/01/08 11:52:18 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Radialpoint
    [2008/03/02 10:49:19 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Shareaza
    [2008/12/28 18:28:41 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Sports Interactive
    [2014/04/30 11:09:12 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\TeamViewer
    [2014/05/14 07:10:39 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\TV-Browser
    [2008/03/08 16:39:03 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\UK's Kalender

    ========== Purity Check ==========



    ========== Files - Unicode (All) ==========
    [2009/09/22 22:41:27 | 000,000,040 | ---- | M] ()(F:\WINDOWS\System32\????????????????????????????????????g) -- F:\WINDOWS\System32\㩆停潲牧浡䘠汩獥噜物楧牂慯扤湡層䍐畧牡層慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g
    [2009/09/22 22:41:27 | 000,000,040 | ---- | C] ()(F:\WINDOWS\System32\????????????????????????????????????g) -- F:\WINDOWS\System32\㩆停潲牧浡䘠汩獥噜物楧牂慯扤湡層䍐畧牡層慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 88 bytes -> F:\Documents and Settings\Paul\Desktop\1219.scr:SummaryInformation

    < End of report >
     

  3. to hide this advert.

  4. 2014/05/15
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Extras.txt Part 1

    OTL Extras logfile created on: 15/05/2014 19:38:31 - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = F:\Documents and Settings\Paul\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    1022.48 Mb Total Physical Memory | 341.93 Mb Available Physical Memory | 33.44% Memory free
    2.13 Gb Paging File | 1.57 Gb Available in Paging File | 73.72% Paging File free
    Paging file location(s): F:\pagefile.sys 1250 2304 [binary data]

    %SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
    Drive C: | 37.27 Gb Total Space | 31.30 Gb Free Space | 84.00% Space Free | Partition Type: NTFS
    Drive F: | 76.32 Gb Total Space | 7.93 Gb Free Space | 10.38% Space Free | Partition Type: NTFS

    Computer Name: PC | User Name: Paul | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .html [@ = FirefoxHTML] -- F:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
    .reg [@ = regfile] -- regedit.exe "%1 "

    [HKEY_USERS\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- F:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- Reg Error: Key error.
    https [open] -- "F:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [open] -- regedit.exe "%1 "
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [locate] -- "F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\locate32.exe" /p "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "AntiVirusOverride" = 1
    "FirewallOverride" = 0
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 0
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
    "139:TCP" = 139:TCP:*:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:mad:xpsp2res.dll,-22002

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
    "6881:TCP" = 6881:TCP:*:Enabled:Blizzard Downloader: 6881
    "26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
    "139:TCP" = 139:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22002

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "F:\Program Files\Microsoft ActiveSync\rapimgr.exe" = F:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)
    "F:\Program Files\Microsoft ActiveSync\wcescomm.exe" = F:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
    "F:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = F:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)
    "F:\Program Files\Windows Live\Messenger\wlcsdk.exe" = F:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
    "F:\Program Files\Windows Live\Messenger\msnmsgr.exe" = F:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
    "F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "F:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe" = F:\Program Files\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:backWeb-8876480 -- ()
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "F:\Program Files\BitTornado\btdownloadgui.exe" = F:\Program Files\BitTornado\btdownloadgui.exe:*:Enabled:btdownloadgui -- ()
    "F:\Program Files\Microsoft ActiveSync\rapimgr.exe" = F:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)
    "F:\Program Files\Microsoft ActiveSync\wcescomm.exe" = F:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
    "F:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = F:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)
    "F:\Program Files\Windows Live\Messenger\wlcsdk.exe" = F:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
    "F:\Program Files\Windows Live\Messenger\msnmsgr.exe" = F:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
    "F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
    "F:\WINDOWS\system32\muzapp.exe" = F:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player -- (Musiccity Co.Ltd.)
    "F:\Program Files\Bonjour\mDNSResponder.exe" = F:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
    "F:\Program Files\TV-Browser\tvbrowser.exe" = F:\Program Files\TV-Browser\tvbrowser.exe:*:Enabled:TV-Browser -- ()
    "F:\Program Files\TV-Browser\tvbrowser_noDD.exe" = F:\Program Files\TV-Browser\tvbrowser_noDD.exe:*:Enabled:TV-Browser (without DirectX) -- ()
    "F:\Program Files\Java\jre7\bin\java.exe" = F:\Program Files\Java\jre7\bin\java.exe:*:Enabled:Java -- (Oracle Corporation)
    "F:\Program Files\Java\jre7\bin\javaw.exe" = F:\Program Files\Java\jre7\bin\javaw.exe:*:Enabled:Java -- (Oracle Corporation)
    "F:\Program Files\iTunes\iTunes.exe" = F:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
    "F:\Program Files\TeamViewer\Version9\TeamViewer.exe" = F:\Program Files\TeamViewer\Version9\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
    "F:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe" = F:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service -- (TeamViewer GmbH)
    "F:\Program Files\PhraseExpress\PhraseExpress.exe" = F:\Program Files\PhraseExpress\PhraseExpress.exe:*:Enabled:phraseExpress -- (Bartels Media GmbH)
    "F:\Program Files\Google\Chrome Remote Desktop\34.0.1847.86\remoting_host.exe" = F:\Program Files\Google\Chrome Remote Desktop\34.0.1847.86\remoting_host.exe:*:Enabled:Chrome Remote Desktop Host -- (Google Inc.)
     
  5. 2014/05/15
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Extras.txt Part 2 (and last)

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
    "{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
    "{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}" = Citrix online plug-in (Web)
    "{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
    "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
    "{0EB60281-1F3E-4B01-96C4-AC1C1D1B4D2B}" = PC Camera (6025 VGA)
    "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{18D47FA1-0440-48D3-A7E0-DA09537FF471}" = Apple Mobile Device Support
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{26A24AE4-039D-4CA4-87B4-2F83217055FF}" = Java 7 Update 55
    "{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
    "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
    "{2F1E5C4C-B20C-42C3-B5F1-1FE2CA207AFE}" = Email Updater
    "{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}" = iTunes
    "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
    "{33565C22-2E44-4B36-9147-23912E838F81}" = Wireless Audio Device Manager
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{418BAAD1-754D-48B4-B078-46EF4F25AF42}" = Google Drive
    "{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4E64E769-E3AA-11D7-B6FB-00055D7C3943}" = USB Product Driver v2.08r011
    "{55392E52-1AAD-44C4-BE49-258FFE72434F}" = Citrix online plug-in (USB)
    "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
    "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
    "{6E524C61-42EC-11D5-98E1-0050BA0133AC}" = Hardware Doctor
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{7500DE13-266F-43F8-8577-A593B1FF20E4}" = Application Suite
    "{7673108D-9DED-4454-9712-FB2771D94446}" = RPS PerfectDiskStub
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
    "{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
    "{812424AC-A8B5-44E6-8D48-07E939D1AD9A}" = Citrix online plug-in (HDX)
    "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
    "{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
    "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9527450C-64B3-11D5-9B31-000021116B62}" = SmartCamera Ver 2.1
    "{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A4B9033B-D183-4A6C-9BCB-6BC8F80B939D}" = RPS CRT
    "{A5D4E41C-2583-46FE-9B99-62496F85C5F3}" = RPS CRT
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}" = Apple Application Support
    "{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
    "{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
    "{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
    "{BEFD9552-C1D4-4A8B-BD44-4F910ACD079E}" = Chrome Remote Desktop Host
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CF53CF7C-D996-43EB-9904-DBED57C25625}" = Citrix online plug-in (DV)
    "{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
    "{E6696A8C-C55A-405C-AFEB-F3880A8BAA45}" = iPod Update 2004-04-28
    "{ECCE5126-9A87-48CC-A2FA-A3D8483AE86B}_is1" = PDFTOEXCEL
    "{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
    "{EFEDD205-43FE-4208-B682-0937E803E19E}_is1" = NexusFont 2.5 (ver 2.5.8.1582)
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9
    "504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
    "7-Zip" = 7-Zip 9.32 alpha
    "Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
    "Auto Care" = Auto Care
    "avast" = avast! Free Antivirus
    "BitTornado" = BitTornado 0.3.17
    "Campaign Cartographer 2" = Campaign Cartographer 2
    "CCleaner" = CCleaner
    "CDisplay_is1" = CDisplay 1.8
    "CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
    "Clipdiary" = Clipdiary 1.4
    "Defraggler" = Defraggler
    "Download_Manager_and_Options" = Download Manager and Options
    "Gadwin PrintScreen" = Gadwin PrintScreen
    "GoogleVideoPlayer" = Google Video Player
    "HijackThis" = HijackThis 1.99.1
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
    "InstallShield_{E6696A8C-C55A-405C-AFEB-F3880A8BAA45}" = iPod Update 2004-04-28
    "InterActual Player" = InterActual Player
    "Jasc Paint Shop Pro 9 GDI+ Patch" = Jasc Paint Shop Pro 9 GDI+ Patch
    "Jasc Paint Shop Pro 9.01 Patch" = Jasc Paint Shop Pro 9.01 Patch
    "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.57
    "Legacy 5.0" = Legacy 5.0
    "Macromedia Shockwave Player" = Macromedia Shockwave Player
    "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012
    "MedalFolders" = MedalFolders 2.0.0.500
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Mozilla Firefox 29.0.1 (x86 en-US)" = Mozilla Firefox 29.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "MSN Toolbar" = MSN Toolbar
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "NVIDIA Display Driver" = NVIDIA Display Driver
    "Opera 20.0.1387.91" = Opera Stable 20.0.1387.91
    "Philips Media Manager 3.3.12.0004" = Philips Media Manager 3.3.12.0004
    "PhraseExpress_is1" = PhraseExpress v10.1.35
    "RealPlayer 16.0" = RealPlayer
    "Revo Uninstaller" = Revo Uninstaller 1.95
    "TeamViewer 9" = TeamViewer 9
    "Temp File Cleaner" = Temp File Cleaner
    "tvbrowser" = TV-Browser 3.3.3
    "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    "WIC" = Windows Imaging Component
    "WinAce Archiver" = WinAce Archiver
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows Mobile Device Handbook" = Windows Mobile® MDA Compact V Handbook
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Facebook Plug-In" = Facebook Plug-In

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 15/05/2014 04:01:57 | Computer Name = PC | Source = Application Error | ID = 1001
    Description = Fault bucket 196813194.

    Error - 15/05/2014 04:02:06 | Computer Name = PC | Source = Application Error | ID = 1001
    Description = Fault bucket 196813194.

    Error - 15/05/2014 05:42:15 | Computer Name = PC | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: A connection with the server could not be established

    Error - 15/05/2014 05:52:19 | Computer Name = PC | Source = SecurityCenter | ID = 1802
    Description = The Windows Security Center Service was unable to establish event
    queries with WMI to monitor third party AntiVirus and Firewall.

    Error - 15/05/2014 06:51:29 | Computer Name = PC | Source = Application Error | ID = 1000
    Description = Faulting application remoting_host.exe, version 35.0.1916.52, faulting
    module remoting_core.dll, version 35.0.1916.52, fault address 0x00025665.

    Error - 15/05/2014 06:51:49 | Computer Name = PC | Source = Application Error | ID = 1001
    Description = Fault bucket 196813194.

    Error - 15/05/2014 06:52:22 | Computer Name = PC | Source = MsiInstaller | ID = 11720
    Description = Product: Chrome Remote Desktop Host -- Error 1720. There is a problem
    with this Windows Installer package. A script required for this install to complete
    could not be run. Contact your support personnel or package vendor. Custom action
    set_auto_start_service script error -2146827859, Microsoft JScript runtime error:
    Automation server can't create object Line 1, Column 1,

    Error - 15/05/2014 11:50:24 | Computer Name = PC | Source = Application Error | ID = 1000
    Description = Faulting application remoting_host.exe, version 35.0.1916.52, faulting
    module remoting_core.dll, version 35.0.1916.52, fault address 0x00025665.

    Error - 15/05/2014 11:53:45 | Computer Name = PC | Source = MsiInstaller | ID = 11720
    Description = Product: Chrome Remote Desktop Host -- Error 1720. There is a problem
    with this Windows Installer package. A script required for this install to complete
    could not be run. Contact your support personnel or package vendor. Custom action
    set_auto_start_service script error -2146827859, Microsoft JScript runtime error:
    Automation server can't create object Line 1, Column 1,

    Error - 15/05/2014 13:38:42 | Computer Name = PC | Source = Application Error | ID = 1001
    Description = Fault bucket 196813194.

    Error - 15/05/2014 13:55:38 | Computer Name = PC | Source = SecurityCenter | ID = 1802
    Description = The Windows Security Center Service was unable to establish event
    queries with WMI to monitor third party AntiVirus and Firewall.

    [ System Events ]
    Error - 14/05/2014 00:04:47 | Computer Name = PC | Source = Service Control Manager | ID = 7001
    Description = The RadialpointIDSDriver service depends on the RadialpointIDSFilter
    service which failed to start because of the following error: %%1068

    Error - 14/05/2014 00:04:47 | Computer Name = PC | Source = Service Control Manager | ID = 7001
    Description = The RadialpointIDSAgent service depends on the RadialpointIDSDriver
    service which failed to start because of the following error: %%1068

    Error - 14/05/2014 00:50:58 | Computer Name = PC | Source = DCOM | ID = 10010
    Description = The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register
    with DCOM within the required timeout.

    Error - 14/05/2014 02:45:09 | Computer Name = PC | Source = Service Control Manager | ID = 7000
    Description = The Virgin Media Security Firewall service failed to start due to
    the following error: %%3

    Error - 14/05/2014 02:45:09 | Computer Name = PC | Source = Service Control Manager | ID = 7000
    Description = The RadialpointIDSShim service failed to start due to the following
    error: %%3

    Error - 14/05/2014 02:45:09 | Computer Name = PC | Source = Service Control Manager | ID = 7001
    Description = The RadialpointIDSFilter service depends on the RadialpointIDSShim
    service which failed to start because of the following error: %%3

    Error - 14/05/2014 02:45:09 | Computer Name = PC | Source = Service Control Manager | ID = 7001
    Description = The RadialpointIDSDriver service depends on the RadialpointIDSFilter
    service which failed to start because of the following error: %%1068

    Error - 14/05/2014 02:45:10 | Computer Name = PC | Source = Service Control Manager | ID = 7001
    Description = The RadialpointIDSAgent service depends on the RadialpointIDSDriver
    service which failed to start because of the following error: %%1068

    Error - 14/05/2014 05:52:52 | Computer Name = PC | Source = DCOM | ID = 10010
    Description = The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register
    with DCOM within the required timeout.

    Error - 14/05/2014 10:52:37 | Computer Name = PC | Source = DCOM | ID = 10010
    Description = The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register
    with DCOM within the required timeout.


    < End of report >
     
  6. 2014/05/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG] Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following
    Code:
    :OTL
    SRV - File not found [Disabled | Stopped] -- -- (ServiceLayer)
    SRV - File not found [Auto | Stopped] -- -- (RP_FWS)
    SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
    SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev)
    DRV - File not found [Kernel | On_Demand | Stopped] -- F:\Program Files\Virgin Media\Security\BitDefender\trufos.sys -- (Trufos)
    DRV - File not found [Kernel | On_Demand | Stopped] -- F:\Program Files\Virgin Media\Security\BitDefender\profos.sys -- (Profos)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- F:\ComboFix\catchme.sys -- (catchme)
    DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\AFGSp50.sys -- (AFGSp50)
    DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\AFGMp50.sys -- (AFGMp50)
    DRV - [2010/11/11 12:03:25 | 000,053,192 | ---- | M] (Radialpoint Inc.) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\rp_skt32.sys -- (RPSKT)
    DRV - [2009/11/02 16:27:02 | 000,025,608 | ---- | M] (AVG Technologies ) [Kernel | Boot | Running] -- F:\WINDOWS\system32\drivers\AVGIDSEH.sys -- (RadialpointIDSEH)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O15 - HKU\S-1-5-21-448539723-2139871995-725345543-1004\..Trusted Domains: ([]msn in My Computer)
    O16 - DPF: {00000161-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaud.cab (Reg Error: Key error.)
    O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/downlo...4D/mp43dmo.CAB (Reg Error: Key error.)
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/downlo...22/wmv9VCM.CAB (Reg Error: Key error.)
    O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/downlo...0C/wmv9dmo.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.virginmedia.com/CST/ver1/xp_mail.cab (Reg Error: Key error.)
    [2010/04/07 20:26:34 | 000,014,532 | -HS- | C] () -- F:\Documents and Settings\Paul\Local Settings\Application Data\GbW53PfLB
    [2010/04/07 20:26:34 | 000,014,532 | -HS- | C] () -- F:\Documents and Settings\All Users\Application Data\GbW53PfLB
    [2012/10/29 17:32:40 | 000,000,000 | ---D | M] -- F:\Documents and Settings\All Users\Application Data\Radialpoint
    [2012/01/08 11:52:18 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Paul\Application Data\Radialpoint
    @Alternate Data Stream - 88 bytes -> F:\Documents and Settings\Paul\Desktop\1219.scr:SummaryInformation
    
    :Services
    
    :Reg
    
    :Files
    C:\FRST
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
    
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    [​IMG] Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Click on "Run ESET Online Scanner" button.
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  7. 2014/05/16
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Ok, new day, new scans! OTL first, then back later with the other 4.....

    OTL

    All processes killed
    ========== OTL ==========
    Service ServiceLayer stopped successfully!
    Service ServiceLayer deleted successfully!
    Service RP_FWS stopped successfully!
    Service RP_FWS deleted successfully!
    Service HidServ stopped successfully!
    Service HidServ deleted successfully!
    File %SystemRoot%\System32\hidserv.dll not found.
    Service AppMgmt stopped successfully!
    Service AppMgmt deleted successfully!
    File %SystemRoot%\System32\appmgmts.dll not found.
    Service WDICA stopped successfully!
    Service WDICA deleted successfully!
    Service upperdev stopped successfully!
    Service upperdev deleted successfully!
    File system32\DRIVERS\usbser_lowerflt.sys not found.
    Service Trufos stopped successfully!
    Service Trufos deleted successfully!
    File F:\Program Files\Virgin Media\Security\BitDefender\trufos.sys not found.
    Service Profos stopped successfully!
    Service Profos deleted successfully!
    File F:\Program Files\Virgin Media\Security\BitDefender\profos.sys not found.
    Service PDRFRAME stopped successfully!
    Service PDRFRAME deleted successfully!
    Service PDRELI stopped successfully!
    Service PDRELI deleted successfully!
    Service PDFRAME stopped successfully!
    Service PDFRAME deleted successfully!
    Service PDCOMP stopped successfully!
    Service PDCOMP deleted successfully!
    Service PCIDump stopped successfully!
    Service PCIDump deleted successfully!
    Service nmwcdnsu stopped successfully!
    Service nmwcdnsu deleted successfully!
    File system32\drivers\nmwcdnsu.sys not found.
    Service lbrtfdc stopped successfully!
    Service lbrtfdc deleted successfully!
    Service i2omgmt stopped successfully!
    Service i2omgmt deleted successfully!
    Service Changer stopped successfully!
    Service Changer deleted successfully!
    Service catchme stopped successfully!
    Service catchme deleted successfully!
    File F:\ComboFix\catchme.sys not found.
    Service AFGSp50 stopped successfully!
    Service AFGSp50 deleted successfully!
    File System32\Drivers\AFGSp50.sys not found.
    Service AFGMp50 stopped successfully!
    Service AFGMp50 deleted successfully!
    File System32\Drivers\AFGMp50.sys not found.
    Error: Unable to stop service RPSKT!
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RPSKT deleted successfully.
    F:\WINDOWS\system32\drivers\rp_skt32.sys moved successfully.
    Service RadialpointIDSEH stopped successfully!
    Service RadialpointIDSEH deleted successfully!
    F:\WINDOWS\system32\drivers\AVGIDSEH.sys moved successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
    Registry value HKEY_USERS\S-1-5-21-448539723-2139871995-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\ deleted successfully.
    Starting removal of ActiveX control {00000161-9980-0010-8000-00AA00389B71}
    F:\WINDOWS\Downloaded Program Files\msaud.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000161-9980-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000161-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{00000161-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000161-9980-0010-8000-00AA00389B71}\ not found.
    Starting removal of ActiveX control {3334504D-9980-0010-8000-00AA00389B71}
    F:\WINDOWS\Downloaded Program Files\mp43dmo.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3334504D-9980-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3334504D-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3334504D-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3334504D-9980-0010-8000-00AA00389B71}\ not found.
    Starting removal of ActiveX control {33564D57-0000-0010-8000-00AA00389B71}
    F:\WINDOWS\Downloaded Program Files\WMV9VCM.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-0000-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-0000-0010-8000-00AA00389B71}\ not found.
    Starting removal of ActiveX control {33564D57-9980-0010-8000-00AA00389B71}
    F:\WINDOWS\Downloaded Program Files\wmv9dmo.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-9980-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Starting removal of ActiveX control {FD0EBBED-0C42-4D0F-82DA-44399B5C420A}
    F:\WINDOWS\Downloaded Program Files\download_xp.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD0EBBED-0C42-4D0F-82DA-44399B5C420A}\ not found.
    F:\Documents and Settings\Paul\Local Settings\Application Data\GbW53PfLB moved successfully.
    F:\Documents and Settings\All Users\Application Data\GbW53PfLB moved successfully.
    F:\Documents and Settings\All Users\Application Data\Radialpoint\Minidumps folder moved successfully.
    F:\Documents and Settings\All Users\Application Data\Radialpoint\Home Security Map folder moved successfully.
    F:\Documents and Settings\All Users\Application Data\Radialpoint folder moved successfully.
    F:\Documents and Settings\Paul\Application Data\Radialpoint\Home Security Map folder moved successfully.
    F:\Documents and Settings\Paul\Application Data\Radialpoint folder moved successfully.
    ADS F:\Documents and Settings\Paul\Desktop\1219.scr:SummaryInformation deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File\Folder C:\FRST not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 278662 bytes

    User: NetworkService
    ->Temp folder emptied: 16384 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Paul
    ->Temp folder emptied: 68032382 bytes
    ->Temporary Internet Files folder emptied: 10387554 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 65481185 bytes
    ->Flash cache emptied: 2082 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 2577 bytes
    %systemroot%\System32\dllcache .tmp files removed: 33792 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 16426 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 2572338 bytes
    RecycleBin emptied: 376112 bytes

    Total Files Cleaned = 140.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default User

    User: LocalService

    User: NetworkService

    User: Paul
    ->Java cache emptied: 0 bytes

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default User

    User: LocalService

    User: NetworkService

    User: Paul
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 05162014_060912

    Files\Folders moved on Reboot...
    File\Folder F:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_a3c.dat not found!
    F:\Documents and Settings\Paul\Local Settings\Temp\WCESLog.log moved successfully.
    File move failed. F:\WINDOWS\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
    File\Folder F:\WINDOWS\temp\_avast_\Webshlock.txt not found!

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  8. 2014/05/16
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Security Check report:-

    Results of screen317's Security Check version 0.99.83
    Windows XP Service Pack 3 x86
    Internet Explorer 8
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    avast! Free Antivirus
    `````````Anti-malware/Other Utilities Check:`````````
    Out of date HijackThis installed!
    SUPERAntiSpyware
    HijackThis 1.99.1
    CCleaner
    Temp File Cleaner
    Java 7 Update 55
    Adobe Flash Player 13.0.0.214
    Mozilla Firefox (29.0.1)
    ````````Process Check: objlist.exe by Laurent````````
    AVAST Software Avast AvastSvc.exe
    AVAST Software Avast AvastUI.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive F:: 35% Defragment your hard drive soon! (Do NOT defrag if SSD!)
    ````````````````````End of Log``````````````````````
     
  9. 2014/05/16
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    FSS report:-

    Farbar Service Scanner Version: 14-05-2014
    Ran by Paul (administrator) on 16-05-2014 at 06:41:10
    Running from "F:\Documents and Settings\Paul\Desktop "
    Microsoft Windows XP Home Edition Service Pack 3 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Security Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Other Services:
    ==============


    File Check:
    ========
    F:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
    F:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
    F:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
    F:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
    F:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
    F:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
    F:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
    F:\WINDOWS\system32\netman.dll => MD5 is legit
    F:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
    F:\WINDOWS\system32\srsvc.dll => MD5 is legit
    F:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
    F:\WINDOWS\system32\wscsvc.dll => MD5 is legit
    F:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
    F:\WINDOWS\system32\wuauserv.dll => MD5 is legit
    F:\WINDOWS\system32\qmgr.dll => MD5 is legit
    F:\WINDOWS\system32\es.dll => MD5 is legit
    F:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
    F:\WINDOWS\system32\svchost.exe => MD5 is legit
    F:\WINDOWS\system32\rpcss.dll => MD5 is legit
    F:\WINDOWS\system32\services.exe => MD5 is legit

    Extra List:
    =======
    aswTdi(13) Gpc(3) IPSec(5) NetBT(6) PSched(7) RPPKT(12) Tcpip(4)
    0x0D00000005000000010000000200000003000000040000000D000000060000000700000008000000090000000A0000000B0000000C000000
    IpSec Tag value is correct.

    **** End of log ****
     
  10. 2014/05/16
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    ESET Scan:-

    F:\Documents and Settings\Paul\My Documents\Firefox Extensions\keylogger-1.6-fx.xpi JS/Chromex.Spy.A trojan deleted - quarantined


    Just to inform you TFC ran ok.
     
  11. 2014/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Your computer is clean [​IMG]

    1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download [​IMG]DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore
    • Reset system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.

    2. Make sure Windows Updates are current.

    3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    4. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    11. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
    About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

    12. Please, let me know, how your computer is doing.
     
  12. 2014/05/18
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Thanks very much for disinfesting this old beast broni! Much appreciated.

    It seems to be running fine at the mo, but the original problem has not gone away through the whole process??
     
  13. 2014/05/18
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download Farbar Recovery Scan Tool and save it to your Desktop.

    Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please copy and paste it to your reply.
     
  14. 2014/05/21
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Hi again!
    FRST.txt Part 1:-

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-05-2014
    Ran by Paul (administrator) on PC on 21-05-2014 07:06:17
    Running from F:\Documents and Settings\Paul\My Documents\Downloads\PC Security Stuff
    Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English(US)
    Internet Explorer Version 8
    Boot Mode: Normal

    The only official download link for FRST:
    Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
    Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
    See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (Logitech Inc.) F:\Program Files\Logitech\iTouch\iTouch.exe
    (Citrix Systems, Inc.) F:\Program Files\Citrix\ICA Client\concentr.exe
    (AVAST Software) F:\Program Files\AVAST Software\Avast\AvastUI.exe
    (Sysinternals - www.sysinternals.com) F:\Documents and Settings\Paul\My Documents\Other Programs\Zoomit\ZoomIt.exe
    (Apple Inc.) F:\Program Files\iTunes\iTunesHelper.exe
    (Oracle Corporation) F:\Program Files\Common Files\Java\Java Update\jusched.exe
    (RealNetworks, Inc.) F:\Program Files\Real\Update\realsched.exe
    (Microsoft Corporation) F:\Program Files\Microsoft ActiveSync\wcescomm.exe
    (Google Inc.) F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    (Google) F:\Program Files\Google\Drive\googledrivesync.exe
    (Gadwin Systems, Inc) F:\Documents and Settings\Paul\My Documents\Other Programs\PrintScreen\PrintScreen.exe
    () F:\Program Files\Clipdiary\ClipDiary.exe
    (Bartels Media GmbH) F:\Program Files\PhraseExpress\phraseexpress.exe
    (Citrix Systems, Inc.) F:\Program Files\Citrix\ICA Client\wfcrun32.exe
    () F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\locate32.exe
    () F:\Program Files\MedalFolders\MedalFolders.exe
    (Microsoft Corporation) F:\PROGRA~1\MICROS~3\rapimgr.exe
    (OpenOffice.org) F:\Program Files\OpenOffice.org 3\program\soffice.exe
    (OpenOffice.org) F:\Program Files\OpenOffice.org 3\program\soffice.bin
    (SUPERAntiSpyware.com) F:\Program Files\SUPERAntiSpyware\SASCore.exe
    (Apple Inc.) F:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (AVAST Software) F:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (Apple Inc.) F:\Program Files\Bonjour\mDNSResponder.exe
    (Oracle Corporation) F:\Program Files\Java\jre7\bin\jqs.exe
    (Microsoft Corporation) F:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    (NVIDIA Corporation) F:\WINDOWS\system32\nvsvc32.exe
    () F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
    (TeamViewer GmbH) F:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
    (Google) F:\Program Files\Google\Drive\googledrivesync.exe
    (Microsoft Corporation) F:\WINDOWS\system32\wscntfy.exe
    (TeamViewer GmbH) F:\Program Files\TeamViewer\Version9\TeamViewer.exe
    (Apple Inc.) F:\Program Files\iPod\bin\iPodService.exe
    (Microsoft Corporation) F:\WINDOWS\system32\taskmgr.exe
    (TeamViewer GmbH) F:\Program Files\TeamViewer\Version9\tv_w32.exe
    (Google Inc.) F:\Program Files\Google\Chrome Remote Desktop\34.0.1847.86\remoting_host.exe
    (Google Inc.) F:\Program Files\Google\Chrome Remote Desktop\34.0.1847.86\remoting_host.exe


    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [NvCplDaemon] => F:\WINDOWS\system32\NvCpl.dll [5058560 2003-10-06] (NVIDIA Corporation)
    HKLM\...\Run: [zBrowser Launcher] => F:\Program Files\Logitech\iTouch\iTouch.exe [892928 2004-03-18] (Logitech Inc.)
    HKLM\...\Run: [ConnectionCenter] => F:\Program Files\Citrix\ICA Client\concentr.exe [103768 2009-09-13] (Citrix Systems, Inc.)
    HKLM\...\Run: [APSDaemon] => F:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
    HKLM\...\Run: [QuickTime Task] => F:\Program Files\QuickTime\qttask.exe [421888 2012-04-18] (Apple Inc.)
    HKLM\...\Run: [AvastUI.exe] => F:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-20] (AVAST Software)
    HKLM\...\Run: [ZoomIt] => F:\Documents and Settings\Paul\My Documents\Other Programs\Zoomit\ZoomIt.exe [551784 2009-10-20] (Sysinternals - www.sysinternals.com)
    HKLM\...\Run: [iTunesHelper] => F:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
    HKLM\...\Run: [SunJavaUpdateSched] => F:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM\...\Run: [TkBellExe] => F:\Program Files\Real\update\realsched.exe [295512 2014-05-17] (RealNetworks, Inc.)
    HKU\S-1-5-21-448539723-2139871995-725345543-1004\...\Run: [H/PC Connection Agent] => F:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation)
    HKU\S-1-5-21-448539723-2139871995-725345543-1004\...\Run: [swg] => F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2007-07-08] (Google Inc.)
    HKU\S-1-5-21-448539723-2139871995-725345543-1004\...\Run: [GoogleDriveSync] => F:\Program Files\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google)
    HKU\S-1-5-21-448539723-2139871995-725345543-1004\...\Run: [Gadwin PrintScreen] => F:\Documents and Settings\Paul\My Documents\Other Programs\PrintScreen\PrintScreen.exe [1842384 2012-05-30] (Gadwin Systems, Inc)
    HKU\S-1-5-21-448539723-2139871995-725345543-1004\...\Run: [clipdiary] => F:\Program Files\Clipdiary\clipdiary.exe [208896 2007-05-22] ()
    HKU\S-1-5-21-448539723-2139871995-725345543-1004\...\Policies\Explorer: [NoBandCustomize] 1
    HKU\S-1-5-21-448539723-2139871995-725345543-1004\...\Policies\Explorer: [ClearRecentDocsOnExit] 0x0000000000000000
    Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\PhraseExpress.lnk
    ShortcutTarget: PhraseExpress.lnk -> F:\Program Files\PhraseExpress\phraseexpress.exe (Bartels Media GmbH)
    Startup: F:\Documents and Settings\Paul\Start Menu\Programs\Startup\Locate32 Autorun.lnk
    ShortcutTarget: Locate32 Autorun.lnk -> F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\locate32.exe ()
    Startup: F:\Documents and Settings\Paul\Start Menu\Programs\Startup\MedalFolders.lnk
    ShortcutTarget: MedalFolders.lnk -> F:\Program Files\MedalFolders\MedalFolders.exe ()
    Startup: F:\Documents and Settings\Paul\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
    ShortcutTarget: OpenOffice.org 3.4.1.lnk -> F:\Program Files\OpenOffice.org 3\program\quickstart.exe ()

    ==================== Internet (Whitelisted) ====================

    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1886441CE21ACB01
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.co.uk/search?sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&q={searchTerms}&rlz=1I7GGLL_en-GB
    SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.co.uk/search?sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&q={searchTerms}&rlz=1I7GGLL_en-GB
    BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
    BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - F:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
    BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - F:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
    Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - F:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
    Toolbar: HKCU - MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Program Files\MSN Toolbar\01.01.2607.0\msgr.en-us.en-gb\msntb.dll (Microsoft Corporation)
    Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: {84818113-96C5-11D2-BE39-006008BF4DD5} http://www.scotlandspeople.gov.uk/Viewers/ActiveXControl/viewdw32.ocx
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
    Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
    Winsock: Catalog5 04 F:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

    FireFox:
    ========
    FF ProfilePath: F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default
    FF Homepage: google.co.uk
    FF Plugin: @adobe.com/FlashPlayer - F:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
    FF Plugin: @Apple.com/iTunes,version=1.0 - F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF Plugin: @java.com/DTPlugin,version=10.55.2 - F:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=10.55.2 - F:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - F:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin: @microsoft.com/WPF,version=3.5 - F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF Plugin: @real.com/nppl3260;version=16.0.3.51 - F:\Program Files\Real\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
    FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
    FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
    FF Plugin: @real.com/nprpjplug;version=6.0.12.46 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF Plugin: @real.com/nprpplugin;version=16.0.3.51 - F:\Program Files\Real\Netscape6\nprpplugin.dll (RealPlayer)
    FF Plugin: @realnetworks.com/npdlplugin;version=1 - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
    FF Plugin: @tools.google.com/Google Update;version=3 - F:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin: @tools.google.com/Google Update;version=9 - F:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin HKCU: @facebook.com/FBPlugin,version=1.0.1 - F:\Documents and Settings\Paul\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
    FF Plugin HKCU: @facebook.com/FBPlugin,version=1.0.3 - F:\Documents and Settings\Paul\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
    FF Extension: Facebook Notification - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\facebook_notification@wips.com [2014-04-03]
    FF Extension: Autofill - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\firefox-autofill@googlegroups.com [2013-06-14]
    FF Extension: Ginger - Grammar and Spell Checker - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\firefox@gingersoftware.com [2014-04-11]
    FF Extension: Secure Login - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\secureLogin@blueimp.net [2012-11-28]
    FF Extension: Stylish-Custom - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\Stylish-Custom@choggi.dyndns.org [2012-10-30]
    FF Extension: AddThis - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79} [2012-12-01]
    FF Extension: MR Tech Toolkit - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC} [2012-10-30]
    FF Extension: WOT - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-05-21]
    FF Extension: ReminderFox - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae} [2014-04-18]
    FF Extension: eCleaner - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd} [2013-06-14]
    FF Extension: Add Bookmark Here ² - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\abhere2@moztw.org.xpi [2012-12-01]
    FF Extension: Autofill - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\firefox-autofill@googlegroups.com.xpi [2013-06-14]
    FF Extension: Save Text To File - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\HighlightedTextToFile@bobbyrne01.org.xpi [2013-08-27]
    FF Extension: Android Desktop Notifications - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\jid0-105eGBfutA8RahNXKJRXP7CPNs0@jetpack.xpi [2014-05-06]
    FF Extension: YouTube Center - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2014-05-11]
    FF Extension: oldnewsfeed - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\oldnewsfeed@jetpack.xpi [2014-04-14]
    FF Extension: No Name - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\savedpasswordeditor@daniel.dawson.xpi [2012-10-30]
    FF Extension: Secure Login - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\secureLogin@blueimp.net.xpi [2012-10-30]
    FF Extension: Show Parent Folder - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\showParentFolder@alice.xpi [2014-04-17]
    FF Extension: UK TV Guide - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\UKTVGuide@mozilla.org.xpi [2013-04-07]
    FF Extension: Vertical Toolbar - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\verticaltoolbar@xuldev.org.xpi [2013-06-14]
    FF Extension: Stylish Sync - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{0e3fc079-afbb-4a00-87e5-9486062d0f9c}.xpi [2012-10-30]
    FF Extension: Capture &amp; Print - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi [2014-04-16]
    FF Extension: ChromaTabs Plus - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{1cff04ef-0c75-4621-ba2a-2efb77346996}.xpi [2014-04-15]
    FF Extension: Organize Status Bar - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{35106bca-6c78-48c7-ac28-56df30b51d2c}.xpi [2012-10-30]
    FF Extension: X-notifier - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi [2013-06-04]
    FF Extension: Stylish - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2012-10-30]
    FF Extension: eCleaner - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi [2013-06-14]
    FF Extension: Tab Mix Plus - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-11-04]
    FF Extension: Menu Editor - F:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\jf2v1cjf.default\Extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi [2012-10-30]
    FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    FF Extension: Microsoft .NET Framework Assistant - F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
    FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
    FF Extension: RealDownloader - F:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []

    ========================== Services (Whitelisted) =================

    R2 !SASCORE; F:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608 2012-07-11] (SUPERAntiSpyware.com)
    R2 avast! Antivirus; F:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-20] (AVAST Software)
    R2 chromoting; F:\Program Files\Google\Chrome Remote Desktop\34.0.1847.86\remoting_host.exe [50504 2014-03-23] (Google Inc.)
    R2 JavaQuickStarterService; F:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-05-13] (Oracle Corporation)
    S4 MSSQLServerADHelper; F:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation)
    S3 PDAgent; F:\Program Files\Raxco\PerfectDisk10\PDAgent.exe [931080 2009-06-08] (Raxco Software, Inc.)
    S3 PDEngine; F:\Program Files\Raxco\PerfectDisk10\PDEngine.exe [1033480 2009-06-08] (Raxco Software, Inc.)
    R2 RealNetworks Downloader Resolver Service; F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
    S3 scan; F:\WINDOWS\System32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
    S3 usprserv; F:\WINDOWS\System32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    R2 aswHwid; F:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-04-20] ()
    R2 aswMonFlt; F:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-04-20] (AVAST Software)
    R1 AswRdr; F:\WINDOWS\system32\drivers\aswRdr.sys [54832 2014-05-15] (AVAST Software)
    R0 aswRvrt; F:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-04-20] ()
    R1 aswSnx; F:\WINDOWS\system32\drivers\aswSnx.sys [777488 2014-05-15] (AVAST Software)
    R1 aswSP; F:\WINDOWS\system32\drivers\aswSP.sys [411680 2014-05-15] (AVAST Software)
    R1 aswTdi; F:\WINDOWS\system32\drivers\aswTdi.sys [57672 2014-04-20] (AVAST Software)
    R0 aswVmm; F:\WINDOWS\system32\Drivers\aswVmm.sys [180632 2014-04-20] ()
    R0 bdfsfltr; F:\WINDOWS\System32\drivers\bdfsfltr.sys [285704 2009-10-23] (BitDefender S.R.L. Bucharest, ROMANIA)
    S3 CCDECODE; F:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
    R2 DefragFS; F:\WINDOWS\system32\Drivers\DefragFS.sys [71696 2009-06-08] (Raxco Software, Inc.)
    R3 FETNDIS; F:\WINDOWS\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. )
    R3 itchfltr; F:\WINDOWS\System32\DRIVERS\itchfltr.sys [12953 2004-03-10] (Logitech, Inc.)
    S3 NdisIP; F:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
    R1 NPPTNT2; F:\WINDOWS\System32\npptNT2.sys [4682 2005-01-05] (INCA Internet Co., Ltd.)
    R3 RPPKT; F:\WINDOWS\System32\DRIVERS\rp_pkt32.sys [48384 2010-11-11] (Radialpoint, Inc.)
    R1 SASDIFSV; F:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 SNPT513; F:\WINDOWS\System32\DRIVERS\snpt513.sys [183040 2003-09-05] ()
    R0 sptd; F:\WINDOWS\System32\Drivers\sptd.sys [642560 2006-07-09] ()
    R0 viaagp1; F:\WINDOWS\System32\DRIVERS\viaagp1.sys [26880 2002-12-27] (VIA Technologies, Inc.)
    R3 VIAudio; F:\WINDOWS\System32\drivers\vinyl97.sys [203776 2005-11-25] (VIA Technologies, Inc.)
    R2 WBHWDOCT; F:\WINDOWS\system32\Drivers\WBHWDOCT.sys [5006 2001-06-15] (Winbond Electronics Corp.)
    S3 wceusbsh; F:\WINDOWS\System32\DRIVERS\wceusbsh.sys [108208 2007-06-28] (Microsoft Corporation)
    S4 IntelIde; No ImagePath
    U5 ScsiPort; F:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
    U3 TlntSvr;

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2014-05-21 07:06 - 2014-05-21 07:06 - 00000000 ____D () F:\FRST
    2014-05-17 10:51 - 2014-05-20 07:42 - 00000276 _____ () F:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-448539723-2139871995-725345543-1004.job
    2014-05-17 10:48 - 2014-05-17 10:48 - 00000655 _____ () F:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
    2014-05-17 10:46 - 2014-05-17 10:46 - 00000000 ____D () F:\Program Files\Common Files\xing shared
    2014-05-17 10:45 - 2014-05-17 10:45 - 00201872 _____ (RealNetworks, Inc.) F:\WINDOWS\system32\rmoc3260.dll
    2014-05-17 10:44 - 2014-05-17 10:44 - 00272896 _____ (Progressive Networks) F:\WINDOWS\system32\pncrt.dll
    2014-05-17 10:44 - 2014-05-17 10:44 - 00006656 _____ (RealNetworks, Inc.) F:\WINDOWS\system32\pndx5016.dll
    2014-05-17 10:44 - 2014-05-17 10:44 - 00005632 _____ (RealNetworks, Inc.) F:\WINDOWS\system32\pndx5032.dll
    2014-05-17 08:37 - 2014-05-17 08:39 - 00000328 _____ () F:\DelFix.txt
    2014-05-16 07:30 - 2014-05-16 07:30 - 00000000 ____D () F:\Program Files\ESET
    2014-05-15 19:23 - 2014-05-17 08:37 - 00000000 ____D () F:\WINDOWS\ERUNT
    2014-05-14 07:39 - 2014-05-15 10:48 - 00008192 ____H () F:\WINDOWS\system32\config\SECURITY.tmp.LOG
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\system.tmp.LOG
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\software.tmp.LOG
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\SAM.tmp.LOG
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\default.tmp.LOG
    2014-05-14 07:18 - 2014-05-14 07:18 - 00000000 _RSHD () F:\cmdcons
    2014-05-14 07:18 - 2006-06-16 01:00 - 00000210 _____ () F:\Boot.bak
    2014-05-14 07:18 - 2004-08-03 23:00 - 00260272 __RSH () F:\cmldr
    2014-05-14 07:14 - 2014-05-15 10:47 - 00000000 ____D () F:\WINDOWS\erdnt
    2014-05-13 16:39 - 2014-05-13 16:36 - 00264616 _____ (Oracle Corporation) F:\WINDOWS\system32\javaws.exe
    2014-05-13 16:39 - 2014-05-13 16:36 - 00145408 _____ (Oracle Corporation) F:\WINDOWS\system32\javacpl.cpl
    2014-05-13 16:37 - 2014-05-13 16:37 - 00094632 _____ (Oracle Corporation) F:\WINDOWS\system32\WindowsAccessBridge.dll
    2014-05-13 16:37 - 2014-05-13 16:37 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\Java
    2014-05-13 16:37 - 2014-05-13 16:36 - 00175528 _____ (Oracle Corporation) F:\WINDOWS\system32\javaw.exe
    2014-05-13 16:37 - 2014-05-13 16:36 - 00175016 _____ (Oracle Corporation) F:\WINDOWS\system32\java.exe
    2014-05-13 08:56 - 2014-05-13 11:02 - 00000000 ____D () F:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
    2014-05-11 09:15 - 2014-05-17 08:43 - 00110296 _____ (Malwarebytes Corporation) F:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2014-05-11 09:15 - 2014-05-17 08:41 - 00000782 _____ () F:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    2014-05-11 09:15 - 2014-05-17 08:41 - 00000000 ____D () F:\Program Files\Malwarebytes Anti-Malware
    2014-05-11 09:15 - 2014-05-17 08:41 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-05-11 09:15 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) F:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2014-05-11 09:15 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) F:\WINDOWS\system32\Drivers\mbam.sys
    2014-05-11 09:08 - 2014-05-11 08:37 - 00688992 _____ (Swearware) F:\Documents and Settings\Paul\My Documents\dds.com
    2014-05-10 06:58 - 2014-05-10 06:59 - 00000000 ____D () F:\Program Files\Mozilla Firefox
    2014-05-08 04:51 - 2014-05-08 04:51 - 00065536 _____ () F:\WINDOWS\Minidump\Mini050814-01.dmp
    2014-05-07 07:42 - 2014-05-07 07:42 - 00000000 ____D () F:\Program Files\7-Zip
    2014-05-07 07:42 - 2014-05-07 07:42 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
    2014-05-06 07:31 - 2014-05-06 07:31 - 00006183 _____ () F:\WINDOWS\FaxSetup.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00002956 _____ () F:\WINDOWS\ocgen.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00002359 _____ () F:\WINDOWS\tsoc.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00002024 _____ () F:\WINDOWS\comsetup.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00001478 _____ () F:\WINDOWS\setupapi.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00001355 _____ () F:\WINDOWS\imsins.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00001230 _____ () F:\WINDOWS\ntdtcsetup.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000958 _____ () F:\WINDOWS\iis6.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000497 _____ () F:\WINDOWS\updspapi.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000342 _____ () F:\WINDOWS\ocmsn.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000309 _____ () F:\WINDOWS\msgsocm.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000000 _____ () F:\WINDOWS\setuperr.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000000 _____ () F:\WINDOWS\setupact.log
    2014-05-06 07:30 - 2014-05-06 07:31 - 00005649 _____ () F:\WINDOWS\KB2964358-IE8.log
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000674 _____ () F:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000674 _____ () F:\Documents and Settings\All Users\Desktop\Opera.lnk
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000000 ____D () F:\Program Files\Opera
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000000 ____D () F:\Documents and Settings\Paul\Local Settings\Application Data\Opera Software
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\Opera Software
    2014-04-29 12:19 - 2014-04-29 12:19 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 9
    2014-04-29 07:21 - 2014-04-30 10:24 - 00000000 ____D () F:\Documents and Settings\All Users\Application Data\BoostSoftware
    2014-04-28 15:44 - 2014-04-28 15:44 - 00000000 ____D () F:\WINDOWS\pss
    2014-04-22 13:06 - 2014-04-23 09:48 - 00301338 _____ () F:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
    2014-04-22 11:03 - 2014-04-22 11:03 - 00000721 _____ () F:\Documents and Settings\Paul\Start Menu\Programs\Temp File Cleaner.lnk
    2014-04-22 11:03 - 2014-04-22 11:03 - 00000715 _____ () F:\Documents and Settings\Paul\Desktop\Temp File Cleaner.lnk
    2014-04-22 11:03 - 2014-04-22 11:03 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\addpcs
    2014-04-22 10:52 - 2014-04-22 11:03 - 00000000 ____D () F:\Program Files\Temp File Cleaner
    2014-04-22 10:45 - 2014-04-22 10:45 - 00000687 _____ () F:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    2014-04-22 09:04 - 2014-04-22 09:04 - 00000699 _____ () F:\Documents and Settings\Paul\Desktop\clipdiary.lnk
    2014-04-22 09:04 - 2014-04-22 09:04 - 00000000 ____D () F:\Program Files\Clipdiary
    2014-04-22 09:04 - 2014-04-22 09:04 - 00000000 ____D () F:\Documents and Settings\Paul\Start Menu\Programs\Clipdiary
    2014-04-22 08:19 - 2014-05-16 10:17 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\Clipdiary

    ==================== One Month Modified Files and Folders =======

    2014-05-21 07:06 - 2014-05-21 07:06 - 00000000 ____D () F:\FRST
    2014-05-21 06:49 - 2009-11-03 21:49 - 00000882 _____ () F:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2014-05-21 06:38 - 2012-10-30 11:12 - 00000000 ____D () F:\Documents and Settings\Paul\My Documents\Internet Stuff
    2014-05-21 06:18 - 2012-10-30 19:00 - 00000830 _____ () F:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2014-05-21 03:51 - 2006-05-08 02:08 - 00000000 ____D () F:\Program Files\Google
    2014-05-21 02:34 - 2006-05-08 02:33 - 01465709 _____ () F:\WINDOWS\WindowsUpdate.log
    2014-05-20 22:33 - 2012-10-29 18:08 - 00000364 ____H () F:\WINDOWS\Tasks\avast! Emergency Update.job
    2014-05-20 07:49 - 2011-08-07 16:44 - 00000882 _____ () F:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cc5518eebf6b00.job
    2014-05-20 07:46 - 2006-05-07 22:16 - 00032626 _____ () F:\WINDOWS\SchedLgU.Txt
    2014-05-20 07:44 - 2013-05-05 09:08 - 00000000 ___RD () F:\Documents and Settings\Paul\My Documents\Google Drive
    2014-05-20 07:42 - 2014-05-17 10:51 - 00000276 _____ () F:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-448539723-2139871995-725345543-1004.job
    2014-05-20 07:42 - 2012-12-14 12:47 - 00000284 _____ () F:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-448539723-2139871995-725345543-1004.job
    2014-05-20 07:38 - 2006-05-07 22:56 - 00000159 _____ () F:\WINDOWS\wiadebug.log
    2014-05-20 07:38 - 2006-05-07 22:56 - 00000050 _____ () F:\WINDOWS\wiaservc.log
    2014-05-20 07:37 - 2014-04-03 03:24 - 00000220 _____ () F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
    2014-05-20 07:37 - 2012-10-30 22:40 - 00000000 ____D () F:\Program Files\MedalFolders
    2014-05-20 07:37 - 2006-05-07 22:13 - 00000006 ____H () F:\WINDOWS\Tasks\SA.DAT
    2014-05-20 07:35 - 2003-03-31 13:00 - 00002422 _____ () F:\WINDOWS\system32\wpa.dbl
    2014-05-19 09:12 - 2006-05-07 22:21 - 00000178 ___SH () F:\Documents and Settings\Paul\ntuser.ini
    2014-05-19 09:12 - 2006-05-07 22:21 - 00000000 ____D () F:\Documents and Settings\Paul
    2014-05-19 09:11 - 2012-12-01 19:09 - 00000000 ____D () F:\Documents and Settings\Paul\My Documents\PhraseExpress
    2014-05-19 08:52 - 2014-03-04 21:27 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\TV-Browser
    2014-05-17 10:50 - 2006-07-21 19:27 - 00000000 ____D () F:\Program Files\Real
    2014-05-17 10:50 - 2006-07-21 19:26 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\Real
    2014-05-17 10:48 - 2014-05-17 10:48 - 00000655 _____ () F:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
    2014-05-17 10:48 - 2014-04-10 09:50 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\RealNetworks
    2014-05-17 10:46 - 2014-05-17 10:46 - 00000000 ____D () F:\Program Files\Common Files\xing shared
    2014-05-17 10:46 - 2010-03-09 23:09 - 00000000 ____D () F:\Documents and Settings\All Users\Application Data\Real
    2014-05-17 10:45 - 2014-05-17 10:45 - 00201872 _____ (RealNetworks, Inc.) F:\WINDOWS\system32\rmoc3260.dll
    2014-05-17 10:44 - 2014-05-17 10:44 - 00272896 _____ (Progressive Networks) F:\WINDOWS\system32\pncrt.dll
    2014-05-17 10:44 - 2014-05-17 10:44 - 00006656 _____ (RealNetworks, Inc.) F:\WINDOWS\system32\pndx5016.dll
    2014-05-17 10:44 - 2014-05-17 10:44 - 00005632 _____ (RealNetworks, Inc.) F:\WINDOWS\system32\pndx5032.dll
    2014-05-17 09:05 - 2013-01-27 10:03 - 00000000 ____D () F:\Program Files\Philips
    2014-05-17 08:45 - 2013-01-27 10:04 - 00000000 ____D () F:\Documents and Settings\Paul\My Documents\Philips Media Manager Sample Media
    2014-05-17 08:43 - 2014-05-11 09:15 - 00110296 _____ (Malwarebytes Corporation) F:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2014-05-17 08:41 - 2014-05-11 09:15 - 00000782 _____ () F:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    2014-05-17 08:41 - 2014-05-11 09:15 - 00000000 ____D () F:\Program Files\Malwarebytes Anti-Malware
    2014-05-17 08:41 - 2014-05-11 09:15 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-05-17 08:39 - 2014-05-17 08:37 - 00000328 _____ () F:\DelFix.txt
    2014-05-17 08:37 - 2014-05-15 19:23 - 00000000 ____D () F:\WINDOWS\ERUNT
    2014-05-16 23:16 - 2012-07-01 14:08 - 00000284 _____ () F:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    2014-05-16 10:17 - 2014-04-22 08:19 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\Clipdiary
    2014-05-16 10:04 - 2012-10-30 10:41 - 00000000 ____D () F:\Documents and Settings\Paul\My Documents\Firefox Extensions
    2014-05-16 07:30 - 2014-05-16 07:30 - 00000000 ____D () F:\Program Files\ESET
    2014-05-15 17:24 - 2006-05-07 22:16 - 00000000 __SHD () F:\Documents and Settings\NetworkService
    2014-05-15 10:56 - 2012-10-29 18:08 - 00777488 _____ (AVAST Software) F:\WINDOWS\system32\Drivers\aswsnx.sys
    2014-05-15 10:56 - 2012-10-29 18:08 - 00411680 _____ (AVAST Software) F:\WINDOWS\system32\Drivers\aswsp.sys
    2014-05-15 10:56 - 2012-10-29 18:08 - 00054832 _____ (AVAST Software) F:\WINDOWS\system32\Drivers\aswrdr.sys
    2014-05-15 10:53 - 2003-03-31 13:00 - 00000851 _____ () F:\WINDOWS\system.ini
    2014-05-15 10:49 - 2006-05-07 22:52 - 00053248 _____ () F:\WINDOWS\system32\config\SECURITY.bak
    2014-05-15 10:49 - 2006-05-07 22:52 - 00024576 _____ () F:\WINDOWS\system32\config\SAM.bak
    2014-05-15 10:49 - 2006-05-07 22:47 - 33964032 _____ () F:\WINDOWS\system32\config\software.bak
    2014-05-15 10:49 - 2006-05-07 22:47 - 11272192 _____ () F:\WINDOWS\system32\config\system.bak
    2014-05-15 10:49 - 2006-05-07 22:47 - 00471040 _____ () F:\WINDOWS\system32\config\default.bak
    2014-05-15 10:48 - 2014-05-14 07:39 - 00008192 ____H () F:\WINDOWS\system32\config\SECURITY.tmp.LOG
    2014-05-15 10:47 - 2014-05-14 07:14 - 00000000 ____D () F:\WINDOWS\erdnt
    2014-05-14 17:52 - 2013-07-26 11:09 - 00000000 ____D () F:\WINDOWS\system32\MRT
    2014-05-14 17:46 - 2006-05-10 08:57 - 90547776 _____ (Microsoft Corporation) F:\WINDOWS\system32\MRT.exe
    2014-05-14 12:18 - 2012-10-30 19:00 - 00692400 _____ (Adobe Systems Incorporated) F:\WINDOWS\system32\FlashPlayerApp.exe
    2014-05-14 12:18 - 2011-09-25 08:53 - 00070832 _____ (Adobe Systems Incorporated) F:\WINDOWS\system32\FlashPlayerCPLApp.cpl
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\system.tmp.LOG
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\software.tmp.LOG
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\SAM.tmp.LOG
    2014-05-14 07:39 - 2014-05-14 07:39 - 00000000 ____H () F:\WINDOWS\system32\config\default.tmp.LOG
    2014-05-14 07:18 - 2014-05-14 07:18 - 00000000 _RSHD () F:\cmdcons
    2014-05-14 07:18 - 2006-05-07 22:47 - 00000327 __RSH () F:\boot.ini
    2014-05-13 16:37 - 2014-05-13 16:37 - 00094632 _____ (Oracle Corporation) F:\WINDOWS\system32\WindowsAccessBridge.dll
    2014-05-13 16:37 - 2014-05-13 16:37 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\Java
    2014-05-13 16:36 - 2014-05-13 16:39 - 00264616 _____ (Oracle Corporation) F:\WINDOWS\system32\javaws.exe
    2014-05-13 16:36 - 2014-05-13 16:39 - 00145408 _____ (Oracle Corporation) F:\WINDOWS\system32\javacpl.cpl
    2014-05-13 16:36 - 2014-05-13 16:37 - 00175528 _____ (Oracle Corporation) F:\WINDOWS\system32\javaw.exe
    2014-05-13 16:36 - 2014-05-13 16:37 - 00175016 _____ (Oracle Corporation) F:\WINDOWS\system32\java.exe
    2014-05-13 11:02 - 2014-05-13 08:56 - 00000000 ____D () F:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
    2014-05-12 07:26 - 2014-05-11 09:15 - 00053208 _____ (Malwarebytes Corporation) F:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2014-05-12 07:25 - 2014-05-11 09:15 - 00023256 _____ (Malwarebytes Corporation) F:\WINDOWS\system32\Drivers\mbam.sys
    2014-05-11 10:07 - 2012-10-28 17:14 - 00000000 ____D () F:\Program Files\Mozilla Maintenance Service
    2014-05-11 10:07 - 2012-10-07 10:42 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB980232_0$
    2014-05-11 09:15 - 2010-04-07 22:16 - 00000000 ____D () F:\Documents and Settings\All Users\Application Data\Malwarebytes
    2014-05-11 08:37 - 2014-05-11 09:08 - 00688992 _____ (Swearware) F:\Documents and Settings\Paul\My Documents\dds.com
    2014-05-10 06:59 - 2014-05-10 06:58 - 00000000 ____D () F:\Program Files\Mozilla Firefox
    2014-05-08 19:49 - 2014-04-03 03:24 - 00000214 _____ () F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
    2014-05-08 07:03 - 2012-12-01 19:07 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\PhraseExpress
    2014-05-08 07:03 - 2012-12-01 19:06 - 00000000 ____D () F:\Program Files\PhraseExpress
    2014-05-08 04:51 - 2014-05-08 04:51 - 00065536 _____ () F:\WINDOWS\Minidump\Mini050814-01.dmp
    2014-05-08 04:51 - 2010-09-22 15:00 - 00000000 ____D () F:\WINDOWS\Minidump
    2014-05-07 07:42 - 2014-05-07 07:42 - 00000000 ____D () F:\Program Files\7-Zip
    2014-05-07 07:42 - 2014-05-07 07:42 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
    2014-05-06 07:52 - 2013-05-05 07:54 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\Google Drive
    2014-05-06 07:31 - 2014-05-06 07:31 - 00006183 _____ () F:\WINDOWS\FaxSetup.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00002956 _____ () F:\WINDOWS\ocgen.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00002359 _____ () F:\WINDOWS\tsoc.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00002024 _____ () F:\WINDOWS\comsetup.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00001478 _____ () F:\WINDOWS\setupapi.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00001355 _____ () F:\WINDOWS\imsins.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00001230 _____ () F:\WINDOWS\ntdtcsetup.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000958 _____ () F:\WINDOWS\iis6.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000497 _____ () F:\WINDOWS\updspapi.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000342 _____ () F:\WINDOWS\ocmsn.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000309 _____ () F:\WINDOWS\msgsocm.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000000 _____ () F:\WINDOWS\setuperr.log
    2014-05-06 07:31 - 2014-05-06 07:31 - 00000000 _____ () F:\WINDOWS\setupact.log
    2014-05-06 07:31 - 2014-05-06 07:30 - 00005649 _____ () F:\WINDOWS\KB2964358-IE8.log
    2014-05-06 07:30 - 2010-01-23 22:31 - 00000000 ____D () F:\WINDOWS\ie8updates
    2014-05-01 14:54 - 2006-05-08 02:08 - 00000000 ____D () F:\Documents and Settings\Paul\Local Settings\Application Data\Google
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000674 _____ () F:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000674 _____ () F:\Documents and Settings\All Users\Desktop\Opera.lnk
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000000 ____D () F:\Program Files\Opera
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000000 ____D () F:\Documents and Settings\Paul\Local Settings\Application Data\Opera Software
    2014-04-30 14:56 - 2014-04-30 14:56 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\Opera Software
    2014-04-30 11:09 - 2012-11-23 11:17 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\TeamViewer
    2014-04-30 10:24 - 2014-04-29 07:21 - 00000000 ____D () F:\Documents and Settings\All Users\Application Data\BoostSoftware
    2014-04-30 09:13 - 2006-05-19 16:08 - 06022144 ____C (Microsoft Corporation) F:\WINDOWS\system32\dllcache\mshtml.dll
    2014-04-30 09:13 - 2006-03-22 17:35 - 06022144 _____ (Microsoft Corporation) F:\WINDOWS\system32\mshtml.dll
    2014-04-29 12:19 - 2014-04-29 12:19 - 00000000 ____D () F:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 9
    2014-04-29 12:19 - 2014-03-04 09:21 - 00000820 _____ () F:\Documents and Settings\All Users\Desktop\TeamViewer 9.lnk
    2014-04-29 07:38 - 2006-05-07 22:21 - 00001604 _____ () F:\Documents and Settings\Paul\Start Menu\Programs\Remote Assistance.lnk
    2014-04-28 15:58 - 2006-05-07 22:10 - 00000000 ____D () F:\WINDOWS\system32\Restore
    2014-04-28 15:56 - 2003-03-31 13:00 - 00000789 _____ () F:\WINDOWS\win.ini
    2014-04-28 15:44 - 2014-04-28 15:44 - 00000000 ____D () F:\WINDOWS\pss
    2014-04-23 09:48 - 2014-04-22 13:06 - 00301338 _____ () F:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
    2014-04-23 09:27 - 2008-01-25 02:30 - 00000000 ____D () F:\WINDOWS\Microsoft.NET
    2014-04-23 09:20 - 2006-05-07 22:53 - 00635712 _____ () F:\WINDOWS\system32\PerfStringBackup.INI
     
  15. 2014/05/21
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    FRST.txt Part 2:-

    2014-04-22 11:13 - 2012-10-07 18:14 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975558_WM8$
    2014-04-22 11:13 - 2012-10-07 17:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB982132$
    2014-04-22 11:13 - 2012-10-07 17:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979687$
    2014-04-22 11:13 - 2012-10-07 17:32 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB981322$
    2014-04-22 11:13 - 2012-10-07 17:29 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971029$
    2014-04-22 11:13 - 2012-10-07 17:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB981997$
    2014-04-22 11:13 - 2012-10-07 17:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB982665$
    2014-04-22 11:13 - 2012-10-07 15:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB980232$
    2014-04-22 11:13 - 2012-10-07 15:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB980218$
    2014-04-22 11:13 - 2012-10-07 15:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979683$
    2014-04-22 11:13 - 2012-10-07 15:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979559$
    2014-04-22 11:13 - 2012-10-07 15:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979482$
    2014-04-22 11:13 - 2012-10-07 15:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979309$
    2014-04-22 11:13 - 2012-10-07 15:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978706$
    2014-04-22 11:13 - 2012-10-07 15:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978601$
    2014-04-22 11:13 - 2012-10-07 15:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978542$
    2014-04-22 11:13 - 2012-10-07 15:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978338$
    2014-04-22 11:13 - 2012-10-07 15:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978251$
    2014-04-22 11:13 - 2012-10-07 15:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978037$
    2014-04-22 11:13 - 2012-10-07 15:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB977914$
    2014-04-22 11:13 - 2012-10-07 15:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB977165$
    2014-04-22 11:13 - 2012-10-07 15:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975713$
    2014-04-22 11:13 - 2012-10-07 15:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975562$
    2014-04-22 11:13 - 2012-10-07 15:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975561$
    2014-04-22 11:13 - 2012-10-07 15:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975560$
    2014-04-22 11:13 - 2012-10-07 15:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975467$
    2014-04-22 11:13 - 2012-10-07 15:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975025$
    2014-04-22 11:13 - 2012-10-07 15:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974571$
    2014-04-22 11:13 - 2012-10-07 15:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974392$
    2014-04-22 11:13 - 2012-10-07 15:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974318$
    2014-04-22 11:13 - 2012-10-07 15:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974112$
    2014-04-22 11:13 - 2012-10-07 15:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973869$
    2014-04-22 11:13 - 2012-10-07 15:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973815$
    2014-04-22 11:13 - 2012-10-07 15:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973687$
    2014-04-22 11:13 - 2012-10-07 15:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973507$
    2014-04-22 11:13 - 2012-10-07 15:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973354$
    2014-04-22 11:13 - 2012-10-07 15:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB972270$
    2014-04-22 11:13 - 2012-10-07 15:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971737$
    2014-04-22 11:13 - 2012-10-07 15:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971657$
    2014-04-22 11:13 - 2012-10-07 15:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971633$
    2014-04-22 11:13 - 2012-10-07 14:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971557$
    2014-04-22 11:13 - 2012-10-07 14:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971486$
    2014-04-22 11:13 - 2012-10-07 14:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971468$
    2014-04-22 11:13 - 2012-10-07 14:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB970430$
    2014-04-22 11:13 - 2012-10-07 14:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB970238$
    2014-04-22 11:13 - 2012-10-07 14:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB969947$
    2014-04-22 11:13 - 2012-10-07 14:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB969059$
    2014-04-22 11:13 - 2012-10-07 14:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB968537$
    2014-04-22 11:13 - 2012-10-07 14:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB968389$
    2014-04-22 11:13 - 2012-10-07 14:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB967715$
    2014-04-22 11:13 - 2012-10-07 14:47 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973687_1$
    2014-04-22 11:13 - 2012-10-07 14:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974112_1$
    2014-04-22 11:13 - 2012-10-07 10:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979559_0$
    2014-04-22 11:13 - 2012-10-07 10:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975562_0$
    2014-04-22 11:13 - 2012-10-07 10:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB980195$
    2014-04-22 11:13 - 2012-10-07 10:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979482_0$
    2014-04-22 11:13 - 2012-10-07 10:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB981793$
    2014-04-22 11:13 - 2012-10-07 10:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB980218_0$
    2014-04-22 11:13 - 2012-10-07 10:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978695_WM9$
    2014-04-22 11:13 - 2012-10-07 10:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978542_0$
    2014-04-22 11:13 - 2012-10-07 10:47 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979683_0$
    2014-04-22 11:13 - 2012-10-07 10:47 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978601_0$
    2014-04-22 11:13 - 2012-10-07 10:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979309_0$
    2014-04-22 11:13 - 2012-10-07 10:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978338_0$
    2014-04-22 11:13 - 2012-10-07 10:45 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB977816$
    2014-04-22 11:13 - 2010-03-13 01:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975561_0$
    2014-04-22 11:13 - 2010-02-26 12:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB979306$
    2014-04-22 11:13 - 2010-02-10 23:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978262$
    2014-04-22 11:13 - 2010-02-10 23:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971468_0$
    2014-04-22 11:13 - 2010-02-10 23:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978251_0$
    2014-04-22 11:13 - 2010-02-10 23:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978037_0$
    2014-04-22 11:13 - 2010-02-10 23:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975713_0$
    2014-04-22 11:13 - 2010-02-10 23:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975560_0$
    2014-04-22 11:13 - 2010-02-10 23:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB978706_0$
    2014-04-22 11:13 - 2010-02-10 23:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB977914_0$
    2014-04-22 11:13 - 2010-02-10 23:35 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB977165_0$
    2014-04-22 11:13 - 2010-01-12 23:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB972270_0$
    2014-04-22 11:13 - 2009-12-10 23:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974318_0$
    2014-04-22 11:13 - 2009-12-10 23:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB970430_0$
    2014-04-22 11:13 - 2009-12-10 23:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973904$
    2014-04-22 11:13 - 2009-12-10 23:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974392_0$
    2014-04-22 11:13 - 2009-12-10 23:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971737_0$
    2014-04-22 11:13 - 2009-11-24 22:13 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB976098-v2$
    2014-04-22 11:13 - 2009-11-24 22:13 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973687_0$
    2014-04-22 11:13 - 2009-11-11 18:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB969947_0$
    2014-04-22 11:13 - 2009-10-14 14:19 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB969059_0$
    2014-04-22 11:13 - 2009-10-14 14:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975025_0$
    2014-04-22 11:13 - 2009-10-14 14:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974112_0$
    2014-04-22 11:13 - 2009-10-14 14:16 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB974571_0$
    2014-04-22 11:13 - 2009-10-14 14:15 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973525$
    2014-04-22 11:13 - 2009-10-14 14:15 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971486_0$
    2014-04-22 11:13 - 2009-10-14 14:14 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB975467_0$
    2014-04-22 11:13 - 2009-10-14 14:14 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB968389_0$
    2014-04-22 11:13 - 2009-09-09 20:32 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971961$
    2014-04-22 11:13 - 2009-09-09 20:32 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB968816_WM9$
    2014-04-22 11:13 - 2009-08-26 13:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB970653-v3$
    2014-04-22 11:13 - 2009-08-18 10:42 - 00000000 __HDC () F:\WINDOWS\$NtUninstallWdf01007$
    2014-04-22 11:13 - 2009-08-14 19:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971657_0$
    2014-04-22 11:13 - 2009-08-14 19:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973869_0$
    2014-04-22 11:13 - 2009-08-14 19:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973540_WM9L$
    2014-04-22 11:13 - 2009-08-14 19:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973507_0$
    2014-04-22 11:13 - 2009-08-14 19:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973354_0$
    2014-04-22 11:13 - 2009-08-14 19:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971557_0$
    2014-04-22 11:13 - 2009-08-14 19:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973815_0$
    2014-04-22 11:13 - 2009-07-15 22:20 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB973346$
    2014-04-22 11:13 - 2009-07-15 22:20 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB971633_0$
    2014-04-22 11:13 - 2009-06-11 19:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB969898$
    2014-04-22 11:13 - 2009-06-11 18:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB970238_0$
    2014-04-22 11:13 - 2009-06-11 18:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB968537_0$
    2014-04-22 11:13 - 2009-04-30 21:44 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961503_0$
    2014-04-22 11:13 - 2009-02-25 00:19 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB967715_0$
    2014-04-22 11:13 - 2008-03-15 22:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallWIC$
    2014-04-22 11:13 - 2007-07-11 15:22 - 00000000 __HDC () F:\WINDOWS\$NtUninstallMSCompPackV1$
    2014-04-22 11:13 - 2007-07-11 15:20 - 00000000 __HDC () F:\WINDOWS\$NtUninstallwmp11$
    2014-04-22 11:13 - 2007-07-11 15:19 - 00000000 __HDC () F:\WINDOWS\$NtUninstallWMFDist11$
    2014-04-22 11:13 - 2007-07-11 15:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallWudf01000$
    2014-04-22 11:12 - 2014-04-09 03:11 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2922229$
    2014-04-22 11:12 - 2014-04-03 03:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2929961$
    2014-04-22 11:12 - 2014-04-03 03:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2930275$
    2014-04-22 11:12 - 2014-04-03 03:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2934207$
    2014-04-22 11:12 - 2014-03-03 13:29 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2916036$
    2014-04-22 11:12 - 2014-03-03 13:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2914368$
    2014-04-22 11:12 - 2013-12-30 12:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2904266$
    2014-04-22 11:12 - 2012-10-07 18:12 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951978$
    2014-04-22 11:12 - 2012-10-07 17:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956744$
    2014-04-22 11:12 - 2012-10-07 14:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961503$
    2014-04-22 11:12 - 2012-10-07 14:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961501$
    2014-04-22 11:12 - 2012-10-07 14:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961373$
    2014-04-22 11:12 - 2012-10-07 14:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961371$
    2014-04-22 11:12 - 2012-10-07 14:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961118$
    2014-04-22 11:12 - 2012-10-07 14:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB960859$
    2014-04-22 11:12 - 2012-10-07 14:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB960803$
    2014-04-22 11:12 - 2012-10-07 14:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB960225$
    2014-04-22 11:12 - 2012-10-07 14:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB959426$
    2014-04-22 11:12 - 2012-10-07 14:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958690$
    2014-04-22 11:12 - 2012-10-07 14:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958687$
    2014-04-22 11:12 - 2012-10-07 14:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958644$
    2014-04-22 11:12 - 2012-10-07 14:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB957097$
    2014-04-22 11:12 - 2012-10-07 14:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB957095$
    2014-04-22 11:12 - 2012-10-07 14:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956844$
    2014-04-22 11:12 - 2012-10-07 14:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956841$
    2014-04-22 11:12 - 2012-10-07 14:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956803$
    2014-04-22 11:12 - 2012-10-07 14:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956802$
    2014-04-22 11:12 - 2012-10-07 14:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956572$
    2014-04-22 11:12 - 2012-10-07 14:47 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB955759$
    2014-04-22 11:12 - 2012-10-07 14:47 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB955069$
    2014-04-22 11:12 - 2012-10-07 14:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB954600$
    2014-04-22 11:12 - 2012-10-07 14:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB954211$
    2014-04-22 11:12 - 2012-10-07 14:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB952954$
    2014-04-22 11:12 - 2012-10-07 14:45 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB952287$
    2014-04-22 11:12 - 2012-10-07 14:45 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB952004$
    2014-04-22 11:12 - 2012-10-07 14:45 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951748$
    2014-04-22 11:12 - 2012-10-07 14:44 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951698$
    2014-04-22 11:12 - 2012-10-07 14:44 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951376-v2$
    2014-04-22 11:12 - 2012-10-07 14:44 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951376$
    2014-04-22 11:12 - 2012-10-07 14:43 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951066$
    2014-04-22 11:12 - 2012-10-07 14:43 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB950974$
    2014-04-22 11:12 - 2012-10-07 14:43 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB950762$
    2014-04-22 11:12 - 2012-10-07 14:43 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB946648$
    2014-04-22 11:12 - 2012-10-07 14:42 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB938464$
    2014-04-22 11:12 - 2012-10-07 14:42 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB923561$
    2014-04-22 11:12 - 2010-01-12 23:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB955759_0$
    2014-04-22 11:12 - 2009-10-14 14:21 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958869$
    2014-04-22 11:12 - 2009-10-14 14:21 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB954155_WM9$
    2014-04-22 11:12 - 2009-09-22 22:44 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB918997$
    2014-04-22 11:12 - 2009-09-09 20:32 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956844_0$
    2014-04-22 11:12 - 2009-08-24 18:44 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961118_0$
    2014-04-22 11:12 - 2009-08-18 12:11 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB925720$
    2014-04-22 11:12 - 2009-08-14 19:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB960859_0$
    2014-04-22 11:12 - 2009-08-14 19:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958470$
    2014-04-22 11:12 - 2009-07-15 22:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961371_0$
    2014-04-22 11:12 - 2009-06-11 19:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961501_0$
    2014-04-22 11:12 - 2009-04-19 20:11 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB959426_0$
    2014-04-22 11:12 - 2009-04-19 20:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB961373_0$
    2014-04-22 11:12 - 2009-04-19 20:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956572_0$
    2014-04-22 11:12 - 2009-04-19 20:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB952004_0$
    2014-04-22 11:12 - 2009-04-19 20:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB960803_0$
    2014-04-22 11:12 - 2009-04-19 20:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB923561_0$
    2014-04-22 11:12 - 2009-03-16 12:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB954708$
    2014-04-22 11:12 - 2009-03-12 13:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB960225_0$
    2014-04-22 11:12 - 2009-03-12 13:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958690_0$
    2014-04-22 11:12 - 2009-03-12 13:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB959772_WM11$
    2014-04-22 11:12 - 2009-02-11 23:17 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB960715$
    2014-04-22 11:12 - 2009-01-15 11:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958687_0$
    2014-04-22 11:12 - 2008-12-12 17:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB955839$
    2014-04-22 11:12 - 2008-12-12 17:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB952069_WM9$
    2014-04-22 11:12 - 2008-12-12 17:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956802_0$
    2014-04-22 11:12 - 2008-12-12 17:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB954600_0$
    2014-04-22 11:12 - 2008-11-12 00:15 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB957097_0$
    2014-04-22 11:12 - 2008-11-12 00:15 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB955069_0$
    2014-04-22 11:12 - 2008-10-23 19:14 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB958644_0$
    2014-04-22 11:12 - 2008-10-15 13:21 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB957095_0$
    2014-04-22 11:12 - 2008-10-15 13:21 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956803_0$
    2014-04-22 11:12 - 2008-10-15 13:21 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956391$
    2014-04-22 11:12 - 2008-10-15 13:20 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB956841_0$
    2014-04-22 11:12 - 2008-10-15 13:20 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB954211_0$
    2014-04-22 11:12 - 2008-09-10 18:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB938464_0$
    2014-04-22 11:12 - 2008-09-10 18:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB954154_WM11$
    2014-04-22 11:12 - 2008-08-14 12:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB953839$
    2014-04-22 11:12 - 2008-08-14 12:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB952954_0$
    2014-04-22 11:12 - 2008-08-14 12:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB952287_0$
    2014-04-22 11:12 - 2008-08-14 12:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951072-v2$
    2014-04-22 11:12 - 2008-08-14 12:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB950974_0$
    2014-04-22 11:12 - 2008-08-14 12:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB946648_0$
    2014-04-22 11:12 - 2008-08-14 12:29 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951066_0$
    2014-04-22 11:12 - 2008-07-26 01:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951748_0$
    2014-04-22 11:12 - 2008-06-20 18:26 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951376-v2_0$
    2014-04-22 11:12 - 2008-06-11 17:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951698_0$
    2014-04-22 11:12 - 2008-06-11 17:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB951376_0$
    2014-04-22 11:12 - 2008-06-11 17:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB950762_0$
    2014-04-22 11:12 - 2008-06-11 17:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB950760$
    2014-04-22 11:12 - 2008-05-27 22:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB932823-v3$
    2014-04-22 11:12 - 2008-05-14 22:42 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB950749$
    2014-04-22 11:12 - 2008-04-08 23:25 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB948881$
    2014-04-22 11:12 - 2008-04-08 23:25 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB941693$
    2014-04-22 11:12 - 2008-04-08 23:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB948590$
    2014-04-22 11:12 - 2008-04-08 23:23 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB945553$
    2014-04-22 11:12 - 2008-03-02 09:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB909394$
    2014-04-22 11:12 - 2008-02-13 01:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB946026$
    2014-04-22 11:12 - 2008-02-13 01:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB943055$
    2014-04-22 11:12 - 2008-01-10 18:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB943485$
    2014-04-22 11:12 - 2008-01-10 18:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB941644$
    2014-04-22 11:12 - 2007-12-12 15:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB942763$
    2014-04-22 11:12 - 2007-12-12 15:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB941569$
    2014-04-22 11:12 - 2007-12-12 15:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB944653$
    2014-04-22 11:12 - 2007-12-12 15:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB941568$
    2014-04-22 11:12 - 2007-11-14 12:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB943460$
    2014-04-22 11:12 - 2007-10-09 23:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB933729$
    2014-04-22 11:12 - 2007-10-09 23:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB941202$
    2014-04-22 11:12 - 2007-08-31 12:25 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB939683$
    2014-04-22 11:12 - 2007-08-29 23:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB933360$
    2014-04-22 11:12 - 2007-08-15 13:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB938828$
    2014-04-22 11:12 - 2007-08-15 13:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB936021$
    2014-04-22 11:12 - 2007-08-15 13:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB921503$
    2014-04-22 11:12 - 2007-08-15 13:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB938829$
    2014-04-22 11:12 - 2007-08-15 10:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB936782_WMP11$
    2014-04-22 11:12 - 2007-07-12 10:33 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB929399$
    2014-04-22 11:12 - 2007-07-11 15:23 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB926239$
    2014-04-22 11:12 - 2007-06-15 12:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB935840$
    2014-04-22 11:12 - 2007-06-15 12:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB929123$
    2014-04-22 11:12 - 2007-06-14 01:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB935839$
    2014-04-22 11:12 - 2007-05-24 09:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB927891$
    2014-04-22 11:12 - 2007-05-09 18:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB930916$
    2014-04-22 11:12 - 2007-04-11 12:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB932168$
    2014-04-22 11:12 - 2007-04-11 12:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB931784$
    2014-04-22 11:12 - 2007-04-11 12:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB931261$
    2014-04-22 11:12 - 2007-04-11 12:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB930178$
    2014-04-22 11:12 - 2007-04-04 01:35 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB925902$
    2014-04-22 11:12 - 2007-03-15 10:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB929338$
    2014-04-22 11:12 - 2007-02-19 02:38 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB927802$
    2014-04-22 11:12 - 2007-02-19 02:38 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB927779$
    2014-04-22 11:12 - 2007-02-19 02:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB931836$
    2014-04-22 11:12 - 2007-02-19 02:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB928255$
    2014-04-22 11:12 - 2007-02-19 02:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB926436$
    2014-04-22 11:12 - 2007-02-19 02:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB924667$
    2014-04-22 11:12 - 2007-02-19 02:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB928843$
    2014-04-22 11:12 - 2007-02-19 02:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB918118$
    2014-04-22 11:12 - 2006-12-27 20:25 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB915865$
    2014-04-22 11:12 - 2006-12-27 20:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB925454$
    2014-04-22 11:12 - 2006-12-27 20:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB914440$
    2014-04-22 11:12 - 2006-12-27 20:23 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB904942$
    2014-04-22 11:12 - 2006-12-12 22:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB925454_0$
    2014-04-22 11:12 - 2006-12-12 22:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB925398_WMP64$
    2014-04-22 11:12 - 2006-12-12 22:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB923689$
    2014-04-22 11:12 - 2006-12-12 22:47 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB926255$
    2014-04-22 11:12 - 2006-12-12 22:47 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB923694$
    2014-04-22 11:12 - 2006-11-15 20:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB924270$
    2014-04-22 11:12 - 2006-11-15 20:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB923980$
    2014-04-22 11:12 - 2006-11-15 20:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB922760$
    2014-04-22 11:12 - 2006-11-15 20:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB920213$
    2014-04-22 11:12 - 2006-10-14 01:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB924191$
    2014-04-22 11:12 - 2006-10-14 01:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB923414$
    2014-04-22 11:12 - 2006-10-14 01:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB922819$
    2014-04-22 11:12 - 2006-10-14 01:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB924496$
    2014-04-22 11:12 - 2006-10-14 01:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB923191$
    2014-04-22 11:12 - 2006-09-28 01:22 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB925486$
    2014-04-22 11:12 - 2006-09-15 00:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB922582$
    2014-04-22 11:12 - 2006-09-15 00:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB920872$
    2014-04-22 11:12 - 2006-09-15 00:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB920685$
    2014-04-22 11:12 - 2006-09-15 00:37 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB919007$
    2014-04-22 11:12 - 2006-08-09 01:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB922616$
    2014-04-22 11:12 - 2006-08-09 01:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB921883$
    2014-04-22 11:12 - 2006-08-09 01:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB920214$
    2014-04-22 11:12 - 2006-08-09 01:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB921398$
    2014-04-22 11:12 - 2006-08-09 01:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB920670$
    2014-04-22 11:12 - 2006-08-09 01:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB918899$
    2014-04-22 11:12 - 2006-08-09 01:40 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB917422$
    2014-04-22 11:12 - 2006-08-09 01:39 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB920683$
    2014-04-22 11:12 - 2006-07-13 19:26 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB917159$
    2014-04-22 11:12 - 2006-07-13 02:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB916595$
    2014-04-22 11:12 - 2006-07-13 02:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB914388$
    2014-04-22 11:12 - 2006-06-16 03:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB917734_WMP10$
    2014-04-22 11:12 - 2006-06-16 03:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB900485$
    2014-04-22 11:12 - 2006-06-16 03:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB887742$
    2014-04-22 11:12 - 2006-06-16 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB918439$
    2014-04-22 11:12 - 2006-06-16 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB917953$
    2014-04-22 11:12 - 2006-06-16 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB917344$
    2014-04-22 11:12 - 2006-06-16 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911280$
    2014-04-22 11:12 - 2006-06-16 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB887472$
    2014-04-22 11:12 - 2006-06-16 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB886185$
    2014-04-22 11:12 - 2006-06-16 03:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB916281$
    2014-04-22 11:12 - 2006-06-16 03:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911567$
    2014-04-22 11:12 - 2006-06-16 03:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB914389$
    2014-04-22 11:12 - 2006-06-16 01:20 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB913580$
    2014-04-22 11:12 - 2006-06-16 01:20 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB913446$
    2014-04-22 11:12 - 2006-06-16 01:19 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB912919$
    2014-04-22 11:12 - 2006-06-16 01:19 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911927$
    2014-04-22 11:12 - 2006-06-16 01:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911562$
    2014-04-22 11:12 - 2006-06-16 01:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB910437$
    2014-04-22 11:12 - 2006-06-16 01:17 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB908531$
    2014-04-22 11:12 - 2006-06-16 01:17 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB908519$
    2014-04-22 11:12 - 2006-06-16 01:16 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB905749$
    2014-04-22 11:12 - 2006-06-16 01:15 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB905414$
    2014-04-22 11:12 - 2006-06-16 01:15 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB902400$
    2014-04-22 11:12 - 2006-06-16 01:14 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB901214$
    2014-04-22 11:12 - 2006-06-16 01:13 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB901190$
    2014-04-22 11:12 - 2006-06-16 01:13 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB901017$
    2014-04-22 11:12 - 2006-06-16 01:12 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB900725$
    2014-04-22 11:12 - 2006-06-16 01:12 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB899591$
    2014-04-22 11:12 - 2006-06-16 01:11 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB899587$
    2014-04-22 11:12 - 2006-06-16 01:11 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896428$
    2014-04-22 11:12 - 2006-06-16 01:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896424$
    2014-04-22 11:12 - 2006-06-16 01:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896423$
    2014-04-22 11:12 - 2006-06-16 01:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896422$
    2014-04-22 11:12 - 2006-06-16 01:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896358$
    2014-04-22 11:12 - 2006-06-16 01:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB893756$
    2014-04-22 11:12 - 2006-06-16 01:08 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB891781$
    2014-04-22 11:12 - 2006-06-16 01:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB890859$
    2014-04-22 11:12 - 2006-06-16 01:07 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB890046$
    2014-04-22 11:12 - 2006-06-16 01:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB888302$
    2014-04-22 11:12 - 2006-06-16 01:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB888113$
    2014-04-22 11:12 - 2006-06-16 01:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB885836$
    2014-04-22 11:12 - 2006-06-16 01:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB885835$
    2014-04-22 11:12 - 2006-06-16 01:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB873339$
    2014-04-22 11:12 - 2006-05-11 10:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB904706$
    2014-04-22 11:12 - 2006-05-10 09:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB899587_0$
    2014-04-22 11:12 - 2006-05-10 09:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896422_0$
    2014-04-22 11:12 - 2006-05-10 09:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB885836_0$
    2014-04-22 11:12 - 2006-05-10 09:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB885835_0$
    2014-04-22 11:12 - 2006-05-10 09:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911927_0$
    2014-04-22 11:12 - 2006-05-10 09:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB835732$
    2014-04-22 11:12 - 2006-05-10 09:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911565$
    2014-04-22 11:12 - 2006-05-10 09:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB901017_0$
    2014-04-22 11:12 - 2006-05-10 09:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB899591_0$
    2014-04-22 11:12 - 2006-05-10 09:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896424_0$
    2014-04-22 11:12 - 2006-05-10 08:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911562_0$
    2014-04-22 11:12 - 2006-05-10 08:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896423_0$
    2014-04-22 11:12 - 2006-05-10 08:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB893756_0$
    2014-04-22 11:12 - 2006-05-10 08:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB912812-IE6SP1-20060322.182418$
    2014-04-22 11:12 - 2006-05-10 08:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB873339_0$
    2014-04-22 11:12 - 2006-05-10 08:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB888113_0$
    2014-04-22 11:12 - 2006-05-10 08:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB910437_0$
    2014-04-22 11:12 - 2006-05-10 08:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896358_0$
    2014-04-22 11:12 - 2006-05-10 08:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911564$
    2014-04-22 11:12 - 2006-05-10 08:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB905495$
    2014-04-22 11:12 - 2006-05-10 08:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB902400_0$
    2014-04-22 11:12 - 2006-05-10 08:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB891781_0$
    2014-04-22 11:12 - 2006-05-10 08:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB905414_0$
    2014-04-22 11:12 - 2006-05-10 08:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB901214_0$
    2014-04-22 11:12 - 2006-05-10 08:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB890046_0$
    2014-04-22 11:12 - 2006-05-10 08:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB912919_0$
    2014-04-22 11:12 - 2006-05-10 08:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB900725_0$
    2014-04-22 11:12 - 2006-05-10 08:52 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB888302_0$
    2014-04-22 11:12 - 2006-05-10 08:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB911567-OE6SP1-20060316.165634$
    2014-04-22 11:12 - 2006-05-10 08:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB908531_0$
    2014-04-22 11:12 - 2006-05-10 08:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB901190_0$
    2014-04-22 11:12 - 2006-05-10 08:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB913580_0$
    2014-04-22 11:12 - 2006-05-10 08:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB905749_0$
    2014-04-22 11:12 - 2006-05-10 08:50 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB896428_0$
    2014-04-22 11:12 - 2006-05-10 08:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB908519_0$
    2014-04-22 11:12 - 2006-05-10 08:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB835409$
    2014-04-22 11:12 - 2006-05-10 08:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB913446_0$
    2014-04-22 11:12 - 2006-05-10 08:48 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB890859_0$
    2014-04-22 11:12 - 2006-05-08 02:39 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB842773$
    2014-04-22 11:12 - 2006-05-08 02:38 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB898461$
    2014-04-22 11:11 - 2013-12-30 14:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2898715$
    2014-04-22 11:11 - 2013-12-30 12:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2900986$
    2014-04-22 11:11 - 2013-12-30 12:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2868626$
    2014-04-22 11:11 - 2013-12-30 12:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2876331$
    2014-04-22 11:11 - 2013-12-30 12:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2862152$
    2014-04-22 11:11 - 2013-12-30 12:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2893984$
    2014-04-22 11:11 - 2013-12-30 12:46 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2893294$
    2014-04-22 11:11 - 2013-12-30 12:45 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2892075$
    2014-04-22 11:11 - 2013-10-09 03:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2862335$
    2014-04-22 11:11 - 2013-10-09 03:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2847311$
    2014-04-22 11:11 - 2013-10-09 03:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2884256$
    2014-04-22 11:11 - 2013-10-09 03:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2868038$
    2014-04-22 11:11 - 2013-10-09 03:06 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2883150$
    2014-04-22 11:11 - 2013-10-09 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2862330$
    2014-04-22 11:11 - 2013-10-07 09:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2876315$
    2014-04-22 11:11 - 2013-10-07 09:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
    2014-04-22 11:11 - 2013-10-07 09:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2876217$
    2014-04-22 11:11 - 2013-10-07 09:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2864063$
    2014-04-22 11:11 - 2013-08-19 10:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2859537$
    2014-04-22 11:11 - 2013-08-19 10:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2850869$
    2014-04-22 11:11 - 2013-08-19 10:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2863058$
    2014-04-22 11:11 - 2013-08-19 10:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2849470$
    2014-04-22 11:11 - 2013-07-26 03:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2834904_WM11$
    2014-04-22 11:11 - 2013-07-26 03:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2834886$
    2014-04-22 11:11 - 2013-07-26 03:26 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2850851$
    2014-04-22 11:11 - 2013-07-26 03:25 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2845187$
    2014-04-22 11:11 - 2013-07-26 03:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2845142_WM64$
    2014-04-22 11:11 - 2013-06-13 10:28 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2839229$
    2014-04-22 11:11 - 2013-06-04 14:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2820197$
    2014-04-22 11:11 - 2013-06-04 14:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2829361$
    2014-04-22 11:11 - 2013-04-10 21:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2820917$
    2014-04-22 11:11 - 2013-04-10 21:55 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2808735$
    2014-04-22 11:11 - 2013-04-10 21:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2813345$
    2014-04-22 11:11 - 2013-04-10 21:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2813170$
    2014-04-22 11:11 - 2013-04-04 19:51 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2807986$
    2014-04-22 11:11 - 2013-02-16 12:42 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2799494$
    2014-04-22 11:11 - 2013-02-16 12:42 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2778344$
    2014-04-22 11:11 - 2013-02-16 12:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2802968$
    2014-04-22 11:11 - 2013-02-16 12:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2780091$
    2014-04-22 11:11 - 2013-01-09 11:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2757638$
    2014-04-22 11:11 - 2012-12-22 04:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2753842-v2$
    2014-04-22 11:11 - 2012-12-12 04:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2779562$
    2014-04-22 11:11 - 2012-12-12 04:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2779030$
    2014-04-22 11:11 - 2012-12-12 04:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2758857$
    2014-04-22 11:11 - 2012-12-12 04:10 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2753842$
    2014-04-22 11:11 - 2012-12-12 04:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2770660$
    2014-04-22 11:11 - 2012-11-16 04:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2761226$
    2014-04-22 11:11 - 2012-11-16 04:09 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2727528$
    2014-04-22 11:11 - 2012-10-11 03:11 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2724197$
    2014-04-22 11:11 - 2012-10-11 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2756822$
    2014-04-22 11:11 - 2012-10-11 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2749655$
    2014-04-22 11:11 - 2012-10-11 03:05 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2661254-v2$
    2014-04-22 11:11 - 2012-10-07 18:35 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2712808$
    2014-04-22 11:11 - 2012-10-07 18:35 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2387149$
    2014-04-22 11:11 - 2012-10-07 18:34 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2707511$
    2014-04-22 11:11 - 2012-10-07 18:34 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2479943$
    2014-04-22 11:11 - 2012-10-07 18:33 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2731847$
    2014-04-22 11:11 - 2012-10-07 18:33 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2659262$
    2014-04-22 11:11 - 2012-10-07 18:32 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2564958$
    2014-04-22 11:11 - 2012-10-07 18:32 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2478971$
    2014-04-22 11:11 - 2012-10-07 18:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2544893-v2$
    2014-04-22 11:11 - 2012-10-07 18:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2345886$
    2014-04-22 11:11 - 2012-10-07 18:28 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2536276-v2$
    2014-04-22 11:11 - 2012-10-07 18:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2646524$
    2014-04-22 11:11 - 2012-10-07 18:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2585542$
    2014-04-22 11:11 - 2012-10-07 18:26 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2631813$
    2014-04-22 11:11 - 2012-10-07 18:25 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2296011$
    2014-04-22 11:11 - 2012-10-07 18:24 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2691442$
    2014-04-22 11:11 - 2012-10-07 18:16 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2115168$
    2014-04-22 11:11 - 2012-10-07 18:13 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2378111_WM9$
    2014-04-22 11:11 - 2012-10-07 18:12 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2443105$
    2014-04-22 11:11 - 2012-10-07 18:11 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2655992$
    2014-04-22 11:11 - 2012-10-07 18:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2481109$
    2014-04-22 11:11 - 2012-10-07 18:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2598479$
    2014-04-22 11:11 - 2012-10-07 18:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2485663$
    2014-04-22 11:11 - 2012-10-07 17:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2736233$
    2014-04-22 11:11 - 2012-10-07 17:59 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2440591$
    2014-04-22 11:11 - 2012-10-07 17:58 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2686509$
    2014-04-22 11:11 - 2012-10-07 17:57 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2507938$
    2014-04-22 11:11 - 2012-10-07 17:56 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2476490$
    2014-04-22 11:11 - 2012-10-07 17:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2483185$
    2014-04-22 11:11 - 2012-10-07 17:54 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2347290$
    2014-04-22 11:11 - 2012-10-07 17:53 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2624667$
    2014-04-22 11:11 - 2012-10-07 17:49 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2705219$
    2014-04-22 11:11 - 2012-10-07 17:39 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2719985$
    2014-04-22 11:11 - 2012-10-07 17:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2718704$
    2014-04-22 11:11 - 2012-10-07 17:36 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2592799$
    2014-04-22 11:11 - 2012-10-07 17:35 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2723135$
    2014-04-22 11:11 - 2012-10-07 17:35 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2570947$
    2014-04-22 11:11 - 2012-10-07 17:35 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2535512$
    2014-04-22 11:11 - 2012-10-07 17:32 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2507618$
    2014-04-22 11:11 - 2012-10-07 17:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2603381$
    2014-04-22 11:11 - 2012-10-07 17:31 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2419632$
    2014-04-22 11:11 - 2012-10-07 17:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2653956$
    2014-04-22 11:11 - 2012-10-07 17:30 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2508429$
    2014-04-22 11:11 - 2012-10-07 17:29 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2506212$
    2014-04-22 11:11 - 2012-10-07 17:28 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2698365$
    2014-04-22 11:11 - 2012-10-07 17:28 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2633952$
    2014-04-22 11:11 - 2012-10-07 17:27 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2619339$
    2014-04-22 11:11 - 2012-10-07 17:26 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2618451$
    2014-04-22 11:11 - 2012-10-07 17:18 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2509553$
    2014-04-22 11:11 - 2012-10-07 17:16 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2676562$
    2014-04-22 11:11 - 2012-10-07 17:04 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2478960$
    2014-04-22 11:11 - 2012-10-07 17:03 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2393802$
    2014-04-22 11:11 - 2012-10-07 17:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2620712$
    2014-04-22 11:11 - 2012-10-07 17:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2584146$
    2014-04-22 11:11 - 2012-10-07 17:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2566454$
    2014-04-22 11:11 - 2012-10-07 17:02 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2423089$
    2014-04-22 11:11 - 2012-10-07 17:01 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2360937$
    2014-04-22 11:11 - 2012-10-07 14:41 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2229593$
    2014-04-22 11:11 - 2012-10-07 11:00 - 00000000 __HDC () F:\WINDOWS\$NtUninstallKB2229593_0$
    2014-04-22 11:11 - 2006-12-27 20:25 - 00000000 __HDC () F:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
    2014-04-22 11:11 - 2006-12-27 20:25 - 00000000 __HDC () F:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
    2014-04-22 11:11 - 2006-06-16 00:46 - 00000000 __HDC () F:\WINDOWS\$NtServicePackUninstall$
    2014-04-22 11:10 - 2006-05-08 02:38 - 00000000 __HDC () F:\WINDOWS\$MSI31Uninstall_KB893803v2$
    2014-04-22 11:10 - 2006-05-08 02:38 - 00000000 ___HD () F:\WINDOWS\$hf_mig$
    2014-04-22 11:03 - 2014-04-22 11:03 - 00000721 _____ () F:\Documents and Settings\Paul\Start Menu\Programs\Temp File Cleaner.lnk
    2014-04-22 11:03 - 2014-04-22 11:03 - 00000715 _____ () F:\Documents and Settings\Paul\Desktop\Temp File Cleaner.lnk
    2014-04-22 11:03 - 2014-04-22 11:03 - 00000000 ____D () F:\Documents and Settings\Paul\Application Data\addpcs
    2014-04-22 11:03 - 2014-04-22 10:52 - 00000000 ____D () F:\Program Files\Temp File Cleaner
    2014-04-22 10:55 - 2011-06-11 08:36 - 00000000 ____D () F:\Program Files\Microsoft.NET
    2014-04-22 10:45 - 2014-04-22 10:45 - 00000687 _____ () F:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    2014-04-22 10:44 - 2010-04-07 23:17 - 00000000 ____D () F:\Program Files\CCleaner
    2014-04-22 09:04 - 2014-04-22 09:04 - 00000699 _____ () F:\Documents and Settings\Paul\Desktop\clipdiary.lnk
    2014-04-22 09:04 - 2014-04-22 09:04 - 00000000 ____D () F:\Program Files\Clipdiary
    2014-04-22 09:04 - 2014-04-22 09:04 - 00000000 ____D () F:\Documents and Settings\Paul\Start Menu\Programs\Clipdiary
    2014-04-21 22:48 - 2006-05-14 09:47 - 00000000 __SHD () F:\Documents and Settings\Paul\UserData
    2014-04-21 14:15 - 2006-07-02 21:09 - 00000000 ____D () F:\Program Files\Java

    Some content of TEMP:
    ====================
    F:\Documents and Settings\Paul\Local Settings\Temp\i4j838.exe
    F:\Documents and Settings\Paul\Local Settings\Temp\lowproc.exe
    F:\Documents and Settings\Paul\Local Settings\Temp\stubhelper.dll


    ==================== Bamital & volsnap Check =================

    F:\WINDOWS\explorer.exe => MD5 is legit
    F:\WINDOWS\system32\winlogon.exe => MD5 is legit
    F:\WINDOWS\system32\svchost.exe => MD5 is legit
    F:\WINDOWS\system32\services.exe => MD5 is legit
    F:\WINDOWS\system32\User32.dll => MD5 is legit
    F:\WINDOWS\system32\userinit.exe => MD5 is legit
    F:\WINDOWS\system32\rpcss.dll => MD5 is legit
    F:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit

    ==================== End Of Log ============================
     
  16. 2014/05/21
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Additional.txt:-

    Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-05-2014
    Ran by Paul at 2014-05-21 07:08:22
    Running from F:\Documents and Settings\Paul\My Documents\Downloads\PC Security Stuff
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    ==================== Installed Programs ======================

    7-Zip 9.32 alpha (HKLM\...\7-Zip) (Version: - )
    Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
    Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
    Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Application Suite (HKLM\...\{7500DE13-266F-43F8-8577-A593B1FF20E4}) (Version: - )
    Auto Care (HKLM\...\Auto Care) (Version: - )
    avast! Free Antivirus (HKLM\...\avast) (Version: 9.0.2018 - Avast Software)
    BitTornado 0.3.17 (HKLM\...\BitTornado) (Version: 0.3.17 - John Hoffman)
    Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
    Campaign Cartographer 2 (HKLM\...\Campaign Cartographer 2) (Version: - )
    CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
    CDisplay 1.8 (HKLM\...\CDisplay_is1) (Version: - dvd8n)
    Chrome Remote Desktop Host (HKLM\...\{BEFD9552-C1D4-4A8B-BD44-4F910ACD079E}) (Version: 34.0.1847.86 - Google Inc.)
    Citrix online plug-in - web (HKLM\...\CitrixOnlinePluginPackWeb) (Version: 11.2.0.31560 - Citrix Systems, Inc.)
    Citrix online plug-in (DV) (Version: 11.2.0.31560 - Citrix Systems, Inc.) Hidden
    Citrix online plug-in (HDX) (Version: 11.2.0.31560 - Citrix Systems, Inc.) Hidden
    Citrix online plug-in (USB) (Version: 11.2.0.31560 - Citrix Systems, Inc.) Hidden
    Citrix online plug-in (Web) (Version: 11.2.0.31560 - Citrix Systems, Inc.) Hidden
    Clipdiary 1.4 (HKLM\...\Clipdiary) (Version: 1.4 - Softvoile)
    Critical Update for Windows Media Player 11 (KB959772) (HKLM\...\KB959772_WM11) (Version: - Microsoft Corporation)
    Defraggler (HKLM\...\Defraggler) (Version: 2.11 - Piriform)
    Download Manager and Options (HKLM\...\Download_Manager_and_Options) (Version: 1.0 - Download Manager and Options)
    Email Updater (HKLM\...\{2F1E5C4C-B20C-42C3-B5F1-1FE2CA207AFE}) (Version: 1.0.4 - Virgin Media)
    ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
    Facebook Plug-In (HKCU\...\Facebook Plug-In) (Version: - Facebook, Inc.)
    Gadwin PrintScreen (HKLM\...\Gadwin PrintScreen) (Version: 4.7 - Gadwin Systems, Inc.)
    Google Drive (HKLM\...\{418BAAD1-754D-48B4-B078-46EF4F25AF42}) (Version: 1.15.6556.8063 - Google, Inc.)
    Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
    Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
    Google Video Player (HKLM\...\GoogleVideoPlayer) (Version: - )
    Hardware Doctor (HKLM\...\{6E524C61-42EC-11D5-98E1-0050BA0133AC}) (Version: - )
    InterActual Player (HKLM\...\InterActual Player) (Version: - )
    iPod for Windows 2006-03-23 (HKLM\...\InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}) (Version: 4.7.0 - Apple Computer, Inc.)
    iPod for Windows 2006-03-23 (Version: 4.7.0 - Apple Computer, Inc.) Hidden
    iPod Update 2004-04-28 (HKLM\...\InstallShield_{E6696A8C-C55A-405C-AFEB-F3880A8BAA45}) (Version: 1.1 - Apple Computer, Inc.)
    iPod Update 2004-04-28 (Version: 1.1 - Apple Computer, Inc.) Hidden
    iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
    Jasc Paint Shop Pro 9 (HKLM\...\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}) (Version: 9.00.0000 - Jasc Software Inc)
    Jasc Paint Shop Pro 9 GDI+ Patch (HKLM\...\Jasc Paint Shop Pro 9 GDI+ Patch) (Version: - )
    Jasc Paint Shop Pro 9.01 Patch (HKLM\...\Jasc Paint Shop Pro 9.01 Patch) (Version: - )
    Java 7 Update 55 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle)
    Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
    Junk Mail filter update (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
    K-Lite Mega Codec Pack 1.57 (HKLM\...\KLiteCodecPack_is1) (Version: 1.57 - )
    Legacy 5.0 (HKLM\...\Legacy 5.0) (Version: 5.0 - Millennia Corporation)
    Logitech Desktop Messenger (HKLM\...\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}) (Version: - )
    Logitech iTouch Software (HKLM\...\{036AA4D4-6D32-11D4-9875-00105ACE7734}) (Version: - )
    Macromedia Shockwave Player (HKLM\...\Macromedia Shockwave Player) (Version: 10.1.0.11 - Macromedia, Inc.)
    Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
    MedalFolders 2.0.0.500 (HKLM\...\MedalFolders) (Version: - )
    Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
    Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
    Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - )
    Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - )
    Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - )
    Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
    Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
    Microsoft ActiveSync (HKLM\...\{99052DB7-9592-4522-A558-5417BBAD48EE}) (Version: 4.5.5096.0 - Microsoft Corporation)
    Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
    Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden
    Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
    Microsoft Internationalized Domain Names Mitigation APIs (Version: - Microsoft Corporation) Hidden
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 (Version: - Microsoft Corporation) Hidden
    Microsoft National Language Support Downlevel APIs (Version: - Microsoft Corporation) Hidden
    Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) (Version: 9.00.1399.06 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2005 Tools Express Edition (Version: 9.00.1399.06 - Microsoft Corporation) Hidden
    Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Mozilla Firefox 29.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 29.0.1 (x86 en-US)) (Version: 29.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
    MSN Toolbar (HKLM\...\MSN Toolbar) (Version: - )
    MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
    MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MSXML 6 Service Pack 2 (KB973686) (HKLM\...\{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}) (Version: 6.20.2003.0 - Microsoft Corporation)
    MSXML4 Parser (HKLM\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios)
    NexusFont 2.5 (ver 2.5.8.1582) (HKLM\...\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version: - xiles)
    NVIDIA Display Driver (HKLM\...\NVIDIA Display Driver) (Version: - )
    OpenOffice.org 3.4.1 (HKLM\...\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
    Opera Stable 20.0.1387.91 (HKLM\...\Opera 20.0.1387.91) (Version: 20.0.1387.91 - Opera Software ASA)
    PC Camera (6025 VGA) (HKLM\...\{0EB60281-1F3E-4B01-96C4-AC1C1D1B4D2B}) (Version: 2.47.0.0 - )
    PC Connectivity Solution (HKLM\...\{0C973594-7DDF-4BD0-84ED-3517F7622037}) (Version: 9.23.3.0 - Nokia)
    PDFTOEXCEL (HKLM\...\{ECCE5126-9A87-48CC-A2FA-A3D8483AE86B}_is1) (Version: - Blue Label Soft)
    PerfectDisk 10 Professional (Version: 10.0.110 - Raxco Software Inc.) Hidden
    PhraseExpress v10.1.35 (HKLM\...\PhraseExpress_is1) (Version: 10.1.35 - Bartels Media GmbH)
    PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - )
    QuickTime (HKLM\...\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
    RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
    RealPlayer (HKLM\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
    RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
    Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
    RPS CRT (Version: 8.0.28 - Virgin Broadband) Hidden
    RPS CRT (Version: 9.0.34 - Virgin Media) Hidden
    RPS PerfectDiskStub (Version: 9.0.34 - Virgin Media) Hidden
    Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden
    SmartCamera Ver 2.1 (HKLM\...\{9527450C-64B3-11D5-9B31-000021116B62}) (Version: 2.01.0001 - MingjongTechnologies CO.,LTD.)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1010 - SUPERAntiSpyware.com)
    TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.28223 - TeamViewer)
    Temp File Cleaner (HKLM\...\Temp File Cleaner) (Version: 4.4.0 - Addpcs, LLC)
    TV-Browser 3.3.3 (HKLM\...\tvbrowser) (Version: 3.3.3 - TV-Browser Team)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
    Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (HKLM\...\{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2836939v3) (Version: 3 - Microsoft Corporation)
    Update for Windows Internet Explorer 7 (KB976749) (Version: 1 - Microsoft Corporation) Hidden
    Update for Windows Internet Explorer 8 (KB975364) (HKLM\...\KB975364-IE8) (Version: 1 - Microsoft Corporation)
    Update for Windows Internet Explorer 8 (KB976662) (HKLM\...\KB976662-IE8) (Version: 1 - Microsoft Corporation)
    Update for Windows Internet Explorer 8 (KB980182) (HKLM\...\KB980182-IE8) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation)
    Update for Windows XP (KB2718704) (HKLM\...\KB2718704) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2736233) (HKLM\...\KB2736233) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2863058) (HKLM\...\KB2863058) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB2934207) (HKLM\...\KB2934207) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB951072-v2) (HKLM\...\KB951072-v2) (Version: 2 - Microsoft Corporation)
    Update for Windows XP (KB951978) (HKLM\...\KB951978) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB955839) (HKLM\...\KB955839) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB961503) (HKLM\...\KB961503) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB971737) (HKLM\...\KB971737) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB973687) (HKLM\...\KB973687) (Version: 1 - Microsoft Corporation)
    Update for Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation)
    USB Product Driver v2.08r011 (HKLM\...\{4E64E769-E3AA-11D7-B6FB-00055D7C3943}) (Version: - )
    WebFldrs XP (Version: 9.50.6513 - Microsoft Corporation) Hidden
    WinAce Archiver (HKLM\...\WinAce Archiver) (Version: 2.61 - e-merge GmbH)
    Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) (HKLM\...\504244733D18C8F63FF584AEB290E3904E791693) (Version: 08/22/2008 7.0.0.0 - Nokia)
    Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
    Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
    Windows Imaging Component (HKLM\...\WIC) (Version: 3.0.0.0 - Microsoft Corporation)
    Windows Internet Explorer 7 (Version: 20061107.210142 - Microsoft Corporation) Hidden
    Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
    Windows Live Call (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
    Windows Live Communications Platform (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
    Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
    Windows Live Essentials (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
    Windows Live Mail (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
    Windows Live Messenger (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
    Windows Live Photo Gallery (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
    Windows Live Sign-in Assistant (HKLM\...\{9422C8EA-B0C6-4197-B8FC-DC797658CA00}) (Version: 5.000.818.6 - Microsoft Corporation)
    Windows Live Sync (HKLM\...\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
    Windows Live Upload Tool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
    Windows Live Writer (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
    Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
    Windows Media Format 11 runtime (Version: - Microsoft Corporation) Hidden
    Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
    Windows Media Player 11 (Version: - Microsoft Corporation) Hidden
    Windows Mobile® MDA Compact V Handbook (HKLM\...\Windows Mobile Device Handbook) (Version: 1.0 - Microsoft Corporation)
    Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
    Wireless Audio Device Manager (HKLM\...\{33565C22-2E44-4B36-9147-23912E838F81}) (Version: 2.0.1 - Philips)
    XML Paper Specification Shared Components Pack 1.0 (Version: - Microsoft Corporation) Hidden

    ==================== Restore Points =========================

    Could not list Restore Points. Check "winmgmt" service or repair WMI.


    ==================== Hosts content: ==========================

    2003-03-31 13:00 - 2014-05-15 10:52 - 00000027 ____A F:\WINDOWS\system32\Drivers\etc\hosts
    127.0.0.1 localhost

    ==================== Scheduled Tasks (whitelisted) =============

    Task: F:\WINDOWS\Tasks\Adobe Flash Player Updater.job => F:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: F:\WINDOWS\Tasks\AppleSoftwareUpdate.job => F:\Program Files\Apple Software Update\SoftwareUpdate.exe
    Task: F:\WINDOWS\Tasks\avast! Emergency Update.job => F:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
    Task: F:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cc5518eebf6b00.job => F:\Program Files\Google\Update\GoogleUpdate.exe
    Task: F:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => F:\Program Files\Google\Update\GoogleUpdate.exe
    Task: F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => F:\WINDOWS\system32\xp_eos.exe
    Task: F:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => F:\WINDOWS\system32\xp_eos.exe
    Task: F:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-448539723-2139871995-725345543-1004.job => F:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: F:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-448539723-2139871995-725345543-1004.job => F:\Program Files\Real\RealUpgrade\realupgrade.exe

    ==================== Loaded Modules (whitelisted) =============

    2014-04-02 21:58 - 2014-04-02 21:58 - 19336120 _____ () F:\Program Files\AVAST Software\Avast\libcef.dll
    2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () F:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () F:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2007-05-22 18:34 - 2007-05-22 18:34 - 00208896 _____ () F:\Program Files\Clipdiary\clipdiary.exe
    2007-05-22 17:44 - 2007-05-22 17:44 - 00350711 _____ () F:\Program Files\Clipdiary\sqlite3.dll
    2012-12-01 19:06 - 2014-04-24 10:09 - 00460072 _____ () F:\Program Files\PhraseExpress\pexlang.dll
    2012-10-10 08:23 - 2011-07-10 19:40 - 01555456 _____ () F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\locate32.exe
    2012-10-10 08:23 - 2011-07-10 19:38 - 00045568 _____ () F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\keyhelper.dll
    2012-10-10 08:23 - 2011-07-10 19:39 - 00124416 _____ () F:\Documents and Settings\Paul\My Documents\Other Programs\Locate32\lan_en.dll
    2012-10-31 08:18 - 2012-10-31 08:18 - 01006080 _____ () F:\Program Files\MedalFolders\MedalFolders.exe
    2012-08-10 17:51 - 2012-10-31 15:43 - 00985088 _____ () F:\Program Files\OpenOffice.org 3\program\libxml2.dll
    2014-05-20 23:50 - 2014-05-20 23:50 - 02253312 _____ () F:\Program Files\AVAST Software\Avast\defs\14052001\algo.dll
    2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
    2005-08-30 09:14 - 2013-01-02 07:49 - 01292288 _____ () F:\WINDOWS\system32\quartz.dll
    2014-05-20 07:37 - 2014-05-20 07:37 - 00098816 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32api.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00110080 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\PyWinTypes27.dll
    2014-05-20 07:37 - 2014-05-20 07:37 - 00364544 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\pythoncom27.dll
    2014-05-20 07:37 - 2014-05-20 07:37 - 00045568 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\_socket.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 01159680 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\_ssl.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00320512 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32com.shell.shell.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00713216 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\_hashlib.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 01175040 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._core_.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00805888 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._gdi_.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00811008 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._windows_.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 01062400 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._controls_.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00735232 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._misc_.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00128512 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\_elementtree.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00127488 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\pyexpat.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00557056 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\pysqlite2._sqlite.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00087552 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\_ctypes.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00119808 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32file.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00108544 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32security.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00018432 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32event.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00038912 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32inet.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00070656 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._html2.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00167936 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32gui.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00011264 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32crypt.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00027136 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\_multiprocessing.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00122368 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._wizard.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00010240 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\select.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00024064 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32pipe.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00686080 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\unicodedata.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00025600 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32pdh.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00525640 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\windows._lib_cacheinvalidation.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00035840 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32process.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00017408 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32profile.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00022528 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\win32ts.pyd
    2014-05-20 07:37 - 2014-05-20 07:37 - 00078336 _____ () F:\Documents and Settings\Paul\Local Settings\Temp\_MEI7122\wx._animate.pyd
    2006-05-09 22:30 - 2008-04-14 01:11 - 00059904 _____ () F:\WINDOWS\system32\devenum.dll
    2006-05-09 22:30 - 2008-04-14 01:11 - 00014336 _____ () F:\WINDOWS\system32\msdmo.dll

    ==================== Alternate Data Streams (whitelisted) =========

    AlternateDataStreams: F:\Documents and Settings\Paul\Desktop\1219.scr:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

    ==================== Safe Mode (whitelisted) ===================

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => " "= "Driver "
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => " "= "Driver "

    ==================== EXE Association (whitelisted) =============


    ==================== Disabled items from MSCONFIG ==============


    ==================== Faulty Device Manager Devices =============

    Name: RAID Controller
    Description: RAID Controller
    Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver ", which starts the Hardware Update wizard.

    Name: Security Services Driver
    Description: Security Services Driver
    Class Guid: {3C9A56DA-221C-483F-A5D7-036D4FE9F4A7}
    Manufacturer: Radialpoint, Inc.
    Service: RPSKT
    Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
    Resolution: A registry problem was detected.
    This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
    Click "Uninstall ", and then click "Scan for hardware changes" to load a usable driver.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (05/21/2014 05:58:34 AM) (Source: Application Error) (EventID: 1001) (User: )
    Description: Fault bucket 196813194.
    The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected.

    Error: (05/21/2014 05:58:31 AM) (Source: Application Error) (EventID: 1001) (User: )
    Description: Fault bucket 196813194.
    The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected.

    Error: (05/21/2014 03:51:50 AM) (Source: MsiInstaller) (EventID: 11720) (User: NT AUTHORITY)
    Description: Product: Chrome Remote Desktop Host -- Error 1720. There is a problem with this Windows Installer package. A script required for this install to complete could not be run. Contact your support personnel or package vendor. Custom action set_auto_start_service script error -2146827859, Microsoft JScript runtime error: Automation server can't create object Line 1, Column 1,

    Error: (05/21/2014 03:49:54 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application remoting_host.exe, version 35.0.1916.52, faulting module remoting_core.dll, version 35.0.1916.52, fault address 0x00025665.
    Processing media-specific event for [remoting_host.exe!ws!]

    Error: (05/20/2014 10:52:31 PM) (Source: MsiInstaller) (EventID: 11720) (User: NT AUTHORITY)
    Description: Product: Chrome Remote Desktop Host -- Error 1720. There is a problem with this Windows Installer package. A script required for this install to complete could not be run. Contact your support personnel or package vendor. Custom action set_auto_start_service script error -2146827859, Microsoft JScript runtime error: Automation server can't create object Line 1, Column 1,

    Error: (05/20/2014 10:50:35 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application remoting_host.exe, version 35.0.1916.52, faulting module remoting_core.dll, version 35.0.1916.52, fault address 0x00025665.
    Processing media-specific event for [remoting_host.exe!ws!]

    Error: (05/20/2014 06:11:50 PM) (Source: Application Error) (EventID: 1001) (User: )
    Description: Fault bucket 196813194.
    The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected.

    Error: (05/20/2014 05:52:49 PM) (Source: MsiInstaller) (EventID: 11720) (User: NT AUTHORITY)
    Description: Product: Chrome Remote Desktop Host -- Error 1720. There is a problem with this Windows Installer package. A script required for this install to complete could not be run. Contact your support personnel or package vendor. Custom action set_auto_start_service script error -2146827859, Microsoft JScript runtime error: Automation server can't create object Line 1, Column 1,

    Error: (05/20/2014 05:50:53 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application remoting_host.exe, version 35.0.1916.52, faulting module remoting_core.dll, version 35.0.1916.52, fault address 0x00025665.
    Processing media-specific event for [remoting_host.exe!ws!]

    Error: (05/20/2014 04:06:35 PM) (Source: Application Error) (EventID: 1001) (User: )
    Description: Fault bucket 196813194.
    The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected.


    System errors:
    =============
    Error: (05/21/2014 03:51:50 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/20/2014 10:52:31 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/20/2014 05:52:49 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/20/2014 00:53:07 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/20/2014 07:57:48 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/18/2014 09:52:41 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/18/2014 04:52:04 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/17/2014 11:52:56 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/17/2014 06:52:33 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.

    Error: (05/17/2014 01:52:31 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: The server {1B1B006D-4EA2-564A-A9A5-76A6CD71AB80} did not register with DCOM within the required timeout.


    Microsoft Office Sessions:
    =========================
    Error: (05/21/2014 05:58:34 AM) (Source: Application Error) (EventID: 1001) (User: )
    Description: 196813194

    Error: (05/21/2014 05:58:31 AM) (Source: Application Error) (EventID: 1001) (User: )
    Description: 196813194

    Error: (05/21/2014 03:51:50 AM) (Source: MsiInstaller) (EventID: 11720) (User: NT AUTHORITY)
    Description: Product: Chrome Remote Desktop Host -- Error 1720. There is a problem with this Windows Installer package. A script required for this install to complete could not be run. Contact your support personnel or package vendor. Custom action set_auto_start_service script error -2146827859, Microsoft JScript runtime error: Automation server can't create object Line 1, Column 1, (NULL)(NULL)(NULL)

    Error: (05/21/2014 03:49:54 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: remoting_host.exe35.0.1916.52remoting_core.dll35.0.1916.5200025665

    Error: (05/20/2014 10:52:31 PM) (Source: MsiInstaller) (EventID: 11720) (User: NT AUTHORITY)
    Description: Product: Chrome Remote Desktop Host -- Error 1720. There is a problem with this Windows Installer package. A script required for this install to complete could not be run. Contact your support personnel or package vendor. Custom action set_auto_start_service script error -2146827859, Microsoft JScript runtime error: Automation server can't create object Line 1, Column 1, (NULL)(NULL)(NULL)

    Error: (05/20/2014 10:50:35 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: remoting_host.exe35.0.1916.52remoting_core.dll35.0.1916.5200025665

    Error: (05/20/2014 06:11:50 PM) (Source: Application Error) (EventID: 1001) (User: )
    Description: 196813194

    Error: (05/20/2014 05:52:49 PM) (Source: MsiInstaller) (EventID: 11720) (User: NT AUTHORITY)
    Description: Product: Chrome Remote Desktop Host -- Error 1720. There is a problem with this Windows Installer package. A script required for this install to complete could not be run. Contact your support personnel or package vendor. Custom action set_auto_start_service script error -2146827859, Microsoft JScript runtime error: Automation server can't create object Line 1, Column 1, (NULL)(NULL)(NULL)

    Error: (05/20/2014 05:50:53 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: remoting_host.exe35.0.1916.52remoting_core.dll35.0.1916.5200025665

    Error: (05/20/2014 04:06:35 PM) (Source: Application Error) (EventID: 1001) (User: )
    Description: 196813194


    ==================== Memory info ===========================

    Percentage of memory in use: 43%
    Total physical RAM: 1022.48 MB
    Available physical RAM: 578.16 MB
    Total Pagefile: 2177.13 MB
    Available Pagefile: 1659.75 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1946.6 MB

    ==================== Drives ================================

    Drive c: (Pablo Jr.) (Fixed) (Total:37.27 GB) (Free:31.3 GB) NTFS
    Drive f: (Pablo) (Fixed) (Total:76.32 GB) (Free:7.37 GB) NTFS ==>[Drive with boot components (Windows XP)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows XP) (Size: 76 GB) (Disk ID: 30723071)
    Partition 1: (Active) - (Size=76 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 37 GB) (Disk ID: 0C9269A7)
    Partition 1: (Not Active) - (Size=37 GB) - (Type=07 NTFS)

    ==================== End Of Log ============================
     
  17. 2014/05/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    All looks clean so there is nothing malware related.

    I can see couple of errors in FRST logs:

    Download Windows Repair (All in One) from this site

    Install the program then run it.

    NOTE 1. In Windows Vista, 7 and 8 right click on the program, click "Run As Administrator ".
    NOTE 2. Disable your antivirus program before running Windows Repair.


    Go to Step 3 and click on Check button next to 1. See If Check Disk Is Needed.
    If the tool that the Check Disk is needed click on Do It button next to 2. Check Disk.
    In that case make sure you restart computer.

    [​IMG]


    Once the above is done go to Step 4 and allow it to run System File Check by clicking on Do It button:

    [​IMG]


    Go to Step 5 and under "System Restore" click on Create button:

    [​IMG]


    Go to Start Repairs tab and click Start button.

    Leave all checkmarks as they're.
    NOTE for Windows 8 users. Reset Registry Permissions is NOT checked by design.

    Click on Start button.

    [​IMG]

    Post Windows Repair log which is located in the following folder:
    64-bit systems - C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Logs
    32-bit systems - C:\Program Files\Tweaking.com\Windows Repair (All in One)\Logs
     
  18. 2014/05/25
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Hi again,

    I followed the above instructions but when running the System File check it kept asking me to insert Windows Disk - which went missing many moons ago - so had to keep skipping the process on each .dll file.

    There are a few reports so here goes:-

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    F:\Documents and Settings\Paul\Desktop>CD /D F:\

    F:\>chkdsk F:
    The type of the file system is NTFS.
    Volume label is Pablo.

    WARNING! F parameter not specified.
    Running CHKDSK in read-only mode.

    CHKDSK is verifying files (stage 1 of 3)...
    41 percent completed.
    Deleting corrupt attribute record (128, " ")
    from file record segment 82544.
    100 percent completed.
    File verification completed.

    Errors found. CHKDSK cannot continue in read-only mode.

    F:\>

    ----------

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    F:\Documents and Settings\Paul\Desktop>CD /D F:\

    F:\>chkdsk F:
    The type of the file system is NTFS.
    Volume label is Pablo.

    WARNING! F parameter not specified.
    Running CHKDSK in read-only mode.

    CHKDSK is verifying files (stage 1 of 3)...
    0 percent completed.
    1 percent completed.
    2 percent completed.
    3 percent completed.
    4 percent completed.
    5 percent completed.
    6 percent completed.
    7 percent completed.
    8 percent completed.
    9 percent completed.
    10 percent completed.
    11 percent completed.
    12 percent completed.
    13 percent completed.
    14 percent completed.
    15 percent completed.
    16 percent completed.
    17 percent completed.
    18 percent completed.
    19 percent completed.
    20 percent completed.
    21 percent completed.
    22 percent completed.
    23 percent completed.
    24 percent completed.
    25 percent completed.
    26 percent completed.
    27 percent completed.
    28 percent completed.
    29 percent completed.
    30 percent completed.
    31 percent completed.
    32 percent completed.
    33 percent completed.
    34 percent completed.
    35 percent completed.
    36 percent completed.
    37 percent completed.
    38 percent completed.
    39 percent completed.
    40 percent completed.
    41 percent completed.
    Deleting corrupt attribute record (128, " ")
    from file record segment 82544.
    42 percent completed.
    43 percent completed.
    44 percent completed.
    45 percent completed.
    46 percent completed.
    47 percent completed.
    48 percent completed.
    49 percent completed.
    50 percent completed.
    51 percent completed.
    52 percent completed.
    53 percent completed.
    54 percent completed.
    55 percent completed.
    56 percent completed.
    57 percent completed.
    58 percent completed.
    59 percent completed.
    60 percent completed.
    61 percent completed.
    62 percent completed.
    63 percent completed.
    64 percent completed.
    65 percent completed.
    66 percent completed.
    67 percent completed.
    68 percent completed.
    69 percent completed.
    70 percent completed.
    71 percent completed.
    72 percent completed.
    73 percent completed.
    74 percent completed.
    75 percent completed.
    76 percent completed.
    77 percent completed.
    78 percent completed.
    79 percent completed.
    80 percent completed.
    81 percent completed.
    82 percent completed.
    83 percent completed.
    84 percent completed.
    85 percent completed.
    86 percent completed.
    87 percent completed.
    88 percent completed.
    89 percent completed.
    90 percent completed.
    91 percent completed.
    92 percent completed.
    93 percent completed.
    94 percent completed.
    95 percent completed.
    96 percent completed.
    97 percent completed.
    98 percent completed.
    99 percent completed.
    100 percent completed.
    File verification completed.

    Errors found. CHKDSK cannot continue in read-only mode.

    F:\>


    ----------

    Running Repair Under Current User Account


    ----------


    System Variables
    --------------------------------------------------------------------------------
    OS: Microsoft Windows XP
    OS Architecture: 32-bit
    OS Version: 5.1.2600
    OS Service Pack: Service Pack 3
    Computer Name: PC
    Windows Drive: F:\
    Windows Path: F:\WINDOWS
    Current Profile: F:\Documents and Settings\Paul
    Current Profile SID: S-1-5-21-448539723-2139871995-725345543-1004
    Current Profile Classes: S-1-5-21-448539723-2139871995-725345543-1004_Classes
    Profiles Location: F:\Documents and Settings
    Profiles Location 2: F:\WINDOWS\ServiceProfiles
    Local Settings AppData: F:\Documents and Settings\Paul\Local Settings\Application Data
    --------------------------------------------------------------------------------

    System Information
    --------------------------------------------------------------------------------
    System Up Time: 0 Days 01:05:23

    Process Count: 56
    Commit Total: 486.37 MB
    Commit Limit: 2.13 GB
    Commit Peak: 563.82 MB
    Handle Count: 16482
    Kernel Total: 76.19 MB
    Kernel Paged: 61.30 MB
    Kernel Non Paged: 14.89 MB
    System Cache: 553.92 MB
    Thread Count: 620
    --------------------------------------------------------------------------------

    Memory Before Cleaning with CleanMem
    --------------------------------------------------------------------------------
    Memory Total: 1,022.48 MB
    Memory Used: 603.41 MB(59.0145%)
    Memory Avail.: 419.07 MB
    --------------------------------------------------------------------------------

    Cleaning Memory Before Starting Repairs...

    Memory After Cleaning with CleanMem
    --------------------------------------------------------------------------------
    Memory Total: 1,022.48 MB
    Memory Used: 427.43 MB(41.8027%)
    Memory Avail.: 595.06 MB
    --------------------------------------------------------------------------
     
  19. 2014/05/25
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Part 1...
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\detect.log
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\i4j838.exe
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\JavaDeployReg.log
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\jusched.log
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\log3
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\lowproc.exe
    F:\DOCUME~1\Paul\LOCALS~1\Temp\Perflib_Perfdata_f0c.dat
    The process cannot access the file because it is being used by another process.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\QTInstallCode.log
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\rn.firefox.sqlite
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\rn.firefox.sqlite-shm
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\rn.firefox.sqlite-wal
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\stubhelper.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\tmp-2cu.xpi
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\WCESCOMM.LOG
    F:\DOCUME~1\Paul\LOCALS~1\Temp\WCESLog.log
    The process cannot access the file because it is being used by another process.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\WcesView.log
    F:\DOCUME~1\Paul\LOCALS~1\Temp\~DF11CE.tmp
    The process cannot access the file because it is being used by another process.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\bz2.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\gdi32.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\kernel32.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\main.exe.manifest
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\mfc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\mfc90u.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\mfcm90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\mfcm90u.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\msvcp100.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\msvcr100.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\psapi.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\pyexpat.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\pysqlite2._sqlite.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\python27.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\pythoncom27.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\PyWinTypes27.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\select.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\shell32.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\unicodedata.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32api.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32com.shell.shell.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32crypt.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32event.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32evtlog.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32file.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32gui.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32inet.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32pdh.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32pipe.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32process.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32profile.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32security.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32trace.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32ts.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32ui.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\win32wnet.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\windows._lib_cacheinvalidation.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._animate.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._controls_.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._core_.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._gdi_.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._html2.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._misc_.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._windows_.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wx._wizard.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wxbase294u_net_vc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wxbase294u_vc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wxmsw294u_adv_vc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wxmsw294u_core_vc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wxmsw294u_html_vc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\wxmsw294u_webview_vc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\_ctypes.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\_elementtree.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\_hashlib.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\_multiprocessing.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\_socket.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\_ssl.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\_win32sysloader.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\fonts\OpenSans-Light.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\fonts\Roboto-Bold.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\fonts\Roboto-Regular.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\fonts\Roboto-Thin.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ar\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\bg\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\bn\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ca\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\cs\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\da\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\de\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\el\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\en\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\en_GB\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\en_US\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\es\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\fi\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\fil\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\fr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\gu\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\he\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\hi\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\hr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\hu\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\id\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\it\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ja\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\kn\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ko\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\lt\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\lv\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ml\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\mr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\nl\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\no\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\pl\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\pt\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\pt_BR\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\pt_PT\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ro\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ru\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\sk\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\sl\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\sr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\sv\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\ta\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\te\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\th\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\tr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\uk\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\vi\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\zh\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\zh-Hans\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\zh-Hant\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\zh_CN\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\zh_HK\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\i18n\locale\zh_TW\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\docs.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdoc16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdoc256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdoc32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdoc48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdraw16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdraw256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdraw32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gdraw48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gform16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gform256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gform32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gform48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-glink16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-glink256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-glink32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-glink48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gsheet16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gsheet256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gsheet32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gsheet48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gslides16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gslides256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gslides32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-gslides48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-sync16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-sync16.xpm
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-sync256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-sync32.xpm
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\drive-sync64.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\exclaim.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\file.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\folder-mac.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\folder-winseven.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\folder-winxp.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\folder.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gdoc.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gdoc.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gdraw.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gdraw.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gform.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gform.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\glink.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\glink.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gnote.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gnote.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gscript.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gscript.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gsheet.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gsheet.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gslides.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gslides.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gtable.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\gtable.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\image_resources.py
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\image_resources.pyo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate1-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate1-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate1.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate1_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate2-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate2-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate2.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate2_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate3-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate3-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate3.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate3_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate4-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate4-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate4.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate4_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate5-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate5-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate5.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate5_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate6-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate6-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate6.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate6_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate7-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate7-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate7.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate7_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate8-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate8-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate8.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-animate8_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-error-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-error-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-error_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-inactive-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-inactive-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-inactive.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-inactive_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-normal-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-normal-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-normal.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-normal_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-pause-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-paused-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-paused-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\mac-paused_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_check.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_check_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_create.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_create_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_docs_16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_down-arrow.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_down-arrow_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_drive-logo.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_drive-logo_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_error_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_file_32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_folder.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_folder_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_folder_32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_google-logo-gray.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_google-logo-gray_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_link.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_link_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_pause.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_pause_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_resume.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_resume_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_settings.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_settings_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_share.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_share_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sheets_16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_slides_16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sm_warning_red.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sm_warning_red_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sm_warning_yellow.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sm_warning_yellow_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sync-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sync.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sync_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sync_anim.gif
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_sync_anim_2x.gif
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_up-arrow.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_up-arrow_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_warning.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_warning_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_warning_color.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_warning_color_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_web.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\menu_web_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup1.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup2-mac.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup2-win.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup3-bottom.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup3-right.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup4-mac.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup4-win.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup5-mac.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\setup5-win.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sharedfolder-mac.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sharedfolder-winseven.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sharedfolder-winxp.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\shareguyicon.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sheets.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\slides.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync_128.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync_menu_done.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync_menu_done_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync_menu_error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync_menu_error_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync_menu_syncing.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\sync_menu_syncing_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\toprighticon.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\warning-hdpi_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\warning_128.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\warning_256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\warning_64.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate1.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate2.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate3.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate4.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate5.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate6.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate7.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-animate8.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win-normal.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win7-error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win7-inactive.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\win7-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\winxp-error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\winxp-inactive.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\winxp-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\__init__.py
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\__init__.pyo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\overlays\Blacklisted.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\overlays\Shared.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\overlays\Synced.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\images\overlays\Syncing.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\js\XMLHttpRequest.js
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\resources\mime\drive.mime.types
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\support\gen_py\dicts.dat
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI7122\support\gen_py\__init__.py
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\bz2.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\gdi32.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\kernel32.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\main.exe.manifest
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\mfc90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\mfc90u.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\mfcm90.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\mfcm90u.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\msvcp100.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\msvcr100.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\psapi.dll
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\pyexpat.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\pysqlite2._sqlite.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\python27.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\pythoncom27.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\PyWinTypes27.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\select.pyd
    Access is denied.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\shell32.dll
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\unicodedata.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32api.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32com.shell.shell.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32crypt.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32event.pyd
    Access is denied.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32evtlog.pyd
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32file.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32gui.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32inet.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32pdh.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32pipe.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32process.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32profile.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32security.pyd
    Access is denied.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32trace.pyd
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32ts.pyd
    Access is denied.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32ui.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32wnet.pyd
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\windows._lib_cacheinvalidation.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._animate.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._controls_.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._core_.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._gdi_.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._html2.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._misc_.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._windows_.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._wizard.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxbase294u_net_vc90.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxbase294u_vc90.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_adv_vc90.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_core_vc90.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_html_vc90.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_webview_vc90.dll
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_ctypes.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_elementtree.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_hashlib.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_multiprocessing.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_socket.pyd
    Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_ssl.pyd
    Access is denied.
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_win32sysloader.pyd
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\fonts\OpenSans-Light.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\fonts\Roboto-Bold.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\fonts\Roboto-Regular.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\fonts\Roboto-Thin.ttf
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ar\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\bg\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\bn\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ca\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\cs\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\da\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\de\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\el\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\en\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\en_GB\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\en_US\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\es\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\fi\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\fil\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\fr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\gu\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\he\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\hi\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\hr\LC_MESSAGES\syncclient.mo
     
  20. 2014/05/25
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Part 2.....
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\hu\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\id\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\it\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ja\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\kn\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ko\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\lt\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\lv\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ml\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\mr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\nl\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\no\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\pl\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\pt\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\pt_BR\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\pt_PT\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ro\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ru\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\sk\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\sl\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\sr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\sv\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\ta\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\te\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\th\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\tr\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\uk\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\vi\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\zh\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\zh-Hans\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\zh-Hant\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\zh_CN\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\zh_HK\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\i18n\locale\zh_TW\LC_MESSAGES\syncclient.mo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\docs.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdoc16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdoc256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdoc32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdoc48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdraw16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdraw256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdraw32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gdraw48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gform16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gform256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gform32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gform48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-glink16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-glink256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-glink32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-glink48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gsheet16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gsheet256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gsheet32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gsheet48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gslides16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gslides256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gslides32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-gslides48.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-sync16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-sync16.xpm
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-sync256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-sync32.xpm
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\drive-sync64.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\exclaim.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\file.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\folder-mac.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\folder-winseven.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\folder-winxp.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\folder.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gdoc.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gdoc.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gdraw.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gdraw.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gform.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gform.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\glink.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\glink.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gnote.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gnote.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gscript.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gscript.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gsheet.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gsheet.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gslides.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gslides.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gtable.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\gtable.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\image_resources.py
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\image_resources.pyo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate1-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate1-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate1.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate1_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate2-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate2-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate2.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate2_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate3-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate3-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate3.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate3_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate4-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate4-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate4.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate4_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate5-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate5-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate5.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate5_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate6-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate6-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate6.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate6_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate7-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate7-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate7.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate7_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate8-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate8-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate8.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-animate8_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-error-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-error-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-error_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-inactive-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-inactive-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-inactive.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-inactive_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-normal-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-normal-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-normal.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-normal_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-pause-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-paused-inverse.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-paused-inverse_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\mac-paused_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_check.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_check_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_create.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_create_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_docs_16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_down-arrow.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_down-arrow_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_drive-logo.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_drive-logo_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_error_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_file_32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_folder.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_folder_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_folder_32.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_google-logo-gray.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_google-logo-gray_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_link.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_link_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_pause.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_pause_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_resume.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_resume_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_settings.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_settings_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_share.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_share_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sheets_16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_slides_16.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sm_warning_red.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sm_warning_red_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sm_warning_yellow.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sm_warning_yellow_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sync-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sync.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sync_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sync_anim.gif
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_sync_anim_2x.gif
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_up-arrow.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_up-arrow_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_warning.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_warning_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_warning_color.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_warning_color_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_web.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\menu_web_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup1.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup2-mac.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup2-win.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup3-bottom.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup3-right.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup4-mac.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup4-win.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup5-mac.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\setup5-win.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sharedfolder-mac.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sharedfolder-winseven.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sharedfolder-winxp.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\shareguyicon.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sheets.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\slides.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync.icns
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync_128.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync_menu_done.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync_menu_done_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync_menu_error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync_menu_error_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync_menu_syncing.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\sync_menu_syncing_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\toprighticon.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\warning-hdpi_2x.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\warning_128.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\warning_256.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\warning_64.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate1.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate2.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate3.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate4.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate5.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate6.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate7.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-animate8.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win-normal.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win7-error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win7-inactive.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\win7-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\winxp-error.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\winxp-inactive.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\winxp-paused.png
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\__init__.py
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\__init__.pyo
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\overlays\Blacklisted.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\overlays\Shared.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\overlays\Synced.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\images\overlays\Syncing.ico
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\js\XMLHttpRequest.js
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\resources\mime\drive.mime.types
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\support\gen_py\dicts.dat
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\support\gen_py\__init__.py
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\~rnsetup\GEMSETUP\msvcr100.dll
    Deleted file - F:\DOCUME~1\Paul\LOCALS~1\Temp\~rnsetup\GEMSETUP\pnrs3260.dll
    F:\DOCUME~1\Paul\LOCALS~1\Temp\Perflib_Perfdata_f0c.dat - The process cannot access the file because it is being used by another process.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\WCESLog.log - The process cannot access the file because it is being used by another process.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\pyexpat.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\pysqlite2._sqlite.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\python27.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\pythoncom27.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\PyWinTypes27.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\select.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\unicodedata.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32api.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32com.shell.shell.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32crypt.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32event.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32file.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32gui.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32inet.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32pdh.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32pipe.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32process.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32profile.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32security.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\win32ts.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\windows._lib_cacheinvalidation.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._animate.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._controls_.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._core_.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._gdi_.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._html2.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._misc_.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._windows_.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wx._wizard.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxbase294u_net_vc90.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxbase294u_vc90.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_adv_vc90.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_core_vc90.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_html_vc90.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\wxmsw294u_webview_vc90.dll - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_ctypes.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_elementtree.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_hashlib.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_multiprocessing.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_socket.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\_MEI8962\_ssl.pyd - Access is denied.
    F:\DOCUME~1\Paul\LOCALS~1\Temp\~DF11CE.tmp - The process cannot access the file because it is being used by another process.
    F:\WINDOWS\Temp\Perflib_Perfdata_a48.dat
    The process cannot access the file because it is being used by another process.
    Deleted file - F:\WINDOWS\Temp\SetupAdmin2548.log
    Deleted file - F:\WINDOWS\Temp\avast_ash\Mozilla Firefox\update.xml
    Deleted file - F:\WINDOWS\Temp\xpi-reader14\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader14\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader15\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader15\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader19\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader19\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader21\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader21\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader34\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader34\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader38\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader38\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader39\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader39\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader44\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader44\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader54\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader54\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader59\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader59\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader62\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader62\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader67\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader67\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader83\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader83\{146f1820-2b0d-49ef-acbf-d85a6986e10c}.xpi
    Deleted file - F:\WINDOWS\Temp\xpi-reader88\install.rdf
    Deleted file - F:\WINDOWS\Temp\xpi-reader88\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi
    F:\WINDOWS\Temp\_avast_\AvastLock.txt
    The process cannot access the file because it is being used by another process.
    F:\WINDOWS\Temp\_avast_\Webshlock.txt
    The process cannot access the file because it is being used by another process.
    F:\WINDOWS\Temp\Perflib_Perfdata_a48.dat - The process cannot access the file because it is being used by another process.
    F:\WINDOWS\Temp\_avast_\AvastLock.txt - The process cannot access the file because it is being used by another process.
    F:\WINDOWS\Temp\_avast_\Webshlock.txt - The process cannot access the file because it is being used by another process.
     
  21. 2014/05/25
    keithy397

    keithy397 Well-Known Member Thread Starter

    Joined:
    2004/11/15
    Messages:
    99
    Likes Received:
    0
    Could Not Find F:\Documents and Settings\Paul\Local Settings\Application Data\iconcache*.db
    The system cannot find the file specified.
    The system cannot find the file specified.

    ----------

    The system cannot find the file specified.
    The system cannot find the file specified.

    ----------

    The Windows Firewall/Internet Connection Sharing (ICS) service is not started.

    More help is available by typing NET HELPMSG 3521.

    [SC] ChangeServiceConfig SUCCESS
    [SC] ChangeServiceConfig SUCCESS
    The Windows Firewall/Internet Connection Sharing (ICS) service is starting.
    The Windows Firewall/Internet Connection Sharing (ICS) service was started successfully.


    The Windows Firewall/Internet Connection Sharing (ICS) service was stopped successfully.

    [SC] ChangeServiceConfig SUCCESS
    [SC] ChangeServiceConfig SUCCESS
    The Windows Firewall/Internet Connection Sharing (ICS) service is starting.
    The Windows Firewall/Internet Connection Sharing (ICS) service was started successfully.


    ----------
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.