We're still getting faster!!
The computer reboots, logs on, and becomes useable at a much faster rate. The "activity light" no longer stays green forever; it's blinking in a reasonable amount of time.
I hope we can speed it up some more, but I probably have a lot of stuff on this computer (bejeweled, etc.)for the amount of memory. But, I 'm willing to lose memory hogs.
Maybe I should mention that when I check the properties for the TOSHIBA DVD-ROM SD-R2512, I get the following message: "Windows cannot load the device driver for this hardware. The driver may be corrupted or missing. (Code 39)." I think it has been like that for a while; and, I will reinstall the driver later. Just thought I'd mention it.
My Primary IDE channel, current transfer mode is "Ultra DMA Mode 5."
Feeling pretty good about the way things have gone with the computer. I may even put my sledge hammer back in the shed
The logs follow, and thanks again.
00dog
Fixed log:
All processes killed
========== OTL ==========
Service ps2mcadapter stopped successfully!
Service ps2mcadapter deleted successfully!
C:\WINDOWS\system32\drivers\ps2mcadapter.sys moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\ deleted successfully.
C:\WINDOWS\tasks\Symantec NetDetect.job moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\UserShell folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint folder moved successfully.
C:\Documents and Settings\Default\Application Data\CheckPoint\ZoneAlarm Toolbar\TrustChecker(2) folder moved successfully.
C:\Documents and Settings\Default\Application Data\CheckPoint\ZoneAlarm Toolbar\TrustChecker folder moved successfully.
C:\Documents and Settings\Default\Application Data\CheckPoint\ZoneAlarm Toolbar\PTPCACHE folder moved successfully.
C:\Documents and Settings\Default\Application Data\CheckPoint\ZoneAlarm Toolbar folder moved successfully.
C:\Documents and Settings\Default\Application Data\CheckPoint folder moved successfully.
C:\Documents and Settings\Default\Application Data\Leadertech\PowerRegister folder moved successfully.
C:\Documents and Settings\Default\Application Data\Leadertech folder moved successfully.
C:\WINDOWS\system32\zllictbl.dat moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Grisoft\AVG Free\avginet.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Grisoft\AVG Free\avgamsvr.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Grisoft\AVG Free\avgcc.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe deleted successfully.
========== FILES ==========
C:\Documents and Settings\Default\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 6486330 bytes
->Temporary Internet Files folder emptied: 50255503 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 1372 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 1993416 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 2069962 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Owner
User: Sippy
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2366217 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 60.00 mb
[EMPTYFLASH]
User: Administrator
->Flash cache emptied: 0 bytes
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
User: Owner
User: Sippy
Total Flash Files Cleaned = 0.00 mb
Restore point Set: OTL Restore Point (0)
OTL by OldTimer - Version 3.2.9.1 log created on 09102010_125440
Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\TMP00000003261FCC2528E89C80 not found!
Registry entries deleted on Reboot...
Procexp log:
Process PID CPU Private Bytes Working Set Description Company Name
DPCs n/a 0 K 0 K Deferred Procedure Calls
Interrupts n/a 0 K 0 K Hardware Interrupts
System Idle Process 0 22.06 0 K 16 K
System 4 0 K 32 K
smss.exe 536 168 K 132 K Windows NT Session Manager Microsoft Corporation
swupdtmr.exe 1404 304 K 132 K
DVDRAMSV.exe 408 440 K 204 K Service of RAMAsst for Windows XP Matsushita Electric Industrial Co., Ltd.
svchost.exe 616 1,004 K 280 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 796 996 K 288 K Generic Host Process for Win32 Services Microsoft Corporation
acs.exe 1320 2,652 K 388 K
KodakCCS.exe 504 956 K 432 K Kodak DC Ring 3 Conduit (Win32) Eastman Kodak Company
ati2evxx.exe 896 568 K 500 K ATI External Event Utility EXE Module ATI Technologies Inc.
svchost.exe 488 1,492 K 544 K Generic Host Process for Win32 Services Microsoft Corporation
CFSvcs.exe 196 1,260 K 716 K Service of ConfigFree. TOSHIBA CORPORATION
svchost.exe 148 1,260 K 748 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1392 2,384 K 820 K Generic Host Process for Win32 Services Microsoft Corporation
LEXBCES.EXE 1812 1,236 K 1,016 K LexBce Service Lexmark International, Inc.
LEXPPS.EXE 1856 1,028 K 1,240 K LEXPPS.EXE Lexmark International, Inc.
svchost.exe 980 1,772 K 1,392 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1664 2,720 K 1,556 K Generic Host Process for Win32 Services Microsoft Corporation
ati2evxx.exe 1292 556 K 1,568 K ATI External Event Utility EXE Module ATI Technologies Inc.
csrss.exe 640 1,660 K 1,896 K Client Server Runtime Process Microsoft Corporation
svchost.exe 1544 1,244 K 1,916 K Generic Host Process for Win32 Services Microsoft Corporation
SmoothView.exe 3640 556 K 2,152 K SmoothView TOSHIBA Corporation
hpwuschd2.exe 3824 592 K 2,276 K hpwuSchd Application Hewlett-Packard
wmpnetwk.exe 1576 5,716 K 2,292 K Windows Media Player Network Sharing Service Microsoft Corporation
TOSCDSPD.exe 176 596 K 2,352 K CD/DVD Drive Acoustic Silencer TOSHIBA
services.exe 716 4.41 1,756 K 2,388 K Services and Controller app Microsoft Corporation
TPSBattM.exe 3240 760 K 2,540 K TOSHIBA Corporation
RAMASST.exe 1312 668 K 2,556 K CD Burning of Windows XP disabling tool for DVD MULTI Drive Matsushita Electric Industrial Co., Ltd.
winlogon.exe 668 6,608 K 2,688 K Windows NT Logon Application Microsoft Corporation
spoolsv.exe 1840 4,464 K 2,696 K Spooler SubSystem App Microsoft Corporation
reader_sl.exe 3736 696 K 2,788 K Adobe Acrobat SpeedLauncher Adobe Systems Incorporated
SynTPLpr.exe 2584 876 K 2,820 K TouchPad Driver Helper Application Synaptics, Inc.
svchost.exe 912 3,056 K 2,988 K Generic Host Process for Win32 Services Microsoft Corporation
lsass.exe 728 3,924 K 3,052 K LSA Shell (Export Version) Microsoft Corporation
alg.exe 3748 1,028 K 3,148 K Application Layer Gateway Service Microsoft Corporation
ctfmon.exe 4032 888 K 3,556 K CTF Loader Microsoft Corporation
tfswctrl.exe 2700 956 K 3,664 K Drive Letter Access Component Sonic Solutions
svchost.exe 452 6,020 K 3,756 K Generic Host Process for Win32 Services Microsoft Corporation
wuauclt.exe 1076 6,552 K 3,840 K Windows Update Microsoft Corporation
TPSMain.exe 3060 2,172 K 3,936 K TOSHIBA Corporation
svchost.exe 440 3,040 K 4,156 K Generic Host Process for Win32 Services Microsoft Corporation
atiptaxx.exe 2608 2,784 K 4,320 K ATI Desktop Control Panel ATI Technologies, Inc.
PadExe.exe 3572 1.47 2,584 K 4,776 K PadTouch Main TOSHIBA
THotkey.exe 3012 3,232 K 6,896 K TOSHIBA
msseces.exe 3912 3,964 K 6,976 K Microsoft Security Essentials User Interface Microsoft Corporation
nmsrvc.exe 220 9,192 K 12,176 K Pure Networks Platform Service Cisco Systems, Inc.
procexp.exe 3156 1.47 12,908 K 17,688 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
svchost.exe 1176 16,864 K 22,628 K Generic Host Process for Win32 Services Microsoft Corporation
explorer.exe 2108 17,276 K 23,420 K Windows Explorer Microsoft Corporation
MsMpEng.exe 1120 70.59 160,868 K 56,304 K AntiMalware Service Executable Microsoft Corporation
OTL Log:
OTL logfile created on: 9/10/2010 5:41:14 PM - Run 4
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Default\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.00 Mb Total Physical Memory | 107.00 Mb Available Physical Memory | 24.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 51.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 30.59 Gb Free Space | 54.73% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOSHIBA-USER
Current User Name: Default
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/07/27 11:00:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Default\Desktop\OTL.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/07/07 15:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/05/24 13:35:52 | 000,322,104 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\drivers\KodakCCS.exe
PRC - [2004/05/13 13:46:02 | 000,053,248 | ---- | M] () -- c:\Toshiba\IVP\swupdate\swupdtmr.exe
PRC - [2004/04/30 18:42:36 | 000,430,080 | ---- | M] (TOSHIBA) -- C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe
PRC - [2004/04/09 19:54:44 | 000,020,480 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
PRC - [2004/03/04 18:41:08 | 000,028,672 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2004/03/03 14:57:36 | 000,278,528 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSMain.exe
PRC - [2004/03/03 14:57:12 | 000,045,056 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSBattM.exe
PRC - [2004/03/02 15:45:28 | 000,135,168 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
PRC - [2004/02/03 16:47:06 | 001,089,589 | ---- | M] (TOSHIBA) -- C:\Program Files\Toshiba\Touch and Launch\PadExe.exe
PRC - [2004/01/22 19:09:00 | 000,098,304 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2003/09/05 05:24:46 | 000,065,536 | ---- | M] (TOSHIBA) -- C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
PRC - [2003/05/23 15:38:26 | 000,106,496 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\DVDRAMSV.exe
PRC - [2003/03/14 13:38:12 | 000,155,648 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\RAMASST.exe
========== Modules (SafeList) ========== MOD - [2010/07/27 11:00:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Default\Desktop\OTL.exe
MOD - [2008/04/13 19:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/03/22 15:51:54 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus®
SRV - [2009/07/07 15:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2004/05/24 13:35:52 | 000,322,104 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\WINDOWS\system32\drivers\KodakCCS.exe -- (KodakCCS)
SRV - [2004/05/13 13:46:02 | 000,053,248 | ---- | M] () [Auto | Running] -- c:\Toshiba\IVP\swupdate\swupdtmr.exe -- (Swupdtmr)
SRV - [2004/04/09 19:54:44 | 000,020,480 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2004/03/04 18:41:08 | 000,028,672 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe -- (CFSvcs)
SRV - [2003/05/23 15:38:26 | 000,106,496 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\NSDriver.sys -- (Ad-Watch Connect Filter)
DRV - [2010/03/25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2009/07/07 15:48:44 | 000,026,672 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\purendis.sys -- (purendis)
DRV - [2009/07/07 15:48:44 | 000,025,392 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\pnarp.sys -- (pnarp)
DRV - [2009/03/25 06:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/10/09 15:42:42 | 000,017,408 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2008/05/04 18:02:11 | 000,022,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbsermpt.sys -- (usbsermpt)
DRV - [2007/03/27 05:27:02 | 000,543,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2004/11/11 19:02:04 | 000,863,744 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/08/08 11:07:07 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2004/08/04 00:31:32 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/07/07 11:27:28 | 000,070,070 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DcPtp.sys -- (DcPTP)
DRV - [2004/07/07 09:55:12 | 000,152,049 | ---- | M] (Eastman Kodak Company) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ExportIt.sys -- (Exportit)
DRV - [2004/06/02 14:19:00 | 000,038,705 | ---- | M] (Eastman Kodak Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\DCFS2k.sys -- (DCFS2K)
DRV - [2004/05/20 09:41:54 | 000,061,564 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DcFpoint.sys -- (DcFpoint)
DRV - [2004/05/20 09:39:42 | 000,008,022 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DcLps.sys -- (DcLps)
DRV - [2004/05/20 09:21:10 | 000,036,918 | ---- | M] (Eastman Kodak Company) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\DcCam.sys -- (DcCam)
DRV - [2004/05/07 14:10:48 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2004/04/21 03:04:00 | 000,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2004/04/21 03:04:00 | 000,098,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2004/04/21 03:04:00 | 000,085,722 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2004/04/21 03:04:00 | 000,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2004/04/21 03:04:00 | 000,025,723 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2004/04/21 03:04:00 | 000,014,235 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2004/04/21 03:04:00 | 000,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2004/04/21 03:04:00 | 000,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2004/04/21 03:04:00 | 000,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2004/04/14 16:52:22 | 000,005,632 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\atiide.sys -- (atiide)
DRV - [2004/02/27 03:31:38 | 000,004,224 | ---- | M] (Toshiba Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NBSMI.sys -- (TVALD)
DRV - [2004/02/27 00:50:38 | 000,611,820 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/02/24 11:08:52 | 000,400,384 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2004/02/20 17:00:44 | 001,265,388 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004/01/22 19:04:16 | 000,178,816 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004/01/14 21:18:16 | 000,005,621 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2004/01/14 21:18:04 | 000,023,219 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2004/01/14 05:21:00 | 000,085,936 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2004/01/14 04:56:00 | 000,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2003/12/05 21:53:00 | 000,068,352 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtlnic51.sys -- (RTL8023)
DRV - [2003/10/27 15:59:00 | 000,013,842 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\atisgkaf.sys -- (caboagp)
DRV - [2003/10/24 15:53:14 | 000,090,416 | ---- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf)
DRV - [2003/07/16 15:27:40 | 000,043,264 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2003/06/11 10:53:22 | 000,006,867 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tbiosdrv.sys -- (TBiosDrv)
DRV - [2003/02/18 21:02:06 | 000,042,092 | ---- | M] (Texas Instruments Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tiumfwl.sys -- (tiumfwl)
DRV - [2003/01/29 16:35:00 | 000,012,032 | ---- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Netdevio.sys -- (Netdevio)
DRV - [2002/12/10 18:13:22 | 000,007,552 | ---- | M] (Texas Instruments Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\tiumflt.sys -- (DevUpper)
DRV - [2002/10/01 11:22:32 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = cdn
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = actsvr.comcastonline.com:8100
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/02 12:52:26 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2010/09/10 12:54:53 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PadTouch] C:\Program Files\Toshiba\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [THotkey] C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.micros...ntent/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3}
http://www.mpix.com/...geUploader5.cab (Image Uploader Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onec...lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.mi...b?1229738550203 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1175996315562 (MUWebControl Class)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C}
http://weddingchanne..._2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF}
http://www.mpix.com/...geUploader6.cab (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupd...8207.5281018519 (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277}
http://office.micros...ntent/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://download.game...aploader_v6.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx1.hotmail....ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Default\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Default\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/05/07 13:04:44 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ========== [2010/09/10 17:21:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Default\Desktop\Process Explorer 9-10-2010
[2010/09/10 13:46:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Default\Desktop\jkdef 9-10-2010
[2010/09/10 13:46:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Default\Desktop\logs to post 9-10-2010
[2010/09/10 12:54:40 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/09/07 18:11:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/09/07 17:39:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2010/08/02 12:27:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Default\Application Data\HpUpdate
[2010/08/02 12:26:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\Hewlett-Packard
[2010/07/26 19:40:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Default\Desktop\logs 7-26-2010
[2010/06/13 09:17:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Default\Local Settings\Application Data\PCHealth
[2010/06/13 02:02:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\PCHealth
[1 C:\Documents and Settings\Default\My Documents\*.tmp files -> C:\Documents and Settings\Default\My Documents\*.tmp -> ]
========== Files - Modified Within 90 Days ========== [2010/09/10 17:34:09 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/10 17:31:11 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/10 17:28:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/10 17:28:28 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/10 17:28:25 | 469,291,008 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/10 17:27:13 | 007,602,176 | ---- | M] () -- C:\Documents and Settings\Default\ntuser.dat
[2010/09/10 17:27:13 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Default\ntuser.ini
[2010/09/10 12:54:53 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010/09/07 23:07:41 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Default\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/09/07 23:06:37 | 000,446,068 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/09/07 23:06:36 | 000,073,234 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/09/07 23:06:33 | 000,525,966 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/07 21:03:55 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/09/07 18:11:23 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/08/31 17:55:51 | 003,652,608 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2010/08/31 17:55:49 | 002,807,808 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2010/08/31 17:52:50 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/08/24 16:30:57 | 000,001,072 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
[2010/08/18 19:51:49 | 000,055,808 | ---- | M] () -- C:\Documents and Settings\Default\My Documents\Christmas cookbook.doc
[2010/08/12 10:18:22 | 000,224,816 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 09:50:00 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/08/12 09:46:32 | 000,000,701 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/08/02 12:59:04 | 000,023,112 | ---- | M] () -- C:\WINDOWS\hpqins15.dat
[2010/07/27 11:00:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Default\Desktop\OTL.exe
[2010/07/16 17:57:37 | 000,000,015 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2010/07/01 16:07:46 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[1 C:\Documents and Settings\Default\My Documents\*.tmp files -> C:\Documents and Settings\Default\My Documents\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/09/07 22:14:01 | 469,291,008 | -HS- | C] () -- C:\hiberfil.sys
[2010/09/07 18:19:09 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/07 18:11:22 | 000,000,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/08/02 12:36:54 | 000,023,112 | ---- | C] () -- C:\WINDOWS\hpqins15.dat
[2010/07/15 14:01:35 | 003,652,608 | R--- | C] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2010/07/01 16:07:46 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2010/07/01 16:07:46 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009/01/16 15:45:48 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2008/05/04 18:30:08 | 000,000,120 | ---- | C] () -- C:\WINDOWS\PbkUser.INI
[2007/03/05 13:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2006/07/28 14:23:26 | 000,796,584 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2005/02/06 12:43:49 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2005/02/06 12:43:13 | 000,000,067 | ---- | C] () -- C:\WINDOWS\swupdate.INI
[2005/02/06 12:36:07 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/12/31 19:05:50 | 000,000,078 | ---- | C] () -- C:\WINDOWS\qwimp.ini
[2004/12/31 19:05:49 | 000,000,511 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2004/08/08 15:50:23 | 000,000,282 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2004/08/08 11:06:58 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2004/06/17 13:50:32 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/06/17 13:41:50 | 000,000,021 | ---- | C] () -- C:\WINDOWS\CS_SETUP.ini
[2004/05/07 14:23:04 | 000,000,264 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/05/07 14:19:47 | 000,001,072 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2004/05/07 14:16:56 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2004/05/07 14:16:56 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2004/05/07 14:16:56 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2004/05/07 14:16:56 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2004/05/07 14:16:56 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2004/05/07 14:16:56 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2004/05/07 14:02:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2004/05/07 13:59:01 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\MousePage.dll
[2004/05/07 13:59:01 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TCtrlIO.dll
[2004/05/07 13:50:00 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
[2004/05/07 13:46:34 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2004/05/07 13:46:31 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2004/05/07 13:46:08 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2004/05/07 13:46:08 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2004/05/07 13:46:08 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2004/05/07 13:46:08 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2004/05/07 13:41:46 | 000,006,867 | ---- | C] () -- C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2004/05/07 13:38:49 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/05/07 13:10:19 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/05/07 13:07:49 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/05/07 13:01:15 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/05/07 12:35:43 | 000,000,384 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/04/23 19:33:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/01/07 17:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2000/09/08 18:53:50 | 000,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll
========== LOP Check ========== [2008/05/04 18:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2005/12/24 15:22:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN
[2007/07/09 20:40:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2005/10/08 12:59:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2010/06/05 01:32:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2005/06/08 23:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2009/07/09 12:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default\Application Data\GARMIN
[2004/05/07 14:05:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default\Application Data\InterTrust
[2004/05/07 15:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default\Application Data\InterVideo
[2005/12/30 18:49:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default\Application Data\Netscape
[2007/04/07 20:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default\Application Data\OfficeUpdate12
[2004/08/08 18:54:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default\Application Data\toshiba
[2009/06/06 23:22:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default\Application Data\Windows Search
[2010/09/10 17:34:09 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ========== < End of report >