I Have Used "TDSSKILLER" and "GOREDFIX" but Still Getting Google Redirect! Have also Carried out Hosts File Clean up
Can Anyone advise me of my next step please
Kind Regards
Crawfordsparky
OTL logfile created on.doc
OTL logfile created on: 08/11/2010 16:02:46 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Mark Cockram\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 7.82 Gb Free Space | 13.99% Space Free | Partition Type: NTFS
Drive E: | 54.43 Gb Total Space | 54.34 Gb Free Space | 99.84% Space Free | Partition Type: NTFS
Computer Name: BUSINESSCOMPUTE | User Name: Mark Cockram | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Mark Cockram\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Mail\WinMail.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe (Interactive Digital Media)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Mark Cockram\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (TOSHIBA Bluetooth Service) -- File not found
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Symantec Core LC) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate Notice Service) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TNaviSrv) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (ISPwdSvc) -- C:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (comHost) -- C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Ex) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
SRV - (CFSvcs) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Driver Services (SafeList) ==========
DRV - (TpChoice) -- C:\Windows\System32\DRIVERS\TpChoice.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (NAVEX15) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20101108.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20101108.002\NAVENG.SYS (Symantec Corporation)
DRV - (IDSvix86) -- C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20101021.002\IDSvix86.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMNDISV) -- C:\Windows\System32\Drivers\SYMNDISV.SYS (Symantec Corporation)
DRV - (SYMTDI) -- C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) -- C:\Windows\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS) -- C:\Windows\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMREDRV) -- C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMDNS) -- C:\Windows\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (SRTSPL) -- C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tos_sps32) -- C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (CplIR) -- C:\Windows\system32\DRIVERS\CplIR.SYS (COMPAL ELECTRONIC INC.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (tifm21) -- C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (KR10N) -- C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (KR10I) -- C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (tosrfec) -- C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (LPCFilter) -- C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {4D144BC3-23FB-47de-90C5-63CCB0139CCF}:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 07:29:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/08 10:44:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b5\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 5\components [2010/10/25 17:14:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b5\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 5\plugins
[2008/09/08 17:25:19 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Mozilla\Extensions
[2010/11/08 09:52:00 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Mozilla\Firefox\Profiles\oelezenx.default\extensions
[2010/07/24 08:15:48 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Mark Cockram\AppData\Roaming\Mozilla\Firefox\Profiles\oelezenx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/09 17:20:43 | 000,000,000 | ---D | M] (TradeManager-Plugin) -- C:\Users\Mark Cockram\AppData\Roaming\Mozilla\Firefox\Profiles\oelezenx.default\extensions\{4D144BC3-23FB-47de-90C5-63CCB0139CCF}
[2010/10/22 08:31:45 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Mozilla\Firefox\Profiles\oelezenx.default\extensions\[email protected]
[2010/11/03 21:23:36 | 000,010,378 | ---- | M] () -- C:\Users\Mark Cockram\AppData\Roaming\Mozilla\Firefox\Profiles\oelezenx.default\searchplugins\mail-online.xml
[2010/09/11 09:06:21 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/23 09:15:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 16:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/08/25 00:24:53 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/25 00:24:53 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/25 00:24:53 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/25 00:24:53 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/11/08 14:47:19 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe (Interactive Digital Media)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA)
O4 - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe (Toshiba)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [{2C8FAD01-26BA-771C-317F-26D7F231F137}] C:\Users\Mark Cockram\AppData\Roaming\Orycu\lyvu.exe ()
O4 - HKCU..\Run: [{79BDA5E5-3FE5-82F4-4CE0-6950B368181C}] C:\Users\Mark Cockram\AppData\Roaming\Nycu\alba.exe ()
O4 - HKCU..\Run: [C:\Users\Mark Cockram\Downloads\ArbAlarm\ArbAlarm\arbAlarm.exe] C:\Users\Mark Cockram\Downloads\ArbAlarm\ArbAlarm\arbAlarm.exe ()
O4 - HKCU..\Run: [feedreader.exe] C:\Program Files\FeedReader30\feedreader.exe ()
O4 - HKCU..\Run: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Limited)
O4 - HKCU..\Run: [TOSCDSPD] File not found
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe File not found
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O9 - Extra Button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not found
O9 - Extra Button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - File not found
O9 - Extra Button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Mark Cockram\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mark Cockram\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/08 15:01:07 | 000,000,000 | ---D | C] -- C:\Users\Mark Cockram\Desktop\GooredFix Backups
[2010/11/08 14:47:12 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/11/08 14:22:06 | 000,000,000 | ---D | C] -- C:\Users\Mark Cockram\Documents\HostsXpert-1
[2010/11/08 12:25:23 | 000,000,000 | ---D | C] -- C:\Users\Mark Cockram\AppData\Local\ElevatedDiagnostics
[2010/11/08 12:23:27 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
[2010/11/08 12:20:01 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ATS
[2010/11/08 10:44:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/11/08 10:43:53 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010/11/08 10:20:43 | 000,000,000 | ---D | C] -- C:\Users\Mark Cockram\AppData\Roaming\Uniblue
[2010/11/08 10:20:38 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2010/11/08 08:54:44 | 000,000,000 | -H-D | C] -- C:\Users\Public\Documents\Windows
[2010/11/08 08:54:43 | 000,000,000 | -H-D | C] -- C:\Users\Public\Documents\Server
[2010/11/05 09:58:31 | 000,000,000 | ---D | C] -- C:\Users\Mark Cockram\AppData\Roaming\Nycu
[2010/11/05 09:58:31 | 000,000,000 | ---D | C] -- C:\Users\Mark Cockram\AppData\Roaming\Ifnuho
[2010/10/26 09:57:25 | 000,000,000 | ---D | C] -- C:\Program Files\Market Samurai
[2010/10/25 17:18:11 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/10/25 17:18:08 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/10/25 17:13:59 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/10/25 17:09:11 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/10/22 08:32:35 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan
[2010/10/22 08:32:35 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2010/10/22 08:32:30 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2009/02/15 11:14:26 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Mark Cockram\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2010/11/08 16:05:25 | 000,000,432 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{5376519B-D2F3-40F8-9047-FB66902F06E0}.job
[2010/11/08 15:46:55 | 000,083,456 | ---- | M] () -- C:\Users\Mark Cockram\Desktop\OTL logfile created on.doc
[2010/11/08 15:45:18 | 000,022,514 | ---- | M] () -- C:\Users\Mark Cockram\Documents\OTL logfile created on.docx
[2010/11/08 14:59:54 | 000,609,196 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/11/08 14:59:54 | 000,108,672 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/11/08 14:54:53 | 000,000,476 | ---- | M] () -- C:\Windows\tasks\SDMsgUpdate (TE).job
[2010/11/08 14:54:51 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2010/11/08 14:54:43 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/08 14:54:43 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/08 14:54:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/11/08 14:54:28 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/08 14:47:19 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2010/11/08 14:03:06 | 000,000,884 | ---- | M] () -- C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/11/08 13:45:51 | 000,000,894 | ---- | M] () -- C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/11/08 12:21:11 | 004,390,912 | ---- | M] () -- C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/11/08 12:21:10 | 000,131,072 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/11/08 12:21:10 | 000,065,536 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/11/08 10:44:40 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/11/08 10:20:40 | 000,000,898 | ---- | M] () -- C:\Users\Mark Cockram\Application Data\Microsoft\Internet Explorer\Quick Launch\SpeedUpMyPC.lnk
[2010/11/08 10:14:04 | 000,012,781 | ---- | M] () -- C:\Users\Mark Cockram\Documents\Champagne Description.docx
[2010/11/07 20:17:05 | 000,023,040 | ---- | M] () -- C:\Users\Mark Cockram\Documents\sunday memories TC homework.doc
[2010/10/26 18:27:37 | 000,828,416 | ---- | M] () -- C:\Users\Mark Cockram\Documents\Finest Gift.msam
[2010/10/26 09:57:45 | 000,000,817 | ---- | M] () -- C:\Users\Public\Desktop\Market Samurai.lnk
[2010/10/25 20:11:26 | 000,000,560 | ---- | M] () -- C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Mark Cockram.job
[2010/10/25 17:19:20 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/10/25 17:14:28 | 000,001,731 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/10/25 16:59:41 | 000,000,629 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
[2010/10/25 16:58:38 | 000,001,854 | ---- | M] () -- C:\Users\Mark Cockram\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/10/24 17:02:52 | 000,001,717 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010/10/19 13:21:40 | 000,021,504 | ---- | M] () -- C:\Users\Mark Cockram\Documents\gift.asam
[2010/10/19 12:58:55 | 000,029,696 | ---- | M] () -- C:\Users\Mark Cockram\Documents\Finest Gift Store.msam
[2010/10/17 11:58:07 | 000,202,752 | ---- | M] () -- C:\Users\Mark Cockram\Documents\buy gifts.msam
[2010/10/16 07:42:47 | 000,375,208 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/10/11 16:06:53 | 000,584,704 | ---- | M] () -- C:\Users\Mark Cockram\Documents\gifts-2-go.msam
========== Files Created - No Company Name ==========
[2010/11/08 15:46:53 | 000,083,456 | ---- | C] () -- C:\Users\Mark Cockram\Desktop\OTL logfile created on.doc
[2010/11/08 15:45:15 | 000,022,514 | ---- | C] () -- C:\Users\Mark Cockram\Documents\OTL logfile created on.docx
[2010/11/08 14:03:06 | 000,000,884 | ---- | C] () -- C:\Users\Public\Desktop\SystemTweaker.lnk
[2010/11/08 13:45:55 | 000,000,346 | ---- | C] () -- C:\Windows\tasks\RegistryBooster.job
[2010/11/08 12:41:49 | 000,000,894 | ---- | C] () -- C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/11/08 12:20:13 | 004,390,912 | ---- | C] () -- C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/11/08 12:20:13 | 000,131,072 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/11/08 12:20:13 | 000,065,536 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/11/08 10:44:40 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/11/08 10:20:40 | 000,000,898 | ---- | C] () -- C:\Users\Mark Cockram\Application Data\Microsoft\Internet Explorer\Quick Launch\SpeedUpMyPC.lnk
[2010/11/08 10:14:02 | 000,012,781 | ---- | C] () -- C:\Users\Mark Cockram\Documents\Champagne Description.docx
[2010/11/07 20:11:33 | 000,023,040 | ---- | C] () -- C:\Users\Mark Cockram\Documents\sunday memories TC homework.doc
[2010/10/26 09:57:45 | 000,000,817 | ---- | C] () -- C:\Users\Public\Desktop\Market Samurai.lnk
[2010/10/25 17:19:20 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/10/25 17:14:28 | 000,001,731 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/10/22 08:32:34 | 000,001,717 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010/10/19 13:16:31 | 000,021,504 | ---- | C] () -- C:\Users\Mark Cockram\Documents\gift.asam
[2010/10/19 12:59:45 | 000,828,416 | ---- | C] () -- C:\Users\Mark Cockram\Documents\Finest Gift.msam
[2010/10/19 12:47:39 | 000,029,696 | ---- | C] () -- C:\Users\Mark Cockram\Documents\Finest Gift Store.msam
[2010/10/17 11:42:59 | 000,202,752 | ---- | C] () -- C:\Users\Mark Cockram\Documents\buy gifts.msam
[2010/05/05 08:11:26 | 000,000,000 | ---- | C] () -- C:\Windows\WinInit.ini
[2009/10/20 17:43:20 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/04/20 12:01:44 | 000,087,552 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2009/02/15 11:15:44 | 000,000,033 | ---- | C] () -- C:\Users\Mark Cockram\AppData\Roaming\pcouffin.log
[2009/02/15 11:14:26 | 000,087,608 | ---- | C] () -- C:\Users\Mark Cockram\AppData\Roaming\inst.exe
[2009/02/15 11:14:26 | 000,007,887 | ---- | C] () -- C:\Users\Mark Cockram\AppData\Roaming\pcouffin.cat
[2009/02/15 11:14:26 | 000,001,144 | ---- | C] () -- C:\Users\Mark Cockram\AppData\Roaming\pcouffin.inf
[2009/01/22 13:36:26 | 000,106,496 | ---- | C] () -- C:\Windows\System32\Converter.dll
[2008/09/23 11:36:43 | 000,000,680 | ---- | C] () -- C:\Users\Mark Cockram\AppData\Local\d3d9caps.dat
[2008/09/17 14:58:18 | 000,000,272 | ---- | C] () -- C:\Users\Mark Cockram\AppData\Roaming\wklnhst.dat
[2008/04/24 09:00:31 | 000,749,568 | R--- | C] () -- C:\Windows\System32\agi1600.dll
[2008/04/24 09:00:30 | 001,777,664 | R--- | C] () -- C:\Windows\System32\zhp1600r.dll
[2008/04/24 09:00:29 | 000,114,688 | R--- | C] () -- C:\Windows\System32\VSHP1600.dll
[2008/03/26 18:40:40 | 000,008,192 | ---- | C] () -- C:\Users\Mark Cockram\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/10 12:49:37 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2007/10/10 12:49:37 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2007/10/10 12:49:37 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2007/10/10 12:49:34 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2007/10/10 12:46:22 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007/10/10 12:45:13 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2007/10/10 12:45:13 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2007/10/10 12:45:13 | 000,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2007/10/10 12:45:13 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2007/07/10 14:38:33 | 000,036,864 | ---- | C] () -- C:\Windows\System32\HWS_Ctrl.dll
[2007/07/10 14:34:00 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2007/07/10 14:34:00 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2007/07/10 14:34:00 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2007/07/10 14:34:00 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2007/07/10 14:34:00 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2007/07/10 14:34:00 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2007/04/13 16:18:39 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2006/12/05 12:05:06 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006/11/02 12:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 07:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005/11/23 13:55:42 | 000,024,576 | ---- | C] () -- C:\Windows\System32\SPCtl.dll
[2005/07/22 20:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
========== LOP Check ==========
[2009/03/18 12:29:15 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Affilorama
[2008/09/11 15:30:57 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/02/12 15:25:01 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Desktop Spider
[2008/03/26 18:13:09 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\DesktopSMS
[2010/04/01 08:42:07 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\DomainSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2009/01/14 09:24:51 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Feedreader
[2009/05/28 10:40:06 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\IBP
[2010/11/08 15:55:48 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Ifnuho
[2010/11/08 14:20:31 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Laqyca
[2009/12/23 12:10:25 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Living Tree Software
[2008/09/19 10:51:27 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2008/10/08 16:38:53 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Nvu
[2010/11/05 09:58:31 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Nycu
[2009/03/10 19:08:47 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Orycu
[2009/06/16 12:21:38 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\SmartDraw
[2009/02/12 15:25:12 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Spider
[2010/09/27 18:50:01 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Spotify
[2008/09/22 10:02:14 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Template
[2010/11/08 12:16:52 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Toshiba
[2010/11/08 14:03:08 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Uniblue
[2010/11/07 11:36:11 | 000,000,000 | ---D | M] -- C:\Users\Mark Cockram\AppData\Roaming\Vso
[2010/11/08 14:54:51 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\RegistryBooster.job
[2010/11/08 14:53:30 | 000,032,622 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/08 14:54:53 | 000,000,476 | ---- | M] () -- C:\Windows\Tasks\SDMsgUpdate (TE).job
[2010/11/08 16:05:25 | 000,000,432 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{5376519B-D2F3-40F8-9047-FB66902F06E0}.job
========== Purity Check ==========
< End of report >
Edited by crawfordsparky, 08 November 2010 - 10:09 AM.