This is on my sons pc. When it boots, there are no icons on the desktop. There are no programs in the program listing (actually only one because I loaded malwarebytes). No errors on screen and I have the lan cable disconnected. This is a windows xp machine.
When I boot into safe mode with networking (with the lan cable connected), I still have no programs in my program list, but I do have a IE icon on the desktop. I google geeks2go, and click on the link to your site, but I get another site.
I think Im infected.
Below is the OTL log.
OTL logfile created on: 9/15/2011 1:18:19 PM - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Program Files
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.94 Gb Total Physical Memory | 2.59 Gb Available Physical Memory | 88.07% Memory free
4.78 Gb Paging File | 4.59 Gb Available in Paging File | 96.04% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Program Files
Drive C: | 232.87 Gb Total Space | 125.53 Gb Free Space | 53.91% Space Free | Partition Type: NTFS
Drive E: | 1.95 Gb Total Space | 0.38 Gb Free Space | 19.51% Space Free | Partition Type: FAT
Computer Name: STEVE-9839F83C4 | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/09/15 12:54:04 | 000,581,632 | ---- | M] (OldTimer Tools) -- C:\Program Files\OTL.exe
PRC - [2008/07/03 05:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS.0\explorer.exe
PRC - [2008/04/14 06:00:00 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS.0\system32\cmd.exe
========== Modules (No Company Name) ==========
MOD - [2011/01/05 09:16:58 | 000,139,776 | -H-- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2010/11/04 01:51:44 | 000,555,624 | -H-- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nvShell.dll
MOD - [2010/07/04 15:32:38 | 000,010,752 | -H-- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll
MOD - [2010/06/03 13:46:00 | 000,067,872 | -H-- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/03/16 10:42:06 | 000,407,336 | -H-- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
========== Driver Services (SafeList) ==========
DRV - [2011/02/06 09:22:41 | 000,420,920 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS.0\System32\Drivers\sptd.sys -- (sptd)
DRV - [2011/01/13 07:43:15 | 000,074,280 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS.0\System32\drivers\si3112.sys -- (Si3112)
DRV - [2002/07/17 01:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS.0\System32\drivers\ASPI32.SYS -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS.0\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/08 14:29:06 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/23 03:14:51 | 000,000,000 | -H-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\IDM\idmmzcc3
[2011/02/06 17:37:10 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\Mozilla\Extensions
[2011/08/31 20:18:00 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\Mozilla\Firefox\Profiles\hc57u5xa.default\extensions
[2011/02/06 17:36:58 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\STEVE.STEVE-9839F83C4\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\HC57U5XA.DEFAULT\EXTENSIONS\[email protected]
[2011/09/08 14:29:06 | 000,134,104 | -H-- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/08 13:03:57 | 000,002,252 | -H-- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2008/04/14 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS.0\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS.0\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS.0\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKCU..\Run: [iSproggler] "C:\DOCUME~1\STEVE~1.STE\LOCALS~1\Temp\Rar$EX00.656\iSproggler.exe" File not found
O4 - HKCU..\Run: [ixgPHgbBMPf.exe] C:\Documents and Settings\All Users.WINDOWS.0\Application Data\ixgPHgbBMPf.exe File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [ZU5YXYWEXDUX4J3YCEXPSKHPZS] C:\Record.Bin\20170B51666.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.72.134 68.87.77.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0A44905A-2098-4961-85BB-5E4D1B897E75}: DhcpNameServer = 68.87.72.134 68.87.77.134
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS.0\system32\userinit.exe) -C:\WINDOWS.0\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Steve.STEVE-9839F83C4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Steve.STEVE-9839F83C4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/15 13:18:09 | 000,581,632 | ---- | C] (OldTimer Tools) -- C:\Program Files\OTL.exe
[2011/09/15 13:17:50 | 000,581,632 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Desktop\OTL.exe
[2011/09/15 11:28:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\Malwarebytes
[2011/09/15 10:02:49 | 000,000,000 | -HSD | C] -- C:\WINDOWS.0\CSC
[2011/09/15 09:48:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/15 09:48:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Malwarebytes
[2011/09/15 09:47:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/09/15 09:35:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Recent
[2011/09/13 22:54:18 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Start Menu\Programs\Data Recovery
[2011/09/13 22:53:46 | 000,357,376 | -H-- | C] (RealVNC Ltd.) -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6DSS92c31Apgjk.exe
[2011/09/01 20:14:10 | 000,000,000 | -H-D | C] -- C:\Program Files\Microsoft Synchronization Services
[2011/09/01 20:14:10 | 000,000,000 | -H-D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011/09/01 20:13:44 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\My Documents\Visual Studio 2010
[2011/09/01 20:13:39 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Microsoft Visual Studio 2010 Express
[2011/09/01 20:12:20 | 000,000,000 | ---D | C] -- C:\WINDOWS.0\symbols
[2011/09/01 20:12:18 | 000,000,000 | -H-D | C] -- C:\Program Files\Microsoft SDKs
[2011/09/01 20:12:18 | 000,000,000 | -H-D | C] -- C:\Program Files\Microsoft Help Viewer
[2011/09/01 20:12:18 | 000,000,000 | -H-D | C] -- C:\Program Files\Common Files\Merge Modules
[2011/09/01 20:12:17 | 000,000,000 | -H-D | C] -- C:\Program Files\Microsoft Visual Studio 10.0
[2011/09/01 20:05:33 | 000,000,000 | -H-D | C] -- C:\Program Files\Microsoft.NET
[2010/05/18 21:54:42 | 307,224,606 | -H-- | C] (Arobas Music ) -- C:\Program Files\GUITAR~1.EXE
[3 C:\WINDOWS.0\*.tmp files -> C:\WINDOWS.0\*.tmp -> ]
[1 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/15 13:14:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS.0\bootstat.dat
[2011/09/15 13:04:26 | 000,000,664 | ---- | M] () -- C:\WINDOWS.0\System32\d3d9caps.dat
[2011/09/15 12:54:04 | 000,581,632 | ---- | M] (OldTimer Tools) -- C:\Program Files\OTL.exe
[2011/09/15 12:54:04 | 000,581,632 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Desktop\OTL.exe
[2011/09/15 09:48:08 | 000,000,804 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS.0\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 09:35:55 | 000,000,927 | -H-- | M] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Recovery.lnk
[2011/09/15 09:34:33 | 000,002,206 | ---- | M] () -- C:\WINDOWS.0\System32\wpa.dbl
[2011/09/13 22:54:21 | 000,000,224 | -H-- | M] () -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\~6DSS92c31Apgjk
[2011/09/13 22:54:21 | 000,000,168 | -H-- | M] () -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\~6DSS92c31Apgjkr
[2011/09/13 22:54:19 | 000,000,909 | -H-- | M] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Desktop\Data Recovery.lnk
[2011/09/13 22:54:11 | 000,000,344 | -H-- | M] () -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6DSS92c31Apgjk
[2011/09/13 22:53:46 | 000,357,376 | -H-- | M] (RealVNC Ltd.) -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6DSS92c31Apgjk.exe
[2011/09/13 15:49:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS.0\tasks\AppleSoftwareUpdate.job
[2011/09/02 19:19:54 | 000,000,190 | -H-- | M] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\webct_upload_applet.properties
[2011/09/01 20:11:12 | 000,457,758 | ---- | M] () -- C:\WINDOWS.0\System32\perfh009.dat
[2011/09/01 20:11:12 | 000,075,818 | ---- | M] () -- C:\WINDOWS.0\System32\perfc009.dat
[2011/09/01 15:02:38 | 000,000,029 | -H-- | M] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Desktop\test.cpp
[3 C:\WINDOWS.0\*.tmp files -> C:\WINDOWS.0\*.tmp -> ]
[1 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/15 10:07:23 | 000,000,664 | ---- | C] () -- C:\WINDOWS.0\System32\d3d9caps.dat
[2011/09/15 09:48:08 | 000,000,804 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.0\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 09:35:55 | 000,000,927 | -H-- | C] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Recovery.lnk
[2011/09/13 22:54:21 | 000,000,224 | -H-- | C] () -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\~6DSS92c31Apgjk
[2011/09/13 22:54:21 | 000,000,168 | -H-- | C] () -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\~6DSS92c31Apgjkr
[2011/09/13 22:54:19 | 000,000,909 | -H-- | C] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Desktop\Data Recovery.lnk
[2011/09/13 22:54:11 | 000,000,344 | -H-- | C] () -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6DSS92c31Apgjk
[2011/09/02 19:19:15 | 000,000,190 | -H-- | C] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\webct_upload_applet.properties
[2011/09/01 14:56:14 | 000,000,029 | -H-- | C] () -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Desktop\test.cpp
[2011/03/24 00:37:34 | 000,014,376 | -H-- | C] () -- C:\WINDOWS.0\System32\mlfcache.dat
[2011/02/25 20:19:32 | 000,041,872 | ---- | C] () -- C:\WINDOWS.0\System32\xfcodec.dll
[2011/02/06 17:46:17 | 000,252,080 | ---- | C] () -- C:\WINDOWS.0\System32\nvdrsdb0.bin
[2011/02/06 17:46:15 | 000,252,080 | ---- | C] () -- C:\WINDOWS.0\System32\nvdrsdb1.bin
[2011/02/06 17:46:15 | 000,000,001 | ---- | C] () -- C:\WINDOWS.0\System32\nvdrssel.bin
[2011/02/06 17:46:06 | 002,292,678 | ---- | C] () -- C:\WINDOWS.0\System32\nvdata.bin
[2011/02/06 17:37:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS.0\nsreg.dat
[2011/02/06 10:42:19 | 000,004,249 | ---- | C] () -- C:\WINDOWS.0\ODBCINST.INI
[2011/02/06 10:40:40 | 000,096,664 | ---- | C] () -- C:\WINDOWS.0\System32\FNTCACHE.DAT
[2011/02/06 09:26:49 | 000,002,048 | --S- | C] () -- C:\WINDOWS.0\bootstat.dat
[2011/02/06 09:14:46 | 000,021,640 | ---- | C] () -- C:\WINDOWS.0\System32\emptyregdb.dat
[2011/02/06 09:07:15 | 000,100,352 | ---- | C] () -- C:\WINDOWS.0\System32\zlib1.dll
[2011/02/06 09:07:01 | 000,162,304 | ---- | C] () -- C:\WINDOWS.0\System32\libpng13.dll
[2009/03/05 13:18:34 | 000,006,144 | ---- | C] () -- C:\WINDOWS.0\System32\FontReg.exe
[2008/04/14 06:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS.0\System32\oembios.bin
[2008/04/14 06:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS.0\System32\mlang.dat
[2008/04/14 06:00:00 | 000,457,758 | ---- | C] () -- C:\WINDOWS.0\System32\perfh009.dat
[2008/04/14 06:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS.0\System32\perfi009.dat
[2008/04/14 06:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS.0\System32\dssec.dat
[2008/04/14 06:00:00 | 000,075,818 | ---- | C] () -- C:\WINDOWS.0\System32\perfc009.dat
[2008/04/14 06:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS.0\System32\mib.bin
[2008/04/14 06:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS.0\System32\perfd009.dat
[2008/04/14 06:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS.0\System32\secupd.dat
[2008/04/14 06:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS.0\System32\oembios.dat
[2008/04/14 06:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS.0\System32\Dcache.bin
[2008/04/14 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS.0\System32\noise.dat
========== LOP Check ==========
[2011/02/15 23:29:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Guitar Pro 6
[2011/02/06 19:10:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Last.fm
[2011/02/06 17:58:41 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/20 01:18:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\.minecraft
[2011/04/26 12:22:11 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\Audacity
[2011/09/04 14:01:10 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\BitTorrent
[2011/02/06 17:49:17 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\DMCache
[2011/03/19 01:57:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\Guitar Pro 6
[2011/02/08 00:56:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Steve.STEVE-9839F83C4\Application Data\iSproggler
========== Purity Check ==========
< End of report >
Thanks!