Jeg har nu fundet ud af at lægge OTL på en USB stick
så her kommer de 2 logfiler:
OTL logfile created on: 11-01-2012 09:04:07 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\twillads.EUROPE\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000406 | Country: Denmark | Language: DAN | Date Format: dd-MM-yyyy
1,24 Gb Total Physical Memory | 0,83 Gb Available Physical Memory | 66,98% Memory free
2,57 Gb Paging File | 2,31 Gb Available in Paging File | 89,90% Paging File free
Paging file location(s): C:\pagefile.sys 1512 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 58,59 Gb Total Space | 32,82 Gb Free Space | 56,01% Space Free | Partition Type: NTFS
Drive E: | 34,56 Gb Total Space | 27,84 Gb Free Space | 80,56% Space Free | Partition Type: NTFS
Drive F: | 488,48 Mb Total Space | 395,25 Mb Free Space | 80,91% Space Free | Partition Type: FAT
Computer Name: TWILLADS-LT | User Name: twillads | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\twillads.EUROPE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Arm_Apps\PCS_Service\pcs_service.exe (Armstrong World Industries)
PRC - C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel(R) Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\bcm1xsup.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\acAuth.dll ()
========== Win32 Services (SafeList) ==========
SRV - (DWMRCS)—C:\WINDOWS\System32\DWRCS.EXE ()
SRV - (SMServer)—C:\WINDOWS\System32\snmvtsvc.exe (SMServer)
SRV - (McAfeeFramework)—C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (PCS_service)—C:\Arm_Apps\PCS_Service\pcs_service.exe (Armstrong World Industries)
SRV - (CcmExec)—C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (Wuser32)—C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe (Microsoft Corporation)
SRV - (WLANKEEPER) Intel(R)—C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel(R) Corporation)
SRV - (Lotus Notes Single Logon)—C:\WINDOWS\system32\nslsvice.exe (IBM Corp)
SRV - (AWI_Services)—C:\WINDOWS\system32\AWIServices.exs ()
SRV - (ExtranetAccess)—C:\Program Files\Nortel Networks\Extranet_serv.exe (Nortel Networks NA, Inc.)
========== Driver Services (SafeList) ==========
DRV - (SndTVideo)—C:\WINDOWS\system32\drivers\SndTVideo.sys (Windows (R) 2000 DDK provider)
DRV - (SndTAudio)—C:\WINDOWS\system32\drivers\SndTAudio.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (s117obex)—C:\WINDOWS\system32\drivers\s117obex.sys (MCCI Corporation)
DRV - (s117mdm)—C:\WINDOWS\system32\drivers\s117mdm.sys (MCCI Corporation)
DRV - (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM)—C:\WINDOWS\system32\drivers\s117mgmt.sys (MCCI Corporation)
DRV - (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM)—C:\WINDOWS\system32\drivers\s117unic.sys (MCCI Corporation)
DRV - (s117mdfl)—C:\WINDOWS\system32\drivers\s117mdfl.sys (MCCI Corporation)
DRV - (s117bus) Sony Ericsson Device 117 driver (WDM)—C:\WINDOWS\system32\drivers\s117bus.sys (MCCI Corporation)
DRV - (prepdrvr)—C:\WINDOWS\system32\CCM\PrepDrv.sys (Microsoft Corporation)
DRV - (s24trans)—C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (ElbyCDFL)—C:\WINDOWS\system32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (w29n51) Intel(R)—C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (b57w2k)—C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (GTIPCI21)—C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (NWADI)—C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (kbstuff)—C:\WINDOWS\system32\drivers\kbstuff5.sys (Microsoft Corporation)
DRV - (idisw2km)—C:\WINDOWS\system32\drivers\idisw2km.sys (Microsoft Corporation)
DRV - (HSF_DPV)—C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH)—C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf)—C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97)—C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (GTwinUSB)—C:\WINDOWS\system32\drivers\GTwinUSB.sys (Gemplus)
DRV - (Eacfilt)—C:\WINDOWS\system32\drivers\eacfilt.sys (Nortel Networks)
DRV - (IPSECSHM)—C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks)
DRV - (IPSECEXT)—C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks)
DRV - (OMCI)—C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (GEMPC430)—C:\WINDOWS\system32\drivers\grclass.sys (Gemplus)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = <local>;*.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: “http://google.dk/”
FF - prefs.js..extensions.enabledItems: .:1.0
FF - prefs.js..network.proxy.ftp: “bieas001”
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher: “bieas001”
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: “bieas001”
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: “10.*,*.europe.armstrong.com,*.americas.armstrong.com,*.pacrim.armstrong.com,intra.armstrong.com,localhost,127.0.0.1”
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: “bieas001”
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl: “bieas001”
FF - prefs.js..network.proxy.ssl_port: 80
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
[2011-11-01 17:31:03 | 000,003,674 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Application Data\Mozilla\Firefox\Profiles\qhl0np61.default\searchplugins\avg-secure-search.xml
O1 HOSTS File: ([2012-01-11 08:48:43 | 000,000,698 |——| M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuNetworkPlaces = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra ‘Tools’ menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra ‘Tools’ menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra ‘Tools’ menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.80.12.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = europe.armstrong.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{26B97A4A-0666-4FFB-87FF-D5108064136F}: DhcpNameServer = 10.80.12.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5B171258-283A-4B9F-A7A7-461D357D1E5B}: DhcpNameServer = 193.162.153.164 194.239.134.83
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{956A7058-DD19-4270-8EB1-0051C087D46E}: NameServer = 10.80.16.61,10.80.16.62
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\Controls\SAPHTMLP.DLL File not found
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - C:\Program Files\SAP\FrontEnd\Controls\SAPHTMLP.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Min aktuelle startside) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\twillads.EUROPE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\twillads.EUROPE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007-11-09 14:39:45 | 000,000,000 |——| M] () - C:\AUTOEXEC.BAT—[ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open]—“%1” %*
O35 - HKLM\..exefile [open]—“%1” %*
O37 - HKLM\...com [@ = ComFile]—“%1” %*
O37 - HKLM\...exe [@ = exefile]—“%1” %*
========== Files/Folders - Created Within 30 Days ==========
[2012-01-11 09:02:19 | 000,584,192 |——| C] (OldTimer Tools)—C:\Documents and Settings\twillads.EUROPE\Desktop\OTL.exe
[2012-01-09 13:23:51 | 000,000,000 | RH-D | C]—C:\Documents and Settings\twillads.EUROPE\Recent
[2011-12-28 21:24:28 | 000,000,000 |—-D | C]—C:\Program Files\Common Files\Java
[2011-12-25 09:44:11 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2011-12-24 15:42:56 | 000,000,000 |—-D | C]—C:\QUARANTINE
[2011-12-24 15:42:56 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\McAfee
[2011-12-24 15:42:45 | 000,000,000 |—-D | C]—C:\Program Files\McAfee
[2011-12-24 15:41:30 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\Lotus Applications
[2011-12-12 15:25:49 | 000,000,000 |—-D | C]—C:\Program Files\Microsoft Visual Studio 8
[2011-12-12 15:22:19 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Microsoft Help
========== Files - Modified Within 30 Days ==========
[2012-01-11 09:02:20 | 000,584,192 |——| M] (OldTimer Tools)—C:\Documents and Settings\twillads.EUROPE\Desktop\OTL.exe
[2012-01-11 08:52:25 | 000,000,455 |——| M] ()—C:\WINDOWS\SMSCFG.ini
[2012-01-11 08:50:30 | 000,002,048 |—S- | M] ()—C:\WINDOWS\bootstat.dat
[2012-01-11 08:46:12 | 000,000,273 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Desktop\Genvej til HostsXpert.lnk
[2012-01-10 16:56:58 | 000,002,497 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Desktop\Microsoft Office Word 2003.lnk
[2012-01-09 13:27:03 | 000,000,784 |——| M] ()—C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012-01-09 08:41:15 | 000,000,177 |——| M] ()—C:\WINDOWS\hpbafd.ini
[2012-01-09 08:34:39 | 000,002,206 |——| M] ()—C:\WINDOWS\System32\wpa.dbl
[2012-01-07 15:27:48 | 000,000,664 |——| M] ()—C:\WINDOWS\System32\d3d9caps.dat
[2011-12-24 15:46:51 | 000,265,416 |——| M] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2011-12-24 15:12:12 | 000,000,412 | -H—| M] ()—C:\WINDOWS\tasks\MP Scheduled Signature Update.job
[2011-12-24 15:12:11 | 000,000,430 | -H—| M] ()—C:\WINDOWS\tasks\MP Scheduled Quick Scan.job
[2011-12-24 15:12:09 | 000,000,406 | -H—| M] ()—C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011-12-24 13:37:22 | 000,214,016 |——| M] ()—C:\WINDOWS\System32\DWRCS.EXE
[2011-12-12 11:19:34 | 000,120,832 |——| M] ()—C:\Documents and Settings\twillads.EUROPE\Application Data\fin.zup
[2011-12-12 10:06:17 | 000,000,284 |——| M] ()—C:\WINDOWS\tasks\AppleSoftwareUpdate.job
========== Files Created - No Company Name ==========
[2012-01-11 08:46:12 | 000,000,273 |——| C] ()—C:\Documents and Settings\twillads.EUROPE\Desktop\Genvej til HostsXpert.lnk
[2012-01-09 13:27:03 | 000,000,784 |——| C] ()—C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2009-11-01 21:01:21 | 000,000,552 |——| C] ()—C:\WINDOWS\System32\d3d8caps.dat
[2009-11-01 20:39:48 | 000,000,664 |——| C] ()—C:\WINDOWS\System32\d3d9caps.dat
[2009-07-08 14:08:14 | 000,005,120 |——| C] ()—C:\Documents and Settings\twillads.EUROPE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-01-21 11:28:47 | 000,000,000 |——| C] ()—C:\WINDOWS\nsreg.dat
[2008-11-12 10:44:26 | 000,183,310 |——| C] ()—C:\WINDOWS\hpoins21.dat
[2008-11-12 10:44:26 | 000,007,262 |——| C] ()—C:\WINDOWS\hpomdl21.dat
[2008-04-15 12:43:59 | 000,000,455 |——| C] ()—C:\WINDOWS\SMSCFG.ini
[2007-11-14 10:58:14 | 000,120,832 |——| C] ()—C:\Documents and Settings\twillads.EUROPE\Application Data\fin.zup
[2007-11-12 15:02:14 | 000,214,016 |——| C] ()—C:\WINDOWS\System32\DWRCS.EXE
[2007-11-12 14:40:50 | 000,000,177 |——| C] ()—C:\WINDOWS\hpbafd.ini
[2007-11-12 09:14:14 | 000,001,558 | R—- | C] ()—C:\WINDOWS\saplogon.ini
[2007-11-12 09:12:40 | 000,045,132 |——| C] ()—C:\WINDOWS\System32\libsapu16.dll
[2007-11-12 09:12:34 | 000,081,920 |——| C] ()—C:\WINDOWS\System32\nlsxdsgn.dll
[2007-11-12 09:12:32 | 003,203,072 |——| C] ()—C:\WINDOWS\System32\lcppn201.dll
[2007-11-12 09:07:31 | 000,175,616 |——| C] ()—C:\WINDOWS\System32\h5menu32.dll
[2007-11-12 09:07:31 | 000,095,744 |——| C] ()—C:\WINDOWS\System32\h5rtf32.dll
[2007-11-12 09:07:31 | 000,051,200 |——| C] ()—C:\WINDOWS\System32\h5tool32.dll
[2007-11-12 09:07:30 | 001,064,960 |——| C] ()—C:\WINDOWS\System32\h5krnl32.dll
[2007-11-12 09:07:29 | 000,188,928 |——| C] ()—C:\WINDOWS\System32\h5icon32.dll
[2007-11-12 09:07:12 | 000,015,872 |——| C] ()—C:\WINDOWS\System32\vtssm32.dll
[2007-11-12 08:56:36 | 000,000,104 |——| C] ()—C:\WINDOWS\notesnsd.ini
[2007-11-11 08:56:23 | 000,000,376 |——| C] ()—C:\WINDOWS\ODBC.INI
[2007-11-09 18:04:45 | 000,192,512 |——| C] ()—C:\WINDOWS\System32\stac97co.dll
[2007-11-09 16:22:14 | 000,086,016 |——| C] ()—C:\WINDOWS\System32\preflib.dll
[2007-11-09 16:22:13 | 000,757,760 |——| C] ()—C:\WINDOWS\System32\bcm1xsup.dll
[2007-11-09 16:22:13 | 000,020,480 |——| C] ()—C:\WINDOWS\System32\WLTRYSVC.EXE
[2007-11-09 15:27:32 | 000,004,161 |——| C] ()—C:\WINDOWS\ODBCINST.INI
[2007-11-09 15:26:23 | 000,265,416 |——| C] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2007-11-09 14:42:47 | 000,002,048 |—S- | C] ()—C:\WINDOWS\bootstat.dat
[2007-11-09 14:36:33 | 000,021,640 |——| C] ()—C:\WINDOWS\System32\emptyregdb.dat
[2005-10-14 15:09:48 | 000,051,304 |——| C] ()—C:\WINDOWS\System32\drivers\atnt40k.sys
[2005-03-22 02:48:05 | 013,107,200 |——| C] ()—C:\WINDOWS\System32\oembios.bin
[2005-03-22 02:48:05 | 000,004,627 |——| C] ()—C:\WINDOWS\System32\oembios.dat
[2004-08-04 13:00:00 | 000,673,088 |——| C] ()—C:\WINDOWS\System32\mlang.dat
[2004-08-04 13:00:00 | 000,486,792 |——| C] ()—C:\WINDOWS\System32\perfh009.dat
[2004-08-04 13:00:00 | 000,272,128 |——| C] ()—C:\WINDOWS\System32\perfi009.dat
[2004-08-04 13:00:00 | 000,218,003 |——| C] ()—C:\WINDOWS\System32\dssec.dat
[2004-08-04 13:00:00 | 000,086,472 |——| C] ()—C:\WINDOWS\System32\perfc009.dat
[2004-08-04 13:00:00 | 000,046,258 |——| C] ()—C:\WINDOWS\System32\mib.bin
[2004-08-04 13:00:00 | 000,028,626 |——| C] ()—C:\WINDOWS\System32\perfd009.dat
[2004-08-04 13:00:00 | 000,004,569 |——| C] ()—C:\WINDOWS\System32\secupd.dat
[2004-08-04 13:00:00 | 000,001,788 |——| C] ()—C:\WINDOWS\System32\Dcache.bin
[2004-08-04 13:00:00 | 000,000,741 |——| C] ()—C:\WINDOWS\System32\noise.dat
[2003-01-07 15:05:08 | 000,002,695 |——| C] ()—C:\WINDOWS\System32\OUTLPERF.INI
[2000-12-14 05:26:30 | 000,057,344 |——| C] ()—C:\WINDOWS\System32\adssecurity.dll
[1999-12-02 20:53:44 | 000,080,896 |——| C] ()—C:\WINDOWS\System32\DUMPEL.EXE
[1999-12-02 19:54:58 | 000,091,648 |——| C] ()—C:\WINDOWS\System32\XCACLS.EXE
[1999-10-25 04:39:16 | 000,015,872 |——| C] ()—C:\WINDOWS\System32\wwiolib.dll
[1997-04-30 21:43:42 | 000,016,896 |——| C] ()—C:\WINDOWS\System32\witzsrch.dll
========== LOP Check ==========
[2011-12-08 09:00:27 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012-01-11 08:40:22 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\AVG2012
[2011-05-16 12:20:25 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\Common Files
[2007-12-17 15:37:44 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\e-Safekey
[2012-01-11 08:39:25 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\MFAData
[2008-10-22 09:38:16 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2008-12-04 20:37:00 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Network Associates
[2007-11-09 18:08:11 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2007-12-26 22:32:15 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\SlySoft
[2009-10-30 21:05:00 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010-04-29 17:35:48 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011-11-01 17:29:30 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\AVG2012
[2008-10-27 08:31:16 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\ieSpell
[2008-11-19 13:13:55 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\Productivity Tools
[2009-11-02 14:35:35 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\Sports Interactive
[2008-11-19 13:59:21 | 000,000,000 |—-D | M]—C:\Documents and Settings\twillads.EUROPE\Application Data\Webex
[2011-12-24 15:12:11 | 000,000,430 | -H—| M] ()—C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
[2011-12-24 15:12:09 | 000,000,406 | -H—| M] ()—C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011-12-24 15:12:12 | 000,000,412 | -H—| M] ()—C:\WINDOWS\Tasks\MP Scheduled Signature Update.job
========== Purity Check ==========
< End of report >