I think I messed up. I ran this as Run scan not quick scan so I deleted the files and ran a second time and didn't get the Extrra file I tried a third time and still didn't get it. So all I have is the OTL which is below:
OTL logfile created on: 5/30/2011 7:45:32 AM - Run 3
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Linda\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 1.15 Gb Available Physical Memory | 61.47% Memory free
3.72 Gb Paging File | 3.11 Gb Available in Paging File | 83.46% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 166.02 Gb Total Space | 150.22 Gb Free Space | 90.48% Space Free | Partition Type: NTFS
Computer Name: 8FCC61F12 | User Name: Linda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/05/30 07:44:16 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Linda\My Documents\Downloads\OTL.scr
PRC - [2011/05/27 17:13:43 | 001,123,328 | -HS- | M] () -- C:\WINDOWS\system32\11.tmp
PRC - [2011/05/27 17:13:32 | 000,201,728 | ---- | M] () -- C:\Documents and Settings\Linda\Application Data\SysWin\lsass.exe
PRC - [2011/05/22 17:06:10 | 001,425,408 | ---- | M] () -- C:\WINDOWS\system32\msrclr4032.exe
PRC - [2011/05/22 17:06:10 | 001,425,408 | ---- | M] () -- C:\WINDOWS\system32\BROSNMP32.exe
PRC - [2011/05/03 13:14:48 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/01/08 18:08:20 | 000,274,608 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2010/11/11 22:45:25 | 001,766,736 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\casc.exe
PRC - [2010/11/11 22:45:24 | 001,115,472 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\ccevtmgr.exe
PRC - [2010/11/11 22:45:24 | 000,251,216 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
PRC - [2010/11/11 22:45:24 | 000,212,992 | ---- | M] (Computer Associates International, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
PRC - [2010/11/11 22:45:24 | 000,206,160 | ---- | M] (Computer Associates International, Inc.) -- C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
PRC - [2010/10/29 20:18:44 | 000,206,152 | ---- | M] (CA) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe
PRC - [2010/09/17 12:21:00 | 000,301,648 | ---- | M] (CA) -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
PRC - [2010/08/24 12:07:34 | 000,740,160 | ---- | M] (CA) -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
PRC - [2010/08/12 14:57:58 | 000,060,416 | ---- | M] () -- C:\Program Files\Avanquest\PowerDesk\PDHookServer.exe
PRC - [2010/02/28 19:37:38 | 001,377,008 | ---- | M] () -- C:\WINDOWS\system32\svcprs32.exe
PRC - [2010/02/28 19:33:56 | 002,347,760 | ---- | M] () -- C:\WINDOWS\system32\mdmcls32.exe
PRC - [2009/08/04 10:42:18 | 000,887,288 | ---- | M] (CA) -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
PRC - [2009/07/31 16:30:14 | 000,150,008 | ---- | M] (CA) -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
PRC - [2009/03/27 22:10:56 | 000,014,336 | ---- | M] (LSI Corporation) -- C:\Program Files\LSI SoftModem\agrsmsvc.exe
PRC - [2008/04/15 00:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/12/14 02:12:02 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
PRC - [1999/10/12 09:53:46 | 000,013,312 | ---- | M] () -- C:\WINDOWS\system32\LMSXXEF.exe
PRC - [1998/12/10 13:57:12 | 000,037,376 | ---- | M] () -- C:\Program Files\TextBridge Pro 8.0\Bin\InstantAccess.exe
========== Modules (SafeList) ========== MOD - [2011/05/30 07:44:16 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Linda\My Documents\Downloads\OTL.scr
MOD - [2011/01/08 18:08:35 | 000,040,448 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2010/09/28 14:10:00 | 000,079,184 | ---- | M] (CA) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-9.0.0.69\QOEHook.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010/08/12 14:57:56 | 000,011,264 | ---- | M] () -- C:\Program Files\Avanquest\PowerDesk\DClickDesktopHook.dll
MOD - [2010/08/12 14:57:32 | 000,103,936 | ---- | M] () -- C:\WINDOWS\system32\FileMonitor32.dll
MOD - [2010/04/25 16:54:00 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2010/04/25 16:54:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
MOD - [1998/12/10 13:40:10 | 000,119,808 | ---- | M] () -- C:\Program Files\TextBridge Pro 8.0\Bin\Tbmhook.dll
========== Win32 Services (SafeList) ========== SRV - [2011/05/22 17:06:10 | 001,425,408 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\BROSNMP32.exe -- (UmxFwHlp32)
SRV - [2010/11/11 22:45:24 | 000,251,216 | ---- | M] (CA, Inc.) [On_Demand | Running] -- C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe -- (CaCCProvSP)
SRV - [2010/11/11 22:45:24 | 000,212,992 | ---- | M] (Computer Associates International, Inc.) [Auto | Running] -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe -- (CAISafe)
SRV - [2010/11/11 22:45:24 | 000,206,160 | ---- | M] (Computer Associates International, Inc.) [Auto | Running] -- C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe -- (ccSchedulerSVC)
SRV - [2010/10/29 20:18:44 | 000,206,152 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe -- (CAAMSvc)
SRV - [2010/09/17 12:21:00 | 000,301,648 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe -- (UmxPol)
SRV - [2010/08/24 12:07:34 | 000,740,160 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe -- (UmxCfg)
SRV - [2010/02/28 19:37:38 | 001,377,008 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\svcprs32.exe -- (WinSvchostManager)
SRV - [2010/02/28 19:33:56 | 002,347,760 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\mdmcls32.exe -- (WinExtManager)
SRV - [2009/08/04 10:42:18 | 000,887,288 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe -- (UmxAgent)
SRV - [2009/07/31 16:30:14 | 000,150,008 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe -- (UmxFwHlp)
SRV - [2009/03/27 22:10:56 | 000,014,336 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ========== DRV - [2010/09/24 11:16:18 | 000,146,000 | ---- | M] (CA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\KmxCF.sys -- (KmxCF)
DRV - [2010/09/24 11:16:18 | 000,115,792 | ---- | M] (CA) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\KmxFw.sys -- (KmxFw)
DRV - [2010/09/24 11:16:18 | 000,061,008 | ---- | M] (CA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\KmxSbx.sys -- (KmxSbx)
DRV - [2010/09/24 11:16:18 | 000,061,008 | ---- | M] (CA) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\KmxFile.sys -- (KmxFile)
DRV - [2010/09/17 12:21:00 | 000,135,248 | ---- | M] (CA) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\KmxAMRT.sys -- (KmxAMRT)
DRV - [2010/09/17 06:00:28 | 000,599,936 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8192su.sys -- (RTL8192su)
DRV - [2010/06/09 06:54:38 | 000,244,304 | ---- | M] (CA) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KmxCfg.sys -- (KmxCfg)
DRV - [2010/05/03 02:12:02 | 000,108,112 | ---- | M] (CA) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\kmxstart.sys -- (KmxStart)
DRV - [2010/03/22 13:58:42 | 000,079,864 | ---- | M] (CA) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\KmxAgent.sys -- (KmxAgent)
DRV - [2010/02/01 11:02:44 | 000,084,984 | ---- | M] (SUNIX Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snxppalx.sys -- (SNXPPALX)
DRV - [2010/01/14 03:44:00 | 000,041,080 | ---- | M] (SUNIX Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snxpcard.sys -- (SNXPCARD)
DRV - [2009/08/13 15:07:12 | 001,163,328 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009/03/27 15:27:04 | 000,598,656 | ---- | M] (Computer Associates International, Inc.) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\KmxAMVet.sys -- (KmxAMVet)
DRV - [2009/02/11 12:40:40 | 005,028,352 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/08/01 18:36:26 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008/08/01 18:36:20 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008/04/13 23:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2007/04/16 21:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2006/01/24 17:38:40 | 000,078,720 | ---- | M] (Netgear Inc. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FA311XP.SYS -- (RTL8023xp)
DRV - [1999/07/31 09:11:54 | 000,058,304 | ---- | M] (Sharp Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\VSP1284D.SYS -- (VSP1284D)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 9B 21 65 03 D6 29 17 48 96 A3 B1 05 2E F5 6E 69 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
[email protected]:2.0.0.108
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {6c821380-3bfa-4a8a-9dc2-a522bc32ff1f}:1.0
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\extensions\\
[email protected]: C:\Program Files\CA\CA Internet Security Suite\RRR Anti-Phishing\Toolbar\Firefox [2010/10/29 20:20:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/08 18:08:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/29 15:15:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/03 13:14:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/05/01 16:44:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/04/03 15:50:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Linda\Application Data\Mozilla\Extensions
[2010/04/03 15:50:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Linda\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/05/29 19:41:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\q95jpmru.default\extensions
[2011/03/06 18:48:31 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\q95jpmru.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/30 07:18:28 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\q95jpmru.default\extensions\{6c821380-3bfa-4a8a-9dc2-a522bc32ff1f}
[2011/05/29 19:41:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/18 12:18:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/08 13:18:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/01/08 18:08:35 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/10/29 20:20:38 | 000,000,000 | ---D | M] (CA Anti-Phishing Toolbar) -- C:\PROGRAM FILES\CA\CA INTERNET SECURITY SUITE\RRR ANTI-PHISHING\TOOLBAR\FIREFOX
[2010/03/29 22:47:49 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2008/04/15 00:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {0365219B-29D6-4817-96A3-B1052EF56E69} - C:\WINDOWS\system32\autodisc32.dll (Borland Software Corporation)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\RRR Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\RRR Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\RRR Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BVRPLiveUpdate] File not found
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [HP AutoIndexer] C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP SchedIndexer] C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe (Hewlett-Packard)
O4 - HKLM..\Run: [InstantAccess] C:\Program Files\TextBridge Pro 8.0\Bin\InstantAccess.exe ()
O4 - HKLM..\Run: [KBDALwow.exe] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [RegisterDropHandler] C:\Program Files\TextBridge Pro 8.0\Bin\RegisterDropHandler.exe ()
O4 - HKLM..\Run: [shginawow.exe] File not found
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WCEFLMS] C:\WINDOWS\System32\WCEFLMS.EXE ()
O4 - HKLM..\Run: [XE Fax LM Status] C:\WINDOWS\System32\LMSXXEF.exe ()
O4 - HKCU..\Run: [PDHookServer] C:\Program Files\Avanquest\PowerDesk\PDHookServer.exe ()
O4 - HKLM..\RunOnceEx: [washindex] C:\Program Files\Washer\washidx.exe ()
O4 - HKLM..\RunServices: [RegisterDropHandler] C:\Program Files\TextBridge Pro 8.0\Bin\RegisterDropHandler.exe ()
O4 - HKLM..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP LaserJet Director.lnk = C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\XE_fx Status Monitor.lnk = C:\Program Files\XWC_90fx\X9ENGSS.EXE (SHARP CORPORATION)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: RTHDBPL = C:\Documents and Settings\Linda\Application Data\SysWin\lsass.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1269900647072 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - AppInit_DLLs: (C:\WINDOWS\system32\FileMonitor32.dll) - C:\WINDOWS\system32\FileMonitor32.dll ()
O20 - AppInit_DLLs: (C:\WINDOWS\system32\mscories32.dll) - C:\WINDOWS\system32\mscories32.dll (Borland Software Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/29 17:29:46 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{719be275-4966-11df-95ef-0026181a0539}\Shell\AutoRun\command - "" = K:\setupSNK.exe
O33 - MountPoints2\{8e574204-08ad-11e0-9653-0026181a0539}\Shell\AutoRun\command - "" = I:\ShellRun.exe StartHere.html
O33 - MountPoints2\{f6ec17ae-3ccf-11df-95cc-0026181a0539}\Shell - "" = Autorun
O33 - MountPoints2\{f6ec17ae-3ccf-11df-95cc-0026181a0539}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6ec17ae-3ccf-11df-95cc-0026181a0539}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-7-5-16-100031972-100019914-100003244-2638.com d:\
O33 - MountPoints2\{f6ec17ae-3ccf-11df-95cc-0026181a0539}\Shell\Open\command - "" = RECYCLER\S-7-5-16-100031972-100019914-100003244-2638.com d:\
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17465059307421696)
========== Files/Folders - Created Within 30 Days ========== [2011/05/29 19:01:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Linda\Desktop\GooredFix Backups
[2011/05/29 18:01:32 | 000,424,960 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\autodisc32.dll
[2011/05/27 17:20:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\WinRAR
[2011/05/27 17:20:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1739438284
[2011/05/27 17:14:26 | 000,000,000 | -HSD | C] -- C:\WINDOWS\System32\SysWoW32
[2011/05/27 17:14:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1245202996
[2011/05/27 17:14:01 | 000,000,000 | -HSD | C] -- C:\WINDOWS\System32\B3CF20ECE12D5ED97AC84A0E0BB05B01
[2011/05/27 17:13:38 | 000,261,632 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\mscories32.dll
[2011/05/27 17:13:33 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Linda\Application Data\SysWin
[2011/05/01 17:05:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Free Convert to DIVX AVI WMV MP4 MPEG Converter
[2011/05/01 17:05:29 | 000,000,000 | ---D | C] -- C:\Program Files\Free Convert to DIVX AVI WMV MP4 MPEG Converter
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Documents and Settings\Linda\*.tmp files -> C:\Documents and Settings\Linda\*.tmp -> ]
[1 C:\Documents and Settings\Linda\My Documents\*.tmp files -> C:\Documents and Settings\Linda\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\Linda\Desktop\*.tmp files -> C:\Documents and Settings\Linda\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/05/30 07:42:24 | 000,000,148 | -HS- | M] () -- C:\WINDOWS\System32\677018883
[2011/05/30 07:42:23 | 000,001,265 | ---- | M] () -- C:\WINDOWS\System32\141579823
[2011/05/30 07:13:40 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2011/05/30 07:13:20 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-299502267-329068152-682003330-1003.job
[2011/05/30 07:13:11 | 000,000,258 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011/05/30 07:12:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/29 22:34:38 | 001,319,877 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2011/05/29 22:34:38 | 000,000,331 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2011/05/29 22:34:38 | 000,000,331 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2011/05/29 22:34:38 | 000,000,085 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2011/05/29 22:34:38 | 000,000,085 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2011/05/29 22:34:38 | 000,000,085 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2011/05/29 22:34:38 | 000,000,085 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2011/05/29 22:34:38 | 000,000,085 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2011/05/29 22:34:38 | 000,000,085 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2011/05/29 22:34:38 | 000,000,049 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2011/05/29 22:34:38 | 000,000,049 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2011/05/29 22:34:38 | 000,000,049 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2011/05/29 22:34:38 | 000,000,049 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2011/05/29 22:34:38 | 000,000,049 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2011/05/29 22:34:38 | 000,000,049 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2011/05/29 22:34:37 | 000,587,452 | ---- | M] () -- C:\WINDOWS\System32\drivers\KmxAgent.asc
[2011/05/29 22:34:37 | 000,010,185 | ---- | M] () -- C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2011/05/29 22:34:14 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-299502267-329068152-682003330-1003.job
[2011/05/29 22:26:09 | 000,000,019 | ---- | M] () -- C:\WINDOWS\System32\288a2a54
[2011/05/29 19:11:29 | 000,000,992 | ---- | M] () -- C:\Documents and Settings\Linda\Desktop\Shortcut to redirectkiller.exe.lnk
[2011/05/29 18:01:34 | 000,201,728 | ---- | M] () -- C:\WINDOWS\System32\mscorier32.exe
[2011/05/29 18:01:32 | 000,424,960 | ---- | M] (Borland Software Corporation) -- C:\WINDOWS\System32\autodisc32.dll
[2011/05/29 16:44:10 | 000,518,144 | -H-- | M] () -- C:\WINDOWS\KBDALwowbad.exe
[2011/05/29 15:41:47 | 000,008,336 | ---- | M] () -- C:\WINDOWS\System32\GnuHashes.ini
[2011/05/29 15:09:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/27 17:14:11 | 000,203,776 | -HS- | M] () -- C:\WINDOWS\System32\unrar.exe
[2011/05/27 17:13:46 | 000,514,048 | -H-- | M] () -- C:\WINDOWS\shginawowbad.exe
[2011/05/27 17:13:38 | 000,261,632 | ---- | M] (Borland Software Corporation) -- C:\WINDOWS\System32\mscories32.dll
[2011/05/27 17:13:38 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\44317220
[2011/05/27 17:13:32 | 000,201,728 | ---- | M] () -- C:\WINDOWS\System32\mscories32.exe
[2011/05/26 19:12:09 | 000,000,181 | ---- | M] () -- C:\WINDOWS\hpbafd.ini
[2011/05/24 18:30:45 | 003,443,534 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\18605_Pompano_CPS.pdf
[2011/05/24 18:25:27 | 003,084,118 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\18605_Pompano.pdf
[2011/05/22 17:06:10 | 001,425,408 | ---- | M] () -- C:\WINDOWS\System32\msrclr4032.exe
[2011/05/22 17:06:10 | 001,425,408 | ---- | M] () -- C:\WINDOWS\System32\BROSNMP32.exe
[2011/05/22 15:08:00 | 000,000,426 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
[2011/05/14 21:52:36 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\Linda\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/08 17:33:22 | 000,117,755 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\leaves.jpg
[2011/05/08 17:28:50 | 000,029,980 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\flower.pdf
[2011/05/08 17:15:23 | 000,024,442 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\carolo swirls.pdf
[2011/05/08 16:52:22 | 000,035,315 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\Carol Business Card Back.pdf
[2011/05/08 16:45:13 | 000,074,208 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\carolo swirls.cdr
[2011/05/08 16:06:37 | 000,056,059 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\Carol Business Card Front1.pdf
[2011/05/08 15:14:11 | 000,117,755 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls6.jpg
[2011/05/08 14:53:52 | 000,046,417 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls5.jpg
[2011/05/08 14:52:19 | 000,041,584 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls3.jpg
[2011/05/08 14:50:34 | 000,028,446 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls1.jpg
[2011/05/08 14:49:01 | 000,036,418 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls.jpg
[2011/05/08 11:37:08 | 000,059,314 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\Backup_of_carolo swirls.cdr
[2011/05/08 11:30:20 | 000,068,881 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\swirl_5.jpg
[2011/05/08 11:29:13 | 000,047,389 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\swirl_4.jpg
[2011/05/08 11:23:41 | 000,142,628 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\swirl_3.jpg
[2011/05/08 11:17:26 | 000,088,047 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\swirl 2.jpg
[2011/05/08 11:14:12 | 000,196,624 | ---- | M] () -- C:\Documents and Settings\Linda\My Documents\swirl.jpg
[2011/05/01 17:05:34 | 000,000,034 | -H-- | M] () -- C:\WINDOWS\System32\Converter_sysquict.dat
[2011/05/01 17:05:30 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Free Convert to DIVX AVI WMV MP4 MPEG Converter.lnk
[2011/05/01 16:54:29 | 003,469,469 | ---- | M] () -- C:\Documents and Settings\Linda\Desktop\J&K 2.JPG
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Documents and Settings\Linda\*.tmp files -> C:\Documents and Settings\Linda\*.tmp -> ]
[1 C:\Documents and Settings\Linda\My Documents\*.tmp files -> C:\Documents and Settings\Linda\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\Linda\Desktop\*.tmp files -> C:\Documents and Settings\Linda\Desktop\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/05/29 19:11:40 | 000,000,992 | ---- | C] () -- C:\Documents and Settings\Linda\Desktop\Shortcut to redirectkiller.exe.lnk
[2011/05/29 18:01:34 | 000,201,728 | ---- | C] () -- C:\WINDOWS\System32\mscorier32.exe
[2011/05/29 16:44:10 | 000,518,144 | -H-- | C] () -- C:\WINDOWS\KBDALwowbad.exe
[2011/05/27 17:58:57 | 000,000,019 | ---- | C] () -- C:\WINDOWS\System32\288a2a54
[2011/05/27 17:27:28 | 000,008,336 | ---- | C] () -- C:\WINDOWS\System32\GnuHashes.ini
[2011/05/27 17:14:26 | 000,001,265 | ---- | C] () -- C:\WINDOWS\System32\141579823
[2011/05/27 17:14:11 | 000,203,776 | -HS- | C] () -- C:\WINDOWS\System32\unrar.exe
[2011/05/27 17:14:11 | 000,000,148 | -HS- | C] () -- C:\WINDOWS\System32\677018883
[2011/05/27 17:14:01 | 000,514,048 | -H-- | C] () -- C:\WINDOWS\shginawowbad.exe
[2011/05/27 17:13:38 | 001,425,408 | ---- | C] () -- C:\WINDOWS\System32\msrclr4032.exe
[2011/05/27 17:13:33 | 001,425,408 | ---- | C] () -- C:\WINDOWS\System32\BROSNMP32.exe
[2011/05/27 17:13:32 | 000,000,098 | ---- | C] () -- C:\WINDOWS\System32\44317220
[2011/05/27 17:13:31 | 000,201,728 | ---- | C] () -- C:\WINDOWS\System32\mscories32.exe
[2011/05/24 18:30:45 | 003,443,534 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\18605_Pompano_CPS.pdf
[2011/05/24 18:25:25 | 003,084,118 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\18605_Pompano.pdf
[2011/05/08 17:33:18 | 000,117,755 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\leaves.jpg
[2011/05/08 17:28:50 | 000,029,980 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\flower.pdf
[2011/05/08 17:15:23 | 000,024,442 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\carolo swirls.pdf
[2011/05/08 16:52:22 | 000,035,315 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\Carol Business Card Back.pdf
[2011/05/08 16:45:13 | 000,059,314 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\Backup_of_carolo swirls.cdr
[2011/05/08 16:06:37 | 000,056,059 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\Carol Business Card Front1.pdf
[2011/05/08 15:14:09 | 000,117,755 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls6.jpg
[2011/05/08 14:53:48 | 000,046,417 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls5.jpg
[2011/05/08 14:52:16 | 000,041,584 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls3.jpg
[2011/05/08 14:50:32 | 000,028,446 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls1.jpg
[2011/05/08 14:48:57 | 000,036,418 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\carolo_swirls.jpg
[2011/05/08 11:37:08 | 000,074,208 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\carolo swirls.cdr
[2011/05/08 11:30:17 | 000,068,881 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\swirl_5.jpg
[2011/05/08 11:29:09 | 000,047,389 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\swirl_4.jpg
[2011/05/08 11:23:37 | 000,142,628 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\swirl_3.jpg
[2011/05/08 11:17:23 | 000,088,047 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\swirl 2.jpg
[2011/05/08 11:13:57 | 000,196,624 | ---- | C] () -- C:\Documents and Settings\Linda\My Documents\swirl.jpg
[2011/05/01 17:05:34 | 000,000,034 | -H-- | C] () -- C:\WINDOWS\System32\Converter_sysquict.dat
[2011/05/01 17:05:30 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Free Convert to DIVX AVI WMV MP4 MPEG Converter.lnk
[2011/05/01 16:54:28 | 003,469,469 | ---- | C] () -- C:\Documents and Settings\Linda\Desktop\J&K 2.JPG
[2010/09/18 15:42:31 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010/09/18 15:42:30 | 000,000,034 | ---- | C] () -- C:\WINDOWS\System32\BD2170W.DAT
[2010/09/18 12:37:29 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/18 12:37:27 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/18 12:37:27 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/09/17 18:58:11 | 000,000,007 | ---- | C] () -- C:\WINDOWS\System32\mkghj.dll
[2010/09/17 18:56:23 | 001,054,032 | ---- | C] () -- C:\WINDOWS\System32\cfgmig32.dll
[2010/09/17 18:56:05 | 005,845,744 | ---- | C] () -- C:\WINDOWS\System32\win32cpr.dll
[2010/09/17 18:56:05 | 002,385,136 | ---- | C] () -- C:\WINDOWS\System32\winsflt_x64.dll
[2010/09/17 18:56:05 | 001,872,624 | ---- | C] () -- C:\WINDOWS\System32\winsflt.dll
[2010/09/17 18:56:05 | 001,377,008 | ---- | C] () -- C:\WINDOWS\System32\svcprs32.exe
[2010/09/17 18:56:05 | 000,286,208 | ---- | C] () -- C:\WINDOWS\System32\winsfinst.exe
[2010/09/17 18:56:04 | 002,347,760 | ---- | C] () -- C:\WINDOWS\System32\mdmcls32.exe
[2010/08/12 14:57:32 | 000,103,936 | ---- | C] () -- C:\WINDOWS\System32\FileMonitor32.dll
[2010/05/24 16:06:04 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\hppapr02.DLL
[2010/05/24 16:06:04 | 000,000,526 | ---- | C] () -- C:\WINDOWS\System32\hppapr02.DAT
[2010/04/18 13:02:05 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\Linda\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/05 20:16:39 | 000,000,272 | ---- | C] () -- C:\WINDOWS\ReadIris.ini
[2010/04/05 13:14:16 | 000,000,331 | ---- | C] () -- C:\WINDOWS\FMTMSAM.INI
[2010/04/05 13:13:33 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\irisco32.dll
[2010/04/05 13:13:28 | 000,000,033 | ---- | C] () -- C:\WINDOWS\hppLangChoice.ini
[2010/04/05 13:13:27 | 000,343,040 | R--- | C] () -- C:\WINDOWS\System32\lffpx7.dll
[2010/04/05 13:13:27 | 000,116,736 | R--- | C] () -- C:\WINDOWS\System32\lfkodak.dll
[2010/04/05 12:43:04 | 000,000,181 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2010/04/03 22:57:23 | 000,009,536 | ---- | C] () -- C:\WINDOWS\System32\XEFX_ENU.DLL
[2010/04/03 22:47:59 | 000,000,095 | ---- | C] () -- C:\WINDOWS\tb96.ini
[2010/04/03 22:43:51 | 000,000,096 | ---- | C] () -- C:\WINDOWS\Tb98.ini
[2010/04/03 22:43:37 | 000,046,512 | ---- | C] () -- C:\WINDOWS\System32\EPSN.DLL
[2010/04/03 22:43:37 | 000,012,126 | ---- | C] () -- C:\WINDOWS\System32\PIXPCZ.DLL
[2010/04/03 22:43:37 | 000,011,934 | ---- | C] () -- C:\WINDOWS\System32\PIXPNR.DLL
[2010/04/03 22:43:37 | 000,009,136 | ---- | C] () -- C:\WINDOWS\System32\INETWH16.DLL
[2010/04/03 22:43:37 | 000,004,528 | ---- | C] () -- C:\WINDOWS\System32\SETBROWS.EXE
[2010/04/03 21:37:08 | 000,000,029 | ---- | C] () -- C:\WINDOWS\spiemon.ini
[2010/04/03 13:22:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\X9QUEMGR.INI
[2010/04/03 13:11:33 | 000,000,689 | ---- | C] () -- C:\WINDOWS\SHSFTSET.INI
[2010/04/03 13:11:33 | 000,000,428 | ---- | C] () -- C:\WINDOWS\spipcl4a.ini
[2010/04/03 13:11:33 | 000,000,147 | ---- | C] () -- C:\WINDOWS\XEROXTW.INI
[2010/04/03 13:11:25 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\LMSXXEF.exe
[2010/04/03 13:11:25 | 000,001,106 | ---- | C] () -- C:\WINDOWS\sd4.ini
[2010/04/03 12:41:47 | 000,026,516 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/03/30 17:10:52 | 000,039,095 | ---- | C] () -- C:\WINDOWS\iccsigs.dat
[2010/03/30 17:10:50 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
[2010/03/29 21:22:02 | 000,340,992 | ---- | C] () -- C:\WINDOWS\unwash.exe
[2010/03/29 21:16:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/03/29 19:01:30 | 000,004,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2010/03/29 17:31:42 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/03/29 17:29:52 | 001,481,728 | ---- | C] () -- C:\WINDOWS\System32\LegitCheckControl.dll
[2010/03/29 17:29:52 | 000,323,072 | ---- | C] () -- C:\WINDOWS\System32\WgaTray.exe
[2010/03/29 17:29:52 | 000,190,976 | ---- | C] () -- C:\WINDOWS\System32\WgaLogon.dll
[2010/03/29 17:26:43 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010/03/29 09:18:31 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/03/29 09:17:11 | 000,393,568 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/01/12 12:03:34 | 002,195,030 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2008/04/15 00:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/04/15 00:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/04/15 00:00:00 | 000,493,054 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/04/15 00:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/04/15 00:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/04/15 00:00:00 | 000,083,598 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/04/15 00:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/04/15 00:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/04/15 00:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/04/15 00:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/04/15 00:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/15 00:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2002/11/20 03:51:59 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2002/03/04 10:16:34 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[2001/10/15 09:52:20 | 000,000,089 | ---- | C] () -- C:\WINDOWS\System32\WCEFSTMN.INI
[2001/09/27 13:45:52 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\WCEFLMS.EXE
========== LOP Check ========== [2010/09/19 15:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avanquest
[2010/09/19 15:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/03/29 18:00:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA
[2010/04/03 12:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/03/29 21:40:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Linda\Application Data\Avanquest
[2010/04/03 14:50:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Linda\Application Data\GetRightToGo
[2010/03/29 22:50:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Linda\Application Data\OpenOffice.org
[2010/04/03 12:44:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Linda\Application Data\ScanSoft
[2011/05/27 17:13:33 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Linda\Application Data\SysWin
[2010/04/03 15:50:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Linda\Application Data\Thunderbird
[2011/01/23 18:52:00 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Linda at 4 52 PM.job
[2011/05/30 07:13:11 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2010/03/21 00:31:26 | 002,228,534 | ---- | M] ( ) -- C:\audacity-win-1.2.6.exe
< MD5 for: EXPLORER.EXE >[2008/04/15 00:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/15 00:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: SVCHOST.EXE >[2008/04/15 00:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/15 00:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: USERINIT.EXE >[2008/04/15 00:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/15 00:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2008/04/15 00:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/15 00:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/05/03 13:14:49 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/05/03 13:14:49 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/05/03 13:14:49 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/05/03 13:14:48 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/05/03 13:14:48 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/05/03 13:14:48 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/02/17 07:43:27 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/02/17 07:43:27 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/02/17 07:43:27 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/02/14 08:17:08 | 000,634,648 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/05/03 13:14:49 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/05/03 13:14:49 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/05/03 13:14:49 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/05/03 13:14:48 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/05/03 13:14:48 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/05/03 13:14:48 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/02/17 07:43:27 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/02/17 07:43:27 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/02/17 07:43:27 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/02/14 08:17:08 | 000,634,648 | ---- | M] (Microsoft Corporation)
< End of report >