I downloaded OTL on a thumb drive and had her run it. Here is the OTL log:
OTL logfile created on: 4/23/2012 3:54:36 AM - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = F:\Documents and Settings\Bubbles2000\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.07 Gb Available Physical Memory | 53.86% Memory free
3.84 Gb Paging File | 2.67 Gb Available in Paging File | 69.47% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
Drive C: | 6.36 Gb Total Space | 1.37 Gb Free Space | 21.52% Space Free | Partition Type: NTFS
Drive D: | 1397.26 Gb Total Space | 1312.35 Gb Free Space | 93.92% Space Free | Partition Type: NTFS
Drive E: | 149.05 Gb Total Space | 61.93 Gb Free Space | 41.55% Space Free | Partition Type: NTFS
Drive F: | 68.11 Gb Total Space | 5.88 Gb Free Space | 8.64% Space Free | Partition Type: NTFS
Drive H: | 7.98 Gb Total Space | 7.98 Gb Free Space | 99.97% Space Free | Partition Type: FAT32
Computer Name: GARGOYLE2 | User Name: Bubbles2000 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/04/23 03:31:42 | 000,594,944 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Bubbles2000\Desktop\OTL.exe
PRC - [2012/03/21 21:14:58 | 000,918,880 | ---- | M] () -- F:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
PRC - [2012/03/21 21:14:53 | 000,982,880 | ---- | M] () -- F:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012/03/12 05:12:01 | 001,694,608 | ---- | M] (Bandoo Media, inc) -- F:\Program Files\Searchqu Toolbar\Datamngr\datamngrUI.exe
PRC - [2012/03/07 11:30:14 | 006,426,672 | ---- | M] (AVAST Software) -- F:\Program Files\AVAST Software\Avast\Setup\avast.setup
PRC - [2012/03/06 17:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- F:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/03/06 17:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- F:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/03/05 15:10:32 | 003,530,752 | ---- | M] () -- C:\ManageEngine\EventLog\mysql\bin\mysqld-nt.exe
PRC - [2012/03/05 15:10:32 | 000,458,008 | ---- | M] (Tanuki Software, Ltd.) -- C:\ManageEngine\EventLog\bin\wrapper.exe
PRC - [2012/03/05 15:10:32 | 000,049,248 | ---- | M] (Sun Microsystems, Inc.) -- C:\ManageEngine\EventLog\jre\bin\java.exe
PRC - [2012/03/03 21:42:56 | 016,575,824 | ---- | M] (Comfort Software Group) -- F:\Program Files\HotAlarmClock\HotAlarmClock.exe
PRC - [2012/02/14 16:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- F:\Documents and Settings\Bubbles2000\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2011/12/01 13:24:20 | 002,624,512 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe
PRC - [2011/11/26 00:54:53 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- F:\Program Files\real\realplayer\Update\realsched.exe
PRC - [2011/11/24 00:05:44 | 006,497,592 | ---- | M] (Yahoo! Inc.) -- F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2011/09/26 19:15:36 | 000,374,152 | ---- | M] (LogMeIn, Inc.) -- F:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2011/09/16 16:10:50 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- F:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2011/08/23 22:20:18 | 000,887,976 | ---- | M] (Ask) -- F:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2011/07/29 13:45:56 | 000,217,256 | ---- | M] (Visicom Media Inc. (Powered by Panda Security)) -- F:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe
PRC - [2011/04/23 20:02:19 | 000,536,576 | ---- | M] () -- F:\Program Files\Nwmao\Rlkkhgs.exe
PRC - [2011/04/03 02:30:39 | 000,399,736 | ---- | M] (BitTorrent, Inc.) -- F:\Program Files\uTorrent\uTorrent.exe
PRC - [2010/09/14 05:46:26 | 000,219,496 | ---- | M] (Microsoft Corporation) -- F:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/09/14 05:46:16 | 000,508,264 | ---- | M] (Microsoft Corporation) -- F:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/07/04 12:51:26 | 000,017,408 | ---- | M] () -- F:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2009/11/10 15:41:14 | 000,036,864 | ---- | M] (MAXA Research Int'l Inc.) -- F:\Program Files\MAXA Security Tools\Lock\tray.exe
PRC - [2009/09/24 18:41:40 | 000,933,888 | ---- | M] (Silicon Motion) -- F:\Program Files\USB2.0 UVC WebCam\USB2.0 UVC WebCam\STIMON.exe
PRC - [2008/07/21 12:59:10 | 001,069,056 | ---- | M] (Audiovox Electronics Corp.) -- F:\Documents and Settings\Bubbles2000\My Documents\RCA Detective\RCADetective.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- F:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2012/04/22 09:52:18 | 001,770,496 | ---- | M] () -- F:\Program Files\AVAST Software\Avast\defs\12042201\algo.dll
MOD - [2012/04/20 16:31:48 | 000,572,128 | ---- | M] () -- F:\Program Files\AVAST Software\Avast\defs\12042201\Sf.bin
MOD - [2012/03/21 21:14:58 | 000,918,880 | ---- | M] () -- F:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
MOD - [2012/03/21 21:14:53 | 000,982,880 | ---- | M] () -- F:\Program Files\AVG Secure Search\vprot.exe
MOD - [2012/03/07 11:30:07 | 000,213,552 | ---- | M] () -- F:\Program Files\AVAST Software\Avast\Setup\setiface.dll
MOD - [2012/03/05 15:10:32 | 003,530,752 | ---- | M] () -- C:\ManageEngine\EventLog\mysql\bin\mysqld-nt.exe
MOD - [2012/03/05 15:10:32 | 000,045,138 | ---- | M] () -- C:\ManageEngine\EventLog\lib\native\AdventnetOper.dll
MOD - [2012/01/09 06:04:52 | 000,998,400 | ---- | M] () -- F:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
MOD - [2012/01/09 06:02:30 | 000,971,264 | ---- | M] () -- F:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
MOD - [2012/01/09 04:08:34 | 005,450,752 | ---- | M] () -- F:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
MOD - [2012/01/09 04:08:27 | 012,430,848 | ---- | M] () -- F:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
MOD - [2012/01/09 04:08:13 | 001,587,200 | ---- | M] () -- F:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
MOD - [2012/01/09 04:06:48 | 007,950,848 | ---- | M] () -- F:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
MOD - [2012/01/09 04:06:37 | 011,490,816 | ---- | M] () -- F:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/12/01 13:24:20 | 002,624,512 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe
MOD - [2011/11/24 00:05:40 | 000,921,600 | ---- | M] () -- F:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2011/11/24 00:05:26 | 000,078,336 | ---- | M] () -- F:\Program Files\Yahoo!\Messenger\pcre.dll
MOD - [2011/11/03 08:28:36 | 001,292,288 | ---- | M] () -- F:\WINDOWS\system32\quartz.dll
MOD - [2011/04/23 20:02:19 | 000,536,576 | ---- | M] () -- F:\Program Files\Nwmao\Rlkkhgs.exe
MOD - [2011/04/23 20:02:19 | 000,020,480 | ---- | M] () -- F:\Program Files\Nwmao\a.dll
MOD - [2010/07/04 14:32:36 | 000,004,608 | ---- | M] () -- F:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2010/07/04 12:51:26 | 000,017,408 | ---- | M] () -- F:\Program Files\Unlocker\UnlockerAssistant.exe
MOD - [2008/04/13 17:11:59 | 000,014,336 | ---- | M] () -- F:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 17:11:51 | 000,059,904 | ---- | M] () -- F:\WINDOWS\system32\devenum.dll
MOD - [2005/04/15 14:18:30 | 000,483,328 | ---- | M] () -- F:\WINDOWS\system32\lxcglmpm.dll
MOD - [2005/03/13 11:32:14 | 000,061,440 | ---- | M] () -- F:\Program Files\Lexmark 2300 Series\lxcgcnv4.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (Ql12nses)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/03/21 21:14:58 | 000,918,880 | ---- | M] () [Auto | Running] -- F:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe -- (vToolbarUpdater10.2.0)
SRV - [2012/03/06 17:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- F:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/03/05 15:10:32 | 000,458,008 | ---- | M] (Tanuki Software, Ltd.) [Auto | Running] -- C:\ManageEngine\EventLog\bin\wrapper.exe -- (eventloganalyzer)
SRV - [2010/09/14 05:46:26 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010/09/14 05:46:16 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- F:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010/08/13 09:13:32 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- F:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2008/04/13 17:12:02 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\WINDOWS\system32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2005/04/15 14:15:30 | 000,491,520 | ---- | M] () [On_Demand | Stopped] -- F:\WINDOWS\system32\lxcgcoms.exe -- (lxcg_device)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\DOCUME~1\BUBBLE~1\LOCALS~1\Temp\vdsdk.sys -- (VDSDK)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS -- (MRESP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS -- (MREMP50)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys -- (FreshIO)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/03/06 17:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- F:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/03/06 17:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- F:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/03/06 17:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- F:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012/03/06 17:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- F:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/03/06 17:01:39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- F:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/03/06 17:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- F:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/03/06 16:58:29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- F:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/03/05 15:10:32 | 000,032,512 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2011/03/18 09:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- F:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2010/12/02 18:17:50 | 000,013,696 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\avwebcam.sys -- (AVWEBCAM)
DRV - [2010/09/14 05:46:26 | 000,018,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\Sftvolxp.sys -- (Sftvol)
DRV - [2010/09/14 05:46:22 | 000,020,584 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- F:\WINDOWS\system32\drivers\Sftredirxp.sys -- (Sftredir)
DRV - [2010/09/14 05:46:20 | 000,209,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\Sftplayxp.sys -- (Sftplay)
DRV - [2010/09/14 05:46:14 | 000,581,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\Sftfsxp.sys -- (Sftfs)
DRV - [2010/07/15 08:44:20 | 000,013,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\epmntdrv.sys -- (epmntdrv)
DRV - [2010/07/15 08:44:20 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2010/07/04 12:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- F:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2010/04/28 07:44:02 | 000,054,760 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- F:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2010/02/11 05:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2007/05/02 16:21:22 | 004,403,712 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [1996/04/03 12:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- F:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?ilc=8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKLM\..\SearchScopes\{CD10120B-C165-4f8d-8C74-639629E238FF}: "URL" = http://mystart.magen...&loc=search_box
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.c...sa&d=2012-03-21 21:15:00&v=10.2.0.3&sap=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://igoogle.com/
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - F:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0FFD0622-4D96-4E1A-AF5A-8F060666C048}: "URL" = http://flvtubesearch...6ea0125f17907aa
IE - HKCU\..\SearchScopes\{909D53DD-ED5F-405B-879E-5F5CD26B7C05}: "URL" = http://www.google.co...Terms}&aq=f&oq=
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...sa&d=2012-03-21 21:15:00&v=10.2.0.3&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/...eferrer:source}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\..\SearchScopes\{C71BC1A6-2DA3-494F-B350-DCA7E3B1066C}: "URL" = http://www.facebook....q={searchTerms}
IE - HKCU\..\SearchScopes\{CD10120B-C165-4f8d-8C74-639629E238FF}: "URL" = http://mystart.magen...&loc=search_box
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incre...box_im2_test_v2
IE - HKCU\..\SearchScopes\{DA86AD01-5D44-4210-AB05-4B50023433F4}: "URL" = http://ws.infospace....r?_iceUrl=true user_id=%userid&tool_id=60231&qkw={searchTerms}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....erms}&fr=mkg028
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....h?fr=mkg030&p="
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngineURL: "http://flvtubesearch...={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchnu.com/406"
FF - prefs.js..keyword.URL: "http://dts.search-re...id=406&sr=0&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: F:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_121.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: F:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: F:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: F:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: F:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: F:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: f:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: f:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: F:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: F:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: f:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: F:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: F:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\npEpicPlayDisplayHost: F:\Program Files\EpicPlay\npEpicHost.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: F:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/11/26 00:55:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: F:\Program Files\AVAST Software\Avast\WebRep\FF [2012/03/07 11:31:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: F:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.2.0.3\ [2012/03/21 21:15:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/28 16:26:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/21 21:08:16 | 000,000,000 | ---D | M]
[2012/03/22 05:06:05 | 000,000,000 | ---D | M] (No name found) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Extensions
[2012/04/22 17:32:37 | 000,000,000 | ---D | M] (No name found) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions
[2012/03/14 10:18:04 | 000,000,000 | ---D | M] (FireShot) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2011/07/18 00:26:50 | 000,000,000 | ---D | M] (Flashblock) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2012/01/25 16:58:52 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/20 04:00:12 | 000,000,000 | ---D | M] (NoScript) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
[2012/03/22 05:05:56 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/11/11 02:15:52 | 000,000,000 | ---D | M] (gTranslate) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}
[2012/04/03 15:16:01 | 000,000,000 | ---D | M] (DownloadHelper) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/05/29 20:24:56 | 000,000,000 | ---D | M] (Answers) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2011/07/07 20:45:06 | 000,000,000 | ---D | M] (Web2PDF converter) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}
[2012/04/14 01:55:19 | 000,000,000 | ---D | M] (Ant Video Downloader) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\[email protected]
[2012/02/05 10:01:31 | 000,000,000 | ---D | M] (Ask Toolbar) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\[email protected]
[2012/04/21 00:37:17 | 000,000,000 | ---D | M] (LavaFox V2-Green) -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\extensions\[email protected]
[2011/11/27 07:03:10 | 000,001,945 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\searchplugins\bing-zugo.xml
[2010/12/04 11:37:46 | 000,004,925 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\searchplugins\deeperweb.xml
[2010/10/17 01:46:49 | 000,002,027 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\searchplugins\google-translate-any--en.xml
[2010/06/02 20:35:18 | 000,002,139 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\searchplugins\MyStart Search.xml
[2012/03/22 05:05:40 | 000,002,519 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\Mozilla\Firefox\Profiles\x88k25g8.default\searchplugins\Search_Results.xml
[2012/03/21 21:15:09 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- F:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\10.2.0.3
() (No name found) -- F:\DOCUMENTS AND SETTINGS\BUBBLES2000\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X88K25G8.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
() (No name found) -- F:\DOCUMENTS AND SETTINGS\BUBBLES2000\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X88K25G8.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
() (No name found) -- F:\DOCUMENTS AND SETTINGS\BUBBLES2000\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X88K25G8.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) -- F:\DOCUMENTS AND SETTINGS\BUBBLES2000\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X88K25G8.DEFAULT\EXTENSIONS\[email protected]
[2012/03/07 11:31:20 | 000,000,000 | ---D | M] (avast! WebRep) -- F:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - Extension: No name found = F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hnhgoncokajlafhnhjmccgcmgggiehjm\
CHR - Extension: No name found = F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\
CHR - Extension: No name found = F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: No name found = F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: No name found = F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: No name found = F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\plccnhhjonaiagjelpfkclblmlppjcik\
O1 HOSTS File: ([2004/08/04 03:00:00 | 000,000,734 | ---- | M]) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (StartNow Toolbar Helper) - {6E13D095-45C3-4271-9475-F3B48227DD9F} - F:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - F:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - F:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - F:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - F:\Program Files\Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - F:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - F:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - F:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (StartNow Toolbar) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - F:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O3 - HKLM\..\Toolbar: (no name) - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - F:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - F:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - F:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - F:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - F:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] F:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] F:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [ApnUpdater] F:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] F:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] F:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DATAMNGR] F:\Program Files\Searchqu Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [LogMeIn GUI] F:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MAXA-LockTray] F:\Program Files\MAXA Security Tools\Lock\tray.exe (MAXA Research Int'l Inc.)
O4 - HKLM..\Run: [Odsspo] F:\Program Files\Nwmao\Rlkkhgs.exe ()
O4 - HKLM..\Run: [StartNowToolbarHelper] "F:\Program Files\StartNow Toolbar\ToolbarHelper.exe" File not found
O4 - HKLM..\Run: [TkBellExe] F:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] F:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [vProt] F:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [VRS] "F:\Program Files\NCH Software\VRS\vrs.exe" -logon File not found
O4 - HKCU..\Run: [HotAlarmClock] F:\Program Files\HotAlarmClock\HotAlarmClock.exe (Comfort Software Group)
O4 - HKCU..\Run: [Messenger (Yahoo!)] F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [uTorrent] F:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\STIMON.lnk = F:\Program Files\USB2.0 UVC WebCam\USB2.0 UVC WebCam\STIMON.exe (Silicon Motion)
O4 - Startup: F:\Documents and Settings\Bubbles2000\Start Menu\Programs\Startup\CNET TechTracker.lnk = F:\Documents and Settings\Bubbles2000\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe ()
O4 - Startup: F:\Documents and Settings\Bubbles2000\Start Menu\Programs\Startup\Dropbox.lnk = F:\Documents and Settings\Bubbles2000\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: F:\Documents and Settings\Bubbles2000\Start Menu\Programs\Startup\RCA Detective.lnk = F:\Documents and Settings\Bubbles2000\My Documents\RCA Detective\RCADetective.exe (Audiovox Electronics Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: F:\Documents and Settings\Bubbles2000\Desktop\Colorado\Colorado = Colorado [2012/03/22 06:32:52 | 000,000,000 | ---D | M]
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E91EA0E0-F8AD-4018-AE7C-BD0430F21082}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - F:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll ()
O20 - AppInit_DLLs: (F:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll) - F:\Program Files\Searchqu Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (F:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll) - F:\Program Files\Searchqu Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (F:\WINDOWS\system32\userinit.exe) - F:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - F:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/20 02:20:52 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/01/27 00:03:47 | 000,027,568 | ---- | M] () - E:\autopay_DPA.pdf -- [ NTFS ]
O33 - MountPoints2\{1141289c-bad5-11df-a03b-001d097dc74a}\Shell\AutoRun\command - "" = H:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/23 03:53:02 | 000,594,944 | ---- | C] (OldTimer Tools) -- F:\Documents and Settings\Bubbles2000\Desktop\OTL.exe
[2012/04/21 11:43:27 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\Desktop\me
[2012/04/21 11:42:52 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\Desktop\dogstw
[2012/04/19 05:18:14 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\Desktop\Suite.aspx_files
[2012/04/13 04:17:28 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\Desktop\Bank info
[2012/04/08 12:40:45 | 000,343,040 | ---- | C] (Microsoft Corporation) -- F:\Documents and Settings\Bubbles2000\Desktop\mspaint.exe
[2012/04/03 15:39:43 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\Ilivid Player
[2012/04/01 12:45:44 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\AppData
[2012/04/01 12:45:43 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\Application Data\searchquband
[2012/04/01 12:33:07 | 000,000,000 | ---D | C] -- F:\Program Files\Multi Webcam Video Recorder
[2012/04/01 12:33:07 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Start Menu\Programs\Multi Webcam Video Recorder
[2012/04/01 12:32:42 | 000,911,944 | ---- | C] (DGTSoft Inc. ) -- F:\Program Files\multi-webcam-video-recorder_setup.exe
[2012/03/29 19:51:41 | 000,000,000 | ---D | C] -- F:\Documents and Settings\All Users\Application Data\NCH Software
[2012/03/25 04:41:34 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Bubbles2000\Desktop\1_files
========== Files - Modified Within 30 Days ==========
[2012/04/23 04:01:00 | 000,000,246 | ---- | M] () -- F:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/04/23 03:48:00 | 000,000,290 | ---- | M] () -- F:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1177238915-1647877149-725345543-1004.job
[2012/04/23 03:47:50 | 000,000,892 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/23 03:47:48 | 000,000,294 | ---- | M] () -- F:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1177238915-1647877149-725345543-500.job
[2012/04/23 03:47:09 | 000,002,048 | --S- | M] () -- F:\WINDOWS\bootstat.dat
[2012/04/23 03:31:42 | 000,594,944 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Bubbles2000\Desktop\OTL.exe
[2012/04/23 00:32:00 | 000,000,896 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/23 00:18:00 | 000,001,002 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1647877149-725345543-1004UA.job
[2012/04/23 00:05:00 | 000,000,830 | ---- | M] () -- F:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/04/22 19:18:00 | 000,000,950 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1647877149-725345543-1004Core1cc209613fe80f2.job
[2012/04/22 04:13:00 | 000,000,302 | ---- | M] () -- F:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1177238915-1647877149-725345543-500.job
[2012/04/20 20:22:02 | 000,000,284 | ---- | M] () -- F:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/04/20 14:56:23 | 000,232,448 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/19 18:47:16 | 004,107,024 | ---- | M] (PC Cleaners) -- F:\WINDOWS\uninst.exe
[2012/04/19 03:15:37 | 000,000,298 | ---- | M] () -- F:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1177238915-1647877149-725345543-1004.job
[2012/04/15 14:48:28 | 000,030,094 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\redhead4.JPG
[2012/04/15 14:35:45 | 000,045,509 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\redhead.jpg
[2012/04/15 14:33:53 | 000,045,481 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\redhead 2.JPG
[2012/04/15 14:29:51 | 000,041,349 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\wow4.JPG
[2012/04/15 04:13:38 | 000,315,187 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\wow.jpg
[2012/04/13 18:20:29 | 000,002,339 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\Google Chrome.lnk
[2012/04/13 18:20:29 | 000,002,317 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/04/12 10:28:00 | 000,000,280 | ---- | M] () -- F:\WINDOWS\tasks\debutShakeIcon.job
[2012/04/11 22:56:56 | 000,000,793 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- F:\WINDOWS\System32\drivers\mbam.sys
[2012/04/04 15:31:12 | 000,122,015 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\shipping ok.jpg
[2012/04/02 19:25:11 | 000,004,982 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Application Data\wklnhst.dat
[2012/04/01 12:33:08 | 000,000,812 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\Multi Webcam Video Recorder.lnk
[2012/04/01 12:32:43 | 000,911,944 | ---- | M] (DGTSoft Inc. ) -- F:\Program Files\multi-webcam-video-recorder_setup.exe
[2012/03/25 05:44:37 | 000,002,258 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\A note to Peter2.rtf
[2012/03/25 04:41:35 | 000,305,771 | ---- | M] () -- F:\Documents and Settings\Bubbles2000\Desktop\1.htm
========== Files Created - No Company Name ==========
[2012/04/20 00:26:25 | 000,014,600 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\My Documents\SniffPass.chm
[2012/04/15 14:48:28 | 000,030,094 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\redhead4.JPG
[2012/04/15 14:33:38 | 000,045,481 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\redhead 2.JPG
[2012/04/15 14:29:51 | 000,041,349 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\wow4.JPG
[2012/04/15 09:32:51 | 000,045,509 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\redhead.jpg
[2012/04/15 04:13:37 | 000,315,187 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\wow.jpg
[2012/04/04 15:31:00 | 000,122,015 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\shipping ok.jpg
[2012/04/01 12:33:08 | 000,000,812 | ---- | C] () -- F:\Documents and Settings\All Users\Desktop\Multi Webcam Video Recorder.lnk
[2012/03/25 05:44:37 | 000,002,258 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\A note to Peter2.rtf
[2012/03/25 04:41:34 | 000,305,771 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Desktop\1.htm
[2012/03/19 11:29:26 | 000,038,187 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Application Data\KeyBlaze.dmp
[2012/03/02 22:59:54 | 000,108,032 | ---- | C] () -- F:\WINDOWS\System32\ff_vfw.dll
[2012/02/20 21:46:15 | 000,000,043 | ---- | C] () -- F:\WINDOWS\gswin32.ini
[2011/11/26 23:18:56 | 002,062,304 | ---- | C] () -- F:\Program Files\installspeedfan443.exe
[2011/10/31 18:16:38 | 015,854,592 | ---- | C] () -- F:\Program Files\Setup.msi
[2011/10/28 17:22:15 | 000,204,800 | ---- | C] () -- F:\WINDOWS\System32\igfxCoIn_v4820.dll
[2011/07/08 01:48:35 | 000,000,007 | ---- | C] () -- F:\WINDOWS\treeskp.sys
[2011/07/08 01:48:35 | 000,000,007 | ---- | C] () -- F:\WINDOWS\sbacknt.bin
[2010/11/29 16:53:55 | 000,000,037 | ---- | C] () -- F:\WINDOWS\Viewer.ini
[2010/09/02 00:33:54 | 000,015,360 | ---- | C] () -- F:\WINDOWS\System32\bdmjpeg.dll
[2010/09/02 00:32:52 | 000,058,368 | ---- | C] () -- F:\WINDOWS\System32\bdmpegv.dll
[2010/08/25 06:28:07 | 000,000,031 | ---- | C] () -- F:\WINDOWS\System32\wocsodsini.dll
[2010/08/25 06:27:47 | 000,000,530 | ---- | C] () -- F:\WINDOWS\System32\tx14_ic.ini
[2010/08/25 06:09:41 | 001,774,720 | ---- | C] () -- F:\WINDOWS\System32\BootMan.exe
[2010/08/25 06:09:41 | 000,086,408 | ---- | C] () -- F:\WINDOWS\System32\setupempdrv03.exe
[2010/08/25 06:09:41 | 000,014,848 | ---- | C] () -- F:\WINDOWS\System32\EuEpmGdi.dll
[2010/08/25 06:09:41 | 000,013,192 | ---- | C] () -- F:\WINDOWS\System32\epmntdrv.sys
[2010/08/25 06:09:41 | 000,008,456 | ---- | C] () -- F:\WINDOWS\System32\EuGdiDrv.sys
[2010/07/23 22:17:42 | 000,000,132 | -H-- | C] () -- F:\Documents and Settings\Bubbles2000\Application Data\lakerda1967.sys
[2010/07/23 22:13:46 | 000,010,584 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Application Data\docXConverter (3).ini
[2010/06/28 06:32:59 | 000,000,025 | ---- | C] () -- F:\WINDOWS\cdplayer.ini
[2010/06/18 01:14:54 | 000,024,575 | ---- | C] () -- F:\WINDOWS\System32\Mpwinapppiobas69.dat
[2010/06/17 14:07:29 | 000,112,156 | ---- | C] () -- F:\WINDOWS\System32\winobj92.dat
[2010/06/15 07:29:22 | 000,000,552 | ---- | C] () -- F:\WINDOWS\System32\d3d8caps.dat
[2010/06/01 19:24:12 | 000,000,754 | ---- | C] () -- F:\WINDOWS\WORDPAD.INI
[2010/05/31 13:49:28 | 000,000,664 | ---- | C] () -- F:\WINDOWS\System32\d3d9caps.dat
[2010/05/29 22:52:43 | 000,040,960 | ---- | C] () -- F:\WINDOWS\System32\lxcgvs.dll
[2010/05/29 22:52:42 | 001,134,592 | ---- | C] () -- F:\WINDOWS\System32\lxcgusb1.dll
[2010/05/29 22:52:42 | 000,708,608 | ---- | C] () -- F:\WINDOWS\System32\lxcgcomc.dll
[2010/05/29 22:52:42 | 000,491,520 | ---- | C] () -- F:\WINDOWS\System32\lxcgcoms.exe
[2010/05/29 22:52:42 | 000,483,328 | ---- | C] () -- F:\WINDOWS\System32\lxcglmpm.dll
[2010/05/29 22:52:42 | 000,413,696 | ---- | C] () -- F:\WINDOWS\System32\lxcgcomm.dll
[2010/05/29 22:52:42 | 000,372,736 | ---- | C] () -- F:\WINDOWS\System32\lxcgih.exe
[2010/05/29 22:52:42 | 000,155,648 | ---- | C] () -- F:\WINDOWS\System32\lxcgprox.dll
[2010/05/29 22:52:42 | 000,114,688 | ---- | C] () -- F:\WINDOWS\System32\lxcgpplc.dll
[2010/05/29 22:52:41 | 001,191,936 | ---- | C] () -- F:\WINDOWS\System32\lxcgserv.dll
[2010/05/28 01:47:07 | 000,000,091 | ---- | C] () -- F:\WINDOWS\DVM.INI
[2010/05/27 23:46:32 | 000,049,152 | ---- | C] () -- F:\WINDOWS\System32\ChCfg.exe
[2010/05/27 22:16:54 | 000,004,982 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Application Data\wklnhst.dat
[2010/05/27 21:45:33 | 000,232,448 | ---- | C] () -- F:\Documents and Settings\Bubbles2000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/27 03:44:01 | 000,000,000 | ---- | C] () -- F:\WINDOWS\nsreg.dat
[2010/05/27 03:36:41 | 000,002,048 | --S- | C] () -- F:\WINDOWS\bootstat.dat
[2010/05/27 03:33:20 | 000,021,640 | ---- | C] () -- F:\WINDOWS\System32\emptyregdb.dat
[2010/05/26 18:41:45 | 000,004,161 | ---- | C] () -- F:\WINDOWS\ODBCINST.INI
[2010/05/26 18:40:52 | 000,157,160 | ---- | C] () -- F:\WINDOWS\System32\FNTCACHE.DAT
========== Alternate Data Streams ==========
@Alternate Data Stream - 199 bytes -> F:\Documents and Settings\All Users\Application Data\TEMP:5C1D8A71
@Alternate Data Stream - 133 bytes -> F:\Documents and Settings\All Users\Application Data\TEMP:029E021F
@Alternate Data Stream - 106 bytes -> F:\Documents and Settings\All Users\Application Data\TEMP:67BC4708
@Alternate Data Stream - 102 bytes -> F:\Documents and Settings\All Users\Application Data\TEMP:029666E0
< End of report >
Thank you in advance for any help you can offer...ed