OK.....ran all the tests/scans; have NO idea what to make of the SpeedTest results - if I even GOT any (created an account just to err on the side of caution). Please explain what it is for which I should be looking to indicate a successful test? Also, you didn't give me parameters for the OTL scan so I didn't include the Extras battery - do I need to run it again? Thanks
Process PID CPU Private Bytes Working Set Description Company Name Verified Signer
alg.exe 1236 1,132 K 100 K Application Layer Gateway Service Microsoft Corporation (Unable to verify) Microsoft Corporation
csrss.exe 452 1,732 K 2,320 K Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows Component Publisher
ctfmon.exe 160 964 K 1,728 K CTF Loader Microsoft Corporation (Verified) Microsoft Windows Component Publisher
explorer.exe 1500 19,188 K 10,404 K Windows Explorer Microsoft Corporation (Unable to verify) Microsoft Corporation
iexplore.exe 3228 10,476 K 4,920 K Internet Explorer Microsoft Corporation (Verified) Microsoft Windows
iexplore.exe 1716 76,180 K 91,696 K Internet Explorer Microsoft Corporation (Verified) Microsoft Windows
lsass.exe 540 3,936 K 900 K LSA Shell (Export Version) Microsoft Corporation (Unable to verify) Microsoft Corporation
mbamgui.exe 1960 3,252 K 788 K Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
mbamservice.exe 1760 121,952 K 41,148 K Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
mDNSResponder.exe 1700 1,164 K 820 K Bonjour Service Apple Inc. (Verified) Apple Inc.
services.exe 520 1,708 K 1,548 K Services and Controller app Microsoft Corporation (Verified) Microsoft Windows Component Publisher
smss.exe 404 168 K 44 K Windows NT Session Manager Microsoft Corporation (Verified) Microsoft Windows Component Publisher
spoolsv.exe 1128 3,100 K 608 K Spooler SubSystem App Microsoft Corporation (Unable to verify) Microsoft Corporation
svchost.exe 692 3,120 K 1,524 K Generic Host Process for Win32 Services Microsoft Corporation (Verified) Microsoft Windows Component Publisher
svchost.exe 788 1,788 K 1,564 K Generic Host Process for Win32 Services Microsoft Corporation (Unable to verify) Microsoft Corporation
svchost.exe 856 24,540 K 13,964 K Generic Host Process for Win32 Services Microsoft Corporation (Verified) Microsoft Windows Component Publisher
svchost.exe 952 1,608 K 1,568 K Generic Host Process for Win32 Services Microsoft Corporation (Verified) Microsoft Windows Component Publisher
svchost.exe 996 3,248 K 1,096 K Generic Host Process for Win32 Services Microsoft Corporation (Verified) Microsoft Windows Component Publisher
svchost.exe 1648 1,252 K 64 K Generic Host Process for Win32 Services Microsoft Corporation (Unable to verify) Microsoft Corporation
System 4 0 K 32 K
winlogon.exe 476 6,004 K 1,132 K Windows NT Logon Application Microsoft Corporation (Verified) Microsoft Windows Component Publisher
wmiprvse.exe 3024 2,364 K 4,928 K (Unable to verify) (null)
wscntfy.exe 1076 552 K 324 K Windows Security Center Notification App Microsoft Corporation (Unable to verify) Microsoft Corporation
Interrupts n/a < 0.01 0 K 0 K Hardware Interrupts and DPCs
procexp.exe 2728 9.00 13,084 K 19,092 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
System Idle Process 0 0 K 16 K
Vino's Event Viewer v01c run on Windows XP in English
Report run at 22/06/2012 6:01:52 PM
Note: All dates below are in the format dd/mm/yyyy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 22/06/2012 5:02:44 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The MCSTRM service failed to start due to the following error: The system cannot find the file specified.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
Vino's Event Viewer v01c run on Windows XP in English
Report run at 22/06/2012 6:06:12 PM
Note: All dates below are in the format dd/mm/yyyy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
OTL logfile created on: 6/22/2012 6:10:51 PM - Run 5
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Documents and Settings\User\Desktop\Spyware & Virus tools\GtGCompCavtools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.30 Mb Total Physical Memory | 137.39 Mb Available Physical Memory | 26.92% Memory free
673.00 Mb Paging File | 266.57 Mb Available in Paging File | 39.61% Paging File free
Paging file location(s): C:\pagefile.sys 192 384 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.64 Gb Total Space | 2.42 Gb Free Space | 12.96% Space Free | Partition Type: NTFS
Drive E: | 74.52 Gb Total Space | 2.09 Gb Free Space | 2.80% Space Free | Partition Type: NTFS
Computer Name: USER-2LHZ6LTLSL | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/06/12 15:29:02 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\Spyware & Virus tools\GtGCompCavtools\OTL.exe
PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- %ProgramFiles%\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/06/21 17:56:43 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/06/14 18:20:14 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2009/09/03 11:53:00 | 000,048,368 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus®
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS -- (MRESP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS -- (MREMP50)
DRV - File not found [Kernel | Auto | Stopped] -- -- (MCSTRM)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\wATV03nt.sys -- (iAimTV2)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012/06/20 02:14:18 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012/06/16 01:00:35 | 000,032,072 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV - [2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2004/08/04 01:31:32 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/08/04 01:29:49 | 000,019,455 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wvchntxx.sys -- (iAimFP4)
DRV - [2004/08/04 01:29:47 | 000,012,063 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wsiintxx.sys -- (iAimFP3)
DRV - [2004/08/04 01:29:45 | 000,025,471 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv10nt.sys -- (iAimTV5)
DRV - [2004/08/04 01:29:45 | 000,023,615 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wch7xxnt.sys -- (iAimTV4)
DRV - [2004/08/04 01:29:44 | 000,022,271 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv06nt.sys -- (iAimTV6)
DRV - [2004/08/04 01:29:43 | 000,033,599 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv04nt.sys -- (iAimTV3)
DRV - [2004/08/04 01:29:42 | 000,019,551 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv02nt.sys -- (iAimTV1)
DRV - [2004/08/04 01:29:41 | 000,029,311 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv01nt.sys -- (iAimTV0)
DRV - [2004/08/04 01:29:40 | 000,011,871 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv09nt.sys -- (iAimFP7)
DRV - [2004/08/04 01:29:39 | 000,011,295 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv08nt.sys -- (iAimFP6)
DRV - [2004/08/04 01:29:38 | 000,011,807 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv07nt.sys -- (iAimFP5)
DRV - [2004/08/04 01:29:37 | 000,012,415 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv01nt.sys -- (iAimFP0)
DRV - [2004/08/04 01:29:37 | 000,012,127 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv02nt.sys -- (iAimFP1)
DRV - [2004/08/04 01:29:37 | 000,011,775 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv05nt.sys -- (iAimFP2)
DRV - [2004/08/04 01:29:36 | 000,161,020 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2002/06/03 11:18:32 | 000,040,832 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371) Creative AudioPCI (ES1371,ES1373) (WDM)
DRV - [2001/08/17 09:28:02 | 000,907,456 | ---- | M] (Conexant) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys -- (HCF_MSFT)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?} IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehpIE - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 9E 5C DB A0 4E CD 01 [binary data]
IE - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...Box&Form=IE8SRCIE - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.yahoo.com/"FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/21 17:53:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/08 19:01:04 | 000,000,000 | ---D | M]
[2008/10/27 18:12:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2012/06/12 21:17:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2dx88my5.default\extensions
[2012/05/20 07:11:49 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2dx88my5.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/10 08:16:13 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus®)) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2dx88my5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2012/06/21 17:53:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/06/14 18:20:49 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/14 18:19:40 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/14 18:19:40 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2012/06/17 16:29:26 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004\..Trusted Domains: streamwrhu.net ([live] https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 66.189.0.100 24.159.64.23 24.247.24.53
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0988B9E-1F28-41A8-A972-714885C819B3}: DhcpNameServer = 66.189.0.100 24.159.64.23 24.247.24.53
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/05 14:02:31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-1547161642-1060284298-1708537768-1004..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/06/22 16:51:41 | 002,674,800 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\User\Desktop\procexp.exe
[2012/06/21 17:58:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Google
[2012/06/21 17:57:23 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012/06/21 17:53:47 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012/06/20 02:14:18 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/06/20 01:00:57 | 017,246,464 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\User\Desktop\SUPERAntiSpyware.exe
[2012/06/20 00:21:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\User\PrivacIE
[2012/06/19 03:17:11 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\User\IETldCache
[2012/06/18 23:30:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012/06/18 23:23:09 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012/06/18 08:06:54 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User\Recent
[2012/06/17 20:49:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012/06/17 19:22:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2012/06/17 19:22:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2012/06/17 19:21:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2012/06/17 17:12:32 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/06/17 16:45:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/06/14 20:04:50 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/06/14 19:54:14 | 004,560,591 | R--- | C] (Swearware) -- C:\Documents and Settings\User\Desktop\ComboFix.exe
[2012/06/13 20:27:00 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/06/02 01:28:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2012/06/02 01:26:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Skype
[2012/06/02 01:17:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype
[2012/05/29 07:26:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2012/05/29 05:19:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\IObit
[2012/05/29 05:18:49 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/06/22 18:08:01 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/22 17:59:45 | 000,061,440 | ---- | M] ( ) -- C:\Documents and Settings\User\Desktop\VEW.exe
[2012/06/22 17:02:19 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/06/22 17:02:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/06/22 17:02:12 | 535,154,688 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/22 16:51:46 | 002,674,800 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\User\Desktop\procexp.exe
[2012/06/21 17:53:51 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/06/21 17:53:51 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/06/21 16:57:24 | 010,857,155 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Lucky Man - [LIVE] - Marillion.mp3
[2012/06/20 08:27:24 | 010,131,155 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Power [LIVE] - Marillion.mp3
[2012/06/20 03:09:20 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/06/20 02:14:18 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/06/20 01:00:57 | 017,246,464 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\User\Desktop\SUPERAntiSpyware.exe
[2012/06/19 12:23:26 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/06/19 11:50:32 | 000,148,531 | ---- | M] () -- C:\Documents and Settings\User\Desktop\PageCapture TU 6-19-12.JPG
[2012/06/19 03:17:18 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/06/19 02:48:44 | 000,122,928 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/18 23:01:07 | 000,432,778 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/06/18 23:01:07 | 000,067,734 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/06/18 08:09:40 | 000,040,020 | ---- | M] () -- C:\Documents and Settings\User\My Documents\CCleaner Registry Backup file 6-18-12.reg
[2012/06/17 18:59:06 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/06/17 16:29:26 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/06/17 16:01:42 | 004,560,591 | R--- | M] (Swearware) -- C:\Documents and Settings\User\Desktop\ComboFix.exe
[2012/06/16 01:00:35 | 000,032,072 | ---- | M] () -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2012/06/15 15:25:31 | 000,053,570 | ---- | M] () -- C:\WINDOWS\System32\Defrag Report filepath name details F 6-15-12
[2012/06/14 20:05:00 | 000,000,420 | RHS- | M] () -- C:\boot.ini
[2012/06/12 15:26:35 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\User\Desktop\MBR.dat
[2012/06/11 20:40:47 | 001,557,759 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Islanders '98 alternative logo design.jpg
[2012/06/08 19:08:20 | 000,228,864 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/06 08:34:14 | 000,000,885 | ---- | M] () -- C:\Documents and Settings\User\Desktop\linkfile_fix.zip
[2012/06/06 08:32:48 | 000,000,745 | ---- | M] () -- C:\Documents and Settings\User\Desktop\xp_exe_fix.zip
[2012/06/05 14:00:10 | 001,801,855 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Hot Pants - Salvage.mp3
[2012/06/05 10:43:40 | 003,471,184 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Out Of Mind Out Of Sight - Models, The.mp3
[2012/06/05 08:14:52 | 002,554,547 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Can't Sleep - Rockets, The.mp3
[2012/06/05 07:51:34 | 004,300,415 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Mama Let Him Play - Doucette.mp3
[2012/06/05 01:21:46 | 005,043,590 | ---- | M] () -- C:\Documents and Settings\User\Desktop\The Joker - Snail.mp3
[2012/06/05 01:04:54 | 003,875,068 | ---- | M] () -- C:\Documents and Settings\User\Desktop\City Slicker - James 'JY' Young with Jan Hammer.mp3
[2012/06/04 21:28:55 | 003,456,182 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Shortcut To Somewhere [from 'Quicksilver'] - Fish with Tony Banks.mp3
[2012/06/04 21:19:02 | 002,705,109 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Two Buffaloes - Rolf Harris.mp3
[2012/06/04 21:16:07 | 003,735,378 | ---- | M] () -- C:\Documents and Settings\User\Desktop\It's Really You - Tarney Spencer Band.mp3
[2012/06/04 20:58:57 | 003,948,955 | ---- | M] () -- C:\Documents and Settings\User\Desktop\On the Run - Lake.mp3
[2012/06/04 20:54:31 | 005,892,883 | ---- | M] () -- C:\Documents and Settings\User\Desktop\A Smile Is Diamond - A Band Called O (10-11!).mp3
[2012/06/04 20:47:24 | 003,763,695 | ---- | M] () -- C:\Documents and Settings\User\Desktop\I Want You To Be Mine [ USA Version ] - Kayak.mp3
[2012/06/04 18:29:23 | 002,392,118 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Hold On To The Night - Starz.mp3
[2012/06/04 18:21:48 | 004,059,670 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Coming Home - Ian Thomas.mp3
[2012/06/04 18:08:50 | 002,907,357 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Northern Lights - Renaissance.mp3
[2012/06/04 17:50:25 | 004,253,185 | ---- | M] () -- C:\Documents and Settings\User\Desktop\She Loves To Be In Love - Charlie.mp3
[2012/06/04 17:38:27 | 006,439,530 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Superstar - Bob McGilpin.mp3
[2012/06/04 17:31:31 | 004,484,317 | ---- | M] () -- C:\Documents and Settings\User\Desktop\I'm Mandy, Fly Me - 10cc.mp3
[2012/05/29 04:59:56 | 015,040,520 | ---- | M] () -- C:\Documents and Settings\User\Desktop\vGrabber_setup.exe
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/06/22 18:00:06 | 000,061,440 | ---- | C] ( ) -- C:\Documents and Settings\User\Desktop\VEW.exe
[2012/06/21 17:56:50 | 000,000,830 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/21 17:53:51 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/06/21 17:53:51 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/06/21 17:53:50 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/06/21 16:18:14 | 010,857,155 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Lucky Man - [LIVE] - Marillion.mp3
[2012/06/20 11:39:29 | 015,040,520 | ---- | C] () -- C:\Documents and Settings\User\Desktop\vGrabber_setup.exe
[2012/06/20 08:16:24 | 010,131,155 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Power [LIVE] - Marillion.mp3
[2012/06/19 12:28:39 | 535,154,688 | -HS- | C] () -- C:\hiberfil.sys
[2012/06/19 11:50:31 | 000,148,531 | ---- | C] () -- C:\Documents and Settings\User\Desktop\PageCapture TU 6-19-12.JPG
[2012/06/18 21:38:10 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/06/18 19:07:53 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/06/18 19:07:53 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/06/18 08:09:33 | 000,040,020 | ---- | C] () -- C:\Documents and Settings\User\My Documents\CCleaner Registry Backup file 6-18-12.reg
[2012/06/16 01:00:35 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2012/06/15 15:25:22 | 000,053,570 | ---- | C] () -- C:\WINDOWS\System32\Defrag Report filepath name details F 6-15-12
[2012/06/14 20:05:00 | 000,000,304 | ---- | C] () -- C:\Boot.bak
[2012/06/14 20:04:55 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/06/12 15:26:35 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\User\Desktop\MBR.dat
[2012/06/11 20:40:57 | 001,557,759 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Islanders '98 alternative logo design.jpg
[2012/06/06 08:34:18 | 000,000,885 | ---- | C] () -- C:\Documents and Settings\User\Desktop\linkfile_fix.zip
[2012/06/06 08:33:09 | 000,000,745 | ---- | C] () -- C:\Documents and Settings\User\Desktop\xp_exe_fix.zip
[2012/06/05 13:59:16 | 001,801,855 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Hot Pants - Salvage.mp3
[2012/06/05 10:40:56 | 003,471,184 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Out Of Mind Out Of Sight - Models, The.mp3
[2012/06/05 08:11:49 | 002,554,547 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Can't Sleep - Rockets, The.mp3
[2012/06/05 07:45:43 | 004,300,415 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Mama Let Him Play - Doucette.mp3
[2012/06/05 00:56:30 | 003,875,068 | ---- | C] () -- C:\Documents and Settings\User\Desktop\City Slicker - James 'JY' Young with Jan Hammer.mp3
[2012/06/04 18:28:18 | 002,392,118 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Hold On To The Night - Starz.mp3
[2012/06/04 18:23:48 | 005,043,590 | ---- | C] () -- C:\Documents and Settings\User\Desktop\The Joker - Snail.mp3
[2012/06/04 18:19:53 | 004,059,670 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Coming Home - Ian Thomas.mp3
[2012/06/04 18:16:29 | 003,763,695 | ---- | C] () -- C:\Documents and Settings\User\Desktop\I Want You To Be Mine [ USA Version ] - Kayak.mp3
[2012/06/04 18:07:47 | 002,907,357 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Northern Lights - Renaissance.mp3
[2012/06/04 18:02:13 | 003,735,378 | ---- | C] () -- C:\Documents and Settings\User\Desktop\It's Really You - Tarney Spencer Band.mp3
[2012/06/04 17:48:21 | 004,253,185 | ---- | C] () -- C:\Documents and Settings\User\Desktop\She Loves To Be In Love - Charlie.mp3
[2012/06/04 17:35:37 | 006,439,530 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Superstar - Bob McGilpin.mp3
[2012/06/04 17:29:24 | 004,484,317 | ---- | C] () -- C:\Documents and Settings\User\Desktop\I'm Mandy, Fly Me - 10cc.mp3
[2012/06/04 17:22:07 | 003,948,955 | ---- | C] () -- C:\Documents and Settings\User\Desktop\On the Run - Lake.mp3
[2012/06/04 17:16:55 | 005,892,883 | ---- | C] () -- C:\Documents and Settings\User\Desktop\A Smile Is Diamond - A Band Called O (10-11!).mp3
[2012/06/01 21:15:16 | 003,456,182 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Shortcut To Somewhere [from 'Quicksilver'] - Fish with Tony Banks.mp3
[2012/05/31 00:16:26 | 002,705,109 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Two Buffaloes - Rolf Harris.mp3
[2012/03/17 12:42:40 | 000,870,128 | ---- | C] () -- C:\Documents and Settings\User\Application Data\mcs.rma
[2011/06/04 09:18:39 | 000,000,022 | --S- | C] () -- C:\Documents and Settings\User\Application Data\Sys2662.Config.Repository.bin
[2010/12/12 15:10:09 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/12 15:10:09 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/12 15:10:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/12 15:10:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/12 15:10:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/06/29 23:37:57 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
========== LOP Check ========== [2011/05/18 03:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Amazon
[2010/07/17 20:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/12/12 14:59:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-4D05119C
[2012/06/04 15:34:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2012/05/08 02:38:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CheckPoint
[2010/12/25 09:09:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\cPgMn08200
[2012/01/07 11:40:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\F-Secure
[2011/09/04 18:13:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2012/06/04 15:28:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/04/24 10:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/02 15:27:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/05/08 10:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{C3243856-7746-4A05-8837-51A28C1CDD82}
[2010/10/17 02:47:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Amazon
[2012/06/15 15:01:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\CBS Interactive
[2012/05/08 03:11:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\CheckPoint
[2009/06/18 22:47:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\com.imeem.DesktopUploader.6C3F108F466C0F04F30B58747CAA4DF34281133B.1
[2012/01/07 11:44:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\f-secure
[2010/11/13 15:59:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\FreeFileViewer
[2012/05/29 05:20:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\IObit
[2009/06/30 18:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\OpenOffice.org
[2012/01/03 19:18:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\OverDrive
[2012/05/13 22:12:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Sevas-S
[2012/05/31 19:25:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Uniblue
========== Purity Check ========== < End of report >