It's been off for the last few months, now that have turned it on it's slow and has pop ups.
OTL logfile created on: 4/23/2013 2:56:51 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Ruth\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
766.98 Mb Total Physical Memory | 235.24 Mb Available Physical Memory | 30.67% Memory free
1.19 Gb Paging File | 0.31 Gb Available in Paging File | 25.93% Paging File free
Paging file location(s): c:\pagefile.sys 500 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 3.57 Gb Free Space | 9.33% Space Free | Partition Type: NTFS
Computer Name: MCQW01 | User Name: Ruth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/04/23 11:16:21 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ruth\Desktop\OTL.exe
PRC - [2013/02/12 14:29:31 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2013/02/12 14:28:38 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2013/02/12 14:28:34 | 000,385,248 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013/02/12 14:28:34 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2013/02/07 20:05:36 | 000,170,912 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2013/02/06 05:01:31 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/01/27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2013/04/22 17:25:53 | 014,717,144 | ---- | M] () -- C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_11_6_602_180.dll
MOD - [2013/02/06 05:00:33 | 003,023,256 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/09/19 19:17:40 | 000,397,088 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2008/04/13 19:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\msdmo.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\TightVNC\WinVNC.exe -- (winvnc)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus®
SRV - [2013/04/22 17:26:00 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/02/12 14:29:31 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013/02/12 14:28:34 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013/02/07 20:05:36 | 000,170,912 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013/02/06 05:01:30 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2003/03/03 14:33:40 | 000,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\wanatw4.sys -- (wanatw)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\wATV03nt.sys -- (iAimTV2)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\el90xbc5.sys -- (EL90XBC)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (bvrp_pci)
DRV - [2013/02/01 17:30:40 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys -- (avipbb)
DRV - [2013/02/01 17:30:38 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\avgntflt.sys -- (avgntflt)
DRV - [2012/11/14 15:05:25 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\avkmgr.sys -- (avkmgr)
DRV - [2012/10/16 17:53:56 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012/08/27 15:50:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys -- (ssmdrv)
DRV - [2011/10/30 14:14:50 | 000,027,600 | ---- | M] (CrystalIdea Software) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\CisUtMonitor.sys -- (CisUtMonitor)
DRV - [2009/03/25 11:06:30 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys -- (mfesmfk)
DRV - [2009/03/25 11:06:28 | 000,214,024 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys -- (mfehidk)
DRV - [2009/03/25 11:06:28 | 000,079,880 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys -- (mfeavfk)
DRV - [2009/03/25 11:06:28 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys -- (mfebopk)
DRV - [2009/03/25 11:05:54 | 000,034,216 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys -- (mferkdk)
DRV - [2004/08/03 22:29:50 | 000,019,455 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys -- (iAimFP4)
DRV - [2004/08/03 22:29:48 | 000,012,063 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys -- (iAimFP3)
DRV - [2004/08/03 22:29:46 | 000,023,615 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys -- (iAimTV4)
DRV - [2004/08/03 22:29:44 | 000,033,599 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys -- (iAimTV3)
DRV - [2004/08/03 22:29:44 | 000,019,551 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys -- (iAimTV1)
DRV - [2004/08/03 22:29:42 | 000,029,311 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys -- (iAimTV0)
DRV - [2004/08/03 22:29:38 | 000,161,020 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys -- (i81x)
DRV - [2004/08/03 22:29:38 | 000,012,415 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys -- (iAimFP0)
DRV - [2004/08/03 22:29:38 | 000,012,127 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys -- (iAimFP1)
DRV - [2004/08/03 22:29:38 | 000,011,775 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys -- (iAimFP2)
DRV - [2003/08/29 04:59:24 | 001,101,696 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys -- (BCMModem)
DRV - [2003/06/11 01:52:26 | 000,098,815 | ---- | M] (Visual Networks) [Kernel | Boot | Unknown] -- C:\WINDOWS\System32\drivers\ipvnmon.sys -- (IPVNMon)
DRV - [2002/11/08 14:45:06 | 000,017,217 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapp.../search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.claro-sea...000000cf1745dc0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SE...S01?FORM=TOOLBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\..\SearchScopes\{E7C37A7C-7F78-47A4-BC64-A4B54BEF46F7}: "URL" = http://www.google.co...ie7&rlz=1I7RNWM
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - prefs.js..extensions.enabledAddons: plugin%40selectionlinks.com:1.5
FF - prefs.js..extensions.enabledAddons: %7B7affbfae-c4e2-4915-8c0f-00fa3ec610a1%7D:5.74.1.9183
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@zylom.com/ZylomGamesPlayer: C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Ruth\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/02/06 05:01:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/02/06 05:00:19 | 000,000,000 | ---D | M]
[2012/10/17 18:28:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ruth\Application Data\Mozilla\Extensions
[2013/02/15 20:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ruth\Application Data\Mozilla\Firefox\Profiles\eza33z31.default\extensions
[2013/02/15 20:33:35 | 000,000,000 | ---D | M] ("AOL Toolbar") -- C:\Documents and Settings\Ruth\Application Data\Mozilla\Firefox\Profiles\eza33z31.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2012/10/24 13:53:52 | 000,000,000 | ---D | M] (SelectionLinks) -- C:\Documents and Settings\Ruth\Application Data\Mozilla\Firefox\Profiles\eza33z31.default\extensions\[email protected]
[2013/02/15 20:33:55 | 000,002,545 | ---- | M] () -- C:\Documents and Settings\Ruth\Application Data\Mozilla\Firefox\Profiles\eza33z31.default\searchplugins\aol-search.xml
[2012/10/02 19:44:57 | 000,001,435 | ---- | M] () -- C:\Documents and Settings\Ruth\Application Data\Mozilla\Firefox\Profiles\eza33z31.default\searchplugins\spamfreesearch.xml
[2013/02/06 04:59:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/02/06 05:01:32 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 20:26:22 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/11 22:25:01 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.claro-sea...000000cf1745dc0
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.claro-sea...000000cf1745dc0
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\Ruth\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 7 U7 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: RealOne Player Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll
CHR - Extension: Super Mario Bros = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\abaipnligghjcjklcoekcgnpkcifgdkc\6.0_0\
CHR - Extension: Angry Birds = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: 3DTin = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\algoakekcdmbbikdjgjdahbfihboglmi\1.1_0\
CHR - Extension: Splitman = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bbceciicbilpdhmlghijikklgjhclnmi\1.0_0\
CHR - Extension: TV = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh\1.0.11_0\
CHR - Extension: ibibo Chess = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bgpnmaohmoiefjealeblfgdfnkepnejg\1_0\
CHR - Extension: YouTube = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Bounceball = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bnonnffemhpfblohaicmfmofbfaaoobf\1.1_0\
CHR - Extension: Bouncy Mouse = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cgdllcbmneiklcmbeclfegccdjholomb\1.2.1_0\
CHR - Extension: Google Search = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Crazy Rollercoaster = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eafhgomkapdagnpmmgilphbolnejepoc\1.3_0\
CHR - Extension: Cut the Rope = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\15_0\
CHR - Extension: Super Mario 63 = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gndaiddfbhkpcljnfdpgemffmlnjfgdp\1_0\
CHR - Extension: Isoball 3 = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj\1.3.0_0\
CHR - Extension: Santa Can Fly = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ijnjeadmcoiglgongpaknblabefpogei\2.0.0_0\
CHR - Extension: Typing Test - KeyHero = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm\1.4.0_0\
CHR - Extension: Cargo Bridge = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\keembkgclppcbilkekfgpobhldjjhpmn\1.5.7_0\
CHR - Extension: Gravity Duck = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\khpikpdaalmlcipfphefaajfiofglcma\1.3.0_0\
CHR - Extension: Bird Brawl = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kmfmnamhddafiplkkobdinpjcnidlplk\1.0.0.0_0\
CHR - Extension: Super Mario World - HD = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pailmekhfbjjgajlehgifomabggldfff\5.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Wolf Toss = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjlncddmdljpioccbmempchonhlifakc\1.1.2.6_0\
CHR - Extension: Cargo Bridge 2 = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pmphjijgcdpmmnfjbemolkdiidinogml\1.0.0_0\
CHR - Extension: Canvas Rider = C:\Documents and Settings\Ruth\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk\0.71_0\
O1 HOSTS File: ([2002/08/29 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Claro LTD Helper Object) - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files\Claro LTD\claro\1.8.3.10\bh\claro.dll File not found
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar4.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll File not found
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar4.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Claro LTD Toolbar) - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - C:\Program Files\Claro LTD\claro\1.8.3.10\claroTlbr.dll File not found
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar4.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: UseDesktopIniCache = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx File not found
O8 - Extra context menu item: Open in new background tab - C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui (Microsoft Corporation)
O8 - Extra context menu item: Open in new foreground tab - C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} http://zone.msn.com/...pandaonline.cab (Reg Error: Key error.)
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} http://zone.msn.com/...pcaploader1.cab (PopCapLoaderCtrl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A6763437-438C-4BBF-A84B-0C3B32E20F8D}: DhcpNameServer = 10.0.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Ruth\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ruth\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 09:59:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/04/23 11:19:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ruth\Desktop\fbi money pan, no safe networking mode - Geeks to Go Forums_files
[2013/04/23 11:17:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ruth\Desktop\Malware and Spyware Cleaning Guide - Geeks to Go Forums_files
[2013/04/23 11:16:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ruth\Desktop\OTL.exe
[2013/04/23 11:08:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2013/04/22 05:15:28 | 000,000,000 | ---D | C] -- C:\3590F75ABA9E485486C100C1A9D4FF06ZZ..ZZ.Z.ZZ..ZZZ
[2013/04/22 05:14:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ruth\Recent
[2012/09/12 12:45:02 | 000,311,296 | ---- | C] (Microsoft Corporation) -- C:\Program Files\sndvol32.exe
[2012/08/24 18:31:27 | 001,384,448 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvbvm60.dll
[2012/08/24 18:31:27 | 001,021,232 | ---- | C] (Microsoft Corporation) -- C:\Program Files\tv_enua.exe
[2012/08/24 18:31:27 | 000,955,656 | ---- | C] (Microsoft Corporation) -- C:\Program Files\spchcpl.exe
[2012/08/24 18:31:27 | 000,598,288 | ---- | C] (Microsoft Corporation) -- C:\Program Files\OLEAUT32.DLL
[2012/08/24 18:31:27 | 000,286,720 | ---- | C] (Microsoft Corporation) -- C:\Program Files\SETUP1.EXE
[2012/08/24 18:31:27 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Program Files\VTEXT.DLL
[2012/08/24 18:31:27 | 000,164,112 | ---- | C] (Microsoft Corporation) -- C:\Program Files\OLEPRO32.DLL
[2012/08/24 18:31:27 | 000,147,728 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ASYCFILT.DLL
[2012/08/24 18:31:27 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Program Files\VB6STKIT.DLL
[2012/08/24 18:31:27 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ST6UNST.EXE
[2012/08/24 18:31:27 | 000,061,440 | ---- | C] (Slackker) -- C:\Program Files\Talking Math Tutor.exe
[2012/08/24 18:31:27 | 000,022,288 | ---- | C] (Microsoft Corporation) -- C:\Program Files\COMCAT.DLL
[2012/08/24 18:31:27 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Program Files\STDOLE2.TLB
[2006/07/04 19:06:11 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Ruth\My Documents\*.tmp files -> C:\Documents and Settings\Ruth\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/04/23 14:35:00 | 000,000,256 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2013/04/23 14:24:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/04/23 14:17:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/23 14:00:03 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2013/04/23 11:19:28 | 000,083,512 | ---- | M] () -- C:\Documents and Settings\Ruth\Desktop\fbi money pan, no safe networking mode - Geeks to Go Forums.htm
[2013/04/23 11:17:55 | 000,102,592 | ---- | M] () -- C:\Documents and Settings\Ruth\Desktop\Malware and Spyware Cleaning Guide - Geeks to Go Forums.htm
[2013/04/23 11:16:21 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ruth\Desktop\OTL.exe
[2013/04/23 11:06:24 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/04/23 11:05:07 | 000,000,311 | ---- | M] () -- C:\Documents and Settings\Ruth\Local Settings\Application Data\poetsch.bat
[2013/04/23 10:59:27 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2013/04/23 10:56:06 | 000,001,252 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2013/04/23 10:55:48 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/23 10:55:46 | 000,000,508 | ---- | M] () -- C:\WINDOWS\tasks\SpeedyPC Update Version3 Startup Task.job
[2013/04/23 10:54:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2013/04/23 10:54:41 | 000,356,952 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/04/23 06:51:04 | 000,457,256 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2013/04/23 06:51:04 | 000,075,754 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2013/04/23 06:44:34 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/04/23 05:34:50 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2013/04/22 20:40:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2013/04/22 17:29:48 | 008,308,875 | ---- | M] () -- C:\Documents and Settings\Ruth\Desktop\lecture_audio.mp3
[2013/04/22 17:20:36 | 008,308,875 | ---- | M] () -- C:\Documents and Settings\Ruth\Desktop\comp14_unit1_lecture_audio.mp3
[2013/04/22 11:48:13 | 037,847,756 | ---- | M] () -- C:\Program Files\PF.Magic.zip
[2013/04/22 10:44:08 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2013/04/22 10:10:13 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Ruth\My Documents\*.tmp files -> C:\Documents and Settings\Ruth\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/04/23 11:19:26 | 000,083,512 | ---- | C] () -- C:\Documents and Settings\Ruth\Desktop\fbi money pan, no safe networking mode - Geeks to Go Forums.htm
[2013/04/23 11:17:46 | 000,102,592 | ---- | C] () -- C:\Documents and Settings\Ruth\Desktop\Malware and Spyware Cleaning Guide - Geeks to Go Forums.htm
[2013/04/23 11:05:07 | 000,000,311 | ---- | C] () -- C:\Documents and Settings\Ruth\Local Settings\Application Data\poetsch.bat
[2013/04/23 05:44:12 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/04/23 04:45:36 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2013/04/23 02:48:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2013/04/23 02:48:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2013/04/22 17:28:43 | 008,308,875 | ---- | C] () -- C:\Documents and Settings\Ruth\Desktop\lecture_audio.mp3
[2013/04/22 17:19:05 | 008,308,875 | ---- | C] () -- C:\Documents and Settings\Ruth\Desktop\comp14_unit1_lecture_audio.mp3
[2013/04/22 11:48:13 | 037,847,756 | ---- | C] () -- C:\Program Files\PF.Magic.zip
[2013/04/22 05:20:42 | 000,356,952 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/05 17:32:08 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2012/11/05 17:24:25 | 000,107,520 | RHS- | C] () -- C:\WINDOWS\System32\TAKDSDecoder.dll
[2012/10/17 19:18:19 | 000,006,096 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/10/16 01:20:31 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/10/07 11:32:22 | 000,025,600 | ---- | C] () -- C:\Documents and Settings\Ruth\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/05 13:31:33 | 000,000,032 | R--- | C] () -- C:\Documents and Settings\All Users\hash.dat
[2012/09/12 12:45:02 | 000,188,029 | ---- | C] () -- C:\Program Files\preview.png
[2012/09/12 10:43:12 | 000,000,057 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Ament.ini
[2012/08/24 14:39:11 | 000,065,536 | -H-- | C] () -- C:\WINDOWS\System32\WebCamLib.dll
[2008/05/08 18:18:01 | 000,000,000 | ---- | C] () -- C:\Program Files\temp01
[2004/12/04 13:19:56 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Ruth\Local Settings\Application Data\fusioncache.dat
[2003/11/29 08:55:00 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\Ruth\Application Data\PFP110JPR.{PB
[2003/11/29 08:55:00 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\Ruth\Application Data\PFP110JCM.{PB
========== ZeroAccess Check ==========
[2003/11/20 09:30:01 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll -- [2008/04/13 19:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 19:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/09/26 10:55:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\.mono
[2013/02/06 20:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\APN
[2008/10/11 17:53:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Astar Games
[2008/10/18 17:20:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem
[2004/08/27 13:42:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BF8051E7-626F-4a11-AF7A-625A7B555862
[2012/11/12 17:50:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Browser Manager
[2006/11/11 19:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA
[2007/08/31 16:12:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Enkord
[2008/09/27 18:23:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2008/10/24 16:15:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2008/10/03 18:34:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FloodLightGames
[2008/08/25 11:37:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreshGames
[2008/09/27 20:39:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2007/04/27 14:50:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gamelab
[2006/12/11 00:12:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Genimo
[2008/10/21 19:17:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Go Go Gourmet
[2008/11/09 13:38:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii
[2008/12/20 10:15:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii Games
[2007/02/16 18:57:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
[2008/03/28 16:45:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2008/05/31 14:31:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lifetime
[2012/10/16 18:12:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
[2008/10/20 18:56:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MonteCristo
[2008/11/05 19:55:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/11/08 19:25:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\My Games
[2008/11/02 21:42:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MythPeople
[2007/06/01 15:55:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008/09/17 19:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NeptunesAdve
[2007/01/15 20:48:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Norbyte
[2009/02/01 15:33:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/05/11 13:42:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayPond
[2008/09/27 22:37:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2006/09/16 02:29:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayTime
[2007/09/01 18:37:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PrettyGoodGames
[2012/08/22 18:15:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidTyping
[2007/11/28 17:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2006/07/28 20:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SonyPicturesGames
[2012/10/17 19:35:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
[2008/09/27 17:05:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/05/17 14:52:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SugarGames
[2010/05/13 18:14:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2013/02/10 15:09:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/08/30 14:01:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TERMINAL Studio
[2004/09/19 18:00:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Learning Company
[2008/10/17 15:07:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TheRace_dev
[2007/06/09 21:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ValuSoft
[2004/08/27 10:16:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Visual Networks
[2008/05/11 15:07:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2012/09/26 10:55:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\.mono
[2007/12/12 20:38:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Age of Japan II
[2008/02/04 18:58:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\AlwaysNeat
[2008/09/04 19:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Ancient Quest of Saqqarah__real
[2008/10/03 19:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Angkor
[2012/08/24 14:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Apowersoft
[2006/11/05 21:35:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Beep Industries
[2007/05/21 13:49:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\BFGTOOLBAR
[2007/09/03 11:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Big Fish Games
[2006/12/09 16:41:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Boomzap
[2008/10/16 18:49:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\cerasus.media
[2007/02/13 16:59:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Chicken Chase
[2013/01/31 21:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Claro LTD
[2008/11/12 11:24:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/11/12 17:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\CrystalIdea Software
[2013/04/22 04:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Dropbox
[2006/11/11 19:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\EA
[2007/10/11 18:47:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\EleFun Games
[2009/02/02 22:18:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Fabulous Finds
[2008/10/24 16:15:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Flood Light Games
[2008/10/03 18:34:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\FloodLightGames
[2009/02/09 22:34:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\ForgottenRiddles2
[2008/10/07 17:44:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Friday's games
[2007/10/05 19:27:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Gaijin Ent
[2007/07/04 13:05:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\GameHouse
[2007/04/27 14:50:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\gamelab
[2008/11/08 19:50:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\gemsweeperextractedgfx
[2006/12/11 00:07:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Genimo
[2012/08/11 21:28:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\GetRightToGo
[2008/12/20 10:15:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Gogii Games
[2008/09/07 17:05:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\ITTNord
[2007/11/28 16:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Jane s Hotel
[2008/12/29 17:27:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\JewelMatch2
[2003/11/28 21:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Leadertech
[2006/04/26 14:30:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Magic Match
[2012/10/08 01:45:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\MAGIX
[2008/10/24 19:50:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Meridian93
[2008/05/18 16:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\My Games
[2008/05/26 20:41:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\MysteryStudio
[2008/08/06 20:17:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Mysteryville2
[2007/01/15 20:48:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Norbyte
[2012/08/23 21:54:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\OpenOffice.org
[2008/02/03 14:14:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Pirateville
[2006/11/01 23:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\pixelStorm
[2009/02/01 15:33:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\PlayFirst
[2008/07/09 17:37:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Playrix Entertainment
[2012/08/22 18:15:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\RapidTyping
[2008/05/10 21:51:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Restorer
[2008/11/09 17:08:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Righteous Kill
[2013/04/22 21:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\spiral
[2013/02/13 18:35:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\splitscreen
[2008/12/22 18:13:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\SprillBermudeEng
[2012/09/12 11:28:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Styler
[2012/10/24 15:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\SumatraPDF
[2007/11/09 17:43:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Super-Cow
[2012/10/05 13:26:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Unity
[2007/09/22 18:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\VeniceMysteryData
[2012/10/11 22:47:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Warsow 1.0
[2006/05/14 18:34:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ruth\Application Data\Wildfire
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:861A898F
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6390D9FB
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:70E897B5
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:221F35CC
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D507AEDA
@Alternate Data Stream - 440 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06ZZ..ZZ.Z.ZZ..ZZZ:1
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F098C56D
@Alternate Data Stream - 182 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4220A65C
@Alternate Data Stream - 180 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BF4BA1F5
@Alternate Data Stream - 178 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1677AB3F
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E8F2B426
@Alternate Data Stream - 170 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:86FA1A34
@Alternate Data Stream - 167 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4C4BD503
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AB0BFA84
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1F86F437
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E0BB7B35
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:687D1056
@Alternate Data Stream - 161 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:23C6969A
@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:10861A5E
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:85F3AC32
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:81F83028
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:09D0186E
@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AB6C1D7
@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D63538E3
@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CC2686CD
@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8C065E0D
@Alternate Data Stream - 154 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B4DCBA8B
@Alternate Data Stream - 154 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8961A52
@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:258F3E77
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91B3E405
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C79FB81
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A47E53E8
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:053FEC11
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9371B810
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:75B1A93C
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5814AB4F
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E1EA0D54
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8A0F20CD
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:766442E5
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2753F1AE
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1792752F
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8D93F5F7
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71236697
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:067DB605
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3EAFDE57
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9A953997
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2AFE59F2
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60516BC3
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B4A0E23
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:45292A84
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07FFC655
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7290F122
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B337D07E
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9398DBB4
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8D02044C
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3214A283
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9E22BBE8
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:981884E7
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C3E753C
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D24FC46
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DAC3B29
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:38020A20
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D055FC10
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B3A35EC
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48F154AF
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DEF96BC8
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B9710577
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:814B9485
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:370EF5E8
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:03392111
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C213B3C4
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:45FE2B4E
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BCAA2E9
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED66F190
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AB6E0B6B
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:92D18A5E
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48FEA089
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3327BC4F
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FD93CF96
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E3C56885
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BDD83DC4
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A360D1FA
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6EC66C03
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:353B7B11
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:090FB735
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4C1D9362
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CCF42AF8
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:22786385
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:95B8F7F6
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B6F784D3
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F65733F1
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C3A4217C
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F54261D3
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9124CA95
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BAD46F6
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B845F669
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B79AEF3
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F8DACDD8
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7F66BF58
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59D05D9A
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:192F4D18
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C4DF735
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5D7E5A8F
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F8104EE7
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E98C5DD9
< End of report >