Going to be largely away until Monday, so I hope it runs OK from in Safe Mode. The log file complained about it, but the actions seem to have taken place. Let me know if "Fix" in FRST was supposed to do more:
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 20-07-2012
Ran by Administrator at 2012-07-21 16:39:46 Run:1
Running from E:\cleanup
ATTENTION: THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
==============================================
C:\Documents and Settings\All Users\Application Data\-Eqhhx9McQjouuwr moved successfully.
C:\Documents and Settings\All Users\Application Data\-Eqhhx9McQjouuw moved successfully.
C:\Documents and Settings\All Users\Application Data\Eqhhx9McQjouuw moved successfully.
C:\Documents and Settings\kristine\1ee7e578-5753.exe moved successfully.
==== End of Fixlog ====
OTL logfile created on: 7/21/2012 5:56:57 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 772.00 Mb Available Physical Memory | 76.00% Memory free
902.00 Mb Paging File | 844.00 Mb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.58 Gb Total Space | 113.07 Gb Free Space | 77.67% Space Free | Partition Type: NTFS
Drive D: | 7.52 Gb Total Space | 2.29 Gb Free Space | 30.42% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet004
========== Win32 Services (SafeList) ==========
SRV - [2012/07/12 18:25:51 | 000,136,616 | -H-- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2012/07/12 18:25:15 | 000,374,184 | -H-- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2012/07/12 11:14:58 | 000,250,056 | -H-- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/23 17:41:45 | 000,086,856 | -H-- | M] (Zenith Infotech Ltd) [Auto] -- C:\Program Files\SAAZOD\SAAZWatchDog.exe -- (SAAZWatchDog)
SRV - [2012/02/23 17:41:45 | 000,086,856 | -H-- | M] (Zenith Infotech Ltd) [Auto] -- C:\Program Files\SAAZOD\SAAZDPMACTL.exe -- (SAAZDPMACTL)
SRV - [2012/02/23 17:41:45 | 000,078,664 | -H-- | M] (Zenith Infotech Ltd) [Auto] -- C:\Program Files\SAAZOD\SAAZRemoteSupport.exe -- (SAAZRemoteSupport)
SRV - [2012/02/23 17:26:24 | 000,077,824 | -H-- | M] (Zenith Infotech Ltd) [Auto] -- C:\Program Files\SAAZOD\SAAZScheduler.exe -- (SAAZScheduler)
SRV - [2011/08/09 13:31:24 | 000,230,216 | -H-- | M] (Zenith Infotech ltd.) [Disabled] -- C:\Program Files\SAAZOD\zSCC\zEvtSVC.exe -- (ZEvtSVC)
SRV - [2011/05/31 14:15:16 | 000,082,760 | -H-- | M] (Zenith Infotech Ltd) [Auto] -- C:\Program Files\SAAZOD\zRealTime\SAAZapsc.exe -- (SAAZapsc)
SRV - [2011/05/31 14:14:38 | 000,082,760 | -H-- | M] (Zenith Infotech Ltd) [Auto] -- C:\Program Files\SAAZOD\zRealTime\SAAZappr.exe -- (SAAZappr)
SRV - [2011/04/18 14:11:40 | 000,028,672 | -H-- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2011/02/15 14:12:51 | 000,389,960 | -H-- | M] (CA) [Auto] -- C:\Program Files\CA\eTrustITM\InoTask.exe -- (InoTask)
SRV - [2010/11/08 13:04:20 | 000,390,528 | -H-- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2009/12/07 16:19:18 | 000,283,888 | -H-- | M] (CA, Inc.) [Auto] -- C:\Program Files\CA\SharedComponents\PPRealtime\bin\ITMRTSVC.exe -- (ITMRTSVC)
SRV - [2009/09/29 15:23:54 | 000,192,512 | -H-- | M] (CA) [Auto] -- C:\Program Files\CA\eTrustITM\InoRpc.exe -- (InoRPC)
SRV - [2009/09/29 15:23:53 | 000,208,896 | -H-- | M] (CA) [Auto] -- C:\Program Files\CA\eTrustITM\InoRT.exe -- (InoRT)
SRV - [2009/09/16 19:22:08 | 000,020,480 | -H-- | M] (Intuit) [Auto] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2009/04/30 20:46:58 | 000,077,824 | -H-- | M] (Zenith Infotech Ltd) [Auto] -- C:\Program Files\SAAZOD\SAAZServerPlus.exe -- (SAAZServerPlus)
SRV - [2007/08/03 19:10:46 | 000,644,408 | -H-- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2007/07/11 23:38:44 | 000,569,344 | -H-- | M] () [Auto] -- C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe -- (TVT Backup Protection Service)
SRV - [2007/07/11 22:19:00 | 000,045,056 | -H-- | M] () [Auto] -- C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe -- (tvtnetwk)
SRV - [2007/05/24 07:08:44 | 000,061,440 | -H-- | M] (Intuit Inc.) [On_Demand] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2007/02/05 07:57:24 | 000,106,496 | -H-- | M] (CA, Inc.) [Auto] -- C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe -- (iGateway)
SRV - [2007/01/04 22:48:52 | 000,112,152 | RH-- | M] (InterVideo) [Auto] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2007/01/04 17:38:08 | 000,024,652 | -H-- | M] (Viewpoint Corporation) [Auto] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/09/13 10:32:12 | 000,128,536 | -H-- | M] (iAnywhere Solutions, Inc.) [Auto] -- C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe -- (QuickBooksDB18)
SRV - [2006/05/23 23:08:06 | 000,622,700 | -H-- | M] (Diskeeper Corporation) [Auto] -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2006/02/23 12:41:02 | 002,045,632 | -H-- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate)
SRV - [2005/10/06 21:12:30 | 000,855,552 | -H-- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Media Connect 2\wmccds.exe -- (WMConnectCDS)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (USBAAPL)
DRV - File not found [Kernel | On_Demand] -- -- (TVTPktFilter)
DRV - File not found [Kernel | On_Demand] -- -- (SymIMMP)
DRV - File not found [Kernel | On_Demand] -- -- (SymIM)
DRV - File not found [Kernel | System] -- -- (SASKUTIL)
DRV - File not found [Kernel | System] -- -- (SASDIFSV)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand] -- -- (mcdbus)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2012/01/31 22:30:34 | 000,083,360 | -H-- | M] (LogMeIn, Inc.) [File_System | Disabled] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2010/09/17 16:40:06 | 000,012,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | Auto] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2008/04/29 04:00:00 | 000,288,896 | -H-- | M] (Marvell) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2007/10/22 04:41:34 | 004,622,848 | -H-- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/10/18 21:14:32 | 000,184,080 | -H-- | M] (Computer Associates) [File_System | Auto] -- C:\WINDOWS\system32\drivers\ino_fltr.sys -- (INO_FLTR)
DRV - [2007/08/06 22:07:02 | 000,027,536 | -H-- | M] (Computer Associates) [File_System | Boot] -- C:\WINDOWS\system32\drivers\ino_flpy.sys -- (INO_FLPY)
DRV - [2007/05/22 18:59:38 | 000,030,336 | -H-- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tvti2c.sys -- (TVTI2C)
DRV - [2007/05/22 03:59:34 | 000,021,376 | -H-- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
DRV - [2006/02/02 08:20:00 | 000,094,332 | -H-- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/02/02 08:20:00 | 000,087,036 | -H-- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/02/02 08:20:00 | 000,086,652 | -H-- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/02/02 08:20:00 | 000,025,628 | -H-- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/02/02 08:20:00 | 000,014,684 | -H-- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/02/02 08:20:00 | 000,006,364 | -H-- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/02/02 08:20:00 | 000,002,496 | -H-- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/11/18 15:02:50 | 000,005,660 | -H-- | M] (Sonic Solutions) [File_System | System] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/11/18 15:02:10 | 000,022,684 | -H-- | M] (Sonic Solutions) [File_System | System] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2003/02/11 16:25:14 | 000,009,216 | -H-- | M] (Primax Electronics Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\PELUSBLF.SYS -- (pelusblf)
DRV - [2003/01/10 16:55:32 | 000,016,384 | -H-- | M] (Primax Electronics Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\PELMOUSE.SYS -- (pelmouse)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator.SMALLBUSINESS_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo.live.com
IE - HKU\Administrator.SMALLBUSINESS_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\Administrator.SMALLBUSINESS_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\Administrator.SMALLBUSINESS_ON_C\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\Administrator.SMALLBUSINESS_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
IE - HKU\Administrator.SMALLBUSINESS_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo.live.com
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\audrey_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\audrey_ON_C\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\audrey_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
IE - HKU\audrey_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\kristine_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo.live.com
IE - HKU\kristine_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\kristine_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\kristine_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\kristine_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.aol.com/?mtmhp=txtlnkusaolp00000051
IE - HKU\kristine_ON_C\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKU\kristine_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\kristine_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\LogMeInRemoteUser_ON_C\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\LogMeInRemoteUser_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
IE - HKU\LogMeInRemoteUser_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\QBDataServiceUser18_ON_C\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkcentre [binary data]
IE - HKU\QBDataServiceUser18_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
IE - HKU\QBDataServiceUser18_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2012/06/22 10:04:41 | 000,000,761 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (AOL Messaging Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (AOL Messaging Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\Administrator.SMALLBUSINESS_ON_C\..\Toolbar\WebBrowser: (AOL Messaging Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKU\Administrator.SMALLBUSINESS_ON_C\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\audrey_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKU\audrey_ON_C\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\kristine_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKU\kristine_ON_C\..\Toolbar\WebBrowser: (AOL Messaging Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKU\kristine_ON_C\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [Realtime Monitor] C:\Program Files\CA\eTrustITM\realmon.exe (CA)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator.SMALLBUSINESS_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\Administrator.SMALLBUSINESS_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\audrey_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\audrey_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\kristine_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\kristine_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\kristine_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LogMeInRemoteUser_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\LogMeInRemoteUser_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\QBDataServiceUser18_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\QBDataServiceUser18_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.25 24.225.193.110 24.225.193.111 208.67.222.222 208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = smallbusiness.local
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: <Company name>)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/30 03:13:35 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{8e2c3f6f-b3c3-11e0-8132-0021971730ba}\Shell - "" = AutoRun
O33 - MountPoints2\{8e2c3f6f-b3c3-11e0-8132-0021971730ba}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8e2c3f6f-b3c3-11e0-8132-0021971730ba}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/07/20 15:29:44 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/20 14:07:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop\CC Support
[2012/07/19 17:08:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kristine\Application Data\SUPERAntiSpyware.com
[2012/07/19 17:08:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2012/07/19 17:01:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kristine\Application Data\Malwarebytes
[2012/07/19 17:01:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/19 17:01:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/07/19 17:01:16 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/07/19 17:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/07/19 15:57:44 | 000,000,000 | --SD | C] -- C:\cfx
[2012/07/19 15:41:43 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\kristine\Desktop\aswMBR.exe
[2012/07/19 15:33:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\FixTDSS
[2012/07/19 15:30:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2012/07/19 15:28:36 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\kristine\Recent
[2012/07/19 10:38:30 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/07/19 10:32:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/07/19 10:32:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/07/19 10:32:47 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/07/19 10:32:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/07/19 10:31:33 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012/07/19 10:29:56 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/19 10:28:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012/07/19 09:56:03 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\kristine\Start Menu\Programs\File Recovery
[2012/06/22 15:24:32 | 000,000,000 | -H-D | C] -- C:\WINDOWS\pss
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/21 16:50:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/07/21 15:31:57 | 000,002,278 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/07/19 17:06:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/19 16:50:51 | 000,000,355 | RHS- | M] () -- C:\boot.ini
[2012/07/19 15:38:52 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\kristine\Desktop\aswMBR.exe
[2012/07/19 15:27:53 | 000,000,236 | -H-- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2012/07/19 15:27:51 | 000,000,882 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/19 10:38:22 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/07/19 10:12:07 | 000,000,245 | ---- | M] () -- C:\Boot.bak
[2012/07/19 09:55:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2012/07/19 09:55:45 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2012/07/19 09:55:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\ThinkVantage
[2012/07/19 09:55:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Syscan
[2012/07/19 09:55:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy SBE
[2012/07/19 09:55:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Remote Support
[2012/07/19 09:55:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks
[2012/07/19 09:55:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Picasa2
[2012/07/19 09:55:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Multimedia Center For Think Offerings
[2012/07/19 09:55:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\PrintMe Internet Printing
[2012/07/19 09:55:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\PC-Doctor 5 for Windows
[2012/07/19 09:55:44 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Mouse
[2012/07/19 09:55:44 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
[2012/07/19 09:55:44 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\JMA
[2012/07/19 09:55:44 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\HP
[2012/07/19 09:55:43 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2012/07/19 09:55:43 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2012/07/19 09:55:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Desktop
[2012/07/19 09:55:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Diskeeper Corporation
[2012/07/19 09:55:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\AIM
[2012/07/19 09:55:42 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2012/07/19 09:50:00 | 000,000,256 | -H-- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2012/07/19 09:47:26 | 000,000,564 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\106.7 Lite fm - 106.7 Lite fm New York.url
[2012/07/19 09:20:00 | 000,000,886 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/19 09:14:00 | 000,000,830 | -H-- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/19 09:13:47 | 000,318,531 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\ERBOE.jpg
[2012/07/19 09:07:10 | 000,002,521 | ---- | M] () -- C:\Documents and Settings\kristine\Desktop\Microsoft Office Outlook 2003.lnk
[2012/07/19 00:42:54 | 000,445,452 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/07/19 00:42:54 | 000,073,202 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/07/19 00:35:11 | 000,001,374 | -H-- | M] () -- C:\WINDOWS\imsins.BAK
[2012/07/17 15:01:48 | 000,011,778 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\Intuit.pdf
[2012/07/17 10:14:23 | 000,000,322 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\PNC Bank.url
[2012/07/16 15:17:23 | 000,011,778 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\ERutherford.pdf
[2012/07/16 10:46:58 | 000,233,455 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\cosco.jpg
[2012/07/12 18:25:15 | 000,087,456 | -H-- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIinit.dll
[2012/07/12 18:25:15 | 000,030,624 | -H-- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIport.dll
[2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/06/28 09:42:34 | 000,309,173 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\carrabbas.jpg
[2012/06/26 13:07:07 | 000,134,731 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\louie.jpg
[2012/06/22 15:24:11 | 000,001,116 | -H-- | M] () -- C:\IPH.PH
[2012/06/22 15:22:20 | 000,002,029 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\Retry AIM Installation.lnk
[2012/06/22 14:46:20 | 000,360,823 | -H-- | M] () -- C:\Documents and Settings\kristine\Desktop\Better Proposal for Louie.jpg
[2012/06/22 10:04:41 | 000,000,761 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-000705.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120717-001837.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120717-001734.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120717-001629.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120716-003026.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120716-002925.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120716-002824.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120713-003030.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120713-002927.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120713-002755.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120710-002002.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120710-001900.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120710-001758.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-002508.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-002405.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-002258.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120706-002327.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120706-002226.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120706-002121.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120703-001444.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120703-001340.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120703-001236.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120702-002509.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120702-002407.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120702-002300.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120629-002334.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120629-002231.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120629-002112.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120626-001514.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120626-001413.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120626-001312.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-000908.backup
[2012/06/22 10:04:41 | 000,000,761 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-000807.backup
[2012/06/22 10:04:41 | 000,000,761 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120719-171050.backup
[2012/06/22 10:04:41 | 000,000,761 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/06/22 00:28:43 | 000,440,483 | RH-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120622-002956.backup
[2012/06/22 00:27:33 | 000,440,483 | RH-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120622-002843.backup
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/19 10:38:46 | 000,000,245 | ---- | C] () -- C:\Boot.bak
[2012/07/19 10:38:34 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/07/19 10:32:47 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/07/19 10:32:47 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/07/19 10:32:47 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/07/19 10:32:47 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/07/19 10:32:47 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/07/19 10:32:29 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/07/19 09:13:26 | 000,318,531 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\ERBOE.jpg
[2012/07/17 15:01:35 | 000,011,778 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\Intuit.pdf
[2012/07/16 15:17:09 | 000,011,778 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\ERutherford.pdf
[2012/07/16 10:46:04 | 000,233,455 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\cosco.jpg
[2012/06/28 09:41:39 | 000,309,173 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\carrabbas.jpg
[2012/06/26 13:02:06 | 000,134,731 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\louie.jpg
[2012/06/22 15:23:17 | 000,000,830 | -H-- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/22 15:22:15 | 000,002,029 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\Retry AIM Installation.lnk
[2012/06/22 14:45:26 | 000,360,823 | -H-- | C] () -- C:\Documents and Settings\kristine\Desktop\Better Proposal for Louie.jpg
[2012/04/26 11:11:31 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\kristine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/16 02:17:16 | 000,003,072 | -H-- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/01/17 00:26:54 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Administrator.SMALLBUSINESS\Ÿ9Ÿ9
[2009/08/03 15:07:42 | 000,403,816 | -H-- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H-- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/04/13 14:16:40 | 004,111,360 | -H-- | C] () -- C:\Program Files\Common Files\Remote Deposit Client.msi
[2008/11/13 15:17:27 | 000,007,680 | -H-- | C] () -- C:\Documents and Settings\audrey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/13 13:29:24 | 000,157,672 | -H-- | C] () -- C:\WINDOWS\hpoins28.dat
[2008/11/13 13:29:24 | 000,000,932 | -H-- | C] () -- C:\WINDOWS\hpomdl28.dat
[2008/11/12 12:17:39 | 000,000,376 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2008/10/10 13:27:08 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2008/10/10 13:06:15 | 000,114,688 | -H-- | C] () -- C:\WINDOWS\desktopset.exe
[2008/10/10 13:02:46 | 000,204,800 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2008/10/10 13:02:46 | 000,200,704 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2008/10/10 13:02:46 | 000,192,512 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2008/10/10 13:02:46 | 000,192,512 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2008/10/10 13:02:46 | 000,188,416 | -H-- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2008/10/10 13:02:46 | 000,020,480 | -H-- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2008/10/10 13:00:59 | 000,000,124 | -H-- | C] () -- C:\WINDOWS\wininit.ini
[2008/10/10 12:56:28 | 000,147,456 | -H-- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4873.dll
[2008/10/10 12:56:14 | 000,049,152 | -H-- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/10/10 12:55:47 | 000,005,528 | -H-- | C] () -- C:\WINDOWS\System32\Setup2k.ini
[2008/10/10 12:55:47 | 000,000,296 | -H-- | C] () -- C:\WINDOWS\System32\presetup.ini
[2008/10/10 12:55:46 | 000,024,576 | -H-- | C] () -- C:\WINDOWS\System32\FSRremoC.DLL
[2008/10/10 12:55:46 | 000,020,480 | -H-- | C] () -- C:\WINDOWS\System32\FSRremoS.EXE
[2008/10/10 12:51:22 | 000,000,138 | -H-- | C] () -- C:\WINDOWS\System32\Softkbd.exe.config
[2007/02/19 15:15:38 | 000,331,264 | -H-- | C] () -- C:\WINDOWS\System32\DP485WIA.dll
[2007/01/16 11:12:12 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\px.ini
[2006/09/05 17:20:36 | 000,079,400 | -H-- | C] () -- C:\WINDOWS\System32\DEVMAN.DLL
[2006/04/30 03:31:51 | 000,004,670 | -H-- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/04/30 03:22:10 | 000,000,791 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2006/04/30 03:19:56 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/04/30 03:10:07 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/04/30 02:55:59 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/04/30 02:55:55 | 000,445,452 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/04/30 02:55:55 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/04/30 02:55:55 | 000,073,202 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/04/30 02:55:55 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/04/30 02:55:54 | 000,004,547 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/04/30 02:55:52 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/04/30 02:55:50 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/04/30 02:55:44 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/04/30 02:55:44 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/04/30 02:55:37 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/04/30 02:55:28 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/04/29 20:04:28 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/04/29 20:03:29 | 000,282,928 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/01/07 16:05:08 | 000,002,695 | -H-- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2008/10/10 13:11:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Administrator.SMALLBUSINESS\Application Data\Lenovo
[2012/07/19 15:33:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\FixTDSS
[2008/10/10 13:11:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Administrator\Application Data\Lenovo
[2008/10/10 13:11:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\audrey\Application Data\Lenovo
[2010/01/28 12:37:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\kristine\Application Data\3M
[2010/09/23 13:13:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\kristine\Application Data\acccore
[2010/01/28 12:36:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\kristine\Application Data\GetRightToGo
[2008/10/10 13:11:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\kristine\Application Data\Lenovo
[2010/11/19 12:58:11 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\kristine\Application Data\PriceGong
[2009/05/19 08:04:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\kristine\Application Data\Viewpoint
[2008/10/10 13:11:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\LogMeInRemoteUser\Application Data\Lenovo
[2008/10/10 13:11:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\QBDataServiceUser18\Application Data\Lenovo
[2010/09/23 13:11:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
[2008/11/18 13:03:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2008/11/13 14:24:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2010/09/09 14:50:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\DNC
[2010/01/04 11:54:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
[2009/04/15 15:30:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\kinoma
[2008/10/10 13:11:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Lenovo
[2012/07/20 10:17:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/04/15 15:31:23 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Marlin
[2009/04/13 13:56:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2008/10/10 13:14:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\PC-Doctor
[2009/04/13 13:55:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Syscan
[2010/05/10 13:53:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/10 09:56:14 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/01/16 10:02:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/19 09:50:00 | 000,000,256 | -H-- | M] () -- C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2012/07/19 15:27:53 | 000,000,236 | -H-- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 834 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:35E5AF34
< End of report >