OTL Log posted below
Used OTLPE to run OTL (thanks Broni for this).
Ran OTL on the Dell, result below - have had to split into two posts, got error message stating too many characters for one post, sorry.
OTL log reads
OTL logfile created on: 3/16/2012 7:42:44 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 84.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): c:\pagefile.sys 372 744 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 16.28 Gb Free Space | 21.86% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled] -- -- (ioloSystemService)
SRV - File not found [Disabled] -- -- (ioloFileInfoList)
SRV - File not found [Auto] -- -- (AMService)
SRV - [2012/02/27 17:24:32 | 000,045,056 | ---- | M] (Intuit) [Auto] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2012/02/27 14:37:34 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2012/02/27 14:36:44 | 000,679,936 | ---- | M] (Intuit, Inc.) [On_Demand] -- C:\Program Files\Intuit\QuickBooks 2010\QBDBMgrN.exe -- (QuickBooksDB22)
SRV - [2011/11/03 14:25:09 | 002,358,656 | ---- | M] (TeamViewer GmbH) [Auto] -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011/10/07 10:17:48 | 000,136,584 | ---- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2011/10/07 10:17:33 | 000,374,152 | ---- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2011/04/27 10:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/01/11 14:04:04 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2010/12/07 16:18:00 | 003,979,632 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2010/07/16 04:05:56 | 000,028,762 | ---- | M] (MyWebSearch.com) [Auto] -- C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE -- (MyWebSearchService)
SRV - [2009/07/07 09:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2008/06/06 09:03:22 | 000,435,488 | ---- | M] (Pervasive Software Inc.) [Auto] -- C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe -- (psqlWGE)
SRV - [2004/03/18 12:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2012/03/16 12:22:25 | 000,098,992 | ---- | M] (Kaspersky Lab, GERT) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\22892082.sys -- (21103785)
DRV - [2011/10/07 10:17:35 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2011/01/11 14:04:04 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2011/01/11 14:04:04 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2010/11/26 14:02:52 | 000,014,776 | ---- | M] () [Kernel | Boot] -- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2010/05/31 11:38:37 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2009/07/07 09:48:44 | 000,026,672 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\purendis.sys -- (purendis)
DRV - [2009/07/07 09:48:44 | 000,025,392 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\pnarp.sys -- (pnarp)
DRV - [2007/10/08 09:38:48 | 000,174,530 | ---- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ov519vid.sys -- (ovt519)
DRV - [2005/03/31 08:22:16 | 000,180,096 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) High Definition Audio Driver (WDM)
DRV - [2005/01/04 14:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=f401415a00000000000000123f883c0b&tlver=1.4.19.19&ss=1&affID=17978
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Charlie_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\Charlie_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uk.msn.com/?ocid=iehp
IE - HKU\Charlie_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\Charlie_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6C 44 43 2B 63 65 CB 01 [binary data]
IE - HKU\Charlie_ON_C\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
IE - HKU\Charlie_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKU\Charlie_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Matthew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.blackle.com/
IE - HKU\Matthew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uk.msn.com/?ocid=iehp
IE - HKU\Matthew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\Matthew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E0 DA EA 1A 71 65 CB 01 [binary data]
IE - HKU\Matthew_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKU\Matthew_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\QBDataServiceUser19_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\QBDataServiceUser22_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (MyWebSearch.com)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\1.bin [2011/09/02 03:22:16 | 000,000,000 | ---D | M]
[2011/05/27 12:52:32 | 000,002,428 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
Hosts file not found
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKLM\..\Toolbar: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKU\Charlie_ON_C\..\Toolbar\WebBrowser: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
O3 - HKU\Matthew_ON_C\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKU\Matthew_ON_C\..\Toolbar\WebBrowser: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Search-Results)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [SmartDefrag] File not found
O4 - HKU\Matthew_ON_C..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil11c_ActiveX.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Limited.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks 2010\QBW32.EXE (Intuit Limited.)
O4 - Startup: C:\Documents and Settings\Charlie\Start Menu\Programs\Startup\AutoLogin.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 16730 = C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\msdubm.exe (nutre dogana)
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Charlie_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Charlie_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Matthew_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\QBDataServiceUser19_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\QBDataServiceUser22_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found
O16 - DPF: {04B6182D-FB75-11D4-90D2-0000B4948C7C}
http://download.cre8tiv.com/cre8tiv3dix/cre8tiv3dix.cab (cre8tiv 3Di ATL Control (Internet))
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://go.microsoft.com/fwlink/?linkid=67633 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/CursorManiaInitialSetup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1215789021796 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1215789386906 (MUWebControl Class)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1}
https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.31.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/1.4/jinstall-14_07-windows-i586.cab (Java Plug-in 1.4.1_07)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/11 07:50:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/16 12:59:03 | 004,438,270 | ---- | C] (Swearware) -- C:\Documents and Settings\Charlie\Desktop\f ddd.exe
[2012/03/16 12:22:25 | 000,098,992 | ---- | C] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\22892082.sys
[2012/03/16 12:14:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\F4D5618A000BDED60126D515D151FC4E
[2012/03/16 11:45:14 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/03/16 11:43:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charlie\Desktop\tdsskiller
[2012/03/16 11:43:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Local Settings
[2012/03/16 11:36:19 | 004,438,270 | ---- | C] (Swearware) -- C:\Documents and Settings\Charlie\Desktop\ComboFix.exe
[2012/03/16 08:03:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charlie\My Documents\SDO-HE-30
[2012/03/16 08:00:53 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Charlie\IECompatCache
[2012/03/16 07:09:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/03/16 06:55:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\Favorites
[2012/03/16 06:53:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/03/16 06:53:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/03/15 14:05:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charlie\My Documents\Simple Doc Organizer FE 3.0
[2012/03/15 14:00:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SDO
[2012/03/15 14:00:36 | 001,224,704 | ---- | C] (Atalasoft, Inc.) -- C:\WINDOWS\System32\AtalaImaging.dll
[2012/03/15 11:01:02 | 000,000,000 | R--D | C] -- C:\Documents and Settings\QBDataServiceUser22\My Documents\My Pictures
[2012/03/15 11:01:02 | 000,000,000 | R--D | C] -- C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Administrative Tools
[2012/03/15 11:01:02 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\QBDataServiceUser22\IETldCache
[2012/03/15 10:47:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop\QuickBooks Letter Templates
[2012/03/15 10:47:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop\Fizz UK Ltd - Images
[2012/03/15 10:43:25 | 000,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2012/03/15 10:40:15 | 000,000,000 | --SD | C] -- C:\Documents and Settings\QBDataServiceUser22\Application Data\Microsoft
[2012/03/15 10:40:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\QBDataServiceUser22\Application Data
[2012/03/15 10:40:15 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\QBDataServiceUser22\Cookies
[2012/03/15 10:40:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\QBDataServiceUser22\Recent
[2012/03/15 10:40:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\QBDataServiceUser22\PrintHood
[2012/03/15 10:40:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\QBDataServiceUser22\NetHood
[2012/03/15 10:40:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\QBDataServiceUser22\Local Settings
[2012/03/15 10:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QBDataServiceUser22\My Documents
[2012/03/15 10:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QBDataServiceUser22\Local Settings\Application Data\Microsoft Help
[2012/03/15 10:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QBDataServiceUser22\Local Settings\Application Data\Microsoft
[2012/03/15 10:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QBDataServiceUser22\Favorites
[2012/03/15 10:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QBDataServiceUser22\Desktop
[2012/03/15 10:40:14 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\QBDataServiceUser22\SendTo
[2012/03/15 10:40:14 | 000,000,000 | R--D | C] -- C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Startup
[2012/03/15 10:40:14 | 000,000,000 | R--D | C] -- C:\Documents and Settings\QBDataServiceUser22\Start Menu
[2012/03/15 10:40:14 | 000,000,000 | R--D | C] -- C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories
[2012/03/15 10:40:14 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\QBDataServiceUser22\Templates
[2012/03/15 10:39:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks
[2012/03/15 10:33:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nuance
[2012/03/15 10:33:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2012/03/15 10:32:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2012/03/15 10:17:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charlie\Desktop\QuickBooks 2010
[2012/03/15 10:06:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\Intuit
[2012/03/15 09:26:43 | 238,996,824 | ---- | C] (Intuit Inc.) -- C:\Documents and Settings\Charlie\Desktop\Update220r7_1213223_en_STD.exe
[2012/03/15 08:04:11 | 000,000,000 | ---D | C] -- C:\Program Files\Dynamic Ventures
[2012/03/15 08:03:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charlie\Local Settings\Application Data\Downloaded Installations
[2012/03/15 07:45:48 | 000,029,016 | ---- | C] (IObit) -- C:\WINDOWS\System32\SmartDefragBootTime.exe
[2012/03/09 13:12:06 | 002,063,920 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Charlie\Desktop\TDSSKiller.exe
[2012/02/27 14:44:14 | 001,721,752 | ---- | C] (Intuit Inc.) -- C:\WINDOWS\System32\InetClnt.dll
[2012/02/27 14:31:46 | 001,694,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\VBA6.DLL
[2012/02/27 14:31:32 | 000,741,008 | ---- | C] (FarPoint Technologies, Inc.) -- C:\WINDOWS\System32\SPR32D30.DLL
[2012/02/15 23:34:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\LocalService\IETldCache
[2007/11/28 11:19:48 | 000,184,320 | ---- | C] ( ) -- C:\WINDOWS\System32\Interop.MSXML2.dll
========== Files - Modified Within 30 Days ==========
[2012/03/16 14:27:28 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/16 13:21:42 | 000,013,668 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/16 13:01:18 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/16 13:01:04 | 000,000,238 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/03/16 12:35:24 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At34.job
[2012/03/16 12:35:00 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At33.job
[2012/03/16 12:22:25 | 000,098,992 | ---- | M] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\22892082.sys
[2012/03/16 12:17:00 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/16 12:15:46 | 000,001,324 | ---- | M] () -- C:\Documents and Settings\Charlie\Desktop\Smart Fortress 2012.lnk
[2012/03/16 12:15:20 | 000,000,112 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\hmDr01.dat
[2012/03/16 12:15:19 | 000,091,136 | ---- | M] () -- C:\WINDOWS\System32\tt7htNPy.com_
[2012/03/16 12:15:19 | 000,091,136 | ---- | M] () -- C:\WINDOWS\System32\tt7htNPy.com
[2012/03/16 12:14:56 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At48.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At46.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At44.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At42.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At40.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At47.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At45.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At43.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At41.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At39.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At38.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At36.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At32.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At30.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At28.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At26.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At37.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At35.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At31.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At29.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At27.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At25.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2012/03/16 12:11:28 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Charlie\Desktop\j07odqhh_gamer.exe
[2012/03/16 12:03:38 | 000,002,057 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/03/16 12:00:23 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/03/16 11:47:22 | 000,000,000 | -HS- | M] () -- C:\WINDOWS\System32\dds_trash_log.cmd
[2012/03/16 11:46:28 | 000,203,760 | ---- | M] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-861567501-1644491937-725345543-1008-0.dat
[2012/03/16 11:46:27 | 000,167,358 | ---- | M] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/03/16 11:43:49 | 002,063,920 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Charlie\Desktop\TDSSKiller.exe
[2012/03/16 11:43:03 | 002,044,822 | ---- | M] () -- C:\Documents and Settings\Charlie\Desktop\tdsskiller.zip
[2012/03/16 11:36:36 | 004,438,270 | ---- | M] (Swearware) -- C:\Documents and Settings\Charlie\Desktop\f ddd.exe
[2012/03/16 11:36:36 | 004,438,270 | ---- | M] (Swearware) -- C:\Documents and Settings\Charlie\Desktop\ComboFix.exe
[2012/03/16 11:32:09 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/03/16 09:07:24 | 000,001,836 | ---- | M] () -- C:\Documents and Settings\Charlie\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickBooks Pro 2012.lnk
[2012/03/16 08:07:48 | 000,073,940 | ---- | M] () -- C:\WINDOWS\unins000.dat
[2012/03/16 08:07:00 | 000,714,590 | ---- | M] () -- C:\WINDOWS\unins000.exe
[2012/03/16 07:19:23 | 000,000,664 | ---- | M] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\d3d9caps.dat
[2012/03/16 07:02:06 | 000,204,054 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\SDO-HE-30.zip
[2012/03/15 23:40:00 | 000,000,432 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Kay's Outlook.job
[2012/03/15 23:20:00 | 000,000,442 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Kay's Files Backup.job
[2012/03/15 23:06:43 | 000,526,486 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/15 23:06:43 | 000,096,342 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/15 23:00:00 | 000,000,454 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack FizzOffice2 Shared Files.job
[2012/03/15 14:05:19 | 000,000,098 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\SDOFE_PATH.ini
[2012/03/15 13:58:39 | 000,165,120 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/15 13:55:40 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/03/15 13:47:12 | 000,204,042 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\SDO-FE-30.zip
[2012/03/15 10:43:28 | 000,001,392 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\XPS Viewer EP.lnk
[2012/03/15 10:40:29 | 000,000,095 | ---- | M] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2012/03/15 10:39:58 | 000,000,000 | R--D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2012/03/15 10:39:34 | 000,002,109 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/03/15 10:39:34 | 000,001,761 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
[2012/03/15 10:39:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks
[2012/03/15 09:26:55 | 238,996,824 | ---- | M] (Intuit Inc.) -- C:\Documents and Settings\Charlie\Desktop\Update220r7_1213223_en_STD.exe
[2012/03/15 07:45:46 | 000,000,823 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Smart Defrag 2.lnk
[2012/03/15 07:45:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Smart Defrag 2
[2012/03/14 12:42:17 | 000,002,491 | ---- | M] () -- C:\Documents and Settings\Charlie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007 (2).lnk
[2012/03/11 14:26:00 | 000,000,494 | ---- | M] () -- C:\hpfr5550.xml
[2012/03/08 14:36:29 | 000,018,821 | ---- | M] () -- C:\Documents and Settings\Charlie\English
[2012/03/08 14:36:26 | 000,002,533 | ---- | M] () -- C:\Documents and Settings\Charlie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007 (2).lnk
[2012/03/08 09:34:37 | 000,316,664 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\RetrieveAllSignInDetailsForm[2].pdf
[2012/03/07 12:45:02 | 000,001,665 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Basic PAYE Tools.lnk
[2012/03/02 10:16:08 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Charlie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/02/27 14:44:14 | 001,721,752 | ---- | M] (Intuit Inc.) -- C:\WINDOWS\System32\InetClnt.dll
[2012/02/27 14:31:46 | 001,694,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\VBA6.DLL
[2012/02/27 14:31:32 | 000,741,008 | ---- | M] (FarPoint Technologies, Inc.) -- C:\WINDOWS\System32\SPR32D30.DLL
[2012/02/21 13:13:33 | 000,404,469 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\Scan0049.jpg
[2012/02/21 13:13:17 | 000,270,615 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\Scan0048.jpg
[2012/02/21 13:12:51 | 000,421,542 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\Scan0046.jpg
[2012/02/21 13:12:30 | 000,327,562 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\Scan0047.jpg
[2012/02/21 13:12:12 | 000,397,937 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\Scan0045.jpg
[2012/02/21 13:11:57 | 000,285,418 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\Scan0044.jpg
[2012/02/21 13:11:37 | 000,342,977 | ---- | M] () -- C:\Documents and Settings\Charlie\My Documents\Scan0043.jpg
========== Files Created - No Company Name ==========
[2012/03/16 12:35:02 | 000,091,136 | ---- | C] () -- C:\WINDOWS\System32\tt7htNPy.com
[2012/03/16 12:15:46 | 000,001,324 | ---- | C] () -- C:\Documents and Settings\Charlie\Desktop\Smart Fortress 2012.lnk
[2012/03/16 12:15:09 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Charlie\Desktop\j07odqhh_gamer.exe
[2012/03/16 12:14:56 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At48.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At46.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At44.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At42.job
[2012/03/16 12:14:56 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At40.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At47.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At45.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At43.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At41.job
[2012/03/16 12:14:56 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At39.job
[2012/03/16 12:14:56 | 000,000,112 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hmDr01.dat
[2012/03/16 12:14:55 | 000,091,136 | ---- | C] () -- C:\WINDOWS\System32\tt7htNPy.com_
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At8.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At6.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At4.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At38.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At36.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At34.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At32.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At30.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At28.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At26.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At24.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At22.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At20.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At18.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At16.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At14.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At12.job
[2012/03/16 12:14:55 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At10.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At9.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At7.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At5.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At37.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At35.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At33.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At31.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At3.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At29.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At27.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At25.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At23.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At21.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At19.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At17.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At15.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At13.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At11.job
[2012/03/16 12:14:55 | 000,000,350 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2012/03/16 11:42:59 | 002,044,822 | ---- | C] () -- C:\Documents and Settings\Charlie\Desktop\tdsskiller.zip
[2012/03/16 09:07:24 | 000,001,836 | ---- | C] () -- C:\Documents and Settings\Charlie\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickBooks Pro 2012.lnk
[2012/03/16 08:07:46 | 000,714,590 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2012/03/16 07:19:23 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\d3d9caps.dat
[2012/03/16 06:53:52 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/03/16 06:42:56 | 000,000,000 | -HS- | C] () -- C:\WINDOWS\System32\dds_trash_log.cmd
[2012/03/15 14:41:44 | 000,204,054 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\SDO-HE-30.zip
[2012/03/15 14:05:19 | 000,000,098 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\SDOFE_PATH.ini
[2012/03/15 14:00:33 | 000,073,940 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2012/03/15 13:57:57 | 000,203,760 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-861567501-1644491937-725345543-1008-0.dat
[2012/03/15 13:57:56 | 000,167,358 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/03/15 13:47:38 | 000,204,042 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\SDO-FE-30.zip
[2012/03/15 10:43:27 | 000,001,392 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\XPS Viewer EP.lnk
[2012/03/15 10:40:15 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Remote Assistance.lnk
[2012/03/15 10:40:15 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Windows Media Player.lnk
[2012/03/15 10:39:34 | 000,002,109 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/03/15 10:39:34 | 000,001,761 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
[2012/03/15 07:45:48 | 000,014,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2012/03/15 07:45:46 | 000,000,823 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Smart Defrag 2.lnk
[2012/03/08 09:34:37 | 000,316,664 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\RetrieveAllSignInDetailsForm[2].pdf
[2012/02/21 13:13:33 | 000,404,469 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\Scan0049.jpg
[2012/02/21 13:13:17 | 000,270,615 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\Scan0048.jpg
[2012/02/21 13:12:51 | 000,421,542 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\Scan0046.jpg
[2012/02/21 13:12:30 | 000,327,562 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\Scan0047.jpg
[2012/02/21 13:12:12 | 000,397,937 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\Scan0045.jpg
[2012/02/21 13:11:57 | 000,285,418 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\Scan0044.jpg
[2012/02/21 13:11:36 | 000,342,977 | ---- | C] () -- C:\Documents and Settings\Charlie\My Documents\Scan0043.jpg
[2012/02/15 17:46:18 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/02/12 08:49:54 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Administrator\hpothb07.tif
[2011/02/12 08:49:54 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Administrator\hpothb07.dat
[2011/01/11 13:05:18 | 000,008,592 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2010/12/15 13:12:52 | 000,000,117 | ---- | C] () -- C:\Documents and Settings\Matthew\jagex_runescape_preferences2.dat
[2010/12/15 13:11:36 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Matthew\jagex_runescape_preferences.dat
[2010/12/15 13:10:17 | 000,000,117 | ---- | C] () -- C:\Documents and Settings\Charlie\jagex_runescape_preferences2.dat
[2010/12/15 13:09:13 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Charlie\jagex_runescape_preferences.dat
[2010/12/01 17:21:38 | 000,000,095 | ---- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2010/11/17 13:03:58 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\Charlie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/14 12:40:46 | 000,002,154 | ---- | C] () -- C:\Documents and Settings\Matthew\English
[2010/10/07 04:14:42 | 000,018,821 | ---- | C] () -- C:\Documents and Settings\Charlie\English
[2010/06/24 13:56:40 | 000,026,436 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/03/22 07:11:44 | 000,019,545 | ---- | C] () -- C:\WINDOWS\hpoins01.dat
[2010/03/22 07:11:44 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat
[2010/03/20 09:43:32 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/02/25 18:25:34 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/02/25 17:43:33 | 000,200,704 | ---- | C] () -- C:\WINDOWS\sel3110.exe
[2010/02/25 17:43:33 | 000,032,528 | ---- | C] () -- C:\WINDOWS\amcap.exe
[2009/08/03 10:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 10:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/03/19 08:13:57 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\TASEIRFn.dll
[2009/03/19 08:13:14 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\TASSGLib.dll
[2008/09/30 14:37:30 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2008/07/12 01:33:36 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\Wh2Robo.dll
[2008/07/11 10:34:06 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/07/11 08:02:29 | 000,004,633 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/07/11 08:00:35 | 000,165,120 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/07/11 07:53:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/07/11 07:45:56 | 000,022,720 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/06/06 09:53:26 | 000,000,392 | ---- | C] () -- C:\WINDOWS\System32\BTRDRVR.SYS
[2008/05/26 16:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 16:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/03/13 04:14:20 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\SgEData.dll
[2008/03/13 04:14:20 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SgELauncher.dll
[2008/03/13 04:14:20 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\SgEEncrypt.dll
[2007/09/27 05:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 05:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 05:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/07/09 12:08:52 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SageFolderBrowser.dll
[2007/07/09 12:07:06 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\SGSTDREG.dll
[2007/07/09 12:07:02 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\SGRegister.dll
[2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 06:00:00 | 000,526,486 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 06:00:00 | 000,096,342 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/03/09 17:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll