Hi Inzanity
In answer to you standard questions - I'm not asking for help on another forum but I have previously tried to install spyware doctor (it wants money) and Kaspersky virus removal tool (it hasn't found it - or at least not all of it)
Here is the log from OTL
OTL logfile created on: 04/02/2010 07:50:09 - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Paul\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 16.49 Gb Free Space | 56.30% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 203.59 Gb Total Space | 189.15 Gb Free Space | 92.91% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: WIGANRECYCLES
Current User Name: Paul
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Paul\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\ATK0100\Hcontrol.exe ()
PRC - C:\WINDOWS\ATK0100\ATKOSD.exe ()
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe (Sony Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe ()
PRC - C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\HotKey Utility\HKWnd.exe (Sony Corporation)
PRC - C:\Program Files\Sony\HotKey Utility\HKServ.exe (Sony Corporation)
PRC - C:\Program Files\Sony\BlueSpace\BlueSpaceNE.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Sony\vaio power management\SPMgr.exe (Sony Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Paul\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (gupdate) Google Update Service (gupdate) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (Ati HotKey Poller) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart) – C:\WINDOWS\system32\ati2sgag.exe ()
========== Driver Services (SafeList) ==========
DRV - (setup_9.0.0.722_03.02.2010_15-00drv) – File not found
DRV - (34039642) – File not found
DRV - (34039641) – File not found
DRV - (w22n51) Intel® – C:\WINDOWS\system32\drivers\w22n51.sys (Intel® Corporation)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (tifmsony) – C:\WINDOWS\system32\drivers\tifmsony.sys (Texas Instruments)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (RimVSerPort) – C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (RimUsb) – C:\WINDOWS\system32\drivers\RimUsb.sys (Research In Motion Limited)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ATKACPI.sys ()
DRV - (E1000) Intel® – C:\WINDOWS\system32\drivers\e1000325.sys (Intel Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (BrUsbSer) – C:\WINDOWS\system32\drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerIf) – C:\WINDOWS\system32\drivers\BrSerIf.sys (Brother Industries Ltd.)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ROOTMODEM) – C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
DRV - (SPI) – C:\WINDOWS\system32\drivers\SonyPI.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bbc.co.uk/news
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010/02/03 21:38:40 | 000,378,487 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 13044 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe ()
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe ()
O4 - HKLM..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKServ.exe (Sony Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06b\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\vaio power management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [VAIO Update 4] C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe (Sony Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\Paul\Start Menu\Programs\Startup\BlueSpace NE.lnk = C:\Program Files\Sony\BlueSpace\BlueSpaceNE.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\Paul\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKLM\..Trusted Domains: 64 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: mendeley.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 64 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1259744190833 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Paul\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Paul\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/11 15:22:22 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/02/04 07:48:02 | 000,548,864 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Paul\Desktop\OTL.exe
[2010/02/04 07:44:52 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/02/03 20:46:46 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/02/03 20:46:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/02/03 18:33:24 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/02/03 18:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Paul\Application Data\WinRAR
[2010/02/03 18:28:48 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/02/03 18:15:31 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Paul\Desktop\mbam-setup (1).exe
[2010/02/03 14:11:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Paul\Local Settings\Application Data\Threat Expert
[2010/02/03 13:33:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/02/03 13:33:06 | 034,628,384 | —- | C] (PC Tools ) – C:\Documents and Settings\Paul\Desktop\sdsetup_aff.exe
[2010/02/03 13:33:01 | 061,803,232 | —- | C] ( ) – C:\Documents and Settings\Paul\Desktop\setup_9.0.0.722_03.02.2010_15-00.exe
[2010/01/21 14:05:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Paul\My Documents\CLASP
[2010/01/19 14:26:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Paul\Application Data\vlc
[2010/01/13 17:33:58 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2010/01/07 13:18:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Paul\My Documents\Paint
[2009/11/29 13:17:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/11/19 15:56:49 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/11/19 15:36:35 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2009/11/19 15:36:34 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intel
[2009/11/11 15:25:29 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/11/11 15:25:13 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/11/11 15:25:13 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/02/04 07:47:11 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Paul\Desktop\OTL.exe
[2010/02/04 07:45:37 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{B856A072-18DA-4A42-BB8F-6828D85EEE9B}.job
[2010/02/04 07:40:37 | 007,077,888 | -H– | M] () – C:\Documents and Settings\Paul\NTUSER.DAT
[2010/02/04 07:40:20 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/04 07:39:23 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/04 07:39:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/03 23:17:06 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/03 22:38:31 | 000,012,826 | -HS- | M] () – C:\Documents and Settings\Paul\Local Settings\Application Data\V2Iu86wOC61hS
[2010/02/03 21:45:49 | 000,064,000 | —- | M] () – C:\Documents and Settings\Paul\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/03 21:38:40 | 000,378,487 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/02/03 20:46:57 | 000,000,933 | —- | M] () – C:\Documents and Settings\Paul\Desktop\Spybot - Search & Destroy.lnk
[2010/02/03 20:26:46 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Paul\ntuser.ini
[2010/02/03 14:47:34 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Paul\Desktop\mbam-setup (1).exe
[2010/02/03 13:56:22 | 055,048,281 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/03 13:31:06 | 034,628,384 | —- | M] (PC Tools ) – C:\Documents and Settings\Paul\Desktop\sdsetup_aff.exe
[2010/02/03 13:27:36 | 061,803,232 | —- | M] ( ) – C:\Documents and Settings\Paul\Desktop\setup_9.0.0.722_03.02.2010_15-00.exe
[2010/02/03 13:02:56 | 000,184,320 | -HS- | M] () – C:\Documents and Settings\Paul\Local Settings\Application Data\av.exe
[2010/02/02 18:22:32 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/01/30 10:33:24 | 000,013,756 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/29 20:36:53 | 000,031,232 | —- | M] () – C:\Documents and Settings\Paul\My Documents\Venford Ezekiel Rouse.doc
[2010/01/27 15:47:38 | 000,008,560 | —- | M] () – C:\Documents and Settings\Paul\My Documents\receipt for cash wages.odt
[2010/01/27 15:18:40 | 000,783,767 | —- | M] () – C:\Documents and Settings\Paul\Desktop\COI SE presentation FINAL.pdf
[2010/01/27 15:15:13 | 000,170,633 | —- | M] () – C:\Documents and Settings\Paul\Desktop\2006SU_POV_Schorr.pdf
[2010/01/25 16:05:33 | 000,016,163 | —- | M] () – C:\Documents and Settings\Paul\My Documents\Profile.odt
[2010/01/25 09:26:00 | 001,333,462 | —- | M] () – C:\Documents and Settings\Paul\Desktop\Wigan council presentation.odp
[2010/01/24 23:48:55 | 000,011,072 | —- | M] () – C:\Documents and Settings\Paul\My Documents\invitation list.odt
[2010/01/24 15:38:50 | 031,828,420 | —- | M] () – C:\Documents and Settings\Paul\Desktop\606_20100123-2111a.mp3
[2010/01/21 13:11:57 | 000,499,050 | —- | M] () – C:\Documents and Settings\Paul\Desktop\Top Tips Cards Final Draft for Signoff.pdf
[2010/01/20 06:30:37 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/19 14:10:38 | 000,000,719 | —- | M] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010/01/18 19:45:56 | 000,292,323 | —- | M] () – C:\Documents and Settings\Paul\Desktop\CRT RRP Information Booklet.pdf
[2010/01/18 10:17:43 | 002,485,760 | —- | M] () – C:\Documents and Settings\Paul\My Documents\Agenda TSG 18.1.10.doc
[2010/01/18 10:17:43 | 000,147,456 | —- | M] () – C:\Documents and Settings\Paul\My Documents\TSG mins 23 June 09.doc
[2010/01/17 17:00:45 | 007,394,969 | —- | M] () – C:\Documents and Settings\Paul\Desktop\NorthWestEnglandRSS.pdf
[2010/01/14 13:45:01 | 000,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2010/01/14 08:24:10 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/05 16:36:20 | 000,017,006 | —- | M] () – C:\Documents and Settings\Paul\My Documents\Closure.odt
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/02/03 20:46:57 | 000,000,933 | —- | C] () – C:\Documents and Settings\Paul\Desktop\Spybot - Search & Destroy.lnk
[2010/02/03 13:02:56 | 000,184,320 | -HS- | C] () – C:\Documents and Settings\Paul\Local Settings\Application Data\av.exe
[2010/02/03 13:02:56 | 000,012,826 | -HS- | C] () – C:\Documents and Settings\Paul\Local Settings\Application Data\V2Iu86wOC61hS
[2010/01/29 20:36:52 | 000,031,232 | —- | C] () – C:\Documents and Settings\Paul\My Documents\Venford Ezekiel Rouse.doc
[2010/01/27 15:47:37 | 000,008,560 | —- | C] () – C:\Documents and Settings\Paul\My Documents\receipt for cash wages.odt
[2010/01/27 15:18:39 | 000,783,767 | —- | C] () – C:\Documents and Settings\Paul\Desktop\COI SE presentation FINAL.pdf
[2010/01/27 15:15:13 | 000,170,633 | —- | C] () – C:\Documents and Settings\Paul\Desktop\2006SU_POV_Schorr.pdf
[2010/01/25 12:59:34 | 000,016,163 | —- | C] () – C:\Documents and Settings\Paul\My Documents\Profile.odt
[2010/01/25 09:25:42 | 001,333,462 | —- | C] () – C:\Documents and Settings\Paul\Desktop\Wigan council presentation.odp
[2010/01/24 23:48:54 | 000,011,072 | —- | C] () – C:\Documents and Settings\Paul\My Documents\invitation list.odt
[2010/01/24 15:38:49 | 031,828,420 | —- | C] () – C:\Documents and Settings\Paul\Desktop\606_20100123-2111a.mp3
[2010/01/21 13:11:56 | 000,499,050 | —- | C] () – C:\Documents and Settings\Paul\Desktop\Top Tips Cards Final Draft for Signoff.pdf
[2010/01/19 14:10:38 | 000,000,719 | —- | C] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010/01/18 19:45:56 | 000,292,323 | —- | C] () – C:\Documents and Settings\Paul\Desktop\CRT RRP Information Booklet.pdf
[2010/01/18 10:17:43 | 002,485,760 | —- | C] () – C:\Documents and Settings\Paul\My Documents\Agenda TSG 18.1.10.doc
[2010/01/18 10:17:43 | 000,147,456 | —- | C] () – C:\Documents and Settings\Paul\My Documents\TSG mins 23 June 09.doc
[2010/01/17 17:00:45 | 007,394,969 | —- | C] () – C:\Documents and Settings\Paul\Desktop\NorthWestEnglandRSS.pdf
[2010/01/05 16:36:20 | 000,017,006 | —- | C] () – C:\Documents and Settings\Paul\My Documents\Closure.odt
[2009/12/01 10:29:21 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/12/01 10:29:21 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/12/01 10:27:20 | 000,000,228 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/12/01 10:27:20 | 000,000,094 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/12/01 10:26:22 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/12/01 10:21:28 | 000,064,000 | —- | C] () – C:\Documents and Settings\Paul\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/19 18:19:01 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2009/11/19 18:09:03 | 000,000,127 | —- | C] () – C:\Documents and Settings\Paul\Local Settings\Application Data\fusioncache.dat
[2009/11/19 17:34:19 | 000,000,000 | —- | C] () – C:\WINDOWS\U55A_25b.INI
[2009/11/19 17:15:48 | 000,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2009/11/19 15:28:07 | 000,000,066 | —- | C] () – C:\WINDOWS\BlueSpaceNE.INI
[2009/11/17 17:39:20 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2007/08/28 05:58:00 | 000,005,760 | —- | C] () – C:\WINDOWS\System32\drivers\ATKACPI.sys
========== LOP Check ==========
[2009/11/11 17:17:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/11/11 15:45:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/11/22 21:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/02/03 20:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/11/22 22:23:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul\Application Data\Blackberry Desktop
[2009/11/22 19:37:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul\Application Data\Lexmark Productivity Studio
[2009/11/19 20:03:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul\Application Data\OpenOffice.org
[2009/11/22 21:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul\Application Data\Research In Motion
[2010/02/04 07:50:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Paul\Application Data\uTorrent
[2010/02/04 07:45:37 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{B856A072-18DA-4A42-BB8F-6828D85EEE9B}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >