I used OTLPE Standard REATOGO to scan and here is an excerpt from the OTL.Txt (the full file is too big for this append). I would appreciate any help.
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.80 Gb Total Space | 46.43 Gb Free Space | 64.66% Space Free | Partition Type: NTFS
Drive X: | 282.52 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2007/01/04 22:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | System] -- C:\WINDOWS\System32\drivers\ustedpqz.sys -- (ustedpqz)
DRV - File not found [Kernel | System] -- C:\WINDOWS\System32\drivers\peulbcyg.sys -- (peulbcyg)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- C:\WINDOWS\System32\drivers\ovyenrnk.sys -- (ovyenrnk)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | System] -- C:\WINDOWS\System32\drivers\cgkqhjcp.sys -- (cgkqhjcp)
DRV - [2010/11/04 18:32:00 | 000,052,224 | ---- | M] () [Kernel | System] -- C:\WINDOWS\PRAGMAtvpqsbpxpb\PRAGMAd.sys -- (PRAGMAtvpqsbpxpb)
DRV - [2009/06/18 00:59:58 | 000,234,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel(R)
DRV - [2009/03/04 06:27:32 | 000,031,744 | ---- | M] () [Kernel | On_Demand] -- C:\Documents and Settings\Marcus\Local Settings\Temp\bDMusicb.sys -- (bDMusicb)
DRV - [2008/08/21 07:00:00 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/01/13 13:33:18 | 005,672,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2006/01/24 17:28:02 | 000,176,128 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2005/10/27 17:36:52 | 000,393,088 | ---- | M] (Sensaura) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005/10/10 00:35:30 | 000,017,792 | ---- | M] (Winbond Electronics Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tpm.sys -- (TPM)
DRV - [2004/10/09 04:51:08 | 000,503,507 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\V0080Dev.sys -- (V0080Dev)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\antithinkpoint_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Mandela_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKU\Mandela_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/IE - HKU\Mandela_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\Mandela_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Mandela_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\Marcus_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKU\Marcus_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\Marcus_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\Marcus_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Other_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKU\Other_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/IE - HKU\Other_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\Other_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{8FA3D377-EADF-4147-995F-3C5752AAA3DE}: C:\Documents and Settings\Marcus\Local Settings\Application Data\{8FA3D377-EADF-4147-995F-3C5752AAA3DE} [2010/10/22 18:41:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{341C3846-05CC-4624-9A56-31F98E1DF826}: C:\Documents and Settings\Other\Local Settings\Application Data\{341C3846-05CC-4624-9A56-31F98E1DF826} [2010/10/23 10:40:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{5271F506-02F6-488C-9C9C-EE7A11FBD895}: C:\Documents and Settings\Mandela\Local Settings\Application Data\{5271F506-02F6-488C-9C9C-EE7A11FBD895} [2010/10/20 20:11:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{C50F3662-0462-40FD-9E17-8D495BB951C3}: C:\Documents and Settings\antithinkpoint\Local Settings\Application Data\{C50F3662-0462-40FD-9E17-8D495BB951C3} [2010/10/24 11:54:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A64541B8-1C2D-48DE-9F65-5DF87872EC56}: C:\Documents and Settings\NetworkService\Local Settings\Application Data\{A64541B8-1C2D-48DE-9F65-5DF87872EC56}\ [2010/11/04 19:06:52 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2008/08/21 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\Mandela_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\Marcus_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\Other_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE ()
O4 - HKLM..\Run: [Fpakepa] C:\WINDOWS\efasazasazasa.DLL (Ask.com)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask .exe (Apple Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4 .exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe ()
O4 - HKU\.DEFAULT..\Run: [dfrgsnapnt.exe] C:\WINDOWS\Temp\dfrgsnapnt.exe ()
O4 - HKU\.DEFAULT..\Run: [Iqepo] C:\WINDOWS\rfat50.DLL (ArcSoft Inc.)
O4 - HKU\Mandela_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ()
O4 - HKU\Marcus_ON_C..\Run: [cleansweep.exe] C:\cleansweep.exe\cleansweep.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXl/yA\Marcus\LOCALS~1\Temp\757160358.exe] C:\DOCUME~1\Marcus\LOCALS~1\Temp\757160358.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlkc] C:\DOCUME~1\Marcus\LOCALS~1\Temp\cmd.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlmc] C:\DOCUME~1\Marcus\LOCALS~1\Temp\mdm.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlne] C:\DOCUME~1\Marcus\LOCALS~1\Temp\lsass.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlo_] C:\DOCUME~1\Marcus\LOCALS~1\Temp\tih74.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlora] C:\DOCUME~1\Marcus\LOCALS~1\Temp\iexplarer.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlotc] C:\DOCUME~1\Marcus\LOCALS~1\Temp\hexdump.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlpe] C:\DOCUME~1\Marcus\LOCALS~1\Temp\csrss.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlppf] C:\DOCUME~1\Marcus\LOCALS~1\Temp\services.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlprc] C:\DOCUME~1\Marcus\LOCALS~1\Temp\install.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlq+] C:\DOCUME~1\Marcus\LOCALS~1\Temp\win32.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlqb] C:\DOCUME~1\Marcus\LOCALS~1\Temp\winamp.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlqc] C:\DOCUME~1\Marcus\LOCALS~1\Temp\win.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlqf] C:\DOCUME~1\Marcus\LOCALS~1\Temp\user.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlqse] C:\DOCUME~1\Marcus\LOCALS~1\Temp\winlogon.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlqvc] C:\DOCUME~1\Marcus\LOCALS~1\Temp\svchost.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlqW] C:\DOCUME~1\Marcus\LOCALS~1\Temp\drweb.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlrf] C:\DOCUME~1\Marcus\LOCALS~1\Temp\smss.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlsPc] C:\DOCUME~1\Marcus\LOCALS~1\Temp\nvsvc32.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [HNUgkHXlud] C:\DOCUME~1\Marcus\LOCALS~1\Temp\system.exe File not found
O4 - HKU\Marcus_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ()
O4 - HKU\Other_ON_C..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe ()
O4 - HKU\Other_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O4 - HKU\Mandela_ON_C..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\antithinkpoint_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Mandela_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Marcus_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Marcus_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\Marcus_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Other_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Other_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653}
http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\.DEFAULT Winlogon: Shell - (C:\Documents and Settings\NetworkService\Application Data\hotfix.exe) - C:\Documents and Settings\NetworkService\Application Data\hotfix.exe ()
O20 - HKU\Mandela_ON_C Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\Marcus_ON_C Winlogon: Shell - (C:\Documents and Settings\Marcus\Application Data\hotfix.exe) - C:\Documents and Settings\Marcus\Application Data\hotfix.exe File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O22 - SharedTaskScheduler: {B6BA40C1-A501-59BD-F413-03B03A2C8952} - dfskea98e4iagjiufhg87df87u - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\DESKTOPGB.gif
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/09 10:56:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/11/09 09:18:35 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\LocalService\IECompatCache
[2010/11/09 08:25:40 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Mandela\IECompatCache
[2010/11/04 19:07:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Creative
[2010/11/04 19:06:59 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\NetworkService\SendTo
[2010/11/04 19:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\{A64541B8-1C2D-48DE-9F65-5DF87872EC56}
[2010/11/04 19:06:40 | 000,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\My Documents\My Pictures
[2010/11/04 19:06:40 | 000,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\My Documents\My Music
[2010/11/04 19:06:40 | 000,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\My Documents
[2010/11/04 19:06:39 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\NetworkService\Recent
[2010/11/04 19:06:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Start Menu
[2010/11/04 19:06:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Desktop
[2010/11/04 18:32:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\PRAGMAtvpqsbpxpb
[2010/11/04 18:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/11/01 19:36:25 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\NetworkService\IECompatCache
[2010/11/01 19:36:22 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\NetworkService\PrivacIE
[3 C:\Documents and Settings\Mandela\My Documents\*.tmp files -> C:\Documents and Settings\Mandela\My Documents\*.tmp -> ]
[16 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]