I have an extremely slow performing computer and AVG 2012 has now identified a trojan. Last week it told me that it was PSW.Agent.ASIO and that it removed it from System.exe, but could not remove it from memory. I've been trying to see how to remove it and so attempted to use VIPRERescue which said it found 8 infections, but mentioned that it only removed 1. When I re-ran AVG overnight now says it has PSW.Generic9.OCX, but no mention of PSW.Agent.ASIO. Again this trojan (PSQ.Generic9.OCX) can't seem to be cleaned from memory. I have also tried Malwarebytes AntiMalware and it couldn't seem to find either trojan.
Thanks in advance for any assistance. I am really am not sure how proceed.
Cheers,
Kerrie
Extract from OTL:
OTL logfile created on: 16/02/2012 07:35:09 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Kerrie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.98 Mb Total Physical Memory | 169.52 Mb Available Physical Memory | 16.72% Memory free
2.38 Gb Paging File | 1.81 Gb Available in Paging File | 75.84% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 6.15 Gb Free Space | 16.49% Space Free | Partition Type: NTFS
Drive D: | 29.35 Gb Total Space | 11.17 Gb Free Space | 38.06% Space Free | Partition Type: NTFS
Computer Name: LOTSASMILES | User Name: Kerrie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/15 15:07:49 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kerrie\My Documents\Downloads\OTL.exe
PRC - [2012/01/24 17:24:26 | 004,200,800 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgui.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/06/06 16:06:12 | 000,251,744 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2011/06/06 15:26:54 | 006,132,576 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2008/04/14 11:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/10/07 21:33:30 | 000,020,480 | ---- | M] (Logitech) -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
PRC - [2006/04/13 23:36:36 | 000,176,128 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
PRC - [2006/04/04 09:55:18 | 000,274,432 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
PRC - [2006/03/10 06:58:00 | 000,217,088 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
PRC - [2006/03/01 00:29:54 | 000,569,413 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
PRC - [2006/03/01 00:25:48 | 000,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2006/03/01 00:25:20 | 000,667,718 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2006/03/01 00:22:50 | 000,397,381 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2006/02/14 22:11:46 | 000,176,128 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
PRC - [2005/11/28 08:39:32 | 000,118,784 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
PRC - [2005/11/28 08:39:30 | 000,131,072 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2005/09/09 13:24:30 | 000,102,400 | ---- | M] () -- C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
PRC - [2005/07/20 03:32:18 | 000,221,184 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\LVCOMSX.EXE
PRC - [2005/06/09 01:14:44 | 000,217,088 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Video\LogiTray.exe
PRC - [2005/06/09 00:44:56 | 000,192,512 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Video\FxSvr2.exe
PRC - [2005/05/24 05:43:28 | 000,053,248 | ---- | M] (Global Locate, Inc.) -- C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe
PRC - [2004/11/17 22:47:16 | 000,118,784 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2004/09/08 20:51:10 | 000,106,496 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
PRC - [2004/08/19 11:40:08 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
PRC - [2004/02/21 00:12:34 | 000,032,768 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\ISB Utility\ISBMgr.exe
PRC - [2002/03/15 02:46:58 | 000,045,056 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\system32\ico.exe
========== Modules (No Company Name) ==========
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/04/01 16:48:48 | 008,217,088 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtGui4.dll
MOD - [2011/04/01 16:41:58 | 002,267,648 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtCore4.dll
MOD - [2008/03/25 15:50:40 | 000,355,112 | ---- | M] () -- C:\WINDOWS\system32\msjetoledb40.dll
MOD - [2006/10/07 21:33:35 | 000,049,152 | ---- | M] () -- C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.4.68-8876480L\Program\clntutil.dll
MOD - [2006/10/07 21:33:30 | 000,114,688 | ---- | M] () -- C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.4.68-8876480L\Program\BWScriptExt.dll
MOD - [2006/10/07 21:33:30 | 000,020,480 | ---- | M] () -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\bwscriptext-8876480.dll
MOD - [2006/10/07 21:33:30 | 000,020,480 | ---- | M] () -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWfiles-8876480.dll
MOD - [2006/10/07 21:33:28 | 000,143,360 | ---- | M] () -- C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.4.68-8876480L\Program\bwfiles.dll
MOD - [2006/03/01 00:39:02 | 000,876,544 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\Libeay32.dll
MOD - [2006/03/01 00:39:02 | 000,208,965 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/03/01 00:39:02 | 000,053,322 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\IntStngs.dll
MOD - [2006/02/14 00:15:04 | 000,970,862 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\acAuth.dll
MOD - [2005/09/09 13:24:30 | 000,102,400 | ---- | M] () -- C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
MOD - [2005/05/21 03:42:20 | 000,010,752 | ---- | M] () -- C:\Program Files\Sony\VAIO Event Service\VESBasePS.dll
MOD - [2004/07/21 03:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011/06/06 15:26:54 | 006,132,576 | ---- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2007/02/05 21:11:18 | 000,075,320 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\Avlib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007/02/05 21:11:16 | 000,112,184 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\Avlib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2006/12/14 13:21:20 | 000,045,056 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2006/12/14 13:02:08 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2006/12/14 12:46:16 | 000,057,344 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2006/06/13 00:37:34 | 002,080,768 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe -- (VAIOMediaPlatform-IntegratedServer-AppServer)
SRV - [2006/05/18 03:43:34 | 000,770,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP)
SRV - [2006/05/18 03:19:26 | 000,155,648 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe -- (VAIOMediaPlatform-Mobile-Gateway)
SRV - [2006/04/13 23:36:36 | 000,176,128 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2006/04/04 09:55:18 | 000,274,432 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -- (Vcsw)
SRV - [2005/11/28 08:39:32 | 000,118,784 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe -- (VzFw)
SRV - [2005/11/28 08:39:30 | 000,131,072 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc)
SRV - [2005/11/25 08:08:54 | 000,073,728 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
SRV - [2005/10/11 21:02:02 | 000,057,344 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP)
SRV - [2005/09/09 13:24:30 | 000,102,400 | ---- | M] () [Auto | Running] -- C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor4.0)
SRV - [2005/07/15 05:10:16 | 000,032,768 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Image Converter 2\IcVzMon.exe -- (Image Converter video recording monitor for VAIO Entertainment)
SRV - [2005/01/04 21:09:36 | 000,398,336 | ---- | M] (Sony Corporation) [Auto | Stopped] -- C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_svc.exe -- (VCI)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (xpsec)
DRV - File not found [Kernel | On_Demand | Running] -- -- (xcpip)
DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/10/04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/07/11 01:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/07/11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/07/11 01:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/05/10 09:06:14 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\netaapl.sys -- (Netaapl)
DRV - [2008/04/14 05:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2007/07/24 18:45:20 | 000,328,824 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ACEDRV10.sys -- (acedrv10)
DRV - [2007/07/11 19:20:26 | 000,201,848 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\acehlp10.sys -- (acehlp10)
DRV - [2006/06/06 16:23:30 | 000,974,464 | R--- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid)
DRV - [2006/05/09 19:27:00 | 004,273,152 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/03/01 01:35:56 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/02/26 14:43:00 | 001,428,480 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2006/02/23 04:13:12 | 000,013,440 | ---- | M] (UPEK Inc.) [File_System | Auto | Running] -- C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys -- (FdRedir)
DRV - [2006/02/23 04:13:04 | 000,033,024 | ---- | M] (UPEK Inc.) [Kernel | Auto | Running] -- C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys -- (FileDisk2)
DRV - [2006/02/21 20:32:32 | 000,226,304 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ti21sony.sys -- (ti21sony)
DRV - [2006/02/09 03:33:34 | 000,062,848 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfhid.sys -- (Tosrfhid)
DRV - [2006/02/03 09:16:08 | 000,108,928 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (Tosrfbd)
DRV - [2006/02/01 04:35:28 | 000,039,808 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2005/12/15 03:07:24 | 000,037,632 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (Tosrfbnp)
DRV - [2005/11/24 23:37:36 | 000,047,104 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)
DRV - [2005/11/21 16:06:02 | 000,009,216 | ---- | M] (Sony Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\shpf.sys -- (shpf)
DRV - [2005/11/12 01:09:52 | 000,052,864 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfsnd.sys -- (TosRfSnd) Bluetooth Audio Device (WDM)
DRV - [2005/10/21 13:19:34 | 000,036,352 | ---- | M] (Infineon Technologies AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ifxtpm.sys -- (IFXTPM)
DRV - [2005/10/18 18:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/10/18 18:52:34 | 000,202,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/10/18 18:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/09/10 07:14:16 | 000,280,448 | ---- | M] (Marvell Semiconductor, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mrvw125.sys -- (W8335XP) Marvell Libertas 802.11b/g Driver for Windows XP (8335)
DRV - [2005/09/02 03:54:26 | 000,032,000 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gtf32bus.sys -- (GTF32BUS)
DRV - [2005/09/02 03:54:12 | 000,007,936 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gtptser.sys -- (GTPTSER)
DRV - [2005/08/30 01:45:24 | 000,018,944 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gtscser.sys -- (GTSCSER)
DRV - [2005/08/02 02:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005/07/12 04:58:56 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\toshidpt.sys -- (toshidpt)
DRV - [2005/06/10 16:55:28 | 000,173,056 | ---- | M] (Funk Software, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\odysseyIM4.sys -- (odysseyIM4)
DRV - [2005/05/27 20:46:22 | 000,913,280 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302AV.SYS -- (PID_08A0) QuickCam IM(PID_08A0)
DRV - [2005/05/27 20:38:00 | 000,007,136 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2005/05/27 20:31:28 | 000,022,016 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2005/01/06 23:42:42 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2004/11/22 15:31:10 | 000,108,767 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/10/05 10:39:18 | 000,057,856 | ---- | M] (Canon Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBVCD.sys -- (USBVCD)
DRV - [2004/10/05 10:39:18 | 000,006,528 | ---- | M] (Canon Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VCIDRV.sys -- (VCIDRV)
DRV - [2004/10/05 10:39:18 | 000,004,992 | ---- | M] (Canon Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBREC.sys -- (USBREC)
DRV - [2003/12/08 21:53:48 | 000,053,600 | ---- | M] (THOMSON) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcan5wn.sys -- (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN)
DRV - [2003/12/08 21:53:46 | 000,070,688 | ---- | M] (THOMSON) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcaudsl.sys -- (alcaudsl)
DRV - [2002/08/20 13:59:32 | 000,071,961 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SonyPI.sys -- (SPI)
DRV - [2000/12/06 02:18:02 | 000,003,952 | ---- | M] (Sony Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\DMICall.sys -- (DMICall)
DRV - [2000/11/09 21:15:08 | 000,048,896 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SonyNC.sys -- (SNC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://remote.nabcapital.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;localhost
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google.co.uk"
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/home.php?#!/?sk=lf"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [email protected]:2.1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@view22.com/Madison: C:\Program Files\view22\version_4\NPView22.dll (View22 Technology)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@view22.com/Madison: C:\Program Files\view22\version_4\NPView22.dll (View22 Technology)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/02/08 13:09:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/15 21:37:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/24 09:09:49 | 000,000,000 | ---D | M]
[2008/09/02 22:50:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kerrie\Application Data\Mozilla\Extensions
[2008/09/02 22:50:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kerrie\Application Data\Mozilla\Extensions\[email protected]
[2011/05/10 22:46:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kerrie\Application Data\Mozilla\Firefox\Profiles\0i51fhww.default\extensions
[2010/04/28 15:28:17 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Kerrie\Application Data\Mozilla\Firefox\Profiles\0i51fhww.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/14 09:17:26 | 000,005,216 | ---- | M] () -- C:\Documents and Settings\Kerrie\Application Data\Mozilla\Firefox\Profiles\0i51fhww.default\searchplugins\linkedin.xml
[2012/02/14 09:17:26 | 000,005,231 | ---- | M] () -- C:\Documents and Settings\Kerrie\Application Data\Mozilla\Firefox\Profiles\0i51fhww.default\searchplugins\linkedinjobs.xml
[2012/01/15 23:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/15 23:43:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2009/09/15 13:30:18 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/12 00:38:14 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/09/13 21:29:00 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\atl71.dll
[2007/09/13 21:29:00 | 000,053,248 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\boost_filesystem-vc71-mt-1_33_1.dll
[2007/09/13 21:29:00 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\msvcp71.dll
[2007/09/13 21:29:00 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\msvcr71.dll
[2011/11/10 05:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/09/13 21:29:00 | 000,172,032 | ---- | M] (View22 Technology) -- C:\Program Files\mozilla firefox\plugins\NPView22.dll
[2007/09/13 21:29:00 | 000,106,496 | ---- | M] (View22 Technology) -- C:\Program Files\mozilla firefox\plugins\v22_base.dll
[2007/09/13 21:29:00 | 000,114,688 | ---- | M] (View22 Technology) -- C:\Program Files\mozilla firefox\plugins\v22_compression.dll
[2007/09/13 21:29:00 | 000,106,496 | ---- | M] (View22 Technology) -- C:\Program Files\mozilla firefox\plugins\v22_connect.dll
[2007/09/13 21:29:00 | 000,229,376 | ---- | M] (View22 Technology) -- C:\Program Files\mozilla firefox\plugins\v22_update.dll
[2007/09/13 21:29:00 | 000,196,608 | ---- | M] (View22 Technology) -- C:\Program Files\mozilla firefox\plugins\v22_utility.dll
[2007/09/13 21:29:00 | 000,065,024 | ---- | M] (View22 Technology) -- C:\Program Files\mozilla firefox\plugins\v22_winapplib.dll
[2011/11/03 09:42:10 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/03 09:42:10 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/03 09:42:10 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/03 09:42:09 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/03 09:42:08 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: View22 Gecko Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPView22.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: DivX\u00AE Content Upload Plugin (Enabled) = C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
CHR - plugin: Harmony Firefox Plugin (Enabled) = C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.4_0\
CHR - Extension: Google Search = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Documents and Settings\Kerrie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/02/26 22:53:53 | 000,302,468 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10428 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\GoogleAFE.dll File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [Lto Manager] C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe (Global Locate, Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SpeedTouch USB Diagnostics] C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (THOMSON Telecom Belgium)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [WinDVR SchSvr] C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe (InterVideo Inc.)
O4 - HKCU..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe (Logitech)
O4 - HKCU..\Run: [LogitechSoftwareUpdate] C:\Program Files\Logitech\Video\ManifestEngine.exe (Logitech Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Search - ?p=ZK File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Transfer by Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm ()
O15 - HKCU\..Trusted Domains: nabcapital.com ([remote] https in Trusted sites)
O15 - HKCU\..Trusted Domains: nabcapital.com ([vpn.remote] https in Trusted sites)
O15 - HKCU\..Trusted Domains: nabcapital.com ([webmail] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {181BCAB2-C89B-4E4B-9E6B-59FA67A426B5} https://vpn.remote.n...vista/nsepa.ocx (Nsepa Control)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1159315280687 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} http://www.bigfishga...sh.1.0.0.58.cab (CPlayFirstDinerDashControl Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.co...aploader_v6.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B054FE6A-06A3-45AF-B9FD-A6FCEFF8B0B3}: DhcpNameServer = 10.176.66.71 10.188.66.103
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\t-mobile - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\psfus: DllName - (fusstub.dll) - C:\WINDOWS\System32\fusstub.dll (UPEK Inc.)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/29 20:40:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{59103543-1e98-11df-974a-0002c7eb228c}\Shell - "" = AutoRun
O33 - MountPoints2\{59103543-1e98-11df-974a-0002c7eb228c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{59103543-1e98-11df-974a-0002c7eb228c}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{753287d2-78c1-11dd-ba00-0002c7eb228c}\Shell\AutoRun\command - "" = I:\InstallTomTomHOME.exe
O33 - MountPoints2\{ea2b6ec8-2074-11e0-9766-0002c7eb228c}\Shell - "" = AutoRun
O33 - MountPoints2\{ea2b6ec8-2074-11e0-9766-0002c7eb228c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ea2b6ec8-2074-11e0-9766-0002c7eb228c}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{ea2b6ecc-2074-11e0-9766-0002c7eb228c}\Shell - "" = AutoRun
O33 - MountPoints2\{ea2b6ecc-2074-11e0-9766-0002c7eb228c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ea2b6ecc-2074-11e0-9766-0002c7eb228c}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/15 15:59:23 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/02/15 15:59:23 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2012/02/15 15:31:39 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2012/02/11 15:56:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Desktop\Sebastian Competition
[2012/02/11 15:39:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Desktop\Album One
[2012/02/11 15:38:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Desktop\Harry - 12 - 24 mths
[2012/02/11 15:00:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012/02/08 20:52:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Application Data\AVG
[2012/02/08 20:51:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/29 00:55:08 | 000,000,000 | ---D | C] -- C:\CF Card 20120228
[2012/01/27 09:48:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Desktop\388CANON
[2012/01/27 01:40:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Application Data\AVG2012
[2012/01/27 01:38:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2012/01/27 01:34:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/01/27 01:34:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2012/01/27 01:14:23 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/01/27 00:32:12 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/01/26 23:22:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Application Data\Media Player Classic
[2012/01/26 15:39:30 | 000,000,000 | ---D | C] -- C:\output media
[2012/01/26 15:38:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Free Convert M4A to MP3 AMR OGG AAC Converter
[2012/01/26 15:38:24 | 000,000,000 | ---D | C] -- C:\Program Files\Free Convert M4A to MP3 AMR OGG AAC Converter
[2012/01/26 15:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
[2012/01/26 15:18:25 | 000,860,160 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\lameACM.acm
[2012/01/26 15:18:24 | 000,118,784 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2012/01/26 15:18:22 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2012/01/26 15:18:07 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2012/01/26 15:14:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2012/01/25 23:03:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kerrie\Desktop\Harry Photos
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/16 06:55:20 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1349642275-1904126512-3643703909-1006UA.job
[2012/02/15 15:55:27 | 089,060,692 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/15 15:15:07 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/15 15:02:20 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/15 14:50:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/15 14:50:42 | 1063,309,312 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/15 14:50:42 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/15 12:53:02 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1349642275-1904126512-3643703909-1006Core.job
[2012/02/15 10:44:11 | 000,188,416 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-15 Draft v0.5.pub
[2012/02/15 10:21:46 | 005,298,176 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Facet5 - Team Distribution - TEMPLATE.xlt
[2012/02/14 16:53:00 | 000,216,729 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood_Park_Newsletter_2012-Feb-15_Draft_v0.5.pdf
[2012/02/14 14:50:03 | 000,058,044 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/02/13 10:59:38 | 000,096,768 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft v0.4.pub
[2012/02/12 19:18:00 | 000,213,026 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\TeamScape Report Frank Caputo.pdf
[2012/02/11 16:03:38 | 000,778,330 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2730-2.jpg
[2012/02/11 16:01:38 | 001,131,941 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2730-1.jpg
[2012/02/11 15:55:40 | 002,701,695 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2730.jpg
[2012/02/11 15:19:20 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2012/02/11 10:33:18 | 003,570,065 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2743.jpg
[2012/02/11 10:32:46 | 003,918,764 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2742.jpg
[2012/02/11 10:31:58 | 003,170,604 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2740.jpg
[2012/02/11 10:28:16 | 003,053,586 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2733.jpg
[2012/02/09 12:00:58 | 005,759,120 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2700.jpg
[2012/02/08 20:28:43 | 000,223,232 | ---- | M] () -- C:\Documents and Settings\Kerrie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/08 14:30:03 | 000,097,792 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft v0.2.pub
[2012/02/08 13:43:04 | 000,097,792 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft v0.1.pub
[2012/02/08 13:09:15 | 000,000,706 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/02/07 23:50:03 | 000,042,232 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\428963_10150500931346771_623961770_9220344_69528869_n.jpg
[2012/02/07 23:49:52 | 000,073,556 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\428902_10150500835171771_623961770_9220061_1520077491_n.jpg
[2012/02/07 23:49:47 | 000,047,477 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\421069_10150500930776771_623961770_9220341_1562293486_n.jpg
[2012/02/07 23:40:29 | 000,099,446 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_5139.JPG
[2012/02/07 23:40:27 | 000,108,203 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_5106.JPG
[2012/02/07 22:00:37 | 000,089,600 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft.pub
[2012/02/07 21:22:51 | 000,011,209 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\customLogo.gif.png
[2012/02/07 21:19:16 | 000,005,732 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\images.jpg
[2012/02/07 20:44:38 | 000,004,854 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Regedit 20120207.reg
[2012/01/26 17:40:55 | 000,002,275 | ---- | M] () -- C:\Documents and Settings\Kerrie\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/26 17:40:54 | 000,002,297 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Google Chrome.lnk
[2012/01/26 15:38:50 | 000,000,034 | -H-- | M] () -- C:\WINDOWS\System32\Converter_sysquict.dat
[2012/01/26 15:38:32 | 000,000,834 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Free Convert M4A to MP3 AMR OGG AAC Converter.lnk
[2012/01/26 15:37:15 | 000,000,942 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Media Player Classic.lnk
[2012/01/26 14:08:41 | 000,057,344 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2012/01/26 02:09:17 | 000,040,162 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\belly2.jpg
[2012/01/26 02:08:34 | 000,037,305 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\Belly.jpg
[2012/01/19 10:39:10 | 004,076,051 | ---- | M] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_5089.JPG
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/15 15:55:27 | 089,060,692 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/15 15:15:07 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/15 11:54:52 | 000,216,729 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood_Park_Newsletter_2012-Feb-15_Draft_v0.5.pdf
[2012/02/15 10:43:52 | 000,188,416 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-15 Draft v0.5.pub
[2012/02/15 10:21:41 | 005,298,176 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Facet5 - Team Distribution - TEMPLATE.xlt
[2012/02/14 14:50:03 | 000,058,044 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/02/13 14:29:05 | 000,213,026 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\TeamScape Report Frank Caputo.pdf
[2012/02/13 10:59:38 | 000,096,768 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft v0.4.pub
[2012/02/11 16:03:36 | 000,778,330 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2730-2.jpg
[2012/02/11 16:01:38 | 001,131,941 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2730-1.jpg
[2012/02/11 15:55:39 | 002,701,695 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2730.jpg
[2012/02/11 15:51:03 | 003,570,065 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2743.jpg
[2012/02/11 15:50:43 | 003,918,764 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2742.jpg
[2012/02/11 15:50:26 | 003,170,604 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2740.jpg
[2012/02/11 15:49:50 | 003,053,586 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2733.jpg
[2012/02/11 15:46:19 | 005,759,120 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_2700.jpg
[2012/02/10 14:56:50 | 1063,309,312 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/08 13:43:14 | 000,097,792 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft v0.2.pub
[2012/02/08 12:49:06 | 000,000,982 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1349642275-1904126512-3643703909-1006UA.job
[2012/02/08 12:48:58 | 000,000,930 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1349642275-1904126512-3643703909-1006Core.job
[2012/02/07 23:50:02 | 000,042,232 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\428963_10150500931346771_623961770_9220344_69528869_n.jpg
[2012/02/07 23:49:51 | 000,073,556 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\428902_10150500835171771_623961770_9220061_1520077491_n.jpg
[2012/02/07 23:49:44 | 000,047,477 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\421069_10150500930776771_623961770_9220341_1562293486_n.jpg
[2012/02/07 23:34:49 | 000,108,203 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_5106.JPG
[2012/02/07 23:33:53 | 000,099,446 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_5139.JPG
[2012/02/07 22:09:09 | 000,097,792 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft v0.1.pub
[2012/02/07 21:22:39 | 000,011,209 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\customLogo.gif.png
[2012/02/07 21:19:05 | 000,005,732 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\images.jpg
[2012/02/07 21:11:29 | 000,089,600 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Pagewood Park Newsletter 2012-Feb-XX Draft.pub
[2012/02/07 20:44:36 | 000,004,854 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Regedit 20120207.reg
[2012/01/27 01:38:34 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/26 15:38:50 | 000,000,034 | -H-- | C] () -- C:\WINDOWS\System32\Converter_sysquict.dat
[2012/01/26 15:38:32 | 000,000,834 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Free Convert M4A to MP3 AMR OGG AAC Converter.lnk
[2012/01/26 15:19:16 | 000,000,942 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Media Player Classic.lnk
[2012/01/26 15:18:37 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2012/01/26 15:18:25 | 000,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml
[2012/01/26 15:18:20 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2012/01/26 15:18:18 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2012/01/26 15:18:13 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2012/01/26 02:09:09 | 000,040,162 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\belly2.jpg
[2012/01/26 02:08:28 | 000,037,305 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\Belly.jpg
[2012/01/25 22:34:38 | 004,076,051 | ---- | C] () -- C:\Documents and Settings\Kerrie\Desktop\IMG_5089.JPG
[2012/01/24 20:43:22 | 000,002,275 | ---- | C] () -- C:\Documents and Settings\Kerrie\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/27 21:24:26 | 000,002,048 | ---- | C] () -- C:\Documents and Settings\Kerrie\Application Data\123 Cheese Prefs
[2009/12/08 21:06:11 | 059,231,275 | ---- | C] () -- C:\WINDOWS\System32\xa121497218.exe
[2009/12/08 21:05:45 | 059,231,275 | ---- | C] () -- C:\WINDOWS\System32\xa121471546.exe
[2009/10/17 15:59:53 | 000,057,344 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/02/26 23:31:31 | 000,003,856 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/01/10 02:35:21 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/01/10 01:05:40 | 000,003,082 | ---- | C] () -- C:\WINDOWS\System32\affv208325p1now.sys
[2009/01/09 21:40:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2008/11/07 03:33:02 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/01/28 18:26:21 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\34CoInstaller.dll
[2008/01/28 18:26:01 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007/11/30 09:30:28 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/11/22 12:00:45 | 000,532,480 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2007/02/23 23:10:20 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2006/12/22 18:34:50 | 000,009,255 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/12/20 18:26:08 | 000,000,528 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2006/12/17 01:48:27 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2006/10/07 21:37:00 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\InstMed.exe
[2006/10/07 21:29:17 | 000,081,920 | R--- | C] () -- C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
[2006/10/02 08:08:45 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2006/09/20 04:58:13 | 000,000,017 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2006/09/20 03:06:48 | 000,000,057 | ---- | C] () -- C:\WINDOWS\init.ini
[2006/09/20 03:05:53 | 000,065,973 | ---- | C] () -- C:\WINDOWS\sem_GCXXUninstall.exe
[2006/09/20 03:05:50 | 000,089,716 | ---- | C] () -- C:\WINDOWS\OptionPluss_PCCardInstallerUninstall.exe
[2006/09/20 03:05:43 | 000,090,499 | ---- | C] () -- C:\WINDOWS\OptionPCCardInstallerUninstall.exe
[2006/09/08 04:10:37 | 000,223,232 | ---- | C] () -- C:\Documents and Settings\Kerrie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/08 02:39:31 | 000,000,582 | ---- | C] () -- C:\WINDOWS\wwwconfig.dat
[2006/09/02 03:21:23 | 000,000,316 | ---- | C] () -- C:\Documents and Settings\Kerrie\Application Data\bbbconfig.dat
[2006/08/09 02:09:12 | 000,000,027 | ---- | C] () -- C:\WINDOWS\VOIPMOUSE.INI
[2006/08/09 00:48:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/08/09 00:47:28 | 000,003,665 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/08/04 10:44:05 | 000,007,207 | R--- | C] () -- C:\WINDOWS\Disktool.INI
[2006/08/04 10:44:05 | 000,006,399 | R--- | C] () -- C:\WINDOWS\fwupgrade.ini
[2006/08/04 10:44:05 | 000,003,677 | R--- | C] () -- C:\WINDOWS\PlaySnd.INI
[2006/08/01 21:11:18 | 000,005,606 | ---- | C] () -- C:\WINDOWS\System32\stci.dll
[2006/07/30 22:23:45 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Kerrie\Local Settings\Application Data\fusioncache.dat
[2006/07/29 07:17:23 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\Kerrie\Application Data\wklnhst.dat
[2006/07/07 04:37:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
[2006/07/07 04:24:49 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/07/07 04:09:40 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2006/05/30 01:35:31 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/05/30 01:06:57 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/05/30 01:06:57 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/05/30 01:06:57 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/05/30 01:06:57 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/05/30 01:06:57 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/05/30 01:06:57 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/05/30 00:51:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VAIOUpdt.INI
[2006/05/29 23:00:08 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/05/29 23:00:08 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2006/05/29 21:31:00 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/05/29 21:30:03 | 000,303,624 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/29 21:08:36 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/05/29 20:43:21 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/05/29 20:37:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/05/29 12:22:06 | 000,003,822 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/05/29 12:21:29 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/05/29 12:21:26 | 000,444,810 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/05/29 12:21:26 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/05/29 12:21:26 | 000,072,686 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/05/29 12:21:26 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/05/29 12:21:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/05/29 12:21:24 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/05/29 12:21:21 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/05/29 12:21:16 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/05/29 12:21:16 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/05/29 12:21:14 | 001,868,868 | ---- | C] () -- C:\WINDOWS\System32\RSA32_16.DLL
[2006/05/29 12:21:06 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/05/29 12:20:56 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/02/15 21:58:40 | 000,335,872 | ---- | C] () -- C:\WINDOWS\System32\VNCX1.exe
[2005/11/01 19:53:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/09/03 00:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/23 07:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2004/10/25 14:57:16 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CUSBInst.exe
[2004/07/21 03:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/16 00:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2003/01/08 02:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2000/01/07 11:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\sysgtime.dll
[2000/01/07 11:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\System32\proclsvr.drv
[1999/01/27 23:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 17:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
========== LOP Check ==========
[2012/01/28 11:48:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2007/08/20 22:34:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2012/01/27 01:14:23 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2008/07/21 23:52:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/12/11 03:54:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
[2008/01/28 18:26:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo
[2006/09/07 12:55:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin
[2009/05/28 16:25:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
[2011/06/30 19:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Leapfrog
[2012/02/15 15:55:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2009/10/23 22:50:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2012/02/10 15:01:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/10/06 00:13:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\View22
[2007/01/29 11:26:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/11/27 21:23:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\123 Cheese
[2009/11/30 17:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Alawar
[2011/07/28 23:01:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Any Video Converter
[2012/02/08 20:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\AVG
[2012/01/27 01:40:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\AVG2012
[2008/05/11 21:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Azureus
[2007/10/12 05:01:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\ForgottenRiddles
[2007/08/11 06:19:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Gamelab
[2009/05/28 16:37:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\GetRightToGo
[2008/01/08 16:36:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Grisoft
[2011/12/15 22:32:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\gtk-2.0
[2008/12/16 10:29:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\ICAClient
[2007/01/09 09:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\InterVideo
[2006/09/07 12:55:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\iWin
[2006/09/25 05:30:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Leadertech
[2007/04/01 10:45:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\NCH Swift Sound
[2011/10/07 20:23:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Opera
[2009/10/23 22:50:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Playfirst
[2009/03/12 18:48:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\ProtectDisc
[2006/07/29 07:07:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Protector Suite
[2007/07/22 01:12:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Sandlot Games
[2009/03/12 18:49:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Strokes 4.0
[2006/07/29 07:17:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\Template
[2008/09/02 22:50:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\TomTom
[2009/04/25 21:00:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2011/04/26 18:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\uTorrent
[2007/11/22 05:52:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kerrie\Application Data\WholeSecurity
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >