Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

My anti-virus program says that win32k.sys is corrupted [Closed]


  • This topic is locked This topic is locked

#1
mnky81

mnky81

    New Member

  • Member
  • Pip
  • 3 posts

I run daily scans on my computer with avg anti-virus and it keeps showing about 22 corrupted files that all have the same root "win.32k.sys[.text] and I don't know if something is wrong with my computer or with my

anti-virus. Please help. Here's the OTL report:



OTL logfile created on: 4/7/2012 9:20:02 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Amber\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.95 Gb Total Physical Memory | 2.56 Gb Available Physical Memory | 43.10% Memory free
11.90 Gb Paging File | 7.88 Gb Available in Paging File | 66.21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 681.29 Gb Total Space | 624.58 Gb Free Space | 91.68% Space Free | Partition Type: NTFS
Drive D: | 17.05 Gb Total Space | 1.87 Gb Free Space | 10.94% Space Free | Partition Type: NTFS

Computer Name: AMBER-HP | User Name: Amber | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/04/07 21:14:10 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Amber\Downloads\OTL.exe
PRC - [2012/03/31 22:57:05 | 000,180,648 | ---- | M] (Google Inc.) -- C:\Users\Amber\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
PRC - [2012/03/06 19:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/03/06 19:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/02/29 16:29:41 | 004,321,112 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AIM\aim.exe
PRC - [2012/02/24 06:43:14 | 000,933,784 | ---- | M] (Support.com, Inc.) -- C:\Program Files (x86)\Office Depot PC Support Agent\esService.exe
PRC - [2012/02/24 06:43:14 | 000,586,136 | ---- | M] (Support.com, Inc.) -- C:\Program Files (x86)\Office Depot PC Support Agent\escont.exe
PRC - [2012/02/16 04:57:46 | 002,575,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2012/02/14 04:52:54 | 005,104,992 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
PRC - [2011/10/13 12:23:45 | 002,042,088 | ---- | M] (GameStop Corp.) -- C:\Program Files (x86)\Impulse\Now\ImpulseNow.exe
PRC - [2011/10/05 13:31:46 | 001,652,736 | R--- | M] (AWS Convergence Technologies, Inc.) -- C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
PRC - [2011/03/28 17:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2011/03/22 15:42:40 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2011/02/18 02:48:24 | 000,265,544 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
PRC - [2011/02/18 02:48:12 | 000,642,888 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
PRC - [2011/02/18 02:47:58 | 000,142,664 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
PRC - [2011/02/15 19:48:52 | 001,071,160 | ---- | M] (Hewlett-Packard Development Company L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
PRC - [2011/01/27 15:38:04 | 000,318,520 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
PRC - [2011/01/23 20:08:52 | 000,770,728 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\lxeamon.exe
PRC - [2011/01/12 22:00:42 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/01/12 22:00:38 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/12/22 16:25:02 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/12/22 16:24:58 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/11/26 10:09:12 | 000,399,344 | ---- | M] (Roxio) -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/11/17 13:53:16 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010/11/09 18:20:36 | 000,586,296 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2010/11/09 18:20:34 | 000,026,680 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2010/04/23 15:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/04/23 15:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2009/10/23 12:31:44 | 000,401,920 | ---- | M] (Amazon.com) -- C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
PRC - [2009/10/23 12:31:44 | 000,326,144 | ---- | M] (Amazon.com) -- C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
PRC - [2009/04/27 15:13:52 | 000,139,944 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\ezprint.exe


========== Modules (No Company Name) ==========

MOD - [2012/04/03 21:56:41 | 000,444,400 | ---- | M] () -- C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\ppgooglenaclpluginchrome.dll
MOD - [2012/04/03 21:56:39 | 003,915,248 | ---- | M] () -- C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\pdf.dll
MOD - [2012/04/03 21:55:14 | 000,122,880 | ---- | M] () -- C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\avutil-51.dll
MOD - [2012/04/03 21:55:12 | 000,220,672 | ---- | M] () -- C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\avformat-53.dll
MOD - [2012/04/03 21:55:11 | 001,747,456 | ---- | M] () -- C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\avcodec-53.dll
MOD - [2012/04/03 21:09:30 | 008,743,584 | ---- | M] () -- C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\gcswf32.dll
MOD - [2012/04/03 08:36:41 | 000,475,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\83fe46ae33b8fd827015387fb6efcd13\IAStorUtil.ni.dll
MOD - [2012/04/03 08:36:41 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\b40ad47b1338dd50c41d2c5571819a09\IAStorCommon.ni.dll
MOD - [2012/04/03 08:35:27 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll
MOD - [2012/04/03 08:34:35 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll
MOD - [2012/04/03 08:33:48 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll
MOD - [2012/04/03 08:33:33 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll
MOD - [2012/04/03 08:32:14 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll
MOD - [2012/04/03 08:31:37 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\a4dbc610559927ab02402b60ab5f7a52\System.Configuration.ni.dll
MOD - [2012/04/03 08:31:35 | 005,459,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\805353f2ad3146e1ca66ddcccf086b0a\System.Xml.ni.dll
MOD - [2012/04/03 08:28:16 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2012/02/29 16:24:17 | 000,176,128 | ---- | M] () -- C:\Program Files (x86)\AIM\nssckbi.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/01/23 20:08:52 | 000,770,728 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\lxeamon.exe
MOD - [2010/04/05 05:56:17 | 002,203,803 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\epwizres.dll
MOD - [2010/04/01 12:24:28 | 001,159,168 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\lxeadrs.dll
MOD - [2010/04/01 12:23:27 | 000,389,120 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\lxeascw.dll
MOD - [2009/10/23 12:31:44 | 000,038,912 | ---- | M] () -- C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\utility.dll
MOD - [2009/05/27 07:16:50 | 000,192,512 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\lxeadatr.dll
MOD - [2009/04/27 15:13:52 | 000,139,944 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\ezprint.exe
MOD - [2009/04/07 14:25:27 | 000,409,600 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\iptk.dll
MOD - [2009/03/30 08:37:47 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\epoemdll.dll
MOD - [2009/03/30 08:37:46 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\epstring.dll
MOD - [2009/03/30 08:37:28 | 000,708,608 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\epwizard.dll
MOD - [2009/03/30 08:35:40 | 000,159,744 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\customui.dll
MOD - [2009/03/30 08:35:22 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\epfunct.dll
MOD - [2009/03/30 08:35:17 | 000,118,784 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\eputil.dll
MOD - [2009/03/30 08:35:05 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\imagutil.dll
MOD - [2009/03/10 01:43:49 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\lxeacaps.dll
MOD - [2009/03/02 10:25:47 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\Lexmark S300-S400 Series\lxeaptp.dll
MOD - [2009/02/20 03:48:43 | 000,023,552 | ---- | M] () -- C:\Windows\SysWOW64\LXEAsmr.dll
MOD - [2009/02/20 03:48:03 | 000,299,008 | ---- | M] () -- C:\Windows\SysWOW64\LXEAsm.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/03/06 19:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2011/05/13 18:58:10 | 000,030,520 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)
SRV:64bit: - [2011/05/07 15:25:40 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/03/11 06:23:16 | 000,297,984 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2011/02/17 01:47:28 | 000,682,040 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe -- (HPAuto)
SRV:64bit: - [2011/01/05 17:41:38 | 001,515,792 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel®
SRV:64bit: - [2011/01/05 17:28:50 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011/01/05 17:26:56 | 000,836,880 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel®
SRV:64bit: - [2010/10/11 05:48:14 | 000,346,168 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/04/14 15:45:36 | 001,052,328 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxeacoms.exe -- (lxea_device)
SRV:64bit: - [2010/04/14 15:45:30 | 000,045,736 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxeaserv.exe -- (lxeaCATSCustConnectService)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/03/03 06:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2012/04/01 02:15:07 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/24 06:43:14 | 000,933,784 | ---- | M] (Support.com, Inc.) [Auto | Running] -- C:\Program Files (x86)\Office Depot PC Support Agent\esService.exe -- (Office Depot PC Support Agent)
SRV - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2012/02/14 04:52:54 | 005,104,992 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2011/12/13 12:17:00 | 004,041,880 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2011/09/09 17:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2011/03/28 17:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
SRV - [2011/02/18 02:48:24 | 000,265,544 | ---- | M] (HP) [Auto | Running] -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe -- (FPLService)
SRV - [2011/02/15 19:48:52 | 001,071,160 | ---- | M] (Hewlett-Packard Development Company L.P.) [On_Demand | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe -- (hpCMSrv)
SRV - [2011/01/12 22:00:42 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010/12/22 16:25:02 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2010/12/22 16:24:58 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010/11/26 10:09:12 | 000,399,344 | ---- | M] (Roxio) [Auto | Running] -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe -- (RoxioNow Service)
SRV - [2010/11/09 18:20:34 | 000,026,680 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)
SRV - [2010/10/12 13:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/04/14 15:45:30 | 000,045,736 | ---- | M] () [Auto | Running] -- C:\Windows\system32\spool\DRIVERS\x64\3\\lxeaserv.exe -- (lxeaCATSCustConnectService)
SRV - [2010/04/14 15:45:21 | 000,598,696 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysWOW64\lxeacoms.exe -- (lxea_device)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/10/23 12:31:44 | 000,401,920 | ---- | M] (Amazon.com) [Auto | Running] -- C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe -- (Amazon Download Agent)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/06 19:04:06 | 000,819,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012/03/06 19:04:04 | 000,337,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012/03/06 19:02:20 | 000,053,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012/03/06 19:01:57 | 000,059,224 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012/03/06 19:01:52 | 000,069,976 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012/03/06 19:01:32 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012/02/22 05:25:50 | 000,382,032 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2012/02/22 05:25:32 | 000,289,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2012/01/31 04:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2011/12/23 13:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011/12/23 13:32:04 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsfiltera.sys -- (AVGIDSFilter)
DRV:64bit: - [2011/12/23 13:32:02 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidseha.sys -- (AVGIDSEH)
DRV:64bit: - [2011/12/23 13:31:58 | 000,124,496 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2011/08/25 00:09:36 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/08/25 00:09:36 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/05/17 13:27:52 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011/05/17 13:27:50 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011/05/13 18:58:16 | 000,030,008 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)
DRV:64bit: - [2011/05/13 18:57:58 | 000,043,320 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)
DRV:64bit: - [2011/05/07 15:58:06 | 009,259,520 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/05/07 14:50:14 | 000,301,568 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/04/15 00:08:26 | 012,228,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
DRV:64bit: - [2011/03/11 06:23:16 | 000,521,728 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2011/02/16 21:11:08 | 000,428,136 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/01/12 21:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/01/12 20:10:44 | 000,333,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2011/01/04 15:29:46 | 008,507,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel®
DRV:64bit: - [2010/12/16 22:28:38 | 001,403,440 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/12/10 17:50:36 | 000,181,248 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010/12/10 17:50:36 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/19 20:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/10/14 14:28:16 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®
DRV:64bit: - [2010/07/28 13:13:50 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 16:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2005/01/03 02:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{DC153A6C-411D-46D5-82B5-C36EE02DAC76}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPNTDF
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
IE - HKLM\..\SearchScopes\{DC153A6C-411D-46D5-82B5-C36EE02DAC76}: "URL" = http://www.amazon.co...s={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPNTDF
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPNTDF
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
IE - HKCU\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
IE - HKCU\..\SearchScopes\{DC153A6C-411D-46D5-82B5-C36EE02DAC76}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Amber\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Amber\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/03/31 19:50:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/03/31 19:50:42 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Amber\AppData\Local\Google\Chrome\Application\18.0.1025.151\gcswf32.dll
CHR - plugin: Simple Pass 2011 (Enabled) = C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe\1.0_0\npwebsitelogon.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2111_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Amber\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\
CHR - Extension: AVG Safe Search = C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2111_0\
CHR - Extension: Gmail = C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Do-Not-Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (AVG Do-Not-Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark S300-S400 Series\ezprint.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [lxeamon.exe] C:\Program Files (x86)\Lexmark S300-S400 Series\lxeamon.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk = C:\Program Files (x86)\Impulse\Now\ImpulseNow.exe (GameStop Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: AVG Do-Not-Track - {DA58ACA7-18A6-403A-93DA-6E4172D43709} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: AVG Do-Not-Track - {DA58ACA7-18A6-403A-93DA-6E4172D43709} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{037E66A3-94ED-43A2-B7B9-6AFA15D36D44}: DhcpNameServer = 172.168.11.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2EA05815-5F54-41BB-BDAF-168977FC72CB}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{b3eb4c3e-f6ab-11de-8926-74e50b1d5972}\Shell - "" = AutoRun
O33 - MountPoints2\{b3eb4c3e-f6ab-11de-8926-74e50b1d5972}\Shell\AutoRun\command - "" = "F:\Ativa File Transfer .exe" bootup
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/07 20:06:48 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\{EE2B6B9D-9C54-4552-BEAA-9CACD67CCEB2}
[2012/04/07 20:06:26 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\{974883FE-BA96-4F5E-B59D-8422F858C1F1}
[2012/04/07 20:06:26 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\{1FFC60A1-4C08-4120-B5CB-1A415D781AFF}
[2012/04/07 18:35:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Sandlot Games
[2012/04/07 16:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\WhoCrashed
[2012/04/07 15:32:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics
[2012/04/07 01:08:46 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\MumboJumbo
[2012/04/06 01:40:35 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\AIMLogger
[2012/04/05 18:30:31 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\PlayFirst
[2012/04/05 18:30:31 | 000,000,000 | ---D | C] -- C:\ProgramData\PlayFirst
[2012/04/04 23:11:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Fugazo
[2012/04/03 23:31:37 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\IDT
[2012/04/03 01:26:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WildGames
[2012/04/03 00:22:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2012/04/03 00:20:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2012/04/03 00:13:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon
[2012/04/03 00:01:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Amazon Games & Software
[2012/04/03 00:01:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Amazon
[2012/04/02 23:54:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tradewinds 2
[2012/04/02 23:53:39 | 000,000,000 | ---D | C] -- C:\True_Patch_Gold_FINAL
[2012/04/01 19:14:24 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Apple Computer
[2012/04/01 19:14:24 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Apple Computer
[2012/04/01 19:14:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/04/01 19:13:56 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2012/04/01 19:13:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/04/01 19:13:22 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/04/01 19:13:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012/04/01 19:13:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2012/04/01 19:13:22 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/04/01 19:12:56 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Apple
[2012/04/01 19:12:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2012/04/01 19:12:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2012/04/01 19:12:12 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/04/01 19:12:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2012/04/01 19:12:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2012/04/01 19:12:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2012/04/01 16:01:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/04/01 16:01:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2012/04/01 05:38:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Activision
[2012/04/01 05:38:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Stardock
[2012/04/01 04:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\Lexmark Printable Web
[2012/04/01 03:56:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Sprint
[2012/04/01 03:55:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Abbyy FineReader 6.0 Sprint
[2012/04/01 03:55:05 | 000,000,000 | ---D | C] -- C:\Program Files\Lexmark Toolbar
[2012/04/01 03:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Ezprint
[2012/04/01 03:20:30 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Adobe
[2012/04/01 03:19:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Lx_cats
[2012/04/01 03:16:29 | 000,000,000 | ---D | C] -- C:\Program Files\Lexmark
[2012/04/01 03:16:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lexmark Toolbar
[2012/04/01 03:16:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lexmark
[2012/04/01 03:15:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lexmark S300-S400 Series
[2012/04/01 03:15:41 | 000,000,000 | ---D | C] -- C:\Program Files\Lexmark S300-S400 Series
[2012/04/01 03:14:59 | 000,000,000 | ---D | C] -- C:\Lexmark
[2012/04/01 03:02:50 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wild Tangent - Fate
[2012/04/01 03:02:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wild Tangent - Fate
[2012/04/01 03:01:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wild Tangent
[2012/04/01 03:00:34 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2012/04/01 03:00:34 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2012/04/01 02:44:58 | 000,000,000 | ---D | C] -- C:\Users\Amber\Desktop\Microsoft Office
[2012/04/01 02:44:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012/04/01 02:44:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012/04/01 02:41:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/04/01 02:41:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2012/04/01 02:41:32 | 000,000,000 | ---D | C] -- C:\Windows\SHELLNEW
[2012/04/01 02:41:23 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Microsoft Help
[2012/04/01 02:41:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2012/04/01 02:41:02 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/04/01 02:32:01 | 004,041,880 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\GameMon.des
[2012/04/01 02:31:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
[2012/04/01 02:31:11 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\npptNT2.sys
[2012/04/01 02:30:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\INCA Shared
[2012/04/01 02:30:11 | 000,000,000 | ---D | C] -- C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
[2012/04/01 02:15:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012/04/01 01:25:13 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Xfire
[2012/04/01 01:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
[2012/04/01 01:25:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
[2012/04/01 01:25:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xfire
[2012/04/01 01:22:08 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeMade
[2012/04/01 01:22:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeMade
[2012/04/01 01:22:07 | 000,000,000 | ---D | C] -- C:\WeMade Entertainment
[2012/04/01 00:40:01 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2012/04/01 00:39:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs
[2012/04/01 00:39:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Guild Wars
[2012/04/01 00:03:18 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cute Knight Kingdom
[2012/04/01 00:03:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cute Knight Kingdom
[2012/04/01 00:03:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cute Knight Kingdom
[2012/04/01 00:01:13 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Westward Kingdoms
[2012/04/01 00:01:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westward Kingdoms
[2012/04/01 00:01:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Westward Kingdoms
[2012/03/31 23:55:48 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual Villagers - New Believers
[2012/03/31 23:55:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Villagers - New Believers
[2012/03/31 23:55:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Virtual Villagers - New Believers
[2012/03/31 23:51:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CSI - NY - The Game
[2012/03/31 23:51:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CSI - NY - The Game
[2012/03/31 23:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012/03/31 23:51:15 | 000,337,240 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012/03/31 23:51:15 | 000,024,408 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/03/31 23:51:14 | 000,819,032 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012/03/31 23:51:14 | 000,258,520 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012/03/31 23:51:14 | 000,069,976 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/03/31 23:51:14 | 000,059,224 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012/03/31 23:51:14 | 000,053,080 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/03/31 23:50:56 | 000,041,184 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012/03/31 23:50:55 | 000,201,352 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012/03/31 23:50:45 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012/03/31 23:50:45 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/03/31 23:30:36 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Stardock
[2012/03/31 23:30:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Gibraltar
[2012/03/31 23:30:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Impulse
[2012/03/31 23:30:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Impulse
[2012/03/31 23:30:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\{EB424B13-2E57-4A45-936F-A4DFB6DB1688}
[2012/03/31 23:29:12 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\PackageAware
[2012/03/31 23:27:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Big Fish Games
[2012/03/31 23:27:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bfgclient
[2012/03/31 23:24:20 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache
[2012/03/31 23:22:59 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\My Received Files
[2012/03/31 23:21:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIM
[2012/03/31 23:20:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Software Update Utility
[2012/03/31 23:07:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/03/31 23:01:46 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/03/31 22:42:48 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\WeatherBug
[2012/03/31 22:42:47 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\WeatherBug
[2012/03/31 22:42:18 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeatherBug
[2012/03/31 22:42:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AWS
[size="2"][2012/03/31 22:17:34 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\acccore[/size]
[size="2"][2012/03/31 22:17:33 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\AIM[/size]
[size="2"][2012/03/31 22:17:30 | 000,000,000 | ---D | C] -- C:\ProgramData\AIM[/size]
[size="2"][2012/03/31 22:17:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AIM[/size]
[size="2"][2012/03/31 22:17:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AOL[/size]
[size="2"][2012/03/31 22:02:06 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\AOL[/size]
[size="2"][2012/03/31 21:58:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Blio[/size]
[size="2"][2012/03/31 21:58:35 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Blio[/size]
[size="2"][2012/03/31 20:34:34 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\{AB93485E-045C-4660-8761-82CB5A05E94F}[/size]
[size="2"][2012/03/31 20:34:20 | 000,000,000 | ---D | C] -- C:\Users\Amber\Tracing[/size]
[size="2"][2012/03/31 20:32:42 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\{22D0AF3B-2078-40BF-A397-416EDD0A3299}[/size]
[size="2"][2012/03/31 20:27:27 | 000,000,000 | ---D | C] -- C:\Users\Amber\Desktop\Fate[/size]
[size="2"][2012/03/31 20:23:29 | 000,000,000 | ---D | C] -- C:\Windows\en[/size]
[size="2"][2012/03/31 20:18:11 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink[/size]
[size="2"][2012/03/31 20:17:59 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\Youcam[/size]
[size="2"][2012/03/31 20:17:59 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\CyberLink[/size]
[size="2"][2012/03/31 20:17:59 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\CyberLink[/size]
[size="2"][2012/03/31 20:13:33 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Windows Live[/size]
[size="2"][2012/03/31 20:00:57 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Google[/size]
[size="2"][2012/03/31 20:00:44 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Deployment[/size]
[size="2"][2012/03/31 20:00:44 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Apps[/size]
[size="2"][color="#222222"][2012/03/31 19:51:39 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\AVG2012[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:52 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\AVG[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:40 | 000,000,000 | -H-D | C] -- C:\$AVG[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:40 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:45:33 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:45:16 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:43:58 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Hewlett-Packard_Developme[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:41:57 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Macromedia[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:41:55 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Adobe[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:36:47 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\CrashDumps[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:09:14 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\OneNote Notebooks[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:09:06 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\My Weblog Posts[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:08:48 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\My Stationery[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:08:48 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\My Games[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:08:47 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\My Data Sources[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:08:45 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\My Albums[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:08:39 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\Guild Wars[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:08:36 | 000,000,000 | ---D | C] -- C:\Users\Amber\Documents\Amazon Downloads[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:06:27 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\ATI[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:06:27 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\ATI[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:33 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Intel Corporation[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:25 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Synaptics[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:11 | 000,000,000 | R--D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:11 | 000,000,000 | R--D | C] -- C:\Users\Amber\Searches[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:11 | 000,000,000 | R--D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:10 | 000,000,000 | -H-D | C] -- C:\Users\Amber\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:02 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Identities[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:00 | 000,000,000 | R--D | C] -- C:\Users\Amber\Contacts[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:04:52 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\hpqlog[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:04:46 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\RemEngine[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:04:25 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Hewlett-Packard[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:04:16 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Hewlett-Packard[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:04:02 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Hewlett-Packard_Company[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:03:00 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\VirtualStore[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:29 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Intel[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | --SD | C] -- C:\Users\Amber\AppData\Roaming\Microsoft[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Videos[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Saved Games[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Pictures[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Music[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Links[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Favorites[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Downloads[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Documents[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\Desktop[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | R--D | C] -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\AppData\Local\Temporary Internet Files[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Templates[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Start Menu[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\SendTo[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Recent[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\PrintHood[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\NetHood[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Documents\My Videos[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Documents\My Pictures[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Documents\My Music[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\My Documents[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Local Settings[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\AppData\Local\History[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Cookies[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\Application Data[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -HSD | C] -- C:\Users\Amber\AppData\Local\Application Data[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | -H-D | C] -- C:\Users\Amber\AppData[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Temp[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | ---D | C] -- C:\Users\Amber\Roaming[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Local\Microsoft[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,000 | ---D | C] -- C:\Users\Amber\AppData\Roaming\Media Center Programs[/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"][color="#E56717"]========== Files - Modified Within 30 Days ==========[/color][/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"][2012/04/07 21:19:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job[/color][/size]
[size="2"][color="#222222"][2012/04/07 21:02:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3447426889-3236702856-658673029-1000UA.job[/color][/size]
[size="2"][color="#222222"][2012/04/07 17:52:34 | 094,123,293 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm[/color][/size]
[size="2"][color="#222222"][2012/04/07 17:52:04 | 000,138,872 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm[/color][/size]
[size="2"][color="#222222"][2012/04/07 17:22:22 | 000,002,590 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - hp.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/07 16:31:29 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0[/color][/size]
[size="2"][color="#222222"][2012/04/07 16:31:29 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0[/color][/size]
[size="2"][color="#222222"][2012/04/07 16:30:04 | 000,005,675 | ---- | M] () -- C:\Users\Amber\AppData\Local\Temp5.html[/color][/size]
[size="2"][color="#222222"][2012/04/07 16:29:49 | 000,001,955 | ---- | M] () -- C:\Users\Amber\AppData\Local\Temp1.html[/color][/size]
[size="2"][color="#222222"][2012/04/07 16:14:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat[/color][/size]
[size="2"][color="#222222"][2012/04/07 14:54:28 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI[/color][/size]
[size="2"][color="#222222"][2012/04/07 14:54:28 | 000,624,178 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat[/color][/size]
[size="2"][color="#222222"][2012/04/07 14:54:28 | 000,106,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat[/color][/size]
[size="2"][color="#222222"][2012/04/07 14:49:05 | 495,865,855 | -HS- | M] () -- C:\hiberfil.sys[/color][/size]
[size="2"][color="#222222"][2012/04/07 05:41:48 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForAmber.job[/color][/size]
[size="2"][color="#222222"][2012/04/07 05:26:37 | 000,261,209 | ---- | M] () -- C:\Windows\SysNative\LexFiles.ulf[/color][/size]
[size="2"][color="#222222"][2012/04/07 05:24:05 | 000,002,001 | ---- | M] () -- C:\Users\Public\Desktop\Launch Lexmark Printer Home.LNK[/color][/size]
[size="2"][color="#222222"][2012/04/06 23:02:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3447426889-3236702856-658673029-1000Core.job[/color][/size]
[size="2"][color="#222222"][2012/04/05 22:03:42 | 000,002,397 | ---- | M] () -- C:\Users\Amber\Desktop\Google Chrome.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 19:14:21 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 15:08:41 | 000,415,744 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT[/color][/size]
[size="2"][color="#222222"][2012/04/01 05:31:02 | 000,001,128 | ---- | M] () -- C:\Users\Amber\Desktop\Fate.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 02:31:55 | 000,002,179 | ---- | M] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 01:25:11 | 000,000,963 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 01:22:12 | 000,000,921 | ---- | M] () -- C:\Users\Amber\Desktop\DigimonBattle.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:57:37 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:51:16 | 000,001,841 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:30:33 | 000,001,156 | ---- | M] () -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:30:32 | 000,000,973 | ---- | M] () -- C:\Users\Public\Desktop\GameStop.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:21:45 | 000,000,746 | -H-- | M] () -- C:\IPH.PH[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:21:02 | 000,001,935 | ---- | M] () -- C:\Users\Amber\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:21:02 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\AIM.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:47:38 | 000,001,254 | ---- | M] () -- C:\Users\Amber\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:42:20 | 000,001,718 | ---- | M] () -- C:\Users\Amber\Desktop\WeatherBug.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:13:41 | 000,000,114 | ---- | M] () -- C:\Windows\wininit.ini[/color][/size]
[size="2"][color="#222222"][2012/03/31 20:47:24 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:53 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:52 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:52 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm[/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"][color="#E56717"]========== Files Created - No Company Name ==========[/color][/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"][2012/04/07 17:52:34 | 094,123,293 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm[/color][/size]
[size="2"][color="#222222"][2012/04/07 17:52:04 | 000,138,872 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm[/color][/size]
[size="2"][color="#222222"][2012/04/07 16:30:04 | 000,005,675 | ---- | C] () -- C:\Users\Amber\AppData\Local\Temp5.html[/color][/size]
[size="2"][color="#222222"][2012/04/07 16:29:49 | 000,001,955 | ---- | C] () -- C:\Users\Amber\AppData\Local\Temp1.html[/color][/size]
[size="2"][color="#222222"][2012/04/01 19:14:21 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 19:12:55 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 05:31:02 | 000,001,128 | ---- | C] () -- C:\Users\Amber\Desktop\Fate.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 04:04:12 | 000,002,001 | ---- | C] () -- C:\Users\Public\Desktop\Launch Lexmark Printer Home.LNK[/color][/size]
[size="2"][color="#222222"][2012/04/01 04:03:25 | 000,000,044 | -H-- | C] () -- C:\Windows\SysNative\lxearwrd.ini[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:14 | 000,109,056 | ---- | C] () -- C:\Windows\SysNative\lxeavs.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:12 | 000,836,608 | ---- | C] ( ) -- C:\Windows\SysNative\lxeacoin.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:08 | 000,450,048 | ---- | C] () -- C:\Windows\SysNative\lxeains.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:08 | 000,245,248 | ---- | C] () -- C:\Windows\SysNative\lxeainsb.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:08 | 000,065,106 | ---- | C] () -- C:\Windows\SysNative\lxeaprpr.chm[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:08 | 000,040,448 | ---- | C] () -- C:\Windows\SysNative\lxeajswr.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:07 | 000,065,536 | ---- | C] () -- C:\Windows\SysNative\lxeagcfg.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:06 | 000,399,360 | ---- | C] () -- C:\Windows\SysNative\lxeacui.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:06 | 000,378,368 | ---- | C] () -- C:\Windows\SysNative\lxeacu.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:06 | 000,148,480 | ---- | C] () -- C:\Windows\SysNative\lxeacuir.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:06 | 000,022,016 | ---- | C] () -- C:\Windows\SysNative\lxeacur.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:06 | 000,008,694 | ---- | C] () -- C:\Windows\SysNative\lxeacommuilogo_rtl.bmp[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:17:06 | 000,008,694 | ---- | C] () -- C:\Windows\SysNative\lxeacommuilogo.bmp[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:06 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeainpa.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:06 | 000,344,064 | ---- | C] () -- C:\Windows\SysWow64\lxeacomx.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:06 | 000,344,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeaiesc.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:06 | 000,331,776 | ---- | C] () -- C:\Windows\SysWow64\LXEAinst.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:06 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\lxeainsr.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:06 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\lxeajswr.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 001,048,576 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeaserv.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 000,847,872 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeausb1.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeapmui.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 000,323,584 | ---- | C] () -- C:\Windows\SysWow64\lxeains.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 000,262,144 | ---- | C] () -- C:\Windows\SysWow64\lxeainsb.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\lxeacu.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 000,090,112 | ---- | C] () -- C:\Windows\SysWow64\lxeacub.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:05 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\lxeacur.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:04 | 000,802,816 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeacomc.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:04 | 000,688,128 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeahbn3.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:04 | 000,598,696 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeacoms.exe[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:04 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\lxealmpm.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:04 | 000,372,736 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeacomm.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:04 | 000,324,264 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeaih.exe[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:03 | 000,373,416 | ---- | C] ( ) -- C:\Windows\SysWow64\lxeacfg.exe[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:16:03 | 000,002,106 | ---- | C] () -- C:\Windows\SysWow64\lxea.loc[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:50 | 001,331,712 | ---- | C] ( ) -- C:\Windows\SysNative\lxeausb1.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:50 | 000,557,568 | ---- | C] ( ) -- C:\Windows\SysNative\lxeainpa.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:50 | 000,547,840 | ---- | C] ( ) -- C:\Windows\SysNative\LXEAhcp.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:50 | 000,515,584 | ---- | C] ( ) -- C:\Windows\SysNative\lxeaiesc.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:50 | 000,495,616 | ---- | C] () -- C:\Windows\SysNative\LXEAinst.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:50 | 000,261,209 | ---- | C] () -- C:\Windows\SysNative\LexFiles.ulf[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:49 | 001,631,744 | ---- | C] ( ) -- C:\Windows\SysNative\lxeaserv.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:49 | 000,979,968 | ---- | C] ( ) -- C:\Windows\SysNative\lxeapmui.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:49 | 000,892,416 | ---- | C] ( ) -- C:\Windows\SysNative\lxealmpm.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:49 | 000,090,624 | ---- | C] () -- C:\Windows\SysNative\lxeainsr.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:48 | 001,104,384 | ---- | C] ( ) -- C:\Windows\SysNative\lxeahbn3.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:48 | 000,520,872 | ---- | C] ( ) -- C:\Windows\SysNative\lxeaih.exe[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:48 | 000,298,496 | ---- | C] () -- C:\Windows\SysNative\lxeagrd.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:48 | 000,073,216 | ---- | C] () -- C:\Windows\SysNative\lxeacub.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:47 | 001,371,648 | ---- | C] ( ) -- C:\Windows\SysNative\lxeacomc.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:47 | 001,052,328 | ---- | C] ( ) -- C:\Windows\SysNative\lxeacoms.exe[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:47 | 000,612,008 | ---- | C] ( ) -- C:\Windows\SysNative\lxeacfg.exe[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:47 | 000,579,584 | ---- | C] ( ) -- C:\Windows\SysNative\lxeacomm.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:46 | 000,002,106 | ---- | C] () -- C:\Windows\SysNative\lxea.loc[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:41 | 000,023,552 | ---- | C] () -- C:\Windows\SysWow64\LXEAsmr.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:40 | 000,381,440 | ---- | C] () -- C:\Windows\SysNative\lxeasm.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:40 | 000,299,008 | ---- | C] () -- C:\Windows\SysWow64\LXEAsm.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 03:15:40 | 000,023,552 | ---- | C] () -- C:\Windows\SysNative\lxeasmr.dll[/color][/size]
[size="2"][color="#222222"][2012/04/01 02:33:39 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForAmber.job[/color][/size]
[size="2"][color="#222222"][2012/04/01 02:31:55 | 000,002,179 | ---- | C] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 02:31:11 | 000,005,174 | ---- | C] () -- C:\Windows\SysWow64\nppt9x.vxd[/color][/size]
[size="2"][color="#222222"][2012/04/01 02:15:08 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job[/color][/size]
[size="2"][color="#222222"][2012/04/01 01:25:11 | 000,000,963 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk[/color][/size]
[size="2"][color="#222222"][2012/04/01 01:22:12 | 000,000,921 | ---- | C] () -- C:\Users\Amber\Desktop\DigimonBattle.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:51:16 | 000,001,841 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:51:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:30:33 | 000,001,156 | ---- | C] () -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:30:32 | 000,000,973 | ---- | C] () -- C:\Users\Public\Desktop\GameStop.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:27:52 | 000,001,927 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Manager.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:27:52 | 000,001,248 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\More Great Games.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:01:48 | 000,002,397 | ---- | C] () -- C:\Users\Amber\Desktop\Google Chrome.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:57:08 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3447426889-3236702856-658673029-1000UA.job[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:57:07 | 000,000,856 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3447426889-3236702856-658673029-1000Core.job[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:42:20 | 000,001,718 | ---- | C] () -- C:\Users\Amber\Desktop\WeatherBug.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:17:30 | 000,001,935 | ---- | C] () -- C:\Users\Amber\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:17:30 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\AIM.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:17:16 | 000,000,746 | -H-- | C] () -- C:\IPH.PH[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:13:41 | 000,000,114 | ---- | C] () -- C:\Windows\wininit.ini[/color][/size]
[size="2"][color="#222222"][2012/03/31 20:47:24 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf[/color][/size]
[size="2"][color="#222222"][2012/03/31 20:21:31 | 000,001,254 | ---- | C] () -- C:\Users\Amber\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:53 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:52 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:50:52 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:17 | 000,001,409 | ---- | C] () -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:12 | 000,001,413 | ---- | C] () -- C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:04:05 | 000,002,312 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Download Store.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:04:05 | 000,002,278 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Trials for QuickBooks, Quicken and TurboTax.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,290 | ---- | C] () -- C:\Users\Amber\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:02:24 | 000,000,272 | ---- | C] () -- C:\Users\Amber\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk[/color][/size]
[size="2"][color="#222222"][2012/02/29 15:21:24 | 000,042,392 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:32:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:23:37 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:22:30 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:22:30 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:22:30 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:22:30 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:22:29 | 013,359,616 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:22:28 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat[/color][/size]
[size="2"][color="#222222"][2012/02/26 07:18:01 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat[/color][/size]
[size="2"][color="#222222"][2011/08/25 00:36:56 | 000,000,068 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat[/color][/size]
[size="2"][color="#222222"][2011/03/04 01:04:58 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL[/color][/size]
[size="2"][color="#222222"][2010/12/16 22:26:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll[/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"][color="#E56717"]========== LOP Check ==========[/color][/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"][2012/03/31 22:17:55 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\acccore[/color][/size]
[size="2"][color="#222222"][2012/03/31 19:51:39 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\AVG2012[/color][/size]
[size="2"][color="#222222"][2012/03/31 21:59:07 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\Blio[/color][/size]
[size="2"][color="#222222"][2012/04/03 23:31:37 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\IDT[/color][/size]
[size="2"][color="#222222"][2012/04/07 01:08:46 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\MumboJumbo[/color][/size]
[size="2"][color="#222222"][2012/04/05 18:30:31 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\PlayFirst[/color][/size]
[size="2"][color="#222222"][2012/04/06 19:28:40 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\QuickScan[/color][/size]
[size="2"][color="#222222"][2012/03/31 23:31:25 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\Stardock[/color][/size]
[size="2"][color="#222222"][2012/03/31 18:05:25 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\Synaptics[/color][/size]
[size="2"][color="#222222"][2012/03/31 22:42:47 | 000,000,000 | ---D | M] -- C:\Users\Amber\AppData\Roaming\WeatherBug[/color][/size]
[size="2"][color="#222222"][2009/07/14 01:08:49 | 000,011,860 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT[/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"][color="#E56717"]========== Purity Check ==========[/color][/color][/size]
[size="2"] [/size]
[size="2"] [/size]
[size="2"] [/size]
[size="2"][color="#222222"][color="#E56717"]========== Alternate Data Streams ==========[/color][/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"]@Alternate Data Stream - 232 bytes -> C:\ProgramData\Temp:898D0B77[/color][/size]
[size="2"][color="#222222"]@Alternate Data Stream - 212 bytes -> C:\ProgramData\Temp:3C9B05C4[/color][/size]
[size="2"][color="#222222"]@Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:C0913157[/color][/size]
[size="2"][color="#222222"]@Alternate Data Stream - 209 bytes -> C:\ProgramData\Temp:F1DEA771[/color][/size]
[size="2"][color="#222222"]@Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:A3E39C6A[/color][/size]
[size="2"] [/size]
[size="2"][color="#222222"]< End of report >[/color][/size][color="#222222"] [/color]


  • 0

Advertisements


#2
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,131 posts
Hello mnky81 and welcome to Geeks To Go !!

My name is Crowbar and I'll be the malware removal Geek that will be helping you remove any infections you may have on your computer.
Please be patient with me as I am currently in training, and all of my responses to you have to be reviewed by my instructor before I post them.
You get an advantage as you have 2 people examining your issue.
  • Please read all of my response through at least once before attempting to follow the procedures described.
  • Please save my instructions as a text file on your desktop, or print them out, as you may not be able to access this thread at times.
  • Please follow the steps exactly as written, in the same order.
  • If there's anything you don't understand or isn't totally clear, please ask me any questions that you may have.
  • Please do not attach any log files to your replies unless I specifically ask you. Instead please copy and paste so as to include the log in your reply. You can do this in separate posts if it's easier for you.
  • This process is not an instant process - please stick with me until I tell you that your machine is clean. If you don't see any symptoms it does not mean your system is clear of malware
  • Please don't run any other scans or other software unless I ask you to, as it will make this repair more difficult.

Sorry for the delay.
Are you still having the same problem?
Your log file is a little old.
Step 1
Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

Step 2
Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it
Posted Image

Click the [Scan] button to start scan
Posted Image

On completion of the scan click [Save log], save it to your desktop and post in your next reply

In your next reply I would like to see:
  • Fresh OTL log
  • aswMBR log

  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP