E machine, runninng XP shows Hour glass(busy) half the time and hard drive works incessantly.
Problem#2
Recently "vprot.exec" error shows upon boot.
Thank you for your time, roc
OTL logfile created on: 2/25/2013 8:33:29 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Susan\My Documents
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.12 Gb Total Physical Memory | 2.63 Gb Available Physical Memory | 84.07% Memory free
4.97 Gb Paging File | 4.44 Gb Available in Paging File | 89.38% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.61 Gb Total Space | 121.90 Gb Free Space | 84.29% Space Free | Partition Type: NTFS
Drive I: | 4.42 Gb Total Space | 2.23 Gb Free Space | 50.50% Space Free | Partition Type: FAT32
Computer Name: E-MACHINE | User Name: Susan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/02/24 09:50:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Susan\My Documents\OTL.exe
PRC - [2013/02/10 12:27:03 | 000,965,296 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe
PRC - [2013/02/06 11:48:30 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2012/08/13 09:57:02 | 010,376,704 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2012/08/13 09:57:02 | 010,368,512 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2012/08/13 02:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgidsagent.exe
PRC - [2012/07/31 02:37:02 | 002,596,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/07/26 02:23:08 | 000,758,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2012/06/13 02:48:24 | 001,255,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2012/03/19 04:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2012/02/14 03:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2012/02/14 03:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/09/09 15:01:16 | 001,804,648 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2013/02/10 12:27:03 | 000,965,296 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe
MOD - [2012/11/01 09:51:46 | 009,814,968 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
MOD - [2012/08/27 20:30:06 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2008/04/14 04:42:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 04:41:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013/02/10 12:27:03 | 000,965,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe -- (vToolbarUpdater14.1.7)
SRV - [2012/08/13 02:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2012/02/14 03:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/02/10 12:27:04 | 000,033,112 | ---- | M] () [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012/08/24 14:43:18 | 000,301,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2012/07/26 02:21:30 | 000,237,408 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2012/04/19 03:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2012/01/31 03:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/12/23 12:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/12/23 12:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2011/12/23 12:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)
DRV - [2011/12/23 12:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2010/07/12 03:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwfd)
DRV - [2010/07/12 03:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwdx)
DRV - [2005/09/14 10:38:00 | 003,856,896 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2005/08/12 15:31:12 | 000,098,432 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata)
DRV - [2005/07/29 18:11:04 | 000,012,928 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/07/29 18:11:02 | 000,034,048 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg....fr&d=2013-01-22 14:41:08&v=14.0.0.14&pid=safeguard&sg=1&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://mysearch.avg....fr&d=2013-01-22 14:41:08&v=14.0.0.14&pid=safeguard&sg=1&sap=hp"
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.152.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..keyword.URL: "http://mysearch.avg....fr&d=2013-01-22 14:41:08&pid=safeguard&sg=1&v=14.0.0.14&sap=ku&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/09/10 11:42:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2012/08/27 18:15:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2012/08/27 18:15:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\14.0.0.14 [2013/01/22 14:41:13 | 000,000,000 | ---D | M]
[2012/01/10 16:53:07 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Susan\Application Data\Mozilla\Extensions
[2012/01/10 16:53:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Susan\Application Data\Mozilla\Firefox\Profiles\zhoeurau.default\extensions
[2012/01/10 16:53:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Susan\Application Data\Mozilla\Firefox\Profiles\zhoeurau.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/04/25 13:32:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\ZHOEURAU.DEFAULT\EXTENSIONS\{20A82645-C095-46ED-80E3-08825760534B}
File not found (No name found) -- C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
File not found (No name found) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
O1 HOSTS File: ([2004/08/16 18:48:49 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\14.0.0.14\AVG SafeGuard toolbar_toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\14.0.0.14\AVG SafeGuard toolbar_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG SafeGuard toolbar\vprot.exe ()
O4 - HKCU..\Run: [HP Officejet 6700 (NET)] C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Susan\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.88.1 8.8.8.8 2.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6E692C47-160E-4729-9BE8-B6C91236BB78}: DhcpNameServer = 192.168.88.1 8.8.8.8 2.2.2.2
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/25 11:55:44 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - I:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - I:\autorun.inf.aug.8 -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/24 09:50:58 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Susan\My Documents\OTL.exe
[2013/02/10 12:28:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/25 07:57:08 | 111,156,118 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2013/02/25 07:53:03 | 000,001,643 | ---- | M] () -- C:\Documents and Settings\Susan\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6700 (Network).lnk
[2013/02/25 07:52:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/02/24 14:00:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2013/02/24 10:10:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2013/02/24 09:50:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Susan\My Documents\OTL.exe
[2013/02/23 20:40:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2013/02/23 19:13:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2013/02/23 16:31:54 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/02/22 18:15:39 | 000,130,498 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2013/02/20 09:08:49 | 000,225,975 | ---- | M] () -- C:\Documents and Settings\Susan\My Documents\ccrw%202013%20membership.3%20-%20Sheet1.pdf
[2013/02/13 16:38:07 | 000,118,952 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/02/13 08:26:43 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/02/12 10:34:45 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/02/10 12:27:04 | 000,033,112 | ---- | M] () -- C:\WINDOWS\System32\drivers\avgtpx86.sys
[2013/02/07 18:37:42 | 000,662,737 | ---- | M] () -- C:\Documents and Settings\Susan\My Documents\Scan0002.pdf
[2013/02/06 11:14:17 | 000,672,937 | ---- | M] () -- C:\Documents and Settings\Susan\My Documents\Scan0001.jpg
[2013/02/05 09:33:31 | 000,071,168 | ---- | M] () -- C:\Documents and Settings\Susan\My Documents\Third Grade Essay Contest Certificate
[2013/01/31 22:11:50 | 000,013,873 | ---- | M] () -- C:\Documents and Settings\Susan\My Documents\Plum Creek Elementary- Third Grade Teachers.odt
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/20 09:08:49 | 000,225,975 | ---- | C] () -- C:\Documents and Settings\Susan\My Documents\ccrw%202013%20membership.3%20-%20Sheet1.pdf
[2013/02/12 10:33:02 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/02/07 18:37:41 | 000,662,737 | ---- | C] () -- C:\Documents and Settings\Susan\My Documents\Scan0002.pdf
[2013/02/06 11:14:16 | 000,672,937 | ---- | C] () -- C:\Documents and Settings\Susan\My Documents\Scan0001.jpg
[2013/02/05 09:33:31 | 000,071,168 | ---- | C] () -- C:\Documents and Settings\Susan\My Documents\Third Grade Essay Contest Certificate
[2013/01/31 09:14:16 | 000,013,873 | ---- | C] () -- C:\Documents and Settings\Susan\My Documents\Plum Creek Elementary- Third Grade Teachers.odt
[2013/01/22 14:41:04 | 000,033,112 | ---- | C] () -- C:\WINDOWS\System32\drivers\avgtpx86.sys
[2012/08/27 18:09:19 | 000,000,057 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Ament.ini
[2012/02/26 20:04:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/01/10 16:37:31 | 000,010,584 | ---- | C] () -- C:\Documents and Settings\Susan\Application Data\docXConverter (3).ini
[2012/01/10 16:37:31 | 000,006,093 | ---- | C] () -- C:\Documents and Settings\Susan\Application Data\PrimoPDFSet.xml
[2012/01/10 16:37:31 | 000,000,310 | ---- | C] () -- C:\Documents and Settings\Susan\Application Data\APUSet.xml
[2012/01/10 16:37:31 | 000,000,132 | -H-- | C] () -- C:\Documents and Settings\Susan\Application Data\lakerda1967.sys
[2012/01/10 16:37:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Susan\Application Data\wklnhst.dat
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrszht.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrszhc.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrstr.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrssv.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrssl.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrssk.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsru.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsptb.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrspt.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrspl.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsno.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsnl.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsko.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsja.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsit.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrshu.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrshe.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsfr.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrszht.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrszhc.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrstr.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrssv.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrssl.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrssk.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsru.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsptb.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrspt.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrspl.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsno.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsnl.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsko.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsja.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsit.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrshu.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrshe.dll
[2011/04/25 15:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsfr.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsfi.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsesm.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrses.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrseng.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsel.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsde.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsda.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrscs.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwrsar.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsfi.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsesm.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrses.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrseng.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsel.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsde.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsda.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrscs.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvrsar.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvmccsrs.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvcolor.exe
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2011/04/25 15:08:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2011/04/25 15:08:39 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2011/04/25 15:08:38 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2011/04/25 15:08:35 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2011/04/25 15:03:17 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011/04/25 12:52:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/04/25 11:53:02 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/04/25 06:39:24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/04/25 06:38:24 | 000,118,952 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2012/12/27 04:24:19 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 06:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 04:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/22 14:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG January 2013 Campaign
[2013/01/22 20:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar
[2013/01/22 14:41:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2012/02/26 20:03:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/05/09 11:43:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2013/02/24 13:14:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2013/01/22 14:41:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\AVG SafeGuard toolbar
[2012/02/02 14:20:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\AVG2012
[2012/01/10 16:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\CheckPoint
[2012/01/10 16:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\FUJIFILM
[2012/01/10 16:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Grisoft
[2012/01/10 16:55:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\iolo
[2012/01/10 16:55:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Juniper Networks
[2012/01/10 16:55:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Leadertech
[2012/01/10 16:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\MailFrontier
[2011/09/30 07:21:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Mikrotik
[2012/01/10 16:52:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\OpenOffice.org
[2011/04/29 13:59:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Opera
[2012/01/10 16:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\SampleView
[2012/01/10 16:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Smith Micro
[2012/01/10 16:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Template
[2012/01/10 16:37:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\The Blocks Company, LLC
========== Purity Check ==========
< End of report >