jontom - this is from otl.txt:
OTL logfile created on: 11/12/2011 10:27:56 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\T. Carlberg\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.07 Mb Total Physical Memory | 344.12 Mb Available Physical Memory | 33.93% Memory free
2.85 Gb Paging File | 2.13 Gb Available in Paging File | 74.89% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.97 Gb Total Space | 32.40 Gb Free Space | 45.65% Space Free | Partition Type: NTFS
Drive F: | 465.64 Gb Total Space | 251.11 Gb Free Space | 53.93% Space Free | Partition Type: FAT32
Computer Name: MAIN | User Name: T. Carlberg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/12 10:26:39 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T. Carlberg\Desktop\OTL.scr
PRC - [2011/10/29 08:33:28 | 002,078,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/12/01 06:26:40 | 000,574,216 | —- | M] (Intel Corporation) – C:\Program Files\Intel\IntelAppStore\bin\serviceManager.exe
PRC - [2010/11/27 17:32:46 | 000,725,344 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/20 08:46:03 | 000,621,920 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/24 15:12:44 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/24 15:12:34 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/24 15:12:25 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/24 15:12:24 | 000,842,592 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2010/05/21 00:28:00 | 011,312,128 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/05/21 00:27:58 | 011,318,784 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/09/29 08:17:50 | 000,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2000/08/07 05:35:37 | 000,192,512 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb01.exe
PRC - [1999/10/22 11:00:32 | 000,043,520 | —- | M] () – C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
PRC - [1999/08/12 06:59:08 | 000,036,864 | —- | M] (Intuit) – C:\QUICKENW\QWDLLS.EXE
========== Modules (No Company Name) ==========
MOD - [2011/07/13 18:49:52 | 000,854,016 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll
MOD - [2011/07/13 18:49:50 | 000,403,456 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll
MOD - [2011/07/13 18:49:50 | 000,270,336 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\log4net\1.2.10.0__1b44e1d426115821\log4net.dll
MOD - [2011/07/13 18:49:49 | 000,471,040 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll
MOD - [2011/07/13 18:49:46 | 000,419,616 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll
MOD - [2011/07/13 18:49:46 | 000,046,880 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll
MOD - [2011/07/13 18:49:46 | 000,023,840 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll
MOD - [2011/07/13 18:49:46 | 000,018,720 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll
MOD - [2011/07/13 18:49:46 | 000,012,064 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll
MOD - [2011/07/13 18:49:45 | 000,270,112 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.445.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll
MOD - [2011/07/13 18:49:45 | 000,120,096 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll
MOD - [2011/07/13 18:49:45 | 000,070,432 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll
MOD - [2011/07/13 18:49:44 | 000,121,632 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll
MOD - [2011/04/13 07:23:12 | 000,212,992 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e0d56c0582316e9ecb4c18186e37217c\System.ServiceProcess.ni.dll
MOD - [2011/04/12 23:55:51 | 007,949,824 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f02cf6430a9fc77908a74ab6925cb73c\System.ni.dll
MOD - [2011/04/12 23:55:18 | 011,490,816 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\62d5f089dd51f18472a7caf1593d9f6b\mscorlib.ni.dll
MOD - [2011/04/12 23:54:27 | 003,182,592 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2011/04/12 23:54:26 | 002,933,248 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2011/04/12 23:54:25 | 000,425,984 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2011/04/12 23:54:21 | 000,626,688 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
MOD - [2011/04/12 23:54:21 | 000,303,104 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2011/04/12 23:54:20 | 000,258,048 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
MOD - [2011/04/12 23:54:19 | 002,048,000 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2011/04/12 23:54:19 | 000,261,632 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2011/04/12 23:54:17 | 000,114,688 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
MOD - [2011/04/12 23:54:11 | 005,025,792 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2011/01/26 08:37:42 | 003,622,128 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\plugin\libbizlplugin.dll
MOD - [2010/12/01 06:26:38 | 000,195,584 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\libgsoap.dll
MOD - [2010/12/01 06:26:36 | 000,400,384 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\sqlite3.dll
MOD - [2010/12/01 06:26:36 | 000,375,808 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\QtXml4.dll
MOD - [2010/12/01 06:26:36 | 000,322,048 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\log4cplus.dll
MOD - [2010/12/01 06:26:36 | 000,013,312 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\featureController.dll
MOD - [2010/12/01 06:26:35 | 002,452,992 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\QtCore4.dll
MOD - [2010/12/01 06:26:35 | 001,008,640 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\QtNetwork4.dll
MOD - [2010/12/01 06:26:34 | 000,062,464 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\zlib1.dll
MOD - [2010/05/04 15:36:28 | 000,970,752 | —- | M] () – C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2004/04/11 17:57:44 | 000,040,960 | —- | M] () – C:\Program Files\Dell\Media Experience\DirWatcher.dll
MOD - [1999/10/26 12:32:14 | 000,050,176 | —- | M] () – C:\Program Files\Adobe\Acrobat 4.0\Distillr\adistres.dll
MOD - [1999/10/22 11:00:32 | 000,043,520 | —- | M] () – C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/07/26 09:16:02 | 001,025,352 | —- | M] () [On_Demand | Stopped] – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)
SRV - [2010/06/24 15:12:34 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2009/09/29 08:17:50 | 000,013,088 | —- | M] (Intuit Inc.) [Auto | Running] – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)
========== Driver Services (SafeList) ==========
DRV - [2011/09/12 19:17:01 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/05 09:26:13 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/06/24 15:12:27 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2010/03/04 09:58:11 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\System32\Drivers\avgrkx86.sys – (AvgRkx86)
DRV - [2004/03/24 07:12:44 | 000,004,272 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\bvrp_pci.sys – (bvrp_pci)
DRV - [2003/11/17 12:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 12:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 12:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys – (HSF_DP)
DRV - [2003/09/19 14:47:24 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys – (pfc)
DRV - [2002/11/08 11:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [1999/08/12 06:59:08 | 000,034,916 | —- | M] (Marimba, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\MrtRate.sys – (mrtRate)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/mail?.intl=us
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found
O1 HOSTS File: ([2010/04/12 20:10:28 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb01.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Intel AppUp(SM) center] C:\Program Files\Intel\IntelAppStore\bin\serviceManager.lnk ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [2231125297] C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\wuj.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\QUICKENW\BILLMIND.EXE (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE (Intuit)
O4 - Startup: C:\Documents and Settings\T. Carlberg\Start Menu\Programs\Startup\AVG Tray Icon.lnk = C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - Startup: C:\Documents and Settings\T. Carlberg\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_20.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: SecurityRisk ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: usgs.gov ([extract.cr] http in Trusted sites)
O15 - HKCU\..Trusted Domains: yahoo.com ([login] https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{124E9C0C-7263-4DDD-A928-3A79B1179208}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 11:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/06/16 22:04:20 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O32 - AutoRun File - [2005/11/15 12:08:04 | 000,000,036 | -H– | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/12 10:26:50 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\T. Carlberg\Desktop\aswMBR.exe
[2011/11/12 10:26:37 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\T. Carlberg\Desktop\OTL.scr
[2011/11/12 00:53:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\T. Carlberg\Recent
[2011/11/11 11:34:37 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\T. Carlberg\Desktop\dds.scr
[2011/11/10 16:11:51 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\T. Carlberg\Desktop\HiJackThis.exe
[2011/11/04 11:49:34 | 000,000,000 | —D | C] – C:\Program Files\FamilySearch
[2011/11/04 11:49:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\FamilySearch
[2011/10/30 20:30:16 | 000,000,000 | —D | C] – C:\Documents and Settings\T. Carlberg\Application Data\Amazon
[2011/10/30 20:29:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Amazon
[2011/10/30 20:29:37 | 000,000,000 | —D | C] – C:\Program Files\Amazon
[2011/10/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files\Citrix
[2006/10/10 13:09:36 | 001,053,198 | —- | C] (Macromedia, Inc.) – C:\Program Files\freemahjongg.exe
[2005/02/25 17:24:19 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\System32\IMPLODE.DLL
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/12 10:31:26 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/11/12 10:27:29 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[2011/11/12 10:27:03 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\T. Carlberg\Desktop\aswMBR.exe
[2011/11/12 10:26:39 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T. Carlberg\Desktop\OTL.scr
[2011/11/12 09:25:19 | 088,953,134 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/11/12 09:21:16 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/11/12 09:20:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/11/11 11:46:21 | 000,002,779 | —- | M] () – C:\WINDOWS\winzip32.ini
[2011/11/11 11:34:42 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\T. Carlberg\Desktop\dds.scr
[2011/11/10 16:11:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\T. Carlberg\Desktop\HiJackThis.exe
[2011/11/09 17:56:43 | 000,001,043 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/11/06 09:05:01 | 000,442,892 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/11/06 09:05:01 | 000,072,158 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/11/02 22:34:01 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/02 07:15:10 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/13 14:58:19 | 000,072,080 | —- | M] () – C:\Documents and Settings\T. Carlberg\g2mdlhlpx.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/10/13 14:58:18 | 000,072,080 | —- | C] () – C:\Documents and Settings\T. Carlberg\g2mdlhlpx.exe
[2011/09/09 15:13:03 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/21 22:45:00 | 000,001,862 | -HS- | C] () – C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\2sj84r4yr1d5210755e
[2011/06/21 22:45:00 | 000,001,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2sj84r4yr1d5210755e
[2011/03/21 01:07:29 | 000,147,264 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/18 17:04:01 | 000,000,058 | -H– | C] () – C:\WINDOWS\popcreg.dat
[2010/07/18 17:04:01 | 000,000,020 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/06/26 11:42:59 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2010/06/26 11:42:59 | 000,002,411 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2009/06/09 18:13:04 | 000,000,581 | —- | C] () – C:\WINDOWS\ArcPad.INI
[2009/04/01 23:10:40 | 000,000,045 | —- | C] () – C:\WINDOWS\TRIMSURV.INI
[2009/04/01 23:05:11 | 000,002,528 | —- | C] () – C:\Documents and Settings\T. Carlberg\Application Data\$_hpcst$.hpc
[2008/11/19 18:26:37 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/09 21:03:39 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/03 19:12:30 | 000,000,048 | —- | C] () – C:\WINDOWS\Usnscsvr.ini
[2007/11/16 12:45:57 | 000,002,779 | —- | C] () – C:\WINDOWS\winzip32.ini
[2007/01/07 11:52:27 | 000,001,369 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/22 20:38:20 | 000,000,021 | —- | C] () – C:\WINDOWS\CS_SETUP.ini
[2006/10/12 16:08:39 | 000,000,551 | —- | C] () – C:\Program Files\Shortcut to freemahjongg.exe.lnk
[2006/02/17 00:07:32 | 000,000,004 | —- | C] () – C:\WINDOWS\info147.sys
[2005/09/17 17:04:24 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/08/07 22:27:43 | 000,000,000 | —- | C] () – C:\WINDOWS\IMPORT71.INI
[2005/05/03 20:34:14 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2005/05/03 20:31:08 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/02/08 22:51:22 | 000,040,129 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2005/02/08 22:51:22 | 000,000,151 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2005/01/21 23:40:15 | 000,000,715 | —- | C] () – C:\WINDOWS\aolback.exe.lnk
[2005/01/02 11:15:36 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\Fpl.dll
[2005/01/02 11:15:22 | 000,332,800 | —- | C] () – C:\WINDOWS\System32\Fpxlib.dll
[2005/01/02 11:15:22 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\Jpeglib.dll
[2005/01/02 11:15:22 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2004/12/12 21:29:52 | 000,004,248 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/11/30 09:57:07 | 000,061,678 | —- | C] () – C:\Documents and Settings\T. Carlberg\Application Data\PFP120JPR.{PB
[2004/11/30 09:57:07 | 000,012,358 | —- | C] () – C:\Documents and Settings\T. Carlberg\Application Data\PFP120JCM.{PB
[2004/11/30 00:23:28 | 000,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2004/11/29 22:46:19 | 000,009,381 | —- | C] () – C:\WINDOWS\mozver.dat
[2004/11/29 21:35:56 | 000,000,335 | —- | C] () – C:\WINDOWS\mozregistry.dat
[2004/11/29 21:35:07 | 000,000,000 | —- | C] () – C:\WINDOWS\netscape.INI
[2004/11/29 17:48:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/29 17:31:49 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2004/11/29 17:25:26 | 000,040,828 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/11/29 17:25:10 | 000,634,087 | —- | C] () – C:\WINDOWS\cd32.exe
[2004/11/29 17:18:18 | 000,001,043 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/11/29 17:18:17 | 000,006,838 | —- | C] () – C:\WINDOWS\ICOADB32.DAT
[2004/11/29 17:18:17 | 000,000,542 | —- | C] () – C:\WINDOWS\intuprof.ini
[2004/11/29 14:31:07 | 000,147,968 | —- | C] () – C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/11/18 00:42:49 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/11/18 00:40:37 | 000,001,097 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/11/18 00:36:48 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/11/18 00:25:16 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/11/18 00:24:32 | 000,442,892 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/11/18 00:24:32 | 000,072,158 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/11/18 00:12:46 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/15 20:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 11:13:12 | 000,000,882 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/10 11:08:08 | 000,253,472 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:03:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:02:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 08:08:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 08:08:26 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 03:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 03:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 03:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 03:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 03:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 03:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 03:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 03:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 14:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2003/07/31 15:16:46 | 000,000,017 | -H– | C] () – C:\WINDOWS\System32\drivers\DVEMODEM.DAT
[2000/04/04 10:15:00 | 000,000,899 | —- | C] () – C:\WINDOWS\TIMEZONE.INI
[1999/01/22 10:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1979/12/31 22:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2010/08/16 21:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/12/27 08:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2004/11/18 00:34:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/03/14 22:56:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/04/20 15:21:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/06/26 22:15:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2010/07/18 17:04:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/09/08 19:38:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\qxwjelar
[2009/11/04 20:55:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2009/04/01 23:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trimble
[2005/01/21 23:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/11/16 11:37:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/10/11 18:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/28 18:28:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/11/02 17:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Amazon
[2010/04/19 09:53:35 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\AVG9
[2007/10/11 19:06:47 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Grisoft
[2005/01/24 12:54:54 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Leadertech
[2006/10/22 20:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Nikon
[2010/11/22 16:07:25 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\OpenOffice.org
[2011/04/12 19:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Rovio
[2009/04/01 23:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Trimble
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 11:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/11/12 10:27:29 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/12 20:16:16 | 000,010,667 | —- | M] () – C:\ComboFix.txt
[2004/08/10 11:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/02/25 17:25:52 | 000,006,116 | —- | M] () – C:\DeIsL1.isu
[2004/11/18 00:15:28 | 000,004,496 | RH– | M] () – C:\DELL.SDR
[2004/08/10 11:14:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 11:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/02/03 00:15:19 | 000,001,536 | -H– | M] () – C:\IPH.PH
[2005/07/17 22:28:19 | 000,102,940 | —- | M] () – C:\mmjb.DDF
[2004/08/10 11:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/18 22:23:47 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2011/11/12 09:20:22 | 2097,152,000 | -HS- | M] () – C:\pagefile.sys
[2011/06/22 18:31:43 | 000,000,404 | —- | M] () – C:\rkill.log
[2007/06/08 14:37:19 | 000,235,988 | —- | M] () – C:\winzip.log
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 11:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 02:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2007/01/10 23:36:48 | 000,231,936 | —- | M] () – C:\WINDOWS\Usnscsvr.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2009/02/12 23:00:34 | 000,001,754 | -H– | M] () – C:\Documents and Settings\T. Carlberg\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2006/10/10 13:09:36 | 001,053,198 | —- | M] (Macromedia, Inc.) – C:\Program Files\freemahjongg.exe
[2006/10/12 16:08:39 | 000,000,551 | —- | M] () – C:\Program Files\Shortcut to freemahjongg.exe.lnk
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 10:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2004/08/10 10:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2004/08/10 10:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2009/04/02 09:23:20 | 000,002,359 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\ GPS Pathfinder Office.lnk
[2009/02/25 19:54:22 | 000,002,447 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Access 9.0.2720.lnk
[2009/08/29 23:11:50 | 000,000,821 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Adobe Photoshop 5.0.lnk
[2011/11/09 11:09:45 | 000,002,305 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Adobe Reader 9.lnk
[2005/02/25 17:24:24 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\ArcView GIS 3.2.lnk
[2005/06/20 12:34:45 | 000,000,574 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Calculator.lnk
[2008/10/18 22:30:54 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
[2009/08/08 17:40:08 | 000,002,471 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Excel 9.0.2720.lnk
[2010/11/22 16:01:01 | 000,000,897 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\OpenOffice.org.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-17 16:04:53
< MD5 for: EXPLORER.EX_ >
[2004/08/04 03:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2011/01/16 15:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\procs\explorer.exe
[2007/06/13 03:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2005/08/16 01:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\h\explorer.exe
< MD5 for: EXPLORER.LNK >
[2008/11/23 16:17:35 | 000,001,475 | —- | M] () MD5=6F71C7603CC287DCF6DDA0F339459B3C – C:\Documents and Settings\T. Carlberg\Start Menu\Explorer.lnk
< MD5 for: EXPLORER.SC_ >
[2004/08/04 03:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2004/08/04 03:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\EXPLORER.SCF
< MD5 for: IEXPLORE.CHM >
[2004/08/04 03:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\I386\IEXPLORE.CHM
[2004/08/04 03:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2004/08/04 03:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\I386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 03:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2007/04/24 06:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 00:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 07:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2008/04/21 23:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 03:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 00:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 00:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2009/08/26 21:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 02:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2011/01/16 15:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\procs\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 02:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2011/04/21 02:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\SoftwareDistribution\Download\d8b42e8b95ac6025753f2f219fcb9b81\sp3qfe\iexplore.exe
[2009/10/27 22:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2006/10/17 13:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2009/12/18 05:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 02:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 16:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2011/06/22 18:59:48 | 001,007,120 | —- | M] () MD5=62B8E10334799A27218FBE57708A9FC1 – C:\Documents and Settings\T. Carlberg\Desktop\iExplore.exe
[2007/10/10 00:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 01:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 00:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 01:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 03:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/27 22:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/06 00:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 18:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 06:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2005/08/16 01:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\h\iexplore.exe
[2009/05/26 18:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\nird\iexplore.exe
[2010/06/17 06:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 03:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/22 21:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2011/04/21 02:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/04/21 02:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\SoftwareDistribution\Download\d8b42e8b95ac6025753f2f219fcb9b81\sp3gdr\iexplore.exe
[2011/04/21 02:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
[2010/12/20 02:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 01:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 03:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 00:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/22 21:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/17 23:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/02/27 22:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2010/10/18 02:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/02/14 03:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 04:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 03:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 03:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 02:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 03:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/26 21:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2011/03/18 16:40:09 | 000,012,293 | —- | M] () MD5=FE63BB1D8B232AB3AC3F943752ED6057 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log
< MD5 for: IEXPLORE.EXE.MUI >
[2006/10/17 13:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE_129510101681562500.EXH >
[2011/05/27 14:50:16 | 000,000,510 | —- | M] () MD5=F3719C648354A4009BE04ADEB884AC21 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510101681562500.exh
< MD5 for: IEXPLORE.EXE_129510101681562500_F.DMP >
[2011/05/27 14:50:16 | 256,252,710 | —- | M] () MD5=8B639A3A3DD41AC705B315B982A725B8 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510101681562500_F.dmp
< MD5 for: IEXPLORE.EXE_129510101681562500_M.DMP >
[2011/05/27 14:49:43 | 000,550,332 | —- | M] () MD5=262A4EF9DF8667AB2602E359EEC3980E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510101681562500_M.dmp
< MD5 for: IEXPLORE.EXE_129510104383593750_F.DMP >
[2011/05/27 14:53:58 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510104383593750_F.dmp
< MD5 for: IEXPLORE.EXE_129510104383593750_M.DMP >
[2011/05/27 14:53:58 | 000,008,675 | —- | M] () MD5=90F36B65402D8E54441CDF29BCEC8493 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510104383593750_M.dmp
< MD5 for: IEXPLORE.EXE_129601588885652277_F.DMP >
[2011/09/10 12:09:16 | 000,589,044 | —- | M] () MD5=1D833150B623297A742E2A0F4C75570D – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588885652277_F.dmp
< MD5 for: IEXPLORE.EXE_129601588885652277_M.DMP >
[2011/09/10 12:08:41 | 001,017,775 | —- | M] () MD5=4DDB95DC3DF9CD473C39AC329D1F961C – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588885652277_M.dmp
< MD5 for: IEXPLORE.EXE_129601588886746027_F.DMP >
[2011/09/10 12:09:16 | 036,368,548 | —- | M] () MD5=B37D938288FF9464A90337DF2BA3854C – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588886746027_F.dmp
< MD5 for: IEXPLORE.EXE_129601588886746027_M.DMP >
[2011/09/10 12:08:46 | 001,018,047 | —- | M] () MD5=9E565EE9ED00FF8DDB286E5A7DEC86BD – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588886746027_M.dmp
< MD5 for: IEXPLORE.EXE_129601588891433527_F.DMP >
[2011/09/10 12:09:16 | 030,859,428 | —- | M] () MD5=570BFC99F5F490460EFBFA8CF2088A77 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891433527_F.dmp
< MD5 for: IEXPLORE.EXE_129601588891433527_M.DMP >
[2011/09/10 12:08:41 | 001,017,775 | —- | M] () MD5=6708A4BAC26AD5B8196D7DBF54989405 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891433527_M.dmp
< MD5 for: IEXPLORE.EXE_129601588891902277_F.DMP >
[2011/09/10 12:09:16 | 000,242,596 | —- | M] () MD5=8A824D5C9EACA4B5EC89417CDDA3AC8E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891902277_F.dmp
< MD5 for: IEXPLORE.EXE_129601588891902277_M.DMP >
[2011/09/10 12:08:46 | 001,017,775 | —- | M] () MD5=50315A94BA8C1F863D8EB42A1D192FFA – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891902277_M.dmp
< MD5 for: IEXPLORE.EXE_129601588892058527_F.DMP >
[2011/09/10 12:09:17 | 016,539,764 | —- | M] () MD5=0110942151877C241F7C7612E8C56999 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892058527_F.dmp
< MD5 for: IEXPLORE.EXE_129601588892058527_M.DMP >
[2011/09/10 12:08:46 | 001,017,775 | —- | M] () MD5=07B1891032D71C8830E3D9A609A2A2C2 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892058527_M.dmp
< MD5 for: IEXPLORE.EXE_129601588892214777_F.DMP >
[2011/09/10 12:09:16 | 000,256,260 | —- | M] () MD5=77613405D2CA244C0A3A9671E1D41194 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892214777_F.dmp
< MD5 for: IEXPLORE.EXE_129601588892214777_M.DMP >
[2011/09/10 12:08:46 | 001,017,775 | —- | M] () MD5=ACF2E8EE5640A6F537B0E0B798407B5B – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892214777_M.dmp
< MD5 for: IEXPLORE.EXE_129625086350625000_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086350625000_F.dmp
< MD5 for: IEXPLORE.EXE_129625086350625000_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=48C0E3E19BD522596394200FD42A8FE6 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086350625000_M.dmp
< MD5 for: IEXPLORE.EXE_129625086352031250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352031250_F.dmp
< MD5 for: IEXPLORE.EXE_129625086352031250_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=CDF1DE6EDE108F8430E3BAEAD5F33E77 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352031250_M.dmp
< MD5 for: IEXPLORE.EXE_129625086352656250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352656250_F.dmp
< MD5 for: IEXPLORE.EXE_129625086352656250_M.DMP >
[2011/10/07 16:50:41 | 000,002,962 | —- | M] () MD5=A8252AE4741641E5390BB2C667C3964F – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352656250_M.dmp
< MD5 for: IEXPLORE.EXE_129625086353281250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353281250_F.dmp
< MD5 for: IEXPLORE.EXE_129625086353281250_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=0EC57E2B342935359E74C9609C9E84AE – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353281250_M.dmp
< MD5 for: IEXPLORE.EXE_129625086353593750_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353593750_F.dmp
< MD5 for: IEXPLORE.EXE_129625086353593750_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=68553CE091A6F3F3B437FDC9A8346FDC – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353593750_M.dmp
< MD5 for: IEXPLORE.EXE_129625086353906250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353906250_F.dmp
< MD5 for: IEXPLORE.EXE_129625086353906250_M.DMP >
[2011/10/07 16:50:41 | 000,002,962 | —- | M] () MD5=301054320E928692A203E178F77068AB – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353906250_M.dmp
< MD5 for: IEXPLORE.EXE_129625086355156250_F.DMP >
[2011/10/07 16:50:35 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086355156250_F.dmp
< MD5 for: IEXPLORE.EXE_129625086355156250_M.DMP >
[2011/10/07 16:50:35 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086355156250_M.dmp
< MD5 for: IEXPLORE.EXE_129625086359375000_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086359375000_F.dmp
< MD5 for: IEXPLORE.EXE_129625086359375000_M.DMP >
[2011/10/07 16:50:41 | 000,002,962 | —- | M] () MD5=06E190F645CE7E047EA89F7C3D27BEC5 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086359375000_M.dmp
< MD5 for: IEXPLORE.EXE_129625136157812500_F.DMP >
[2011/10/07 18:13:36 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625136157812500_F.dmp
< MD5 for: IEXPLORE.EXE_129625136157812500_M.DMP >
[2011/10/07 18:13:35 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625136157812500_M.dmp
< MD5 for: IEXPLORE.EXE_129643353311750000_F.DMP >
[2011/10/28 20:15:31 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129643353311750000_F.dmp
< MD5 for: IEXPLORE.EXE_129643353311750000_M.DMP >
[2011/10/28 20:15:31 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129643353311750000_M.dmp
< MD5 for: IEXPLORE.EXE_129645082446250000_F.DMP >
[2011/10/30 20:17:59 | 020,742,620 | —- | M] () MD5=377754828791126A22020359A5AE7A84 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082446250000_F.dmp
< MD5 for: IEXPLORE.EXE_129645082446250000_M.DMP >
[2011/10/30 20:17:44 | 000,655,524 | —- | M] () MD5=6A61E00B64CE712CFAA2FBC89A071936 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082446250000_M.dmp
< MD5 for: IEXPLORE.EXE_129645082448906250_F.DMP >
[2011/10/30 20:17:58 | 020,742,620 | —- | M] () MD5=EEB0B12F5C880C8631B8801ADBE14C8A – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082448906250_F.dmp
< MD5 for: IEXPLORE.EXE_129645082448906250_M.DMP >
[2011/10/30 20:17:44 | 000,654,460 | —- | M] () MD5=E91DB7D7A77BE1236FBD16F1CED73F55 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082448906250_M.dmp
< MD5 for: IEXPLORE.EXE_129645082450156250_F.DMP >
[2011/10/30 20:17:59 | 020,742,620 | —- | M] () MD5=9712C6CF42DC19726C98F60215EAD108 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082450156250_F.dmp
< MD5 for: IEXPLORE.EXE_129645082450156250_M.DMP >
[2011/10/30 20:17:41 | 000,655,524 | —- | M] () MD5=F87DE5F77FE61DC7F05FD4E0D8931294 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082450156250_M.dmp
< MD5 for: IEXPLORE.EXE_129648421191875000_F.DMP >
[2011/11/03 17:03:07 | 029,324,566 | —- | M] () MD5=7B43C6AE15D356443959CD3345EC4D0C – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421191875000_F.dmp
< MD5 for: IEXPLORE.EXE_129648421191875000_M.DMP >
[2011/11/03 17:02:24 | 001,085,340 | —- | M] () MD5=D4E6B1DCBBBFB3EE93EDC1E0C753794F – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421191875000_M.dmp
< MD5 for: IEXPLORE.EXE_129648421195937500_F.DMP >
[2011/11/03 17:03:07 | 029,324,566 | —- | M] () MD5=2EA0068F75BD1488D42C4289B480E25A – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421195937500_F.dmp
< MD5 for: IEXPLORE.EXE_129648421195937500_M.DMP >
[2011/11/03 17:02:23 | 001,085,340 | —- | M] () MD5=3FDA6EDBF3EC8FAF3EEF2A9BFE125E29 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421195937500_M.dmp
< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2011/11/02 21:58:57 | 000,095,374 | —- | M] () MD5=6C2F1406923F4915100C801D8BB18434 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 03:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2004/08/04 03:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\IEXPLORE.HLP
< MD5 for: WINLOGON.EXE >
[2004/08/04 03:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\I386\WINLOGON.EXE
[2009/05/26 18:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe
< End of report >