O1 HOSTS File: ([2013/06/27 13:11:38 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:
64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {687578B9-7132-4A7A-80E4-30EE31099E03} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {BEBC2A28-82AB-4CC7-810E-9A3DF7A1970F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {687578B9-7132-4A7A-80E4-30EE31099E03} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {BEBC2A28-82AB-4CC7-810E-9A3DF7A1970F} - No CLSID value found.
O3 - HKU\S-1-5-21-2108723901-1102379063-3819353076-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-2108723901-1102379063-3819353076-1001..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - Startup: C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Gal\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JustCloud.lnk = C:\Program Files (x86)\JustCloud\JustCloud.exe (JustCloud.com)
O4 - Startup: C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2108723901-1102379063-3819353076-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2108723901-1102379063-3819353076-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2108723901-1102379063-3819353076-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-2108723901-1102379063-3819353076-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16:
64bit: - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (Reg Error: Key error.)
O16:
64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 10.21.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A7E2C78C-EEB4-4D08-B7E9-AEE14FD11CA7}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B4D4D5FB-C52D-4100-A93F-140488D5660E}: DhcpNameServer = 82.102.139.10 82.102.139.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4F1C0D9-1BFD-4AFC-8617-3978E0F22E04}: DhcpNameServer = 10.0.0.138
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/06/28 11:59:21 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Gal\Desktop\OTL.exe
[2013/06/28 11:58:11 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/06/28 11:58:06 | 000,000,000 | ---D | C] -- C:\JRT
[2013/06/28 11:57:54 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Gal\Desktop\JRT.exe
[2013/06/27 13:44:00 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Roaming\AVG2013
[2013/06/27 13:43:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/06/27 13:42:43 | 000,000,000 | -H-D | C] -- C:\$AVG
[2013/06/27 13:42:42 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013/06/27 13:32:39 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Local\Avg2013
[2013/06/27 13:12:13 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/06/27 13:08:21 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/06/27 12:53:13 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/06/27 12:53:13 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/06/27 12:53:13 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/06/27 12:53:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/06/27 12:52:31 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/06/27 12:51:41 | 005,083,698 | R--- | C] (Swearware) -- C:\Users\Gal\Desktop\ComboFix.exe
[2013/06/27 00:13:22 | 000,000,000 | ---D | C] -- C:\Users\Gal\SyncFolder
[2013/06/27 00:11:50 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JustCloud
[2013/06/27 00:11:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JustCloud
[2013/06/25 13:21:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/06/25 13:16:55 | 000,000,000 | ---D | C] -- C:\Users\Gal\Desktop\mbar
[2013/06/25 13:05:52 | 000,000,000 | ---D | C] -- C:\Users\Gal\Desktop\RK_Quarantine
[2013/06/24 11:28:47 | 000,000,000 | ---D | C] -- C:\Users\Gal\Desktop\virus
[2013/06/20 13:03:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/06/20 13:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/06/20 13:03:04 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/06/20 13:03:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013/06/20 13:03:04 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/06/20 12:57:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/06/20 12:57:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2013/06/19 12:21:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Books Downloader
[2013/06/19 12:21:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google Books Downloader
[2013/06/19 12:20:47 | 000,000,000 | ---D | C] -- C:\Users\Gal\Desktop\HQuY1f26BSkC
[2013/06/15 12:25:26 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Local\Programs
[2013/06/15 12:24:53 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Roaming\Malwarebytes
[2013/06/15 12:24:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/06/15 10:35:15 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Roaming\TuneUp Software
[2013/06/14 18:11:05 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Roaming\HTML Executable
[2013/06/14 18:10:29 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Local\MFAData
[2013/06/13 18:25:56 | 000,000,000 | ---D | C] -- C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\x264 Video Codec
[2013/06/13 18:25:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\x264 Video Codec
[2013/06/02 11:00:00 | 000,000,000 | ---D | C] -- C:\Users\Gal\Desktop\רווק
========== Files - Modified Within 30 Days ==========
[2013/06/28 12:18:00 | 000,000,942 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/28 12:15:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2108723901-1102379063-3819353076-1001UA.job
[2013/06/28 12:02:57 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/28 12:02:57 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/28 12:01:25 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2013/06/28 11:58:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Gal\Desktop\OTL.exe
[2013/06/28 11:57:03 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Gal\Desktop\JRT.exe
[2013/06/28 11:55:21 | 000,000,938 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/28 11:55:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/28 11:55:15 | 3054,940,160 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/28 11:52:45 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2108723901-1102379063-3819353076-1001Core.job
[2013/06/28 11:50:30 | 000,648,201 | ---- | M] () -- C:\Users\Gal\Desktop\adwcleaner.exe
[2013/06/28 11:49:37 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/27 18:00:43 | 116,309,383 | ---- | M] () -- C:\Users\Gal\Documents\Untitled Multitrack 2.asnd
[2013/06/27 17:58:47 | 234,464,532 | ---- | M] () -- C:\Users\Gal\Documents\misF.mp4
[2013/06/27 17:42:11 | 234,477,358 | ---- | M] () -- C:\Users\Gal\Documents\mis.mp4
[2013/06/27 17:30:04 | 058,103,944 | ---- | M] () -- C:\Users\Gal\Documents\mis.wav
[2013/06/27 17:27:35 | 174,527,249 | ---- | M] () -- C:\Users\Gal\Documents\mis.asnd
[2013/06/27 17:06:25 | 225,554,432 | ---- | M] () -- C:\Users\Gal\Documents\13603848.m4v
[2013/06/27 17:06:25 | 007,208,960 | ---- | M] () -- C:\Users\Gal\Documents\13603848.aac
[2013/06/27 17:06:25 | 000,000,000 | ---- | M] () -- C:\Users\Gal\Documents\mis2.mp4
[2013/06/27 17:05:18 | 058,104,210 | ---- | M] () -- C:\Users\Gal\Documents\tal.wav
[2013/06/27 13:43:11 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/27 13:11:38 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/06/27 13:11:07 | 000,001,673 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2013/06/27 13:11:05 | 000,002,512 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[2013/06/27 09:52:55 | 005,083,698 | R--- | M] (Swearware) -- C:\Users\Gal\Desktop\ComboFix.exe
[2013/06/27 00:13:22 | 000,001,621 | ---- | M] () -- C:\Users\Gal\Desktop\Sync Folder.lnk
[2013/06/27 00:11:51 | 000,001,079 | ---- | M] () -- C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JustCloud.lnk
[2013/06/27 00:11:51 | 000,001,069 | ---- | M] () -- C:\Users\Gal\Desktop\JustCloud.lnk
[2013/06/26 14:55:41 | 000,783,200 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/26 14:55:41 | 000,655,280 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/06/26 14:55:41 | 000,122,152 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/06/25 22:38:26 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2013/06/25 13:03:49 | 003,759,104 | ---- | M] () -- C:\Users\Gal\Desktop\RogueKillerX64.exe
[2013/06/24 18:08:24 | 000,000,021 | ---- | M] () -- C:\Windows\SurCode.INI
[2013/06/20 13:04:00 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/06/20 12:57:52 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/06/19 12:21:20 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\Google Books Downloader.lnk
[2013/06/15 10:52:31 | 002,135,908 | ---- | M] () -- C:\Users\Gal\Desktop\License Keys For all Antivirus.zip
[2013/06/10 10:05:24 | 000,001,246 | ---- | M] () -- C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2013/06/07 19:32:10 | 000,001,152 | ---- | M] () -- C:\Users\Gal\Application Data\Microsoft\Internet Explorer\Quick Launch\BS.Player FREE.lnk
[2013/06/07 19:32:10 | 000,001,128 | ---- | M] () -- C:\Users\Public\Desktop\BS.Player FREE.lnk
[2013/06/06 18:05:49 | 000,001,049 | ---- | M] () -- C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/06/06 18:05:40 | 000,001,013 | ---- | M] () -- C:\Users\Gal\Desktop\Dropbox.lnk
========== Files Created - No Company Name ==========
[2013/06/28 11:50:39 | 000,648,201 | ---- | C] () -- C:\Users\Gal\Desktop\adwcleaner.exe
[2013/06/27 18:00:29 | 116,309,383 | ---- | C] () -- C:\Users\Gal\Documents\Untitled Multitrack 2.asnd
[2013/06/27 17:49:38 | 234,464,532 | ---- | C] () -- C:\Users\Gal\Documents\misF.mp4
[2013/06/27 17:32:04 | 234,477,358 | ---- | C] () -- C:\Users\Gal\Documents\mis.mp4
[2013/06/27 17:29:58 | 058,103,944 | ---- | C] () -- C:\Users\Gal\Documents\mis.wav
[2013/06/27 17:27:30 | 174,527,249 | ---- | C] () -- C:\Users\Gal\Documents\mis.asnd
[2013/06/27 17:06:25 | 225,554,432 | ---- | C] () -- C:\Users\Gal\Documents\13603848.m4v
[2013/06/27 17:06:25 | 007,208,960 | ---- | C] () -- C:\Users\Gal\Documents\13603848.aac
[2013/06/27 17:06:25 | 000,000,000 | ---- | C] () -- C:\Users\Gal\Documents\mis2.mp4
[2013/06/27 17:05:14 | 058,104,210 | ---- | C] () -- C:\Users\Gal\Documents\tal.wav
[2013/06/27 13:43:11 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/27 12:53:13 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/06/27 12:53:13 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/06/27 12:53:13 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/06/27 12:53:13 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/06/27 12:53:13 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/06/27 00:13:22 | 000,001,621 | ---- | C] () -- C:\Users\Gal\Desktop\Sync Folder.lnk
[2013/06/27 00:11:51 | 000,001,079 | ---- | C] () -- C:\Users\Gal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JustCloud.lnk
[2013/06/27 00:11:51 | 000,001,069 | ---- | C] () -- C:\Users\Gal\Desktop\JustCloud.lnk
[2013/06/25 13:05:00 | 003,759,104 | ---- | C] () -- C:\Users\Gal\Desktop\RogueKillerX64.exe
[2013/06/20 13:04:00 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/06/20 12:57:52 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/06/19 12:21:20 | 000,001,106 | ---- | C] () -- C:\Users\Public\Desktop\Google Books Downloader.lnk
[2013/06/14 18:11:44 | 002,135,908 | ---- | C] () -- C:\Users\Gal\Desktop\License Keys For all Antivirus.zip
[2013/06/13 22:22:27 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/15 14:52:46 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2013/03/21 20:20:02 | 000,769,286 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/24 12:49:16 | 000,026,900 | ---- | C] () -- C:\Users\Gal\AppData\Local\dt.dat
[2012/12/06 01:39:09 | 000,765,952 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012/12/06 01:39:09 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012/12/02 20:33:56 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe
[2012/07/04 20:00:23 | 000,000,600 | ---- | C] () -- C:\Users\Gal\PUTTY.RND
[2012/06/02 13:26:59 | 000,245,456 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/05/08 11:11:48 | 000,185,856 | ---- | C] () -- C:\Windows\SysWow64\Bmp2Jpeg.dll
[2012/04/02 21:26:19 | 000,000,132 | ---- | C] () -- C:\Users\Gal\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/01/10 21:29:54 | 013,904,384 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/11/04 09:11:50 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/11/03 20:35:15 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/10/05 21:50:23 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011/10/05 13:52:17 | 000,000,132 | ---- | C] () -- C:\Users\Gal\AppData\Roaming\Adobe AIFF Format CS5 Prefs
[2011/09/15 13:46:00 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/09/14 10:28:29 | 000,000,118 | ---- | C] () -- C:\Users\Gal\.jupload.properties
[2011/09/13 19:29:17 | 000,000,023 | ---- | C] () -- C:\Windows\SWFDecompiler.INI
[2011/06/03 14:16:54 | 000,001,563 | ---- | C] () -- C:\Users\Gal\AppData\Local\server.conf
[2011/05/14 11:14:58 | 000,000,600 | ---- | C] () -- C:\Users\Gal\AppData\Local\PUTTY.RND
[2011/02/02 17:23:09 | 000,001,456 | ---- | C] () -- C:\Users\Gal\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/07/21 15:18:32 | 000,008,704 | ---- | C] () -- C:\Users\Gal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2009/07/14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/02/27 08:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/27 07:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 15:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/01/31 13:12:05 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/01/31 13:12:05 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2011/01/25 00:25:42 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\adma
[2012/10/17 16:54:23 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Ashampoo
[2010/06/19 00:12:12 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Asus WebStorage
[2011/09/17 16:37:34 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\AtomPark
[2010/08/03 20:50:49 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Audacity
[2013/06/27 13:44:00 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\AVG2013
[2010/10/18 07:51:39 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Avid
[2011/09/19 15:36:22 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\BOXEE
[2013/04/13 13:04:02 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\BSplayer
[2012/12/06 19:14:07 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\BSplayer Pro
[2010/12/11 15:55:20 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/09/13 10:35:56 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\CoffeeCup Software
[2012/03/29 13:25:36 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2011/03/20 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\com.adobe.ResourceCentral
[2010/09/17 15:53:31 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\DAEMON Tools Lite
[2010/09/17 05:38:04 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\DAEMON Tools Net
[2012/06/23 15:38:16 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Digiarty
[2013/06/28 11:56:00 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Dropbox
[2011/12/27 12:23:01 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\EurekaLog
[2011/10/25 22:45:36 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\FileZilla
[2012/07/21 16:06:38 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\GARMIN
[2013/05/20 09:51:03 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\GMATPrep
[2010/07/13 18:20:58 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Gold Wave Editor Pro
[2013/06/14 18:11:05 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\HTML Executable
[2011/11/05 15:53:57 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\ICAClient
[2011/03/31 14:45:33 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\ImTOO
[2013/03/14 07:46:20 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\IObit
[2011/12/26 23:16:17 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\JAM Software
[2010/10/18 12:12:10 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Kalypso Media
[2013/01/19 01:57:36 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Macro Recorder
[2011/03/31 14:21:11 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Modiac
[2010/07/01 17:39:40 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\OpenOffice.org
[2010/12/13 10:02:15 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\PACE Anti-Piracy
[2012/02/10 20:46:02 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\redsn0w
[2011/01/22 10:53:11 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\ResourceCentral.E6E1B28A311BC518DB6C6883EA3757FDE0E90ADC.1
[2011/03/29 09:24:51 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Rovio
[2011/09/15 15:03:40 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\SendBlaster2
[2010/12/11 15:48:14 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/11/10 11:36:47 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\StatSoft
[2011/12/02 20:35:32 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\SynthMaker
[2010/11/27 13:23:40 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\SystemRequirementsLab
[2012/03/29 12:01:02 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\TCXConverter
[2011/05/14 10:14:43 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\TightVNC
[2013/06/15 10:35:15 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\TuneUp Software
[2013/02/15 17:51:18 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Unity
[2013/06/27 15:20:18 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\uTorrent
[2013/06/03 18:59:39 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\VDownloader
[2011/11/08 09:55:37 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\Wireshark
[2013/05/10 20:06:02 | 000,000,000 | ---D | M] -- C:\Users\Gal\AppData\Roaming\XBMC
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/02/09 19:21:23 | 000,000,162 | -H-- | M] ()(C:\Users\Gal\Desktop\~$?????, ??????????? ????? ??????? ??????????? - ??? ? ?, ????? ?, 2011.docx) -- C:\Users\Gal\Desktop\~$ืจืืก, ืชืืืืจืืืช ืงืืื ืืขืืืช ืขืืฉืืืืืช - ืฉื ื ื, ืกืืก ื, 2011.docx
[2012/02/09 19:21:23 | 000,000,162 | -H-- | C] ()(C:\Users\Gal\Desktop\~$?????, ??????????? ????? ??????? ??????????? - ??? ? ?, ????? ?, 2011.docx) -- C:\Users\Gal\Desktop\~$ืจืืก, ืชืืืืจืืืช ืงืืื ืืขืืืช ืขืืฉืืืืืช - ืฉื ื ื, ืกืืก ื, 2011.docx
========== Alternate Data Streams ==========
@Alternate Data Stream - 996 bytes -> C:\Users\Gal\AppData\Local\lU46kMwiqQIGDLA:I9iznG4yU0Hka2qdbvjbUn7Wcxh
@Alternate Data Stream - 198 bytes -> C:\ProgramData\Temp:0C1EFF69
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:4CF61E54
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 1117 bytes -> C:\ProgramData\Microsoft:welMF5eu6AWJ0OU45CHukjY
@Alternate Data Stream - 1108 bytes -> C:\ProgramData\Microsoft:NL8TYMwIX9YAY1JiRlFck7
@Alternate Data Stream - 1039 bytes -> C:\ProgramData\Microsoft:YCvYmXBtBUddCjIYSkgkr
@Alternate Data Stream - 1019 bytes -> C:\ProgramData\Microsoft:hntiw6RCjNgjWwH2wxsuwJ5f
< End of report >