Ask toolbar and McAfee Security Scan Plus have been deleted.
New ComboFix log below...
ComboFix 11-12-18.01 - Fname Lname 12/18/2011 18:21:36.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3062.1838 [GMT -5:00]
Running from: c:\users\Fname Lname\Desktop\ComboFix.exe
Command switches used :: c:\users\Fname Lname\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BigFix.lnk"
"c:\users\Fname Lname\Documents\Documents\Ke43yta.exe"
"c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\AVG Secure Search
c:\program files\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll
c:\program files\AVG Secure Search\about.gif
c:\program files\AVG Secure Search\avguidx.dll
c:\program files\AVG Secure Search\calc.gif
c:\program files\AVG Secure Search\CleanHistory.gif
c:\program files\AVG Secure Search\configuration.xml
c:\program files\AVG Secure Search\current.gif
c:\program files\AVG Secure Search\Facebook.gif
c:\program files\AVG Secure Search\favicon.ico
c:\program files\AVG Secure Search\feedback.gif
c:\program files\AVG Secure Search\help.gif
c:\program files\AVG Secure Search\icon18.gif
c:\program files\AVG Secure Search\iGearedHelper.dll
c:\program files\AVG Secure Search\labs.gif
c:\program files\AVG Secure Search\lip.exe
c:\program files\AVG Secure Search\MigrationTool.exe
c:\program files\AVG Secure Search\note.gif
c:\program files\AVG Secure Search\PageStatus.gif
c:\program files\AVG Secure Search\PostInstall.exe
c:\program files\AVG Secure Search\radio\bg.gif
c:\program files\AVG Secure Search\radio\play.gif
c:\program files\AVG Secure Search\radio\play_hover.gif
c:\program files\AVG Secure Search\radio\radio.html
c:\program files\AVG Secure Search\radio\radio.js
c:\program files\AVG Secure Search\radio\stations.xml
c:\program files\AVG Secure Search\radio\stop.gif
c:\program files\AVG Secure Search\radio\stop_hover.gif
c:\program files\AVG Secure Search\radio\v_minus.gif
c:\program files\AVG Secure Search\radio\v_minus_1.gif
c:\program files\AVG Secure Search\radio\v_plus.gif
c:\program files\AVG Secure Search\radio\v_plus_1.gif
c:\program files\AVG Secure Search\radio\vol_line_emp.gif
c:\program files\AVG Secure Search\radio\vol_line_full.gif
c:\program files\AVG Secure Search\radio\vol_line_half.gif
c:\program files\AVG Secure Search\remote_configuration.xml
c:\program files\AVG Secure Search\search.gif
c:\program files\AVG Secure Search\SecuredSearch.gif
c:\program files\AVG Secure Search\setup.bmp
c:\program files\AVG Secure Search\toolbar.zip
c:\program files\AVG Secure Search\ToolbarBroker.exe
c:\program files\AVG Secure Search\Uninstall.exe
c:\program files\AVG Secure Search\vprot.exe
c:\program files\AVG Secure Search\weather.gif
c:\program files\AVG Secure Search\windows.gif
c:\program files\Common Files\AVG Secure Search
c:\program files\Common Files\AVG Secure Search\CommonInstaller\9.0.1\CommonInstaller.exe
c:\program files\Common Files\AVG Secure Search\InstalledProducts.ini
c:\program files\Common Files\AVG Secure Search\ScriptHelperInstaller\9.0.1\ScriptHelper.exe
c:\program files\Common Files\AVG Secure Search\ToolBandTlb\9.0.1\toolband
c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\UpdaterConfig.ini
c:\programdata\AVG Secure Search
c:\programdata\AVG Secure Search\9.0.0.18\chrome.manifest
c:\programdata\AVG Secure Search\9.0.0.18\chrome\avg.jar
c:\programdata\AVG Secure Search\9.0.0.18\components\FF4\IToolbarhomewmp.xpt
c:\programdata\AVG Secure Search\9.0.0.18\components\FF4\toolbarhomewmp.dll
c:\programdata\AVG Secure Search\9.0.0.18\components\IToolbarhomewmp.xpt
c:\programdata\AVG Secure Search\9.0.0.18\components\toolbarhomeApi.js
c:\programdata\AVG Secure Search\9.0.0.18\components\toolbarhomewmp.dll
c:\programdata\AVG Secure Search\9.0.0.18\icon.png
c:\programdata\AVG Secure Search\9.0.0.18\install.rdf
c:\programdata\AVG Secure Search\9.0.0.18\locale\en-US\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\locale\en-US\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\avg.xml
c:\programdata\AVG Secure Search\9.0.0.18\modules\avgJsm.js
c:\programdata\AVG Secure Search\9.0.0.18\modules\configuration.js
c:\programdata\AVG Secure Search\9.0.0.18\modules\configuration_0.css
c:\programdata\AVG Secure Search\9.0.0.18\modules\configuration_0.xul
c:\programdata\AVG Secure Search\9.0.0.18\modules\EmailNotifier.js
c:\programdata\AVG Secure Search\9.0.0.18\modules\HistoryCleaner.js
c:\programdata\AVG Secure Search\9.0.0.18\modules\IOJsm.js
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\cs\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\cs\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\da\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\da\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\de\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\de\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\en\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\en\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\es-es\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\es-es\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\es\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\es\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\fr\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\fr\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\hu\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\hu\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\id\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\id\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\it\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\it\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ja\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ja\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ko\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ko\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ms\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ms\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\nl\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\nl\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\pl\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\pl\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\pt-br\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\pt-br\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\pt\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\pt\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ru\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\ru\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\sk\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\sk\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\sr\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\sr\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\tr\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\tr\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\zh-cn\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\zh-cn\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\zh-tw\global.dtd
c:\programdata\AVG Secure Search\9.0.0.18\modules\locale\zh-tw\global.properties
c:\programdata\AVG Secure Search\9.0.0.18\modules\Preferences.js
c:\programdata\AVG Secure Search\9.0.0.18\modules\propertiesJsm.js
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\about.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\ajax-loader.gif
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\calc.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\CleanHistory.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\close.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\current.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\Facebook.gif
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\feedback.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\feedicon.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\help.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\icon_search.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\icon18.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\information-24.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\labs.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\loader.gif
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\note.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\PageStatus.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\questionmarkIcon.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioBg.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioEqu.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioEqu_on.gif
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioHandle.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioMenuArrow_off.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioMenuArrow_on.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioPlay_off.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioPlay_on.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioStop_off.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioStop_on.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioVol.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RadioVolBg.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\RealLogo.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\search.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\SecuredSearch.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\sliderWhite.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\weather.gif
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\window-close.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\windows.png
c:\programdata\AVG Secure Search\9.0.0.18\modules\skin\WMPLogo.png
c:\programdata\AVG2012
c:\programdata\AVG2012\Cfg\admin.cfg
c:\programdata\AVG2012\Cfg\changecfgreg.cfg
c:\programdata\AVG2012\Cfg\csl.cfg
c:\programdata\AVG2012\Cfg\emssrv.cfg
c:\programdata\AVG2012\Cfg\erd.cfg
c:\programdata\AVG2012\Cfg\idp.cfg
c:\programdata\AVG2012\Cfg\krnl.cfg
c:\programdata\AVG2012\Cfg\mail.cfg
c:\programdata\AVG2012\Cfg\mailsrv.cfg
c:\programdata\AVG2012\Cfg\mailsrvvsapi.cfg
c:\programdata\AVG2012\Cfg\malrep.cfg
c:\programdata\AVG2012\Cfg\scan.cfg
c:\programdata\AVG2012\Cfg\sched.cfg
c:\programdata\AVG2012\Cfg\setup.cfg
c:\programdata\AVG2012\Cfg\spsrv.cfg
c:\programdata\AVG2012\Cfg\update.cfg
c:\programdata\AVG2012\Cfg\updatecomps.cfg
c:\programdata\AVG2012\Cfg\user.cfg
c:\programdata\AVG2012\cfgall\changecfgreg.cfg
c:\programdata\AVG2012\cfgall\falsealarm.cfg
c:\programdata\AVG2012\cfgall\krnlall.cfg
c:\programdata\AVG2012\cfgall\srmall.cfg
c:\programdata\AVG2012\cfgall\updateall.cfg
c:\programdata\AVG2012\cfgall\userall.cfg
c:\programdata\AVG2012\Chjw\1caa3991aa396882.dat
c:\programdata\AVG2012\Chjw\1caa3991aa396882\025bde27-c082-413c-a8cd-4d34e062aa24
c:\programdata\AVG2012\Chjw\1caa3991aa396882\1da2db46-530a-4916-97d0-d528365c7a1a
c:\programdata\AVG2012\Chjw\1caa3991aa396882\92601d74-a65e-4275-8483-d977db2f1a0c
c:\programdata\AVG2012\Chjw\1caa3991aa396882\a1eca464-8c79-4f01-89c9-c63368989718
c:\programdata\AVG2012\Chjw\1caa3991aa396882\a7668827-8663-4d4a-a77e-9c38fe859e13
c:\programdata\AVG2012\Chjw\1caa3991aa396882\avgcchff.dat
c:\programdata\AVG2012\Chjw\1caa3991aa396882\avgcchfi.dat
c:\programdata\AVG2012\Chjw\1caa3991aa396882\avgcchmf.dat
c:\programdata\AVG2012\Chjw\1caa3991aa396882\avgcchmi.dat
c:\programdata\AVG2012\Chjw\1caa3991aa396882\b4140b5c-5952-4104-b17b-4312dad27c19
c:\programdata\AVG2012\Chjw\1caa3991aa396882\ccbf797e-0c2d-4322-bf61-9b2ef1f8526d
c:\programdata\AVG2012\Chjw\1caa3991aa396882\d4937825-fb40-4b47-812b-974de7339525
c:\programdata\AVG2012\Chjw\2c420be0420bada0.dat
c:\programdata\AVG2012\Chjw\2c420be0420bada0\avgcchff.dat
c:\programdata\AVG2012\Chjw\2c420be0420bada0\avgcchfi.dat
c:\programdata\AVG2012\Chjw\2c420be0420bada0\avgcchmf.dat
c:\programdata\AVG2012\Chjw\2c420be0420bada0\avgcchmi.dat
c:\programdata\AVG2012\IDS\config\md5Cache.dat
c:\programdata\AVG2012\IDS\config\quarantinedList.zip
c:\programdata\AVG2012\IDS\config\userList.zip
c:\programdata\AVG2012\log\arklog.cfg
c:\programdata\AVG2012\log\avgcfg.log
c:\programdata\AVG2012\log\avgcfg.log.lock
c:\programdata\AVG2012\log\avgcfgex.log
c:\programdata\AVG2012\log\avgcfgex.log.lock
c:\programdata\AVG2012\log\avgchjw.log
c:\programdata\AVG2012\log\avgchjw.log.1
c:\programdata\AVG2012\log\avgchjw.log.10
c:\programdata\AVG2012\log\avgchjw.log.2
c:\programdata\AVG2012\log\avgchjw.log.3
c:\programdata\AVG2012\log\avgchjw.log.4
c:\programdata\AVG2012\log\avgchjw.log.5
c:\programdata\AVG2012\log\avgchjw.log.6
c:\programdata\AVG2012\log\avgchjw.log.7
c:\programdata\AVG2012\log\avgchjw.log.8
c:\programdata\AVG2012\log\avgchjw.log.9
c:\programdata\AVG2012\log\avgchjw.log.lock
c:\programdata\AVG2012\log\avgchjwsrv.log
c:\programdata\AVG2012\log\avgchjwsrv.log.1
c:\programdata\AVG2012\log\avgchjwsrv.log.10
c:\programdata\AVG2012\log\avgchjwsrv.log.2
c:\programdata\AVG2012\log\avgchjwsrv.log.3
c:\programdata\AVG2012\log\avgchjwsrv.log.4
c:\programdata\AVG2012\log\avgchjwsrv.log.5
c:\programdata\AVG2012\log\avgchjwsrv.log.6
c:\programdata\AVG2012\log\avgchjwsrv.log.7
c:\programdata\AVG2012\log\avgchjwsrv.log.8
c:\programdata\AVG2012\log\avgchjwsrv.log.9
c:\programdata\AVG2012\log\avgchjwsrv.log.lock
c:\programdata\AVG2012\log\avgcore.log
c:\programdata\AVG2012\log\avgcore.log.1
c:\programdata\AVG2012\log\avgcore.log.10
c:\programdata\AVG2012\log\avgcore.log.2
c:\programdata\AVG2012\log\avgcore.log.3
c:\programdata\AVG2012\log\avgcore.log.4
c:\programdata\AVG2012\log\avgcore.log.5
c:\programdata\AVG2012\log\avgcore.log.6
c:\programdata\AVG2012\log\avgcore.log.7
c:\programdata\AVG2012\log\avgcore.log.8
c:\programdata\AVG2012\log\avgcore.log.9
c:\programdata\AVG2012\log\avgcore.log.lock
c:\programdata\AVG2012\log\avgcsl.log
c:\programdata\AVG2012\log\avgcsl.log.1
c:\programdata\AVG2012\log\avgcsl.log.2
c:\programdata\AVG2012\log\avgcsl.log.lock
c:\programdata\AVG2012\log\avgdiagex.log
c:\programdata\AVG2012\log\avgdiagex.log.lock
c:\programdata\AVG2012\log\avgemc.log
c:\programdata\AVG2012\log\avgemc.log.1
c:\programdata\AVG2012\log\avgemc.log.2
c:\programdata\AVG2012\log\avgemc.log.3
c:\programdata\AVG2012\log\avgemc.log.4
c:\programdata\AVG2012\log\avgemc.log.lock
c:\programdata\AVG2012\log\avgexc.log
c:\programdata\AVG2012\log\avgexc.log.lock
c:\programdata\AVG2012\log\avgldr.log
c:\programdata\AVG2012\log\avgldr.log.1
c:\programdata\AVG2012\log\avgldr.log.2
c:\programdata\AVG2012\log\avgldr.log.lock
c:\programdata\AVG2012\log\avglng.log
c:\programdata\AVG2012\log\avglng.log.1
c:\programdata\AVG2012\log\avglng.log.lock
c:\programdata\AVG2012\log\avgmail.cfg
c:\programdata\AVG2012\log\avgns.log
c:\programdata\AVG2012\log\avgns.log.1
c:\programdata\AVG2012\log\avgns.log.10
c:\programdata\AVG2012\log\avgns.log.2
c:\programdata\AVG2012\log\avgns.log.3
c:\programdata\AVG2012\log\avgns.log.4
c:\programdata\AVG2012\log\avgns.log.5
c:\programdata\AVG2012\log\avgns.log.6
c:\programdata\AVG2012\log\avgns.log.7
c:\programdata\AVG2012\log\avgns.log.8
c:\programdata\AVG2012\log\avgns.log.9
c:\programdata\AVG2012\log\avgns.log.lock
c:\programdata\AVG2012\log\avgpostinst.log
c:\programdata\AVG2012\log\avgpostinst.log.lock
c:\programdata\AVG2012\log\avgrs.log
c:\programdata\AVG2012\log\avgrs.log.1
c:\programdata\AVG2012\log\avgrs.log.10
c:\programdata\AVG2012\log\avgrs.log.2
c:\programdata\AVG2012\log\avgrs.log.3
c:\programdata\AVG2012\log\avgrs.log.4
c:\programdata\AVG2012\log\avgrs.log.5
c:\programdata\AVG2012\log\avgrs.log.6
c:\programdata\AVG2012\log\avgrs.log.7
c:\programdata\AVG2012\log\avgrs.log.8
c:\programdata\AVG2012\log\avgrs.log.9
c:\programdata\AVG2012\log\avgrs.log.lock
c:\programdata\AVG2012\log\avgscan.log
c:\programdata\AVG2012\log\avgscan.log.1
c:\programdata\AVG2012\log\avgscan.log.10
c:\programdata\AVG2012\log\avgscan.log.2
c:\programdata\AVG2012\log\avgscan.log.3
c:\programdata\AVG2012\log\avgscan.log.4
c:\programdata\AVG2012\log\avgscan.log.5
c:\programdata\AVG2012\log\avgscan.log.6
c:\programdata\AVG2012\log\avgscan.log.7
c:\programdata\AVG2012\log\avgscan.log.8
c:\programdata\AVG2012\log\avgscan.log.9
c:\programdata\AVG2012\log\avgscan.log.lock
c:\programdata\AVG2012\log\avgsched.log
c:\programdata\AVG2012\log\avgsched.log.1
c:\programdata\AVG2012\log\avgsched.log.10
c:\programdata\AVG2012\log\avgsched.log.2
c:\programdata\AVG2012\log\avgsched.log.3
c:\programdata\AVG2012\log\avgsched.log.4
c:\programdata\AVG2012\log\avgsched.log.5
c:\programdata\AVG2012\log\avgsched.log.6
c:\programdata\AVG2012\log\avgsched.log.7
c:\programdata\AVG2012\log\avgsched.log.8
c:\programdata\AVG2012\log\avgsched.log.9
c:\programdata\AVG2012\log\avgsched.log.lock
c:\programdata\AVG2012\log\avgsrm.log
c:\programdata\AVG2012\log\avgsrm.log.1
c:\programdata\AVG2012\log\avgsrm.log.2
c:\programdata\AVG2012\log\avgsrm.log.3
c:\programdata\AVG2012\log\avgsrm.log.4
c:\programdata\AVG2012\log\avgsrm.log.5
c:\programdata\AVG2012\log\avgsrm.log.6
c:\programdata\AVG2012\log\avgsrm.log.7
c:\programdata\AVG2012\log\avgsrm.log.8
c:\programdata\AVG2012\log\avgsrm.log.lock
c:\programdata\AVG2012\log\avgsrmac.log
c:\programdata\AVG2012\log\avgsrmac.log.1
c:\programdata\AVG2012\log\avgsrmac.log.2
c:\programdata\AVG2012\log\avgsrmac.log.lock
c:\programdata\AVG2012\log\avgtbapi.cfg
c:\programdata\AVG2012\log\avgtbapi.log.lock
c:\programdata\AVG2012\log\avgtdi.log
c:\programdata\AVG2012\log\avgtdi.log.1
c:\programdata\AVG2012\log\avgtdi.log.lock
c:\programdata\AVG2012\log\avgual.2011-11-29.log
c:\programdata\AVG2012\log\avgual.log
c:\programdata\AVG2012\log\avgual.log.lock
c:\programdata\AVG2012\log\avgui.log
c:\programdata\AVG2012\log\avgui.log.1
c:\programdata\AVG2012\log\avgui.log.10
c:\programdata\AVG2012\log\avgui.log.2
c:\programdata\AVG2012\log\avgui.log.3
c:\programdata\AVG2012\log\avgui.log.4
c:\programdata\AVG2012\log\avgui.log.5
c:\programdata\AVG2012\log\avgui.log.6
c:\programdata\AVG2012\log\avgui.log.7
c:\programdata\AVG2012\log\avgui.log.8
c:\programdata\AVG2012\log\avgui.log.9
c:\programdata\AVG2012\log\avgui.log.lock
c:\programdata\AVG2012\log\avguidraw.log
c:\programdata\AVG2012\log\avguidraw.log.1
c:\programdata\AVG2012\log\avguidraw.log.lock
c:\programdata\AVG2012\log\avguilog.cfg
c:\programdata\AVG2012\log\avgupd.log
c:\programdata\AVG2012\log\avgupd.log.1
c:\programdata\AVG2012\log\avgupd.log.2
c:\programdata\AVG2012\log\avgupd.log.lock
c:\programdata\AVG2012\log\avgupdm.log
c:\programdata\AVG2012\log\avgwd.log
c:\programdata\AVG2012\log\avgwd.log.1
c:\programdata\AVG2012\log\avgwd.log.10
c:\programdata\AVG2012\log\avgwd.log.2
c:\programdata\AVG2012\log\avgwd.log.3
c:\programdata\AVG2012\log\avgwd.log.4
c:\programdata\AVG2012\log\avgwd.log.5
c:\programdata\AVG2012\log\avgwd.log.6
c:\programdata\AVG2012\log\avgwd.log.7
c:\programdata\AVG2012\log\avgwd.log.8
c:\programdata\AVG2012\log\avgwd.log.9
c:\programdata\AVG2012\log\avgwd.log.lock
c:\programdata\AVG2012\log\avgwdsvc.log
c:\programdata\AVG2012\log\avgwdsvc.log.1
c:\programdata\AVG2012\log\avgwdsvc.log.2
c:\programdata\AVG2012\log\avgwdsvc.log.3
c:\programdata\AVG2012\log\avgwdsvc.log.4
c:\programdata\AVG2012\log\avgwdsvc.log.5
c:\programdata\AVG2012\log\avgwdsvc.log.6
c:\programdata\AVG2012\log\avgwdsvc.log.7
c:\programdata\AVG2012\log\avgwdsvc.log.lock
c:\programdata\AVG2012\log\cfgexlog.cfg
c:\programdata\AVG2012\log\cfglog.cfg
c:\programdata\AVG2012\log\chjwlog.cfg
c:\programdata\AVG2012\log\commonpriv.log
c:\programdata\AVG2012\log\commonpriv.log.1
c:\programdata\AVG2012\log\commonpriv.log.10
c:\programdata\AVG2012\log\commonpriv.log.2
c:\programdata\AVG2012\log\commonpriv.log.3
c:\programdata\AVG2012\log\commonpriv.log.4
c:\programdata\AVG2012\log\commonpriv.log.5
c:\programdata\AVG2012\log\commonpriv.log.6
c:\programdata\AVG2012\log\commonpriv.log.7
c:\programdata\AVG2012\log\commonpriv.log.8
c:\programdata\AVG2012\log\commonpriv.log.9
c:\programdata\AVG2012\log\commonpriv.log.lock
c:\programdata\AVG2012\log\corelog.cfg
c:\programdata\AVG2012\log\csllog.cfg
c:\programdata\AVG2012\log\emclog.cfg
c:\programdata\AVG2012\log\fixcfg.log
c:\programdata\AVG2012\log\fixcfg.log.1
c:\programdata\AVG2012\log\fixcfg.log.lock
c:\programdata\AVG2012\log\history.xml
c:\programdata\AVG2012\log\ldrlog.cfg
c:\programdata\AVG2012\log\lnglog.cfg
c:\programdata\AVG2012\log\lscanlog.cfg
c:\programdata\AVG2012\log\nslog.cfg
c:\programdata\AVG2012\log\privlog.cfg
c:\programdata\AVG2012\log\publog.cfg
c:\programdata\AVG2012\log\rslog.cfg
c:\programdata\AVG2012\log\scanlog.cfg
c:\programdata\AVG2012\log\schedlog.cfg
c:\programdata\AVG2012\log\srmlog.cfg
c:\programdata\AVG2012\log\tdilog.cfg
c:\programdata\AVG2012\log\updlog.cfg
c:\programdata\AVG2012\log\vault.log
c:\programdata\AVG2012\log\vault.log.1
c:\programdata\AVG2012\log\vault.log.2
c:\programdata\AVG2012\log\vault.log.3
c:\programdata\AVG2012\log\vault.log.4
c:\programdata\AVG2012\log\vault.log.5
c:\programdata\AVG2012\log\vault.log.lock
c:\programdata\AVG2012\log\vaultlog.cfg
c:\programdata\AVG2012\log\wdlog.cfg
c:\programdata\AVG2012\log\wdsvclog.cfg
c:\programdata\AVG2012\lsdb\prev\prvcache.dat
c:\programdata\AVG2012\lsdb\prev\prvglbl.dat
c:\programdata\AVG2012\scanlogs\I_00000001.log
c:\programdata\AVG2012\scanlogs\I_00000003.log
c:\programdata\AVG2012\scanlogs\I_00000004.log
c:\programdata\AVG2012\scanlogs\I_00000005.log
c:\programdata\AVG2012\scanlogs\I_00000006.log
c:\programdata\AVG2012\scanlogs\I_00000007.log
c:\programdata\AVG2012\scanlogs\I_00000008.log
c:\programdata\AVG2012\scanlogs\I_00000009.log
c:\programdata\AVG2012\scanlogs\I_00000010.log
c:\programdata\AVG2012\scanlogs\I_00000011.log
c:\programdata\AVG2012\scanlogs\I_00000012.log
c:\programdata\AVG2012\scanlogs\I_00000013.log
c:\programdata\AVG2012\scanlogs\I_00000014.log
c:\programdata\AVG2012\scanlogs\I_00000015.log
c:\programdata\AVG2012\scanlogs\I_00000016.log
c:\programdata\AVG2012\scanlogs\I_00000017.log
c:\programdata\AVG2012\scanlogs\I_00000018.log
c:\programdata\AVG2012\scanlogs\I_00000019.log
c:\programdata\AVG2012\scanlogs\I_00000020.log
c:\programdata\AVG2012\scanlogs\I_00000021.log
c:\programdata\AVG2012\scanlogs\I_00000022.log
c:\programdata\AVG2012\scanlogs\I_00000023.log
c:\programdata\AVG2012\scanlogs\I_00000024.log
c:\programdata\AVG2012\scanlogs\I_00000025.log
c:\programdata\AVG2012\scanlogs\I_00000026.log
c:\programdata\AVG2012\scanlogs\I_00000027.log
c:\programdata\AVG2012\scanlogs\I_00000028.log
c:\programdata\AVG2012\scanlogs\I_00000029.log
c:\programdata\AVG2012\scanlogs\I_00000030.log
c:\programdata\AVG2012\scanlogs\I_00000031.log
c:\programdata\AVG2012\scanlogs\I_00000032.log
c:\programdata\AVG2012\scanlogs\I_00000033.log
c:\programdata\AVG2012\scanlogs\I_00000034.log
c:\programdata\AVG2012\scanlogs\I_00000035.log
c:\programdata\AVG2012\scanlogs\I_00000036.log
c:\programdata\AVG2012\scanlogs\I_00000037.log
c:\programdata\AVG2012\scanlogs\I_00000038.log
c:\programdata\AVG2012\scanlogs\I_00000039.log
c:\programdata\AVG2012\scanlogs\I_00000040.log
c:\programdata\AVG2012\scanlogs\I_00000041.log
c:\programdata\AVG2012\scanlogs\I_00000042.log
c:\programdata\AVG2012\scanlogs\I_00000043.log
c:\programdata\AVG2012\scanlogs\I_00000044.log
c:\programdata\AVG2012\scanlogs\I_00000045.log
c:\programdata\AVG2012\scanlogs\I_00000046.log
c:\programdata\AVG2012\scanlogs\I_00000047.log
c:\programdata\AVG2012\scanlogs\I_00000048.log
c:\programdata\AVG2012\scanlogs\I_00000049.log
c:\programdata\AVG2012\scanlogs\I_00000050.log
c:\programdata\AVG2012\scanlogs\I_00000051.log
c:\programdata\AVG2012\scanlogs\I_00000052.log
c:\programdata\AVG2012\scanlogs\I_00000053.log
c:\programdata\AVG2012\scanlogs\I_00000054.log
c:\programdata\AVG2012\scanlogs\I_00000055.log
c:\programdata\AVG2012\scanlogs\I_00000056.log
c:\programdata\AVG2012\scanlogs\I_00000057.log
c:\programdata\AVG2012\scanlogs\I_00000058.log
c:\programdata\AVG2012\scanlogs\I_00000059.log
c:\programdata\AVG2012\scanlogs\I_00000060.log
c:\programdata\AVG2012\scanlogs\I_00000061.log
c:\programdata\AVG2012\scanlogs\I_00000062.log
c:\programdata\AVG2012\scanlogs\I_00000063.log
c:\programdata\AVG2012\scanlogs\I_00000064.log
c:\programdata\AVG2012\scanlogs\I_00000065.log
c:\programdata\AVG2012\scanlogs\I_00000066.log
c:\programdata\AVG2012\scanlogs\I_00000067.log
c:\programdata\AVG2012\scanlogs\I_00000068.log
c:\programdata\AVG2012\scanlogs\I_00000069.log
c:\programdata\AVG2012\scanlogs\I_00000070.log
c:\programdata\AVG2012\scanlogs\I_00000071.log
c:\programdata\AVG2012\scanlogs\I_00000072.log
c:\programdata\AVG2012\scanlogs\I_00000073.log
c:\programdata\AVG2012\scanlogs\I_00000074.log
c:\programdata\AVG2012\scanlogs\I_00000075.log
c:\programdata\AVG2012\scanlogs\I_00000076.log
c:\programdata\AVG2012\scanlogs\I_00000077.log
c:\programdata\AVG2012\scanlogs\I_00000078.log
c:\programdata\AVG2012\scanlogs\I_00000079.log
c:\programdata\AVG2012\scanlogs\I_00000080.log
c:\programdata\AVG2012\scanlogs\I_00000081.log
c:\programdata\AVG2012\scanlogs\I_00000082.log
c:\programdata\AVG2012\scanlogs\I_00000083.log
c:\programdata\AVG2012\scanlogs\I_00000084.log
c:\programdata\AVG2012\scanlogs\I_00000085.log
c:\programdata\AVG2012\scanlogs\I_00000086.log
c:\programdata\AVG2012\scanlogs\I_00000087.log
c:\programdata\AVG2012\scanlogs\I_00000088.log
c:\programdata\AVG2012\scanlogs\I_00000089.log
c:\programdata\AVG2012\scanlogs\I_00000090.log
c:\programdata\AVG2012\scanlogs\I_00000091.log
c:\programdata\AVG2012\scanlogs\I_00000092.log
c:\programdata\AVG2012\scanlogs\I_00000093.log
c:\programdata\AVG2012\scanlogs\I_00000094.log
c:\programdata\AVG2012\scanlogs\I_00000095.log
c:\programdata\AVG2012\scanlogs\I_00000096.log
c:\programdata\AVG2012\scanlogs\I_00000097.log
c:\programdata\AVG2012\scanlogs\I_00000098.log
c:\programdata\AVG2012\scanlogs\I_00000099.log
c:\programdata\AVG2012\scanlogs\I_00000100.log
c:\programdata\AVG2012\scanlogs\I_00000101.log
c:\programdata\AVG2012\scanlogs\I_00000102.log
c:\programdata\AVG2012\scanlogs\I_00000103.log
c:\programdata\AVG2012\scanlogs\I_00000104.log
c:\programdata\AVG2012\scanlogs\I_00000105.log
c:\programdata\AVG2012\scanlogs\I_00000106.log
c:\programdata\AVG2012\scanlogs\I_00000107.log
c:\programdata\AVG2012\scanlogs\I_00000108.log
c:\programdata\AVG2012\scanlogs\I_00000109.log
c:\programdata\AVG2012\scanlogs\I_00000110.log
c:\programdata\AVG2012\scanlogs\I_00000111.log
c:\programdata\AVG2012\scanlogs\I_00000112.log
c:\programdata\AVG2012\scanlogs\I_00000113.log
c:\programdata\AVG2012\scanlogs\I_00000114.log
c:\programdata\AVG2012\scanlogs\I_00000115.log
c:\programdata\AVG2012\scanlogs\I_00000116.log
c:\programdata\AVG2012\scanlogs\I_00000117.log
c:\programdata\AVG2012\scanlogs\I_00000118.log
c:\programdata\AVG2012\scanlogs\I_00000119.log
c:\programdata\AVG2012\scanlogs\I_00000120.log
c:\programdata\AVG2012\scanlogs\I_00000121.log
c:\programdata\AVG2012\scanlogs\I_00000122.log
c:\programdata\AVG2012\scanlogs\I_00000123.log
c:\programdata\AVG2012\scanlogs\I_00000124.log
c:\programdata\AVG2012\scanlogs\I_00000125.log
c:\programdata\AVG2012\scanlogs\I_00000126.log
c:\programdata\AVG2012\scanlogs\I_00000127.log
c:\programdata\AVG2012\scanlogs\I_00000128.log
c:\programdata\AVG2012\scanlogs\I_00000129.log
c:\programdata\AVG2012\scanlogs\I_00000130.log
c:\programdata\AVG2012\scanlogs\I_00000131.log
c:\programdata\AVG2012\scanlogs\I_00000132.log
c:\programdata\AVG2012\scanlogs\I_00000133.log
c:\programdata\AVG2012\scanlogs\I_00000134.log
c:\programdata\AVG2012\scanlogs\I_00000135.log
c:\programdata\AVG2012\scanlogs\I_00000136.log
c:\programdata\AVG2012\scanlogs\I_00000137.log
c:\programdata\AVG2012\scanlogs\I_00000138.log
c:\programdata\AVG2012\scanlogs\I_00000139.log
c:\programdata\AVG2012\scanlogs\I_00000140.log
c:\programdata\AVG2012\scanlogs\I_00000141.log
c:\programdata\AVG2012\scanlogs\I_00000142.log
c:\programdata\AVG2012\scanlogs\I_00000143.log
c:\programdata\AVG2012\scanlogs\I_00000144.log
c:\programdata\AVG2012\scanlogs\I_00000145.log
c:\programdata\AVG2012\scanlogs\I_00000146.log
c:\programdata\AVG2012\scanlogs\I_00000147.log
c:\programdata\AVG2012\scanlogs\I_00000148.log
c:\programdata\AVG2012\scanlogs\I_00000149.log
c:\programdata\AVG2012\scanlogs\I_00000150.log
c:\programdata\AVG2012\scanlogs\I_00000151.log
c:\programdata\AVG2012\scanlogs\I_00000152.log
c:\programdata\AVG2012\scanlogs\I_00000153.log
c:\programdata\AVG2012\scanlogs\I_00000154.log
c:\programdata\AVG2012\scanlogs\I_00000155.log
c:\programdata\AVG2012\scanlogs\I_00000156.log
c:\programdata\AVG2012\scanlogs\I_00000157.log
c:\programdata\AVG2012\scanlogs\I_00000158.log
c:\programdata\AVG2012\scanlogs\I_00000159.log
c:\programdata\AVG2012\scanlogs\I_00000160.log
c:\programdata\AVG2012\scanlogs\I_00000161.log
c:\programdata\AVG2012\scanlogs\I_00000162.log
c:\programdata\AVG2012\scanlogs\I_00000163.log
c:\programdata\AVG2012\scanlogs\I_00000164.log
c:\programdata\AVG2012\scanlogs\I_00000165.log
c:\programdata\AVG2012\scanlogs\I_00000166.log
c:\programdata\AVG2012\scanlogs\I_00000167.log
c:\programdata\AVG2012\scanlogs\I_00000168.log
c:\programdata\AVG2012\scanlogs\I_00000169.log
c:\programdata\AVG2012\scanlogs\I_00000170.log
c:\programdata\AVG2012\scanlogs\I_00000171.log
c:\programdata\AVG2012\scanlogs\I_00000172.log
c:\programdata\AVG2012\scanlogs\I_00000173.log
c:\programdata\AVG2012\scanlogs\I_00000174.log
c:\programdata\AVG2012\scanlogs\I_00000175.log
c:\programdata\AVG2012\scanlogs\I_00000176.log
c:\programdata\AVG2012\scanlogs\I_00000177.log
c:\programdata\AVG2012\scanlogs\I_00000178.log
c:\programdata\AVG2012\scanlogs\I_00000179.log
c:\programdata\AVG2012\scanlogs\I_00000180.log
c:\programdata\AVG2012\scanlogs\I_00000181.log
c:\programdata\AVG2012\scanlogs\I_00000182.log
c:\programdata\AVG2012\scanlogs\I_00000183.log
c:\programdata\AVG2012\scanlogs\I_00000184.log
c:\programdata\AVG2012\scanlogs\I_00000185.log
c:\programdata\AVG2012\scanlogs\I_00000186.log
c:\programdata\AVG2012\scanlogs\I_00000187.log
c:\programdata\AVG2012\scanlogs\I_00000188.log
c:\programdata\AVG2012\scanlogs\I_00000189.log
c:\programdata\AVG2012\scanlogs\I_00000190.log
c:\programdata\AVG2012\scanlogs\I_00000191.log
c:\programdata\AVG2012\scanlogs\I_00000192.log
c:\programdata\AVG2012\scanlogs\I_00000193.log
c:\programdata\AVG2012\scanlogs\I_00000194.log
c:\programdata\AVG2012\scanlogs\I_00000195.log
c:\programdata\AVG2012\scanlogs\I_00000196.log
c:\programdata\AVG2012\scanlogs\I_00000197.log
c:\programdata\AVG2012\scanlogs\I_00000198.log
c:\programdata\AVG2012\scanlogs\I_00000199.log
c:\programdata\AVG2012\scanlogs\I_00000200.log
c:\programdata\AVG2012\scanlogs\I_00000201.log
c:\programdata\AVG2012\scanlogs\I_00000202.log
c:\programdata\AVG2012\scanlogs\I_00000203.log
c:\programdata\AVG2012\scanlogs\I_00000204.log
c:\programdata\AVG2012\scanlogs\I_00000205.log
c:\programdata\AVG2012\scanlogs\I_00000206.log
c:\programdata\AVG2012\scanlogs\I_00000207.log
c:\programdata\AVG2012\scanlogs\I_00000208.log
c:\programdata\AVG2012\scanlogs\I_00000209.log
c:\programdata\AVG2012\scanlogs\I_00000210.log
c:\programdata\AVG2012\scanlogs\I_00000211.log
c:\programdata\AVG2012\scanlogs\I_00000212.log
c:\programdata\AVG2012\scanlogs\I_00000213.log
c:\programdata\AVG2012\scanlogs\I_00000214.log
c:\programdata\AVG2012\scanlogs\I_00000215.log
c:\programdata\AVG2012\scanlogs\I_00000216.log
c:\programdata\AVG2012\scanlogs\I_00000217.log
c:\programdata\AVG2012\scanlogs\I_00000218.log
c:\programdata\AVG2012\scanlogs\I_00000219.log
c:\programdata\AVG2012\scanlogs\I_00000220.log
c:\programdata\AVG2012\scanlogs\I_00000221.log
c:\programdata\AVG2012\scanlogs\I_00000222.log
c:\programdata\AVG2012\scanlogs\I_00000223.log
c:\programdata\AVG2012\scanlogs\I_00000224.log
c:\programdata\AVG2012\scanlogs\I_00000225.log
c:\programdata\AVG2012\scanlogs\I_00000226.log
c:\programdata\AVG2012\scanlogs\I_00000227.log
c:\programdata\AVG2012\scanlogs\I_00000228.log
c:\programdata\AVG2012\scanlogs\I_00000229.log
c:\programdata\AVG2012\scanlogs\I_00000230.log
c:\programdata\AVG2012\scanlogs\I_00000231.log
c:\programdata\AVG2012\scanlogs\I_00000232.log
c:\programdata\AVG2012\scanlogs\I_00000233.log
c:\programdata\AVG2012\scanlogs\I_00000234.log
c:\programdata\AVG2012\scanlogs\I_00000235.log
c:\programdata\AVG2012\scanlogs\I_00000236.log
c:\programdata\AVG2012\scanlogs\I_00000237.log
c:\programdata\AVG2012\scanlogs\I_00000238.log
c:\programdata\AVG2012\scanlogs\I_00000239.log
c:\programdata\AVG2012\scanlogs\I_00000240.log
c:\programdata\AVG2012\scanlogs\I_00000241.log
c:\programdata\AVG2012\scanlogs\I_00000242.log
c:\programdata\AVG2012\scanlogs\I_00000243.log
c:\programdata\AVG2012\scanlogs\I_00000244.log
c:\programdata\AVG2012\scanlogs\I_00000245.log
c:\programdata\AVG2012\scanlogs\I_00000246.log
c:\programdata\AVG2012\scanlogs\I_00000247.log
c:\programdata\AVG2012\scanlogs\I_00000248.log
c:\programdata\AVG2012\scanlogs\I_00000249.log
c:\programdata\AVG2012\scanlogs\I_00000250.log
c:\programdata\AVG2012\scanlogs\I_00000251.log
c:\programdata\AVG2012\scanlogs\I_00000252.log
c:\programdata\AVG2012\scanlogs\I_00000253.log
c:\programdata\AVG2012\scanlogs\I_00000254.log
c:\programdata\AVG2012\scanlogs\I_00000255.log
c:\programdata\AVG2012\scanlogs\I_00000256.log
c:\programdata\AVG2012\scanlogs\I_00000257.log
c:\programdata\AVG2012\scanlogs\I_00000258.log
c:\programdata\AVG2012\scanlogs\I_00000259.log
c:\programdata\AVG2012\scanlogs\I_00000260.log
c:\programdata\AVG2012\scanlogs\I_00000261.log
c:\programdata\AVG2012\scanlogs\I_00000262.log
c:\programdata\AVG2012\scanlogs\I_00000263.log
c:\programdata\AVG2012\scanlogs\I_00000264.log
c:\programdata\AVG2012\scanlogs\I_00000265.log
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BigFix.lnk
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_vToolbarUpdater
.
.
((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-18 23:37 . 2011-12-18 23:43 -------- d-----w- c:\users\Fname Lname\AppData\Local\temp
2011-12-18 23:37 . 2011-12-18 23:37 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2011-12-18 23:37 . 2011-12-18 23:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-17 16:33 . 2009-04-11 04:39 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-12-14 14:56 . 2011-12-14 14:56 -------- d-----w- c:\programdata\WindowsSearch
2011-12-13 23:33 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-13 23:33 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-13 23:33 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-13 23:33 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-12-13 23:33 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-12-13 23:33 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-13 23:32 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-01 03:53 . 2011-12-01 03:23 92432 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2011-12-01 03:42 . 2011-12-01 03:42 -------- d-----w- c:\programdata\Trend Micro
2011-12-01 03:32 . 2011-12-01 03:32 -------- d-----w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2011-11-30 02:38 . 2011-11-30 04:38 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
2011-11-30 00:33 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-30 00:33 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-30 00:33 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-30 00:33 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-30 00:32 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-30 00:32 . 2011-11-28 17:52 55128 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-30 00:32 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2011-11-30 00:32 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-30 00:31 . 2011-11-30 00:31 -------- d-----w- c:\programdata\AVAST Software
2011-11-30 00:31 . 2011-11-30 00:31 -------- d-----w- c:\program files\AVAST Software
2011-11-30 00:09 . 2011-12-01 13:05 -------- d-----w- c:\program files\Trend Micro
2011-11-23 21:06 . 2011-11-23 21:06 -------- d-----w- c:\windows\Sun
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-20 21:02 . 2011-11-09 13:20 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-11-12 19:40 . 2009-11-12 19:41 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\tbMyAs.dll" [2009-12-31 2349080]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn1\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2009-12-31 15:53 2349080 ----a-w- c:\program files\MyAshampoo\tbMyAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\tbMyAs.dll" [2009-12-31 2349080]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}"= "c:\program files\MyAshampoo\tbMyAs.dll" [2009-12-31 2349080]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
c:\users\FNAMERE~1\AppData\Local\Temp\knf.dll [BU]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-08 39408]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Aim"="c:\program files\AIM\aim.exe" [2010-03-08 3972440]
"googletalk"="c:\users\Fname Lname\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-26 865840]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Gateway\traybar.exe" [2007-09-13 638976]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [BU]
"HostManager"="c:\program files\Common Files\AOL\1230828047\ee\AOLSoftware.exe" [2006-09-26 50736]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SigmatelSysTrayApp"="sttray.exe" [2007-09-07 405504]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
.
c:\users\Fname Lname\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 135664]
R3 JakNDis;Jaksta Service;c:\windows\system32\DRIVERS\JakNDis.sys [2010-10-26 28256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-11-28 55128]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S3 JakNDisMP;JakNDisMP;c:\windows\system32\DRIVERS\JakNDis.sys [2010-10-26 28256]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 03:13]
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 03:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\users\Fname Lname\AppData\Roaming\Mozilla\Firefox\Profiles\2wcv829m.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://flvtubesearch.co/?tmp=toolbar_FLVTube_homepage&prt=flvtubetb04ff&clid=00fbc1ff0a8644ba825c0c74651ff15b&subid=3067
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: GameBox: gamebox@toolbar - %profile%\extensions\gamebox@toolbar
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: MyAshampoo Toolbar: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - %profile%\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
FF - Ext: AIM Toolbar: {c2f863cd-0429-48c7-bb54-db756a951760} - %profile%\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Move Media Player:
moveplayer@movenetworks.com - c:\users\Fname Lname\AppData\Roaming\Move Networks
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
.