OTL logfile created on: 9/23/2012 11:44:06 AM - Run 1
OTL by OldTimer - Version 3.2.66.0 Folder = C:\Users\ayee\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.91 Gb Available Physical Memory | 63.78% Memory free
5.98 Gb Paging File | 4.82 Gb Available in Paging File | 80.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 137.14 Gb Free Space | 58.91% Space Free | Partition Type: NTFS
Computer Name: AYEE-PC | User Name: ayee | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/23 11:35:22 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\ayee\Desktop\OTL.exe
PRC - [2012/09/14 19:07:19 | 000,136,616 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2012/09/11 21:58:20 | 000,374,184 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/03/22 22:17:53 | 000,234,784 | ---- | M] (Apple Inc.) -- C:\Program Files\AirPrint\airprint.exe
PRC - [2011/06/23 21:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/02/24 22:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 05:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/11/08 13:04:20 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2010/09/17 16:40:06 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2008/09/29 09:07:00 | 000,143,088 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2008/09/29 09:07:00 | 000,124,240 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/09/29 09:07:00 | 000,067,904 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2008/09/29 09:07:00 | 000,062,800 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
PRC - [2008/09/29 09:07:00 | 000,026,672 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
PRC - [2008/09/29 09:07:00 | 000,019,456 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
PRC - [2008/03/14 05:00:00 | 000,226,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2008/03/14 05:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2008/02/13 03:00:20 | 007,336,576 | ---- | M] () -- C:\AppServ\MySQL\bin\mysqld.exe
PRC - [2008/01/17 10:37:26 | 000,024,635 | ---- | M] (Apache Software Foundation) -- C:\AppServ\Apache2.2\bin\httpd.exe
PRC - [2006/05/23 22:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) -- C:\Windows\System32\StkASv2K.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\XTrapD12.dllzBackupAssistService\Parameters -- (zBackupAssistService)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\tdcmdpst.dllj.dll -- (Via4in1)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\se59mdfl.dll -- (vetmsgnt)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\pavagente.dll -- (usbmate)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\Intels51.dll -- (USBCCID)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\toddsrv.dll -- (trioservice)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\tosrfbnp.dll -- (transcode360)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\askernel.dll -- (tosrfbnp)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\lxrsge10s.dll -- (symtdi)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ZSMC211.dll -- (swmidi)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\X10UIF.dll -- (suservice)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\hSONYPVh.dll -- (SRTSPL)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\aawservice.dll -- (spcsutilityservice)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\msfs.dll -- (Sntnlusb)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\vproeventmonitor.dll -- (Slntamr)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\DCamUSBEMPIA.dll--- | m] (microsoft corporation) -- (Sk9920nt)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\MA_CMIDI.dll -- (SiRemFil)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\jobserver_report.dll -- (sfilter)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\WmiAcpi.dll -- (se44unic)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\IntelC53.dll -- (SaiH040B)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\rt2870.dlls\s7otranx\Parameters -- (s7otranx)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\LUsbFilt.dll -- (roxwatch)
SRV - File not found [Auto | Stopped] -- \.\globalroot\C:\Windows\system32\svchost.exe -- (relational)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\SE2Emdm.dll -- (qcdonner)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\Epfwndis.dll -- (PD0620VID)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\sprtsvc_ddoctorv2.dll -- (PAC7302)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\sonypvu1.dlll client\nissrv.e -- (olregcap)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\dot4print.dll client\nissrv.ex -- (OEM02Dev)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\monfilt.dll -- (NxSysMon)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ptserial.dll -- (NVNET)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\eloggersvc6.dlln -- (nod32krn)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\scramby.dll -- (nalntservice)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\pxfhbus.dll -- (mdvrmng)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\personalsecuredriveservice.dllrameters -- (mcmispupdmgr)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\dimension4.dllwlicenseservice\parameters -- (maxbackserviceint)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\tme3srv.dll\lwwlicenseservice\Parameters -- (lwwlicenseservice)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\pdlnatdl.dllice.exe -- (iwebmsg)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\vetmsgnt.dll -- (id2scaps)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\EL2000.dll -- (hnmsvc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\rslinx.dll -- (hdthermal)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\tosrfcom.dll -- (gtndis5)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\FA312.dll -- (genmcmn)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\ilicensesvc.dll.0\wpf\presentationfontcache.exe -- (GcKernel)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\dktknsrv.dll -- (FireHook)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\elotouchscreen.dllsys,-100 -- (fingrd32)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\AppnApi.dll -- (F700isw)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\c-dillasrv.dll -- (DniVad)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\i8042prt.dll -- (dmisrv)
SRV - File not found [Auto | Stopped] -- \.\globalroot\C:\Windows\system32\svchost.exe -- (DELTA)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\pdlnemsg.dll55) -- (curtainssyssvc)
SRV - File not found [Auto | Stopped] -- \.\globalroot\C:\Windows\system32\svchost.exe -- (CTEDSPFX.DLL)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\RAPIProtocol.dlll -- (cqmgstor)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\splitter.dllms.dll -- (cqcpu)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\sysaudio.dll -- (caili)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\cwafeventrouter.dll -- (btwdndis)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\RecAgent.dllSB -- (btserial)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\TOSHIBASoftModem.dll -- (bcserver)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\kpfwsvc.dll -- (basfipm)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\sym_hi.dlle -- (ATNT40K)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\cacheserver.dllileDeviceService.exe -- (atkdisplf)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\eSettingsService.dll -- (AsusACPI)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\iirsp.dll -- (astcc)
SRV - File not found [Auto | Stopped] -- %systemroot%\system32\a016mdm.dll -- (aeaudio)
SRV - [2012/09/14 19:07:19 | 000,136,616 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\ramaint.exe -- (LMIMaint)
SRV - [2012/09/11 21:58:20 | 000,374,184 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/03/22 22:17:53 | 000,234,784 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\AirPrint\airprint.exe -- (AirPrint)
SRV - [2010/11/22 23:47:51 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/11/22 22:40:46 | 000,306,432 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2010/11/08 13:04:20 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2009/07/13 18:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 18:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [Unknown (2018998034) | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 18:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/09/29 09:07:00 | 000,143,088 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe -- (McShield)
SRV - [2008/09/29 09:07:00 | 000,067,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2008/09/29 09:07:00 | 000,062,800 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe -- (McTaskManager)
SRV - [2008/09/29 09:07:00 | 000,019,456 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe -- (McAfeeEngineService)
SRV - [2008/03/14 05:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2008/02/13 03:00:20 | 007,336,576 | ---- | M] () [Auto | Running] -- C:\AppServ\MySQL\bin\mysqld.exe -- (mysql)
SRV - [2008/01/17 10:37:26 | 000,024,635 | ---- | M] (Apache Software Foundation) [Auto | Running] -- C:\AppServ\Apache2.2\bin\httpd.exe -- (Apache2.2)
SRV - [2007/12/20 11:41:56 | 000,029,440 | ---- | M] (TuneUp Software GmbH) [Auto | Stopped] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2006/05/23 22:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) [Auto | Running] -- C:\Windows\System32\StkASv2K.exe -- (StkASSrv)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS -- (MRESP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS -- (MREMP50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\ayee\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2012/09/23 11:29:26 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E01902AB-BDF8-4DFB-8DE4-BCB8C0560DA6}\MpKsl7a6629b6.sys -- (MpKsl7a6629b6)
DRV - [2012/09/23 09:20:36 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E01902AB-BDF8-4DFB-8DE4-BCB8C0560DA6}\MpKsl3f4809a2.sys -- (MpKsl3f4809a2)
DRV - [2012/09/11 21:58:28 | 000,083,392 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2010/11/20 05:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 05:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 05:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 03:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 03:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 02:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 02:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 02:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/09/17 16:40:06 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2010/09/17 16:40:06 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2009/07/13 15:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32)
DRV - [2009/07/13 15:02:49 | 000,046,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2008/09/29 09:07:00 | 000,340,592 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2008/09/29 09:07:00 | 000,090,360 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2008/09/29 09:07:00 | 000,074,648 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2008/09/29 09:07:00 | 000,064,432 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2008/09/29 09:07:00 | 000,062,704 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2008/09/29 09:07:00 | 000,042,424 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2006/09/26 19:01:36 | 000,241,628 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\StkAMini.sys -- (StkAMini)
DRV - [2006/08/01 22:44:04 | 000,004,772 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\StkScan.sys -- (StkScan)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 99 32 42 51 7D 98 CD 01 [binary data]
IE - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
http://isearch.avg.com/search?cid={...ccccc6508f4&lang=en&ds=AVG&pr=fr&d=2012-05-09 07:05:04&v=11.0.0.9&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.2163
FF - prefs.js..extensions.enabledItems: {F53C93F1-07D5-430c-86D4-C9531B27DFAF}:12.0.0.2166
FF - prefs.js..extensions.enabledItems: avg@toolbar:11.0.0.9
FF - prefs.js..keyword.URL: "
http://isearch.avg.com/search?cid={...lang=en&pr=fr&d=2012-03-29 14:50:02&sap=ku&q="
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/15 12:51:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/21 19:35:47 | 000,000,000 | ---D | M]
[2010/12/31 17:22:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ayee\AppData\Roaming\Mozilla\Extensions
[2012/06/16 13:12:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ayee\AppData\Roaming\Mozilla\Firefox\Profiles\dpqx62sf.default\extensions
[2009/07/13 16:11:12 | 000,004,819 | ---- | M] () (No name found) -- C:\Users\ayee\AppData\Roaming\Mozilla\Firefox\Profiles\dpqx62sf.default\extensions\
tnnreimtpx@tnnreimtpx.org.xpi
[2012/05/11 21:41:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/02/02 16:34:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/26 10:29:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX\DONOTTRACK
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
File not found (No name found) -- C:\PROGRAMDATA\AVG SECURE SEARCH\11.0.0.9
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/09/13 17:50:45 | 000,003,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.168\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.168\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.168\gcswf32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: AVG Safe Search = C:\Users\ayee\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: AVG Safe Search = C:\Users\ayee\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\
CHR - Extension: AVG Do Not Track = C:\Users\ayee\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
O1 HOSTS File: ([2012/09/22 21:54:25 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" File not found
O4 - HKLM..\Run: [LogMeIn GUI] C:\Windows\System32\systray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] KEY File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ShStatEXE] E File not found
O4 - HKU\S-1-5-21-4045639339-2855752252-783212770-1000..\Run: [FreeRAM XP] C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions (TM))
O4 - HKU\S-1-5-21-4045639339-2855752252-783212770-1000..\Run: [MobileDocuments] File not found
O4 - HKU\.DEFAULT..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
O4 - HKU\S-1-5-18..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4045639339-2855752252-783212770-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab (DLM Control)
O16 - DPF: {682C59F5-478C-4421-9070-AD170D143B77}
http://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab (Launcher Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/ractrl.cab?lmi=724 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45A86153-9909-4614-BE95-1CC5BD995AD2}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A443267E-3FD7-4789-8355-77987337FDE2}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\HmelyoffLabs\VHToolkit\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/23 11:34:51 | 000,601,600 | ---- | C] (OldTimer Tools) -- C:\Users\ayee\Desktop\OTL.exe
[2012/09/23 10:14:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/09/23 10:12:15 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/09/23 10:12:13 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/09/23 10:11:20 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2012/09/23 10:10:30 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/09/23 07:07:33 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/09/22 21:54:51 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/22 20:48:16 | 000,000,000 | ---D | C] -- C:\Users\ayee\AppData\Local\temp
[2012/09/22 20:15:43 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/09/22 20:15:43 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/09/22 20:15:43 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/09/22 20:15:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/22 20:08:36 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/09/22 20:04:07 | 004,754,913 | R--- | C] (Swearware) -- C:\Users\ayee\Desktop\ComboFix.exe
[2012/09/22 16:37:59 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\ayee\Desktop\aswMBR.exe
[2012/09/22 16:33:31 | 000,000,000 | ---D | C] -- C:\Users\ayee\Documents\RK_Quarantine
[2012/09/22 08:12:31 | 000,000,000 | ---D | C] -- C:\FRST
[2012/09/22 06:50:16 | 000,904,282 | ---- | C] (Farbar) -- C:\Users\ayee\Documents\FRST.exe
[2012/09/21 21:15:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[2012/09/21 20:44:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/09/20 20:34:57 | 000,000,000 | ---D | C] -- C:\Program Files\Eusing Free Registry Cleaner
[2012/09/20 20:01:33 | 000,000,000 | ---D | C] -- C:\Users\ayee\AppData\Roaming\PC Cleaners
[2012/09/20 20:01:22 | 000,000,000 | ---D | C] -- C:\Users\ayee\AppData\Roaming\PCPro
[2012/09/20 20:01:22 | 000,000,000 | ---D | C] -- C:\ProgramData\PC1Data
[2012/09/19 19:36:19 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt
[2012/09/18 21:19:10 | 000,000,000 | ---D | C] -- C:\Users\ayee\Documents\Iphone 3gs 5.1
[2012/09/18 21:13:55 | 000,000,000 | ---D | C] -- C:\Users\ayee\Documents\Iphone 3gs 5.1.1
[2012/09/15 16:40:15 | 000,022,400 | ---- | C] (IObit) -- C:\Windows\System32\RegistryDefragBootTime.exe
[2012/09/15 13:47:36 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2012/09/15 13:47:23 | 000,000,000 | ---D | C] -- C:\Users\ayee\AppData\Roaming\IObit
[2012/09/15 13:43:10 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2012/09/15 12:50:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/09/15 12:49:48 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012/09/15 09:31:37 | 000,000,000 | ---D | C] -- C:\Users\ayee\AppData\Roaming\Opera
[2012/09/15 09:31:37 | 000,000,000 | ---D | C] -- C:\Users\ayee\AppData\Local\Opera
[2012/09/15 09:30:46 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2012/09/09 13:52:43 | 016,144,455 | ---- | C] (Rockers Team) -- C:\Users\ayee\Documents\rt_7_lite_win7_Vista_x86.exe
[2012/09/08 13:07:09 | 000,000,000 | ---D | C] -- C:\Users\ayee\Documents\dell_vista_drivers
[2012/09/02 15:27:55 | 000,000,000 | ---D | C] -- C:\Users\ayee\Documents\Redsn0w0.9.14b2
[2012/09/01 11:13:55 | 000,000,000 | R--D | C] -- C:\Users\ayee\Documents\Documents
========== Files - Modified Within 30 Days ==========
[2012/09/23 11:36:16 | 000,016,448 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 11:36:16 | 000,016,448 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 11:35:22 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\ayee\Desktop\OTL.exe
[2012/09/23 11:32:25 | 000,933,680 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/23 11:32:25 | 000,212,412 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/23 11:27:24 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/23 11:26:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/23 11:26:04 | 2408,398,848 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/23 10:20:06 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/23 10:14:03 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/09/23 09:19:48 | 000,408,256 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/09/22 22:05:51 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/09/22 21:54:25 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/09/22 20:05:18 | 004,754,913 | R--- | M] (Swearware) -- C:\Users\ayee\Desktop\ComboFix.exe
[2012/09/22 18:34:21 | 000,046,454 | ---- | M] () -- C:\Users\ayee\Documents\news.zip
[2012/09/22 18:07:39 | 000,000,512 | ---- | M] () -- C:\Users\ayee\Documents\MBR.dat
[2012/09/22 16:39:35 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\ayee\Desktop\aswMBR.exe
[2012/09/22 16:31:20 | 001,388,032 | ---- | M] () -- C:\Users\ayee\Documents\RogueKiller.exe
[2012/09/22 06:50:45 | 000,904,282 | ---- | M] (Farbar) -- C:\Users\ayee\Documents\FRST.exe
[2012/09/22 06:23:29 | 000,190,479 | ---- | M] () -- C:\Users\ayee\Documents\SirefefMissingServicesRegistryFix.zip
[2012/09/21 21:17:55 | 199,468,312 | ---- | M] () -- C:\Users\ayee\Documents\eusing_2012_09_21.reg
[2012/09/15 22:19:24 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/15 12:50:54 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/09/15 09:30:58 | 000,001,775 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2012/09/11 21:58:28 | 000,083,392 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIRfsClientNP.dll
[2012/09/11 21:58:23 | 000,030,624 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIport.dll
[2012/09/11 21:58:22 | 000,087,456 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIinit.dll
[2012/09/11 21:42:32 | 198,359,374 | ---- | M] () -- C:\Users\ayee\Documents\BACKUP.REG
[2012/09/09 13:52:55 | 016,144,455 | ---- | M] (Rockers Team) -- C:\Users\ayee\Documents\rt_7_lite_win7_Vista_x86.exe
[2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/09/01 14:00:07 | 000,120,044 | ---- | M] () -- C:\Users\ayee\Documents\blued-gui.rar
========== Files Created - No Company Name ==========
[2012/09/23 10:14:03 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/09/23 10:11:22 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/09/22 22:05:30 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/09/22 20:15:43 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/09/22 20:15:43 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/09/22 20:15:43 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/09/22 20:15:43 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/09/22 20:15:43 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/09/22 18:07:39 | 000,000,512 | ---- | C] () -- C:\Users\ayee\Documents\MBR.dat
[2012/09/22 16:30:57 | 001,388,032 | ---- | C] () -- C:\Users\ayee\Documents\RogueKiller.exe
[2012/09/22 06:23:26 | 000,190,479 | ---- | C] () -- C:\Users\ayee\Documents\SirefefMissingServicesRegistryFix.zip
[2012/09/21 21:16:20 | 199,468,312 | ---- | C] () -- C:\Users\ayee\Documents\eusing_2012_09_21.reg
[2012/09/15 22:19:24 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/15 12:50:54 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/09/15 12:50:39 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012/09/15 09:30:58 | 000,001,775 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012/09/11 21:42:02 | 198,359,374 | ---- | C] () -- C:\Users\ayee\Documents\BACKUP.REG
[2012/09/01 14:00:07 | 000,120,044 | ---- | C] () -- C:\Users\ayee\Documents\blued-gui.rar
[2012/05/12 08:35:36 | 000,000,600 | ---- | C] () -- C:\Users\ayee\AppData\Local\PUTTY.RND
[2012/05/10 21:38:23 | 000,000,068 | ---- | C] () -- C:\Windows\Crypkey.ini
[2012/05/10 21:38:19 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe
[2012/05/10 21:38:19 | 000,019,584 | ---- | C] () -- C:\Windows\System32\Ckldrv.sys
[2012/05/10 21:38:19 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
[2012/05/10 21:38:19 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe
[2012/04/29 09:56:05 | 000,000,000 | ---- | C] () -- C:\ProgramData\-06QucbADZ6ZevM
[2012/04/29 09:55:58 | 000,000,480 | ---- | C] () -- C:\ProgramData\06QucbADZ6ZevM
[2012/02/18 20:55:19 | 000,000,001 | ---- | C] () -- C:\ProgramData\ERQE3II7.exe_.b
[2012/02/18 07:57:25 | 000,187,432 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2012/01/12 14:18:02 | 000,000,197 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011/12/31 07:42:00 | 000,000,000 | ---- | C] () -- C:\Windows\System32\lhah8C3.com_.b
[2011/12/24 09:45:36 | 000,000,001 | ---- | C] () -- C:\Windows\System32\lhah8C3.com.b
[2011/12/24 07:13:40 | 000,000,112 | ---- | C] () -- C:\ProgramData\CK8lbl0G1.dat
[2011/12/20 18:44:03 | 000,011,300 | -HS- | C] () -- C:\Users\ayee\AppData\Local\p45gq71falo0e34xqp2sdbtn63027hndp
[2011/12/20 18:44:03 | 000,011,300 | -HS- | C] () -- C:\ProgramData\p45gq71falo0e34xqp2sdbtn63027hndp
[2011/12/20 16:52:24 | 000,011,484 | -HS- | C] () -- C:\Users\ayee\AppData\Local\4a24mk4f80s857
[2011/12/20 16:52:24 | 000,011,484 | -HS- | C] () -- C:\ProgramData\4a24mk4f80s857
[2011/07/03 18:48:20 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/07/03 18:45:51 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/07/03 17:54:37 | 000,000,600 | ---- | C] () -- C:\Users\ayee\AppData\Roaming\winscp.rnd
[2011/05/16 13:31:44 | 000,008,592 | ---- | C] () -- C:\Windows\System32\ractrlkeyhook.dll
========== ZeroAccess Check ==========
[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 21:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 18:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/03/29 14:51:26 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\AVG2012
[2012/03/25 10:49:47 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\DA0FCCD6
[2012/04/07 18:15:10 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\DiskAid
[2011/07/04 12:40:19 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\GetRightToGo
[2012/09/21 19:28:07 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\IObit
[2012/09/15 09:31:37 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\Opera
[2012/09/20 20:01:33 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\PC Cleaners
[2012/05/11 10:32:26 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\PCDr
[2012/09/20 20:01:35 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\PCPro
[2012/09/02 16:38:25 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\redsn0w
[2011/07/04 12:50:22 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\ScanToPDF_4
[2010/11/22 22:40:48 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\TuneUp Software
[2012/09/23 07:53:53 | 000,000,000 | ---D | M] -- C:\Users\ayee\AppData\Roaming\uTorrent
[2012/05/05 10:32:19 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\AVG2012
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 298 bytes -> C:\Windows\System32\drivers\whqvndhd.sys:changelist
< End of report >