[2011/09/06 17:01:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\AppData\Roaming\Mozilla\Extensions
[2012/03/24 22:28:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\1cwwilqw.default\extensions
[2012/03/24 22:27:23 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\1cwwilqw.default\extensions\
ffxtlbr@incredibar.com
[2012/03/24 22:28:04 | 000,000,000 | ---D | M] (Codec-C) -- C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\1cwwilqw.default\extensions\
info@allpremiumplay.info
[2012/03/24 22:27:08 | 000,002,203 | ---- | M] () -- C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\1cwwilqw.default\searchplugins\MyStart Search.xml
[2011/09/06 17:00:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/05/14 21:15:36 | 000,000,000 | ---D | M] (AVG Do Not Track) -- C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/05/17 16:51:26 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4
[2012/05/14 21:18:57 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\11.0.0.9
[2012/03/15 02:06:53 | 000,521,086 | ---- | M] () (No name found) -- C:\USERS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1CWWILQW.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012/02/21 23:35:23 | 000,634,964 | ---- | M] () (No name found) -- C:\USERS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1CWWILQW.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/03/15 02:52:26 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/15 02:52:23 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/05/14 21:18:32 | 000,003,747 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/15 02:52:23 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/15 02:52:23 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/03/15 02:52:23 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/03/15 02:52:23 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - Extension: YouTube = C:\Users\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Users\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O1 HOSTS File: ([2012/05/22 00:21:56 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:
64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:
64bit: - BHO: (SSOIEAddonBHO Class) - {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files (x86)\Sensible Vision\Fast Access\x64\FAIESSO.dll (Sensible Vision )
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SSOIEAddonBHO Class) - {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [CCE] "C:\Users\Documents\cce_2.4.225190.192_x64\CCE\CCE.exe" -showlog File not found
O4:
64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:
64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NUSB3MON] c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKU\S-1-5-21-781594651-822235961-4032767447-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-781594651-822235961-4032767447-1001..\Run: [Facebook Update] C:\Users\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-781594651-822235961-4032767447-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKU\S-1-5-21-781594651-822235961-4032767447-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-781594651-822235961-4032767447-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-781594651-822235961-4032767447-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-781594651-822235961-4032767447-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-781594651-822235961-4032767447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-781594651-822235961-4032767447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-781594651-822235961-4032767447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-781594651-822235961-4032767447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:
64bit: - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:
64bit: - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:
64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:
64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:
64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7958C39-6B94-4F35-8E4E-0600D11AA165}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll ()
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\FastAccess: DllName - (C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll) - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/05/25 00:01:00 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Desktop\OTL.exe
[2012/05/23 12:38:15 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{2E80DBD3-CB09-4577-ADDB-0264A3575290}
[2012/05/23 12:38:13 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{A9961265-7C6E-44C1-B908-FAD20CF8C35E}
[2012/05/22 01:52:10 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/05/22 01:37:36 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/05/21 23:53:58 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/05/21 23:53:58 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/05/21 23:53:58 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/05/21 23:51:54 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/05/21 23:51:49 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/05/21 15:36:16 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{511B1229-AC87-49F6-8C4D-37BBBD903301}
[2012/05/21 03:03:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/21 03:01:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/05/21 03:01:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/05/20 23:19:59 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{919D67AB-A792-4367-999A-FF41DE231A08}
[2012/05/20 11:19:53 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{861490AC-D124-466D-A6D7-52A65717EFDF}
[2012/05/19 23:19:46 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{EC54D119-0434-41EC-96D9-F1808388CF5B}
[2012/05/19 23:19:43 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{576E9C1A-5358-4967-AB87-2DD7866FA43B}
[2012/05/17 16:51:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/05/17 16:43:32 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{3BD3C5E8-60D0-4833-B645-15B3F2FCFE0D}
[2012/05/16 20:55:29 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Desktop\dds.scr
[2012/05/16 20:50:00 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{32352F11-7926-43A0-9354-2BF0F4791824}
[2012/05/16 20:49:55 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{15D31062-D869-4A70-AB12-D74CB86D1712}
[2012/05/16 20:07:54 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Logs
[2012/05/16 19:01:30 | 000,000,000 | ---D | C] -- C:\Users\AppData\Roaming\Malwarebytes
[2012/05/16 19:00:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/16 19:00:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/05/16 19:00:13 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/05/16 19:00:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/05/16 18:48:51 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/15 13:41:48 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{5A04FA96-EABE-4845-BA67-DBACD763E870}
[2012/05/15 13:41:43 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{BBE6264D-2A68-4800-A2B8-015D1867FA86}
[2012/05/15 02:34:53 | 000,000,000 | ---D | C] -- C:\CCE_Quarantine
[2012/05/14 21:40:16 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{423CEC0D-2004-4454-A099-BCDF2312A151}
[2012/05/14 21:40:13 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{498D5AF4-F1B9-41AB-B559-59186E3367DB}
[2012/05/14 21:29:15 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{554F4DCC-4408-42E0-B739-FFF38D4295B9}
[2012/05/14 21:29:06 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{5896EFDE-D7EE-4897-9CC3-52DA2FF1269F}
[2012/05/14 21:20:11 | 000,000,000 | ---D | C] -- C:\Users\AppData\Roaming\AVG2012
[2012/05/14 21:19:10 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\AVG Secure Search
[2012/05/14 21:18:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2012/05/14 21:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
[2012/05/14 21:18:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
[2012/05/14 21:18:12 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/05/14 21:18:03 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\AVG
[2012/05/14 21:15:07 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2012/05/14 21:15:07 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG
[2012/05/14 21:15:07 | 000,000,000 | ---D | C] -- C:\$AVG
[2012/05/14 21:13:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2012/05/14 20:55:17 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012/05/13 15:31:25 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{83D603F4-B387-4440-9B3E-503AED698492}
[2012/05/13 15:30:47 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{275B06AB-C2D2-48FB-91C6-356E067C18FA}
[2012/05/13 00:26:24 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{66F2D374-B4D6-4A3C-884C-6C3E30E599D3}
[2012/05/11 02:47:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/05/11 02:46:58 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/05/11 02:46:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/05/10 19:16:47 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{63B22C47-4F10-43BC-B32D-FBBDC9306B07}
[2012/05/10 19:16:38 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{53EEDB83-3F20-408B-AC2A-4EF547C9FE46}
[2012/05/10 19:01:27 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{5EB2F1AF-9BDE-480D-8FBB-88F201AA4E36}
[2012/05/10 19:01:14 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{AFFAC9C8-21AB-43B2-BBAA-9A2F925AF7B3}
[2012/05/08 22:48:50 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{004AAD1B-9D2F-4B8D-B1A4-4FBEB5CFA90D}
[2012/05/08 22:48:47 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{196275D9-DECB-4814-A5C0-5B789E34D22B}
[2012/05/08 22:33:22 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{9F378C95-6E78-4D60-9F3C-8ED4DE9ABF99}
[2012/05/08 22:33:19 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{2D6E3FF3-7660-44C4-88F5-A39E495A500A}
[2012/05/08 22:17:14 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{546144EE-F822-4100-8951-D59D72D5BADD}
[2012/05/08 22:17:11 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{D268ECE6-1179-42D5-93EA-28D0B3CE0555}
[2012/05/08 21:59:56 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{23F1EE78-F4BE-4C36-AA73-04E33A34E87F}
[2012/05/08 21:59:53 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{9C2C6943-FB79-41FD-95D0-FB83D1DE17ED}
[2012/05/08 21:44:30 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{10D81D15-8570-4B0C-AB52-0CB1BB6724FD}
[2012/05/08 21:44:28 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{6D5D8408-1940-470C-882E-474E5C80474A}
[2012/05/08 21:28:52 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{F73BECC9-87CD-4FA4-B707-B575C329AFAA}
[2012/05/08 21:28:48 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{01C44C2B-4700-4DA0-B330-4C1CBEFD8F3F}
[2012/05/08 21:13:18 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{D8DA013A-C187-4738-B887-C04EABCE141A}
[2012/05/08 21:13:15 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{9A8E0FBD-9DC8-47B1-AD9C-FA24DA442BE5}
[2012/05/08 20:55:46 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{4B0225C0-71A8-4A32-9C95-580BAFA40C59}
[2012/05/08 20:55:41 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{3D98D9E2-5FB2-4106-91DE-831A0355DAF1}
[2012/05/08 20:40:21 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{A3DB3C92-A37C-4CD4-94A8-FEA0F743DA94}
[2012/05/08 20:40:17 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{2BBC333D-76EF-4404-810B-689AE98AC355}
[2012/05/07 22:14:49 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{C324B7E5-0571-4F3A-8AE7-9F16A4FBAA4A}
[2012/05/07 22:14:43 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{C10CD24C-1B0D-448B-AE99-29137896777F}
[2012/05/03 21:48:22 | 000,000,000 | ---D | C] -- C:\Users\Documents\DCIM
[2012/05/03 14:11:29 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{E7BED813-2A0B-45B2-BF66-FF1CAF438716}
[2012/05/03 14:11:20 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{133F4749-501E-4DCD-8239-1E5763DE4898}
[2012/05/03 01:01:00 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{33DEF11A-2433-4779-BD26-1759AF1109A6}
[2012/05/03 01:00:51 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{99DCE95E-E193-4198-A439-B11FC5DB8824}
[2012/05/02 02:06:06 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{6FDB95B8-1C2E-4150-9C3F-660D1A07AB56}
[2012/05/02 02:06:02 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{A8B311D1-DC53-4CD7-B1C9-3ECC349CABD7}
[2012/05/01 00:37:45 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{603B1B63-F837-47ED-B1BA-D0200F8792DC}
[2012/05/01 00:37:37 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{8C1B94C8-8D8E-49D7-BBDD-D268EF66BFBD}
[2012/04/29 00:31:40 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{7A367AEA-82E4-4DCB-B28F-14BDAD302079}
[2012/04/29 00:31:37 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{27149282-0155-45FF-A904-BA5F540E9C34}
[2012/04/29 00:16:08 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{98423971-1548-436B-BFA5-C93593ED20C0}
[2012/04/29 00:16:05 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{C96C4B59-CEAE-44C3-A270-ABC07F789ADC}
[2012/04/29 00:00:02 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{DB1F90DD-481F-4CEC-A0D9-761F22E77A8C}
[2012/04/28 23:59:57 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{DE7F3B96-9A59-4172-9860-AB1316F2E535}
[2012/04/28 23:44:11 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{D9648D87-85E6-4622-B626-D75B9AED8C6A}
[2012/04/28 23:44:09 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{2A9B4C4A-D1A3-4B87-9334-D72B87110809}
[2012/04/28 23:27:55 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{81D3111E-16FD-4ED8-909C-5A5D9A1E7503}
[2012/04/28 23:27:52 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{9ABE36D3-8E04-4E20-8853-BD79E6F97D96}
[2012/04/28 23:11:26 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{B6C76102-42BD-4DE4-A096-B98B2B27E3EB}
[2012/04/28 23:11:22 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{F7562416-CB0C-4EDB-8DDB-D729AB8B170B}
[2012/04/28 22:55:34 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{D1C0351E-2D6F-4B17-B7B7-80EB33E6C220}
[2012/04/28 22:55:32 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{6E6B1F89-27CD-4488-85A9-A9A1D7FD3DB9}
[2012/04/28 22:39:29 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{934CFF75-28DE-4684-82E3-B314B0E6DE3B}
[2012/04/28 22:39:27 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{B3B410C7-A445-4B00-BE1A-1F2746DEC79D}
[2012/04/28 22:23:51 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{E5312F45-C5E3-4099-8EF6-00C296100E58}
[2012/04/28 22:23:48 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{41B257A3-890D-4B20-8CF9-844A245A6E85}
[2012/04/28 03:20:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/04/28 03:20:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/04/26 20:26:49 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{272D8BBF-1748-439C-AE68-C0202A721B60}
[2012/04/26 20:26:43 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{5BB0673A-9833-457B-830B-5105AA6827A0}
[2012/04/26 02:42:04 | 000,000,000 | ---D | C] -- C:\Users\AppData\Local\{78042398-CA91-4DEB-A964-7541D203DE75}
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Users\Desktop\*.tmp files -> C:\Users\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/25 00:01:05 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Desktop\OTL.exe
[2012/05/24 23:40:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/24 23:21:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/24 23:01:03 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-781594651-822235961-4032767447-1001UA.job
[2012/05/24 22:54:32 | 098,988,293 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/05/24 22:06:30 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/24 22:06:30 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/24 22:03:17 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/24 22:02:56 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-781594651-822235961-4032767447-1001Core.job
[2012/05/24 21:54:04 | 000,002,342 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012/05/24 21:51:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/05/23 12:38:50 | 000,727,334 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/23 12:38:50 | 000,629,326 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/05/23 12:38:50 | 000,111,220 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/05/22 18:53:45 | 000,160,276 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/05/22 16:23:15 | 3010,695,168 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/22 00:21:56 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/05/19 22:55:29 | 547,464,414 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/05/17 21:33:04 | 000,000,512 | ---- | M] () -- C:\Users\Desktop\MBR.dat
[2012/05/17 18:56:41 | 000,044,607 | ---- | M] () -- C:\Users\Desktop\Bootkit Remover.zip
[2012/05/17 16:51:27 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/17 16:46:21 | 000,625,471 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/05/16 20:55:36 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Desktop\dds.scr
[2012/05/16 20:01:51 | 000,302,592 | ---- | M] () -- C:\Users\Desktop\GMER.exe
[2012/05/16 19:00:52 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/16 18:57:26 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/14 21:52:56 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/05/14 21:18:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/05/14 21:18:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012/05/14 21:18:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/05/12 19:47:43 | 000,353,456 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/11 02:47:49 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Users\Desktop\*.tmp files -> C:\Users\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/24 22:54:32 | 098,988,293 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/05/22 18:53:45 | 000,160,276 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/05/21 23:53:58 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/05/21 23:53:58 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/05/21 23:53:58 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/05/21 23:53:58 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/05/21 23:53:58 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/05/17 21:33:04 | 000,000,512 | ---- | C] () -- C:\Users\Desktop\MBR.dat
[2012/05/17 18:56:36 | 000,044,607 | ---- | C] () -- C:\Users\Desktop\Bootkit Remover.zip
[2012/05/17 16:46:21 | 000,625,471 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/05/16 20:01:31 | 000,302,592 | ---- | C] () -- C:\Users\Desktop\GMER.exe
[2012/05/16 19:00:52 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/14 21:51:34 | 000,002,016 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/05/14 21:51:33 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/05/14 21:19:04 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/14 21:18:03 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/05/14 21:18:03 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012/05/14 21:18:03 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/05/11 02:47:49 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/04/26 02:44:39 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2011/02/21 20:18:42 | 000,735,726 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/02 00:38:36 | 000,008,192 | ---- | C] () -- C:\Users\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/26 23:51:13 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/11/25 00:53:35 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010/11/25 00:53:35 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/11/25 00:53:35 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010/11/25 00:53:35 | 000,104,796 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010/11/25 00:53:34 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010/11/02 12:40:34 | 000,087,176 | ---- | C] () -- C:\Windows\SysWow64\FAIEExtension.dll
[2010/11/02 12:40:30 | 000,057,480 | ---- | C] () -- C:\Windows\SysWow64\FAib.dll
[2010/11/02 12:40:24 | 000,248,968 | ---- | C] () -- C:\Windows\SysWow64\FACrashRpt.dll
========== LOP Check ==========
[2012/05/14 21:20:11 | 000,000,000 | ---D | M] -- C:\Users\AppData\Roaming\AVG2012
[2012/03/17 14:39:20 | 000,000,000 | ---D | M] -- C:\Users\AppData\Roaming\ICQ
[2011/02/07 00:21:56 | 000,000,000 | ---D | M] -- C:\Users\AppData\Roaming\PeaZip
[2012/05/02 02:00:30 | 000,000,000 | ---D | M] -- C:\Users\AppData\Roaming\SoftGrid Client
[2012/03/17 14:39:20 | 000,000,000 | ---D | M] -- C:\Users\AppData\Roaming\TeamViewer
[2011/02/21 20:19:29 | 000,000,000 | ---D | M] -- C:\Users\AppData\Roaming\TP
[2012/05/22 00:35:05 | 000,000,000 | ---D | M] -- C:\Users\AppData\Roaming\uTorrent
[2012/05/24 22:02:56 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-781594651-822235961-4032767447-1001Core.job
[2012/05/24 23:01:03 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-781594651-822235961-4032767447-1001UA.job
[2012/05/01 00:32:58 | 000,032,536 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/05/22 01:37:34 | 000,027,628 | ---- | M] () -- C:\ComboFix.txt
[2010/12/18 01:25:46 | 000,003,694 | RH-- | M] () -- C:\dell.sdr
[2010/12/18 00:17:06 | 000,001,254 | ---- | M] () -- C:\freefallprotection.log
[2012/05/22 16:23:15 | 3010,695,168 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/22 16:23:15 | 4014,260,224 | -HS- | M] () -- C:\pagefile.sys
[2010/12/18 00:10:55 | 000,002,320 | ---- | M] () -- C:\RHDSetup.log
[2012/02/16 23:37:48 | 000,000,510 | ---- | M] () -- C:\settings.ini
[2012/03/24 22:27:29 | 000,000,400 | ---- | M] () -- C:\user.js
[2011/11/04 22:39:03 | 000,002,957 | ---- | M] () -- C:\WirelessDiagLog.csv
< %systemroot%\Fonts\*.com >
[2009/07/14 13:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 13:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 13:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 13:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 04:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 12:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/11 16:26:50 | 000,000,221 | -HS- | M] () -- C:\Users\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/05/16 20:01:51 | 000,302,592 | ---- | M] () -- C:\Users\Desktop\GMER.exe
[2012/03/01 22:45:58 | 000,241,664 | ---- | M] (
www.CompulsiveCode.com) -- C:\Users\Desktop\JPEGtoPDF.exe
[2012/05/16 18:57:26 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/25 00:01:05 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Desktop\OTL.exe
[2 C:\Users\Desktop\*.tmp files -> C:\Users\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/05/24 23:21:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/24 22:02:56 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-781594651-822235961-4032767447-1001Core.job
[2012/05/24 23:01:03 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-781594651-822235961-4032767447-1001UA.job
[2012/05/24 22:03:17 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/24 23:40:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/22 16:23:36 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/05/01 00:32:58 | 000,032,536 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/11 05:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/07/13 13:34:10 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/07/13 13:34:10 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2010/12/18 00:10:51 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2010/12/18 00:10:51 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/07/13 13:34:10 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/02/18 18:27:14 | 000,000,402 | -HS- | M] () -- C:\Users\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/11/09 16:36:56 | 000,000,625 | ---- | M] () -- C:\ProgramData\hpzinstall.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< >
< End of report >