========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 64 29 AA A5 D1 54 CF 01 [binary data]
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.skidata.net
IE - HKU\S-1-5-21-746137067-789336058-1275210071-24234\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 172.16.10.104:8080
IE - HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\SearchScopes,DefaultScope =
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Windows\SysWOW64\npdeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@vmware.com/vmrc,version=5.1.0.00000: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Firefox\np-vmware-vmrc.dll (VMware, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013/10/29 13:16:04 | 000,000,000 | ---D | M]
[2014/04/07 10:37:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/04/07 10:38:13 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2014/04/18 07:40:18 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmIEPlg.dll File not found
O2:
64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmIEPlg32.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (no name) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:
64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:
64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:
64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:
64bit: - HKLM..\Run: [DellAccessSystray] C:\Program Files\Dell\Dell Data Protection\Access\DellAccessSysTray.exe (Wave Systems)
O4:
64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [FDispPos] C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe ()
O4:
64bit: - HKLM..\Run: [MCTDUtil] C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe ()
O4:
64bit: - HKLM..\Run: [MFNetworkScanUtility] C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE (CANON INC.)
O4:
64bit: - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:
64bit: - HKLM..\Run: [TdmNotify] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Acronis International GmbH)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKU\S-1-5-21-746137067-789336058-1275210071-24234..\Run: [DellSystemDetect] C:\Users\PRTH\AppData\Local\Apps\2.0\5XXQYROZ.MQG\ETKECZ83.APG\dell..tion_0f612f649c4a10af_0005.0006_f9e15713f5aac8ac\DellSystemDetect.exe (Dell)
O4 - HKU\S-1-5-21-746137067-789336058-1275210071-24234..\Run: [Driver Support] C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe (PC Drivers Headquarters)
O4 - HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DontSetAutoplayCheckbox = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutorun = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-746137067-789336058-1275210071-24234\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-746137067-789336058-1275210071-24234\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-746137067-789336058-1275210071-24234\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:
64bit: - Extra context menu item: Download all with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dlall.htm ()
O8:
64bit: - Extra context menu item: Download selected with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dlselected.htm ()
O8:
64bit: - Extra context menu item: Download video with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dlfvideo.htm ()
O8:
64bit: - Extra context menu item: Download with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dllink.htm ()
O8 - Extra context menu item: Download all with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with FileKiddo Download Manager - C:\Program Files (x86)\FileKiddo Download Manager\dllink.htm ()
O13 - gopher Prefix: missing
O15:
64bit: - ..Trusted Domains: dynamics.com ([online] https in Trusted sites)
O15:
64bit: - ..Trusted Domains: dynamics.com ([resources] https in Trusted sites)
O15 - HKU\S-1-5-21-746137067-789336058-1275210071-24234\..Trusted Domains: dell.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-746137067-789336058-1275210071-24234\..Trusted Domains: pc-l-prth ([]http in Local intranet)
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751}
https://sdusavsrv/officescan/console/html/ClientInstall/WinNTChk.cab (ObjWinNTCheck Class)
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B}
https://sdusavsrv/officescan/console/html/ClientInstall/setupini.cab (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class)
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B}
https://sdusavsrv/officescan/console/html/ClientInstall/setup.cab (OfficeScan Corp Edition Web-Deployment SetupCtrl Class)
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4}
https://sdusavsrv/officescan/console/html/root/AtxEnc.cab (Encrypt Class)
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B}
https://sdusavsrv/officescan/console/html/ClientInstall/RemoveCtrl.cab (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0}
https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab (DLC Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab (Java Plug-in 1.7.0_51)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab (Java Plug-in 1.7.0_51)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com//activex/ractrl.cab?lmi=1058 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.26.10.8 172.16.10.90
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = skidata.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2EFC32B-D241-4E36-977A-475F6F407220}: DhcpNameServer = 172.26.10.8 172.16.10.90
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ED687666-28DD-440D-B17D-8EB62937FD11}: DhcpNameServer = 192.168.169.1
O18:
64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmIEPlg.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmIEPlg32.dll File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:
64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20:
64bit: - Winlogon\Notify\spba: DllName - (C:\Program Files\Common Files\SPBA\homefus2.dll) - C:\Program Files\Common Files\SPBA\homefus2.dll (Authentec Inc.)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/04/18 10:23:35 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/04/18 10:10:45 | 000,033,856 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\hamachi.sys
[2014/04/18 10:10:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2014/04/18 10:10:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2014/04/18 09:08:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/04/18 08:00:44 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Skype
[2014/04/18 07:40:19 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\VirtualStore
[2014/04/18 07:27:35 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\TeamViewer
[2014/04/18 07:24:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/04/18 07:24:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/04/18 07:24:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/04/18 07:24:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/04/18 07:24:14 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/04/17 12:15:31 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents\SQL Server Management Studio
[2014/04/17 11:12:01 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\CrashDumps
[2014/04/17 10:07:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/04/17 10:04:52 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Desktop\mbar
[2014/04/17 09:01:58 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Desktop\RK_Quarantine
[2014/04/17 08:54:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileKiddo Download Manager
[2014/04/17 08:54:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileKiddo Download Manager
[2014/04/17 08:46:55 | 000,000,000 | ---D | C] -- C:\ProgramData\UAB
[2014/04/17 08:46:54 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\PC_Drivers_Headquarters
[2014/04/17 08:46:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Driver Support
[2014/04/17 08:46:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Support
[2014/04/17 08:46:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver Support
[2014/04/17 08:46:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2014/04/16 08:53:57 | 000,000,000 | R--D | C] -- C:\Users\PRTH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014/04/16 08:53:57 | 000,000,000 | R--D | C] -- C:\Users\PRTH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014/04/15 13:19:23 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Dell
[2014/04/15 13:03:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2014/04/15 13:03:00 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2014/04/15 13:02:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2014/04/15 12:51:16 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2014/04/15 12:51:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
[2014/04/15 12:34:41 | 000,551,936 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys
[2014/04/15 12:34:40 | 002,213,376 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll
[2014/04/15 12:34:40 | 000,697,856 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll
[2014/04/15 12:34:40 | 000,499,200 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll
[2014/04/15 12:34:40 | 000,256,000 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\st646491.dll
[2014/04/15 12:34:40 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2014/04/15 12:24:09 | 000,000,000 | ---D | C] -- C:\Windows\Dell
[2014/04/15 11:33:55 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
[2014/04/15 11:33:39 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Deployment
[2014/04/15 11:33:39 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Apps
[2014/04/15 10:18:13 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\AVG2014
[2014/04/15 10:17:59 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\TuneUp Software
[2014/04/15 10:17:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2014/04/15 10:17:52 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2014
[2014/04/15 10:17:52 | 000,000,000 | ---D | C] -- C:\$AVG
[2014/04/15 10:17:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2014/04/15 10:16:03 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2014/04/15 10:16:03 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\MFAData
[2014/04/15 10:16:03 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2014/04/15 10:16:03 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Avg2014
[2014/04/14 13:48:25 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\LavasoftStatistics
[2014/04/14 13:32:19 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\adawarebp
[2014/04/14 13:32:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Browsing Protection
[2014/04/14 13:32:08 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\SecureSearch
[2014/04/14 13:31:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft
[2014/04/14 13:29:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2014/04/14 13:29:47 | 000,000,000 | ---D | C] -- C:\downloads
[2014/04/14 11:30:10 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Yahoo!
[2014/04/14 10:55:45 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Oracle
[2014/04/14 10:54:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2014/04/14 10:54:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/04/14 10:54:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
[2014/04/14 10:54:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/04/11 11:23:12 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Wave Systems Corp
[2014/04/11 08:40:58 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents\My Scans
[2014/04/11 08:39:20 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Canon
[2014/04/10 15:36:32 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Programs
[2014/04/10 13:19:43 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2014/04/10 08:04:34 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Macromedia
[2014/04/08 18:44:05 | 000,000,000 | ---D | C] -- C:\ProgramData\GroupPolicy
[2014/04/08 16:10:49 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Cisco
[2014/04/08 15:43:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belkin
[2014/04/08 15:43:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Belkin
[2014/04/08 15:01:41 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Adobe
[2014/04/07 18:39:08 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\NuGet
[2014/04/07 10:37:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014/04/07 10:19:54 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents\My Web Sites
[2014/04/07 10:19:54 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents\IISExpress
[2014/04/07 10:18:32 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents\Visual Studio 2010
[2014/04/07 10:05:29 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\TortoiseSVN
[2014/04/07 09:26:27 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents\My PSP Files
[2014/04/07 09:20:09 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Corel
[2014/04/07 09:06:11 | 000,000,000 | R--D | C] -- C:\Users\PRTH\Pictures
[2014/04/07 09:06:10 | 000,000,000 | R--D | C] -- C:\Users\PRTH\Videos
[2014/04/07 09:06:10 | 000,000,000 | R--D | C] -- C:\Users\PRTH\Music
[2014/04/07 08:34:14 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Softland
[2014/04/03 13:00:06 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\ElevatedDiagnostics
[2014/04/03 12:50:47 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Wave Systems Corp
[2014/04/03 12:50:32 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\LogMeIn
[2014/04/03 12:50:32 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Intel Corporation
[2014/04/03 12:50:31 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\LogMeIn Hamachi
[2014/04/03 12:50:28 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Logitech
[2014/04/03 12:50:26 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Subversion
[2014/04/03 10:12:29 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\TSVNCache
[2014/04/03 09:13:52 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Mozilla
[2014/04/03 08:07:54 | 000,000,000 | ---D | C] -- C:\Installs
[2014/04/03 07:43:49 | 000,000,000 | ---D | C] -- C:\log
[2014/04/03 07:20:39 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Macromedia
[2014/04/03 06:25:01 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Roaming\Adobe
[2014/04/03 06:22:49 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents
[2014/04/03 06:22:49 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Broadcom
[2014/04/03 06:22:49 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Documents\Bluetooth Exchange Folder
[2014/04/03 05:35:20 | 000,000,000 | -H-D | C] -- C:\Users\PRTH\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2014/04/03 05:05:47 | 000,000,000 | ---D | C] -- C:\Maven
[2014/04/03 04:58:18 | 000,000,000 | ---D | C] -- C:\Users\PRTH\New folder
[2014/04/03 04:57:10 | 000,000,000 | ---D | C] -- C:\Users\PRTH\AppData\Local\Eclipse
[2014/04/03 04:27:21 | 000,000,000 | ---D | C] -- C:\Users\PRTH\Connectors
[2014/04/03 04:18:37 | 000,000,000 | ---D | C] -- C:\Eclipse
[2014/04/03 04:14:34 | 000,000,000 | ---D | C] -- C:\Users\PRTH\.m2
[2014/04/03 04:04:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2014/04/03 04:01:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2014/04/02 23:08:43 | 000,000,000 | ---D | C] -- C:\SVN.SDAGDWH
[2014/04/01 21:03:14 | 000,236,824 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2014/03/31 16:20:54 | 000,274,200 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
[2014/03/31 16:06:26 | 000,130,840 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2014/03/27 22:14:26 | 000,192,792 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2014/03/27 22:14:24 | 000,153,368 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys
[2014/03/27 22:07:10 | 000,236,824 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2014/03/27 22:05:02 | 000,324,376 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2014/03/27 22:03:16 | 000,032,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys
[2014/03/27 19:37:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/03/27 19:37:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014/03/27 19:37:11 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2014/03/25 08:32:23 | 000,119,000 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/03/25 08:32:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/03/25 08:32:13 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/03/25 08:32:13 | 000,063,192 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/03/25 08:32:13 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/03/25 08:32:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/03/25 08:32:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/03/20 09:45:15 | 000,000,000 | ---D | C] -- C:\ProgramData\NuGet
[2014/03/20 09:45:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NuGet
[2014/03/20 09:34:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression
[2014/03/20 09:30:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Web Tools
[2014/03/20 08:28:42 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Identity Foundation
[2014/03/20 08:28:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Identity Foundation
[2014/03/20 08:28:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Open XML SDK
[2014/03/20 08:13:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Dynamics AX
[2014/03/20 08:11:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Dynamics AX
[2014/03/20 08:09:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Chart Controls
========== Files - Modified Within 30 Days ==========
[2014/04/18 10:17:39 | 000,020,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/04/18 10:17:39 | 000,020,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/04/18 10:14:38 | 001,160,562 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/04/18 10:14:38 | 000,928,162 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/04/18 10:14:38 | 000,223,920 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/04/18 10:10:24 | 000,002,813 | ---- | M] () -- C:\Windows\SysNative\GManager.ini
[2014/04/18 10:10:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/04/18 10:10:20 | 4248,915,966 | -HS- | M] () -- C:\hiberfil.sys
[2014/04/18 09:49:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/04/18 09:46:17 | 000,000,081 | ---- | M] () -- C:\Windows\SysNative\oymcjq.rub
[2014/04/18 09:32:40 | 000,006,710 | RHS- | M] () -- C:\Users\PRTH\ntuser.pol
[2014/04/18 07:40:18 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/04/18 07:13:10 | 000,002,242 | -H-- | M] () -- C:\Users\PRTH\Documents\Default.rdp
[2014/04/17 10:07:56 | 000,119,000 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/04/17 10:05:37 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/04/17 08:54:30 | 000,001,102 | ---- | M] () -- C:\Users\PRTH\Desktop\FileKiddo Download Manager.lnk
[2014/04/17 08:48:19 | 000,001,036 | ---- | M] () -- C:\Users\PRTH\Desktop\Continue Software Installation Installation.lnk
[2014/04/17 08:46:33 | 000,002,301 | ---- | M] () -- C:\Users\Public\Desktop\Driver Support.lnk
[2014/04/17 08:40:52 | 000,000,898 | ---- | M] () -- C:\Users\PRTH\AppData\Roaming\SDCAROOTSRV.skidata.net_SKIDATARootCA.cer
[2014/04/17 08:20:31 | 000,002,305 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2014/04/15 12:51:04 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
[2014/04/15 12:46:38 | 001,148,168 | ---- | M] () -- C:\Windows\SysNative\oem105.inf
[2014/04/15 10:17:59 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/04/15 02:53:53 | 000,009,242 | ---- | M] () -- C:\Windows\cfgall.ini
[2014/04/14 21:38:32 | 000,001,090 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 9.lnk
[2014/04/10 15:36:48 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/04/10 13:35:24 | 000,000,064 | ---- | M] () -- C:\Windows\SysNative\lzei.lcg
[2014/04/10 13:35:24 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\iidysn.tlj
[2014/04/10 13:19:50 | 000,305,834 | --S- | M] () -- C:\Windows\SysNative\yyimgf.chu
[2014/04/10 08:05:38 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\lmhosts
[2014/04/08 18:54:27 | 000,003,858 | ---- | M] () -- C:\Users\PRTH\Documents\04072014OpentTransDFWFail.csv
[2014/04/08 16:52:37 | 000,001,543 | ---- | M] () -- C:\Users\PRTH\Documents\04072014RemoteOpenTransDFWFail.csv
[2014/04/07 11:19:41 | 000,002,828 | -HS- | M] () -- C:\Windows\SysWow64\KGyGaAvL.sys
[2014/04/07 09:40:07 | 000,002,093 | ---- | M] () -- C:\Users\PRTH\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk
[2014/04/07 09:40:07 | 000,002,069 | ---- | M] () -- C:\Users\Public\Desktop\Corel Paint Shop Pro X.lnk
[2014/04/07 08:37:18 | 002,290,744 | ---- | M] () -- C:\Users\PRTH\Documents\04072014OpenTransDFW.csv
[2014/04/03 09:51:16 | 000,063,192 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/04/03 09:50:58 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/04/03 04:34:40 | 000,001,223 | ---- | M] () -- C:\Users\PRTH\Desktop\sdtecsrv - Shortcut.lnk
[2014/04/01 21:03:14 | 000,236,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2014/03/31 16:20:54 | 000,274,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
[2014/03/31 16:06:26 | 000,130,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2014/03/27 22:14:26 | 000,192,792 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2014/03/27 22:14:24 | 000,153,368 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys
[2014/03/27 22:07:10 | 000,236,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2014/03/27 22:05:02 | 000,324,376 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2014/03/27 22:03:16 | 000,032,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys
[2014/03/27 19:34:52 | 000,383,376 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/03/20 08:51:49 | 000,001,172 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Dynamics AX 2012.lnk
[2014/03/20 08:48:46 | 000,000,101 | ---- | M] () -- C:\Windows\SysNative\InstallUtil.InstallLog
========== Files Created - No Company Name ==========
[2014/04/18 10:19:31 | 000,000,898 | ---- | C] () -- C:\Users\PRTH\AppData\Roaming\SDCAROOTSRV.skidata.net_SKIDATARootCA.cer
[2014/04/18 07:24:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/04/18 07:24:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014/04/18 07:24:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/04/18 07:24:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/04/18 07:24:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/04/17 08:54:30 | 000,001,102 | ---- | C] () -- C:\Users\PRTH\Desktop\FileKiddo Download Manager.lnk
[2014/04/17 08:48:19 | 000,001,036 | ---- | C] () -- C:\Users\PRTH\Desktop\Continue Software Installation Installation.lnk
[2014/04/17 08:46:33 | 000,002,301 | ---- | C] () -- C:\Users\Public\Desktop\Driver Support.lnk
[2014/04/15 12:58:42 | 000,022,814 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2014/04/15 12:51:04 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
[2014/04/15 12:46:42 | 001,148,168 | ---- | C] () -- C:\Windows\SysNative\oem105.inf
[2014/04/15 10:17:59 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/04/14 13:32:55 | 000,002,305 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2014/04/10 13:45:36 | 000,000,081 | ---- | C] () -- C:\Windows\SysNative\oymcjq.rub
[2014/04/10 13:35:24 | 000,000,064 | ---- | C] () -- C:\Windows\SysNative\lzei.lcg
[2014/04/10 13:35:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\iidysn.tlj
[2014/04/10 13:19:50 | 000,305,834 | --S- | C] () -- C:\Windows\SysNative\yyimgf.chu
[2014/04/08 16:55:03 | 000,003,858 | ---- | C] () -- C:\Users\PRTH\Documents\04072014OpentTransDFWFail.csv
[2014/04/08 16:55:02 | 000,001,543 | ---- | C] () -- C:\Users\PRTH\Documents\04072014RemoteOpenTransDFWFail.csv
[2014/04/07 10:16:07 | 000,002,093 | ---- | C] () -- C:\Users\PRTH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Araxis Merge.lnk
[2014/04/07 09:40:07 | 000,002,093 | ---- | C] () -- C:\Users\PRTH\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk
[2014/04/07 08:39:19 | 002,290,744 | ---- | C] () -- C:\Users\PRTH\Documents\04072014OpenTransDFW.csv
[2014/04/07 08:32:46 | 000,002,242 | -H-- | C] () -- C:\Users\PRTH\Documents\Default.rdp
[2014/04/07 07:33:49 | 000,001,732 | ---- | C] () -- C:\Users\PRTH\AppData\Roaming\skidata_netCA.cer
[2014/04/03 04:34:40 | 000,001,223 | ---- | C] () -- C:\Users\PRTH\Desktop\sdtecsrv - Shortcut.lnk
[2014/03/25 08:32:17 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/03/20 08:48:34 | 000,000,101 | ---- | C] () -- C:\Windows\SysNative\InstallUtil.InstallLog
[2014/03/20 08:48:33 | 000,001,184 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Dynamics AX 2012.lnk
[2014/03/20 08:48:33 | 000,001,172 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Dynamics AX 2012.lnk
[2014/02/10 12:38:25 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2013/11/12 13:16:07 | 000,002,828 | -HS- | C] () -- C:\Windows\SysWow64\KGyGaAvL.sys
[2013/11/01 14:33:52 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\mctudll.dll
[2013/11/01 14:33:51 | 000,430,080 | ---- | C] () -- C:\Windows\SysWow64\UDLL.dll
[2013/10/30 08:11:21 | 000,000,172 | ---- | C] () -- C:\Windows\ODBC.INI
[2013/10/24 11:15:16 | 000,009,242 | ---- | C] () -- C:\Windows\cfgall.ini
[2013/10/24 10:45:07 | 000,006,710 | RHS- | C] () -- C:\Users\PRTH\ntuser.pol
[2013/10/10 13:35:10 | 000,009,584 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2013/08/27 14:00:08 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2013/05/23 09:09:44 | 000,598,384 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng700.bin
[2013/05/23 09:09:38 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2013/05/23 09:09:37 | 000,754,652 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng700.bin
[2013/05/23 08:57:10 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\instsrv.exe
[2013/05/23 08:57:10 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2013/03/08 08:37:36 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_zh-HK.dll
[2013/03/08 08:37:34 | 000,091,648 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_hr.dll
[2013/03/08 08:37:34 | 000,090,112 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_sl.dll
[2013/03/08 08:37:34 | 000,090,112 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_sk.dll
[2013/03/08 08:37:32 | 000,089,088 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_tr.dll
[2013/03/08 08:37:30 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_ro.dll
[2013/03/08 08:37:30 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_pt-BR.dll
[2013/03/08 08:37:30 | 000,092,672 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_hu.dll
[2013/03/08 08:37:28 | 000,090,112 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_fi.dll
[2013/03/08 08:37:28 | 000,084,992 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_he.dll
[2013/03/08 08:37:26 | 000,097,280 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_el.dll
[2013/03/08 08:37:26 | 000,091,136 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_cs.dll
[2013/03/08 08:37:26 | 000,087,040 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_ar.dll
[2013/03/08 08:37:24 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_zh-CHT.dll
[2013/03/08 08:37:24 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_zh-CHS.dll
[2013/03/08 08:37:22 | 000,091,648 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_sv.dll
[2013/03/08 08:37:22 | 000,091,648 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_ru.dll
[2013/03/08 08:37:20 | 000,094,720 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_pt.dll
[2013/03/08 08:37:20 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_pl.dll
[2013/03/08 08:37:20 | 000,090,112 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_no.dll
[2013/03/08 08:37:18 | 000,097,792 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_nl.dll
[2013/03/08 08:37:18 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_ko.dll
[2013/03/08 08:37:16 | 000,095,232 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_it.dll
[2013/03/08 08:37:16 | 000,095,232 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_fr.dll
[2013/03/08 08:37:16 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_ja.dll
[2013/03/08 08:37:14 | 000,094,720 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_es.dll
[2013/03/08 08:37:12 | 000,095,744 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_de.dll
[2013/03/08 08:37:12 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\Internationalization_da.dll
[2012/09/13 14:58:34 | 001,008,640 | ---- | C] () -- C:\Windows\SysWow64\DemoLicense.dll
[2012/08/28 08:58:31 | 001,152,034 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/28 07:47:18 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/08/28 07:21:03 | 000,029,649 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/08/27 15:48:36 | 000,755,188 | ---- | C] () -- C:\Windows\SysWow64\igkrng700.bin
[2012/08/27 15:48:35 | 000,561,508 | ---- | C] () -- C:\Windows\SysWow64\igfcg700m.bin
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 19:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 18:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/10/24 11:20:57 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Wave Systems Corp
[2014/04/15 10:18:13 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\AVG2014
[2014/04/11 08:39:20 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\Canon
[2014/04/07 18:39:08 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\NuGet
[2014/04/14 10:55:45 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\Oracle
[2014/04/14 13:32:08 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\SecureSearch
[2014/04/07 08:34:14 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\Softland
[2014/04/03 12:50:26 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\Subversion
[2014/04/18 07:27:35 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\TeamViewer
[2014/04/15 10:17:59 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\TuneUp Software
[2014/04/03 12:50:48 | 000,000,000 | ---D | M] -- C:\Users\PRTH\AppData\Roaming\Wave Systems Corp
[2013/05/23 11:19:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ImgBurn
[2012/08/28 07:43:22 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Softland
[2013/05/23 08:53:53 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Wave Systems Corp
========== Purity Check ==========
< End of report >