O1 HOSTS File: ([2012/07/26 00:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:
64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Archivos de programa\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2:
64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Archivos de programa\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
O2:
64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Archivos de programa\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [ETDCtrl] C:\Archivos de programa\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-2189366859-98369154-2125593965-1003..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2189366859-98369154-2125593965-1003..\Run: [uTorrent] C:\Users\jomaa_000\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2189366859-98369154-2125593965-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O9:
64bit: - Extra Button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:
64bit: - Extra 'Tools' menuitem : &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:
64bit: - Extra Button: Complemento Hacer clic para llamar de Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Archivos de programa\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:
64bit: - Extra 'Tools' menuitem : Complemento Hacer clic para llamar de Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Archivos de programa\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:
64bit: - Extra Button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:
64bit: - Extra 'Tools' menuitem : Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABB59B2D-1049-4A17-9565-08D0AA78429B}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\osf - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:
64bit: - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27:
64bit: - HKLM IFEO\excel.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\groove.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\hamachi-2-ui.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\infopath.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\lync.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\manager1.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\misc.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\msaccess.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\msoev.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\msotd.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\mspub.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\OcPubMgr.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\onenote.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\outlook.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\powerpnt.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\skype.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\smanager.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27:
64bit: - HKLM IFEO\Winword.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\excel.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\groove.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\hamachi-2-ui.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\infopath.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\lync.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\manager1.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\misc.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\msaccess.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\msoev.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\msotd.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\mspub.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\OcPubMgr.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\onenote.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\outlook.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\powerpnt.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\skype.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\smanager.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O27 - HKLM IFEO\Winword.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG)
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c7e6c6f0-77da-11e2-be6c-50b7c35fbc97}\Shell - "" = AutoRun
O33 - MountPoints2\{c7e6c6f0-77da-11e2-be6c-50b7c35fbc97}\Shell\AutoRun\command - "" = "E:\setup\rsrc\Autorun.exe"
O33 - MountPoints2\{c7e6c6f0-77da-11e2-be6c-50b7c35fbc97}\Shell\dinstall\command - "" = E:\Directx\dxsetup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/05/10 23:20:57 | 000,000,000 | ---D | C] -- C:\windows\ERUNT
[2013/05/10 23:20:15 | 000,000,000 | ---D | C] -- C:\JRT
[2013/05/10 22:26:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/05/10 22:13:49 | 000,000,000 | ---D | C] -- C:\FRST
[2013/05/10 19:37:11 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Local\WinZip
[2013/05/10 19:36:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2013/05/10 19:36:05 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Add-in Express
[2013/05/10 19:35:52 | 000,000,000 | ---D | C] -- C:\ProgramData\WinZip
[2013/05/10 19:35:51 | 000,000,000 | ---D | C] -- C:\Program Files\WinZip
[2013/05/10 17:27:38 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Local\Macromedia
[2013/05/10 17:13:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/05/10 17:12:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013/05/10 17:07:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/05/10 16:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013/05/10 16:51:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2013/05/10 16:25:12 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2013/05/10 16:06:38 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Desktop\RK_Quarantine
[2013/05/10 04:04:00 | 000,030,752 | ---- | C] (EldoS Corporation) -- C:\windows\SysNative\drivers\ElRawDsk.sys
[2013/05/10 04:03:46 | 000,000,000 | ---D | C] -- C:\ProgramData\iolo
[2013/05/09 17:55:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2013/05/06 12:47:16 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Activision
[2013/05/06 12:47:16 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\Activision
[2013/05/06 12:47:03 | 000,000,000 | -HSD | C] -- C:\windows\ftpcache
[2013/05/06 12:37:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2013/05/06 04:37:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
[2013/05/06 04:36:59 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\AIMP3
[2013/05/06 04:24:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AIMP3
[2013/05/06 04:22:20 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Local\DFX
[2013/05/06 04:19:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DFX Audio Enhancer
[2013/05/06 04:19:29 | 000,000,000 | ---D | C] -- C:\ProgramData\DFX
[2013/05/06 04:19:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DFX
[2013/05/06 04:19:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DFX
[2013/05/06 04:17:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp
[2013/05/05 18:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/05/05 15:22:47 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\eIntaller
[2013/05/02 20:34:04 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Plantillas personalizadas de Office
[2013/05/02 15:56:24 | 000,000,000 | --SD | C] -- C:\ProgramData\DSS
[2013/05/02 15:35:18 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2013/05/02 15:21:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games
[2013/05/02 06:04:17 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\Lionhead Studios
[2013/05/02 05:55:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2013/05/02 05:48:58 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Games for Windows - LIVE Demos
[2013/05/02 05:48:01 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\xlive
[2013/05/02 05:48:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
[2013/05/01 15:59:09 | 000,035,192 | ---- | C] (AVG) -- C:\windows\SysNative\TURegOpt.exe
[2013/05/01 15:59:08 | 000,026,488 | ---- | C] (AVG) -- C:\windows\SysNative\authuitu.dll
[2013/05/01 15:59:05 | 000,021,880 | ---- | C] (AVG) -- C:\windows\SysWow64\authuitu.dll
[2013/05/01 15:58:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp
[2013/05/01 15:57:52 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\AVG
[2013/05/01 15:57:05 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG
[2013/05/01 15:56:49 | 000,000,000 | --SD | C] -- C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
[2013/05/01 13:10:19 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Youcam
[2013/05/01 02:38:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CyberLink
[2013/04/30 18:04:01 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Libros y pdfs
[2013/04/30 17:56:17 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Notas
[2013/04/30 02:41:29 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Local\ElevatedDiagnostics
[2013/04/29 19:45:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013/04/29 19:45:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2013/04/29 02:56:36 | 000,683,664 | ---- | C] (Realtek ) -- C:\windows\SysNative\drivers\Rt630x64.sys
[2013/04/27 22:41:32 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Local\LogMeIn Hamachi
[2013/04/27 16:07:38 | 003,653,632 | ---- | C] (Qualcomm Atheros Communications, Inc.) -- C:\windows\SysNative\athw8x.sys
[2013/04/22 05:23:00 | 000,033,856 | -H-- | C] (LogMeIn, Inc.) -- C:\windows\SysNative\hamachi.sys
[2013/04/21 20:03:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\thechineseroom
[2013/04/21 19:58:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\thechineseroom
[2013/04/21 11:39:48 | 000,000,000 | ---D | C] -- C:\windows\Minidump
[2013/04/21 03:22:43 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\.minecraft
[2013/04/20 15:45:53 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\AVG2013
[2013/04/20 15:40:04 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\TuneUp Software
[2013/04/20 15:39:14 | 000,000,000 | -H-D | C] -- C:\$AVG
[2013/04/20 15:39:14 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013/04/20 15:38:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2013/04/20 15:30:27 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Local\MFAData
[2013/04/20 15:30:27 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2013/04/20 15:30:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Common Files
[2013/04/20 15:30:27 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Local\Avg2013
[2013/04/16 21:01:45 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\dvdcss
[2013/04/16 20:41:19 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\Documents\Avatar
[2013/04/16 19:55:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplay
[2013/04/16 19:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDisplay
[2013/04/14 19:11:12 | 000,000,000 | ---D | C] -- C:\Users\jomaa_000\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013/04/14 19:11:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Download Assistant
[2013/04/11 01:48:08 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2013/02/25 19:43:34 | 002,063,240 | ---- | C] (Samsung Electronics) -- C:\ProgramData\MakeMarkerFile.exe
========== Files - Modified Within 30 Days ==========
[2013/05/10 23:24:00 | 000,001,058 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/10 23:19:49 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/05/10 23:18:24 | 000,001,054 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/10 23:17:46 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013/05/10 23:10:22 | 000,074,703 | ---- | M] () -- C:\windows\SysWow64\mfc45.dat
[2013/05/10 22:22:00 | 000,000,954 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2189366859-98369154-2125593965-1002UA.job
[2013/05/10 22:22:00 | 000,000,932 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2189366859-98369154-2125593965-1002Core.job
[2013/05/10 22:01:36 | 001,798,556 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013/05/10 22:01:36 | 000,799,280 | ---- | M] () -- C:\windows\SysNative\perfh00A.dat
[2013/05/10 22:01:36 | 000,710,244 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013/05/10 22:01:36 | 000,163,056 | ---- | M] () -- C:\windows\SysNative\perfc00A.dat
[2013/05/10 22:01:36 | 000,132,614 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013/05/10 21:26:06 | 000,000,960 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2189366859-98369154-2125593965-1003UA.job
[2013/05/10 21:26:03 | 000,000,938 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2189366859-98369154-2125593965-1003Core.job
[2013/05/10 08:35:18 | 000,003,472 | ---- | M] () -- C:\bootsqm.dat
[2013/05/10 04:25:19 | 000,000,406 | ---- | M] () -- C:\windows\SysNative\ioloBootDefrag.cfg
[2013/05/10 03:36:11 | 000,000,154 | ---- | M] () -- C:\windows\Reimage.ini
[2013/05/09 20:41:32 | 000,476,127 | ---- | M] () -- C:\Users\jomaa_000\Desktop\Transmetropolitan_13_p16.jpg
[2013/05/09 20:29:35 | 000,473,721 | ---- | M] () -- C:\Users\jomaa_000\Desktop\Transmetropolitan_13_p09.jpg
[2013/05/08 08:56:22 | 000,628,743 | ---- | M] () -- C:\Users\jomaa_000\Desktop\AdwCleaner.exe
[2013/05/07 03:53:28 | 000,000,022 | ---- | M] () -- C:\windows\cmm.dat
[2013/05/06 14:45:58 | 000,011,264 | ---- | M] () -- C:\Users\jomaa_000\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/06 12:46:22 | 000,000,319 | ---- | M] () -- C:\windows\game.ini
[2013/05/01 19:16:25 | 000,007,618 | ---- | M] () -- C:\Users\jomaa_000\AppData\Local\Resmon.ResmonCfg
[2013/04/30 00:05:20 | 005,043,744 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2013/05/10 23:10:22 | 000,074,703 | ---- | C] () -- C:\windows\SysWow64\mfc45.dat
[2013/05/10 16:51:29 | 000,001,175 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/05/10 08:35:18 | 000,003,472 | ---- | C] () -- C:\bootsqm.dat
[2013/05/10 04:25:19 | 000,000,406 | ---- | C] () -- C:\windows\SysNative\ioloBootDefrag.cfg
[2013/05/10 03:34:05 | 000,000,154 | ---- | C] () -- C:\windows\Reimage.ini
[2013/05/09 20:41:32 | 000,476,127 | ---- | C] () -- C:\Users\jomaa_000\Desktop\Transmetropolitan_13_p16.jpg
[2013/05/09 20:29:35 | 000,473,721 | ---- | C] () -- C:\Users\jomaa_000\Desktop\Transmetropolitan_13_p09.jpg
[2013/05/08 08:56:17 | 000,628,743 | ---- | C] () -- C:\Users\jomaa_000\Desktop\AdwCleaner.exe
[2013/05/07 03:53:28 | 000,000,022 | ---- | C] () -- C:\windows\cmm.dat
[2013/05/06 12:46:22 | 000,000,319 | ---- | C] () -- C:\windows\game.ini
[2013/05/01 15:58:34 | 000,002,205 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp.lnk
[2013/04/30 00:04:59 | 005,043,744 | ---- | C] () -- C:\windows\SysNative\FNTCACHE.DAT
[2013/04/27 16:07:38 | 000,331,272 | ---- | C] () -- C:\windows\SysNative\athw8x.inf
[2013/04/27 16:07:38 | 000,080,062 | ---- | C] () -- C:\windows\SysNative\athw8x.cat
[2013/04/24 09:17:41 | 000,387,867 | ---- | C] () -- C:\windows\SysNative\ApnDatabase.xml
[2013/04/14 19:11:07 | 000,001,085 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk
[2013/04/09 14:33:17 | 000,011,264 | ---- | C] () -- C:\Users\jomaa_000\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/04/09 14:30:29 | 000,129,024 | ---- | C] () -- C:\windows\SysWow64\AVERM.dll
[2013/04/09 14:30:29 | 000,028,672 | ---- | C] () -- C:\windows\SysWow64\AVEQT.dll
[2013/04/08 06:26:59 | 000,007,618 | ---- | C] () -- C:\Users\jomaa_000\AppData\Local\Resmon.ResmonCfg
[2013/03/31 05:20:24 | 000,000,001 | -H-- | C] () -- C:\windows\mulch200.ini
[2013/03/03 04:06:58 | 000,000,153 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2013/02/25 19:43:34 | 000,003,004 | ---- | C] () -- C:\ProgramData\MakeMarkerFile.xml
[2013/02/15 20:53:21 | 000,083,968 | ---- | C] () -- C:\windows\SysWow64\OEMLicense.dll
[2013/02/12 19:26:34 | 000,042,880 | ---- | C] () -- C:\windows\SysWow64\xfcodec.dll
[2012/12/14 03:42:30 | 000,963,452 | ---- | C] () -- C:\windows\SysWow64\igcodeckrng600.bin
[2012/12/14 03:42:30 | 000,064,512 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2012/12/14 03:42:28 | 000,272,928 | ---- | C] () -- C:\windows\SysWow64\igvpkrng600.bin
[2012/12/14 03:42:24 | 000,754,652 | ---- | C] () -- C:\windows\SysWow64\igcodeckrng700.bin
[2012/12/14 03:42:24 | 000,598,384 | ---- | C] () -- C:\windows\SysWow64\igvpkrng700.bin
[2012/07/26 03:13:10 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat
[2012/07/26 03:13:09 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT
[2012/07/26 02:21:26 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2012/07/25 20:17:42 | 000,043,520 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2012/07/25 15:37:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2012/07/25 15:28:31 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2012/06/02 09:31:19 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\windows\SysWow64\xlive.dll.cat
========== ZeroAccess Check ==========
[2013/02/15 21:53:36 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/03/01 21:45:01 | 019,748,864 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/03/02 03:23:07 | 017,560,576 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/25 22:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/25 22:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/25 22:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/04/30 02:51:16 | 000,000,000 | ---D | M] -- C:\Users\Guido\AppData\Roaming\AVG2013
[2013/02/21 22:48:48 | 000,000,000 | ---D | M] -- C:\Users\Guido\AppData\Roaming\DAEMON Tools Pro
[2013/03/27 14:32:28 | 000,000,000 | ---D | M] -- C:\Users\Guido\AppData\Roaming\FreeArc
[2013/03/16 20:11:10 | 000,000,000 | ---D | M] -- C:\Users\Guido\AppData\Roaming\Iminent
[2013/02/26 21:10:51 | 000,000,000 | ---D | M] -- C:\Users\Guido\AppData\Roaming\LolClient
[2013/02/26 22:25:34 | 000,000,000 | ---D | M] -- C:\Users\Guido\AppData\Roaming\SPORE
[2013/04/28 00:11:36 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\.minecraft
[2013/05/06 12:47:16 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\Activision
[2013/05/10 21:19:00 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\AIMP3
[2013/03/31 05:20:36 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\AudioMulch
[2013/04/19 22:32:48 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\Autodesk
[2013/05/01 15:57:52 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\AVG
[2013/04/20 15:45:53 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\AVG2013
[2013/04/14 19:11:12 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013/04/29 19:24:51 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\DAEMON Tools Pro
[2013/05/05 15:22:47 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\eIntaller
[2013/02/17 14:59:32 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\ExpressFiles
[2013/04/30 00:22:59 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\FreeArc
[2013/05/02 06:04:17 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\Lionhead Studios
[2013/02/18 13:58:44 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\LolClient
[2013/04/30 00:22:59 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\MusicBee
[2013/02/21 02:48:09 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\SPORE
[2013/05/01 16:42:36 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\TuneUp Software
[2013/04/01 05:49:17 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\Ultra Fractal 5
[2013/02/15 23:15:14 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\Unity
[2013/05/10 05:11:21 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\uTorrent
[2013/02/15 21:19:33 | 000,000,000 | ---D | M] -- C:\Users\jomaa_000\AppData\Roaming\Vtools
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:A1EDB939
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp

1B5B4F1
< End of report >