Teochter
Topic Starter
Hi
I hope somone can help me with this, I've tried everything I know and not been able to remove this thing! I deleted any Bandoo stuff, via my add / remove programs panel, as I heard they were somehow connected. I also tried to remove it via the "Add Ons Management" route; however, the option to remove searchqu/406 appears as "grayed out" but not for anything else. Looks like this is a deliberate device to prevent it's removal. As per instructions, I'm pasting below both the Extras.txt and OTL files, hope you can help me get rid of this darned thing!
Best wishes
Ian
(END)
OTL Extras logfile created on: 02/12/2011 13:48:08 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.99 Gb Total Physical Memory | 2.07 Gb Available Physical Memory | 69.32% Memory free
3.57 Gb Paging File | 2.64 Gb Available in Paging File | 73.91% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.46 Gb Total Space | 214.44 Gb Free Space | 76.73% Space Free | Partition Type: NTFS
Drive E: | 465.65 Gb Total Space | 431.28 Gb Free Space | 92.62% Space Free | Partition Type: FAT32
Computer Name: USER-92C49880C3 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – (Microsoft Corporation)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\acs\AOLDial.exe" = C:\Program Files\Common Files\AOL\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialler – (America Online)
"C:\Program Files\Common Files\AOL\acs\AOLacsd.exe" = C:\Program Files\Common Files\AOL\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Services – (AOL LLC)
"C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.6\waol.exe" = C:\Program Files\AOL Desktop 9.6\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00107ED7-7DB8-47CD-A50F-E2422D13298F}" = Serif WebPlus Starter Edition 3.0
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{16DABD39-A174-4C6B-A2C4-A492E64933C8}" = AVG 2012
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{54B19DCE-232F-45A3-80D9-2141DEDF6D8F}" = Simple Adblock
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5F1ECD36-0DFA-4C58-830B-0F089083407F}" = AVG 2012
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78D62D17-D970-42DA-B8CF-5E5576293B33}" = Final Draft 7
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}" = System Requirements Lab for Intel
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AI RoboForm" = RoboForm 7-6-1 (All Users)
"AOL Broadband Toolbar" = AOL Broadband Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AVG" = AVG 2012
"Belarc Advisor" = Belarc Advisor 8.2
"CobBackup8" = Cobian Backup 8
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MouseSuite98" = Mouse Suite
"Mozilla Firefox 8.0.1 (x86 en-GB)" = Mozilla Firefox 8.0.1 (x86 en-GB)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SopCast" = SopCast 3.4.0
"Veetle TV" = Veetle TV
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.1.11
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 29/11/2011 05:47:44 | Computer Name = USER-92C49880C3 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240022, P2 processdownloadresults, P3
download, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials
(edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 02/12/2011 05:18:19 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 06:13:27 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7000
Description = The MBAMSwissArmy service failed to start due to the following error:
%%2
Error - 02/12/2011 08:34:54 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:34:54 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 08:34:57 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:34:57 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 08:35:04 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:35:04 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 08:40:04 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:40:05 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
< End of report >
OTL logfile created on: 02/12/2011 13:48:08 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.99 Gb Total Physical Memory | 2.07 Gb Available Physical Memory | 69.32% Memory free
3.57 Gb Paging File | 2.64 Gb Available in Paging File | 73.91% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.46 Gb Total Space | 214.44 Gb Free Space | 76.73% Space Free | Partition Type: NTFS
Drive E: | 465.65 Gb Total Space | 431.28 Gb Free Space | 92.62% Space Free | Partition Type: FAT32
Computer Name: USER-92C49880C3 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\user\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\acs\AOLacsd.exe (AOL LLC)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\ico.exe (Primax Electronics Ltd.)
PRC - C:\WINDOWS\system32\FSRremoS.EXE ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\{6c914a0b-b677-4a73-8a01-db8b914cc7bf}\components\RadioWMPCoreGecko8.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\WINDOWS\system32\Primomonnt.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\WINDOWS\system32\FSRremoS.EXE ()
========== Win32 Services (SafeList) ==========
SRV - (avgfws) – C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (MpKsl7aff1b0f) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A7A5C2B6-47A2-4F94-8272-CF7548D9C8A3}\MpKsl7aff1b0f.sys (Microsoft Corporation)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (CamDrL) Logitech QuickCam Pro 3000(CamDrl) – C:\WINDOWS\system32\drivers\Camdrl.sys (Logitech Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (pelusblf) – C:\WINDOWS\system32\drivers\pelusblf.sys (Primax Electronics Ltd.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (pelmouse) – C:\WINDOWS\system32\drivers\PELMOUSE.SYS (Primax Electronics Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {4a6e1b85-1193-4a2a-aab8-7417f275f18a} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E 06 EA CB EE B0 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {4a6e1b85-1193-4a2a-aab8-7417f275f18a} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "Softonic-EngUK_ Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3031756&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&appid;=102&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/11/22 09:21:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/10/25 15:47:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/27 10:05:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/12/02 09:17:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/12/02 09:18:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions
[2011/12/01 15:56:44 | 000,000,000 | —D | M] (Serif WebPlus Community Toolbar) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\{07364a98-eb02-4736-bc54-ebe437fccb87}
[2011/11/09 17:07:44 | 000,000,000 | —D | M] (Softonic-EngUK_ Community Toolbar) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\{6c914a0b-b677-4a73-8a01-db8b914cc7bf}
[2011/08/13 14:49:01 | 000,000,000 | —D | M] (Bandoo for Firefox) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\[removed]
[2011/12/01 15:56:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\trash
[2011/11/08 16:15:42 | 000,002,519 | —- | M] () – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\searchplugins\Search_Results.xml
[2011/12/02 09:17:45 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/20 10:32:06 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/10/20 10:18:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\{C2B1F3AE-5CD5-49B7-8A0C-2C3BCBBBB294}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
[2011/11/21 04:21:46 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/21 01:23:17 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/21 01:09:48 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/21 01:23:17 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/21 01:23:17 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/05 13:08:57 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
[2011/11/08 16:15:42 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/11/21 01:23:17 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_0\npSkypeChromePlugin.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1829_0\plugins/avgnpss.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: AVG Safe Search = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\
O1 HOSTS File: ([2004/08/04 10:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (AOL Broadband Toolbar Loader) - {776a9d06-e178-4aa0-aee4-b4de3a64ad28} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~2\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SimpleAdblock Class) - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Common Files\Simple Adblock\SimpleAdblock.dll (Simple Adblock)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~2\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (AOL Broadband Toolbar) - {e6ed7f95-e571-4f81-8757-5eb11252703d} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Broadband Toolbar) - {E6ED7F95-E571-4F81-8757-5EB11252703D} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.co.uk ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: aol.com ([mail] http in Trusted sites)
O15 - HKCU\..Trusted Domains: aol.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1302524918559 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s…el_4.4.24.0.cab (SysInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DE4DE603-F4F3-4AC7-922C-377CB5146A44}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - http://googleads.g.doubleclick.net/pagead/…AjIItI_WN72Tg5M
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/28 21:59:11 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{30ecadd0-d714-11e0-bcb0-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{30ecadd0-d714-11e0-bcb0-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{30ecadd0-d714-11e0-bcb0-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/02 13:38:08 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2011/12/02 12:32:33 | 000,000,000 | -HSD | C] – C:\Documents and Settings\user\Desktop\Temporary Internet Files
[2011/11/30 22:48:32 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\More Walmart martians!!
[2011/11/27 23:51:17 | 008,143,920 | —- | C] (AVG ) – C:\Documents and Settings\user\Desktop\avg_pct_stf_all_2012_26_c3.exe
[2011/11/26 10:13:44 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\BLEEPING COMPUTER STUFF
[2011/11/25 14:47:40 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Simple Adblock
[2011/11/25 14:47:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Simple Adblock
[2011/11/25 14:10:56 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\New Folder
[2011/11/25 14:09:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\New Folder (2)
[2011/11/25 10:33:48 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/11/24 17:32:29 | 001,247,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\LIVE WRITER-setup-web.exe
[2011/11/24 15:21:18 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\C - DRIVE - CLONE
[2011/11/24 14:07:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Cobian Backup 8
[2011/11/24 12:33:42 | 001,566,512 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\user\Desktop\TDSSKiller.exe
[2011/11/23 16:22:59 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\BACKUP CLONE OF C- DRIVE
[2011/11/23 16:22:50 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\AUTORUNS
[2011/11/23 15:59:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Runtime Software
[2011/11/23 15:58:50 | 000,000,000 | —D | C] – C:\Program Files\Runtime Software
[2011/11/23 14:17:35 | 000,000,000 | —D | C] – C:\Program Files\Cobian Backup 8
[2011/11/23 14:14:18 | 015,492,608 | —- | C] (Luis Cobian, CobianSoft) – C:\Documents and Settings\user\My Documents\Cobian Backup - cbSetup.exe
[2011/11/23 13:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Safe mirror
[2011/11/23 13:34:39 | 000,000,000 | —D | C] – C:\Program Files\Cobian Backup 10
[2011/11/23 12:55:15 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\ElevatedDiagnostics
[2011/11/21 15:44:03 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/11/21 15:41:13 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2011/11/21 15:41:13 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2011/11/21 15:40:03 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/11/21 12:22:09 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\ms-eissentialsl.exe
[2011/11/18 16:23:27 | 000,218,112 | —- | C] (Soeperman Enterprises Ltd.) – C:\Documents and Settings\user\Desktop\HijackThis.exe
[2011/11/18 10:27:09 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2011/11/17 10:06:43 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\tdsskiller
[2011/11/16 12:36:17 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\DESKTOP TEMP INTERNET FILES
[2011/11/13 16:29:10 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Final Draft
[2011/11/13 15:03:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\FINAL DRAFT STUFF
[2011/11/13 14:45:15 | 016,537,808 | —- | C] (Nullsoft, Inc.) – C:\Documents and Settings\user\My Documents\winamp5621_full_emusic-7plus_all.exe
[2011/11/13 13:34:22 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\McAfee
[2011/11/13 13:33:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2011/11/13 10:27:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/11/13 10:27:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2011/11/13 10:27:37 | 000,000,000 | —D | C] – C:\Program Files\McAfee Security Scan
[2011/11/12 12:35:22 | 026,864,760 | —- | C] (Nitro PDF Software) – C:\Documents and Settings\user\Desktop\nitro_pdf_reader.exe
[2011/11/12 12:32:30 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\PrimoPDF
[2011/11/12 09:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\duchod
[2011/11/12 09:25:46 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\Kecupy1
[2011/11/11 17:39:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PrimoPDF
[2011/11/11 17:39:34 | 000,000,000 | —D | C] – C:\Program Files\Nitro PDF
[2011/11/11 17:00:52 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\Ebook compiler
[2011/11/10 16:43:27 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Start Menu\Programs\Google Chrome
[2011/11/09 15:09:04 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2011/11/09 13:52:10 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11
[2011/11/08 15:50:37 | 000,000,000 | —D | C] – C:\Program Files\FoxTabFLVPlayer
[2011/11/07 23:03:36 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\image001111
[2011/11/07 09:51:18 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\RONALDO LEAVES UT'D-msg-31883-9
[2011/11/07 09:05:23 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\Probeerditeensa
[2011/11/05 14:14:04 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\Scott Blanchard Stuff
[2011/11/05 13:09:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\~0
[2011/11/03 17:49:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/03 17:49:15 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/03 08:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\image001
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/02 13:47:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003UA.job
[2011/12/02 13:38:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2011/12/02 12:34:30 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/02 12:34:28 | 000,000,616 | -H– | M] () – C:\WINDOWS\tasks\ConfigExec.job
[2011/12/02 12:34:27 | 000,000,386 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On user Logon.job
[2011/12/02 12:24:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\tasks\DataUpload.job
[2011/12/02 12:03:53 | 111,238,080 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/02 10:04:53 | 000,002,198 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/12/02 10:01:43 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\user\Desktop\TDSSKiller.exe
[2011/12/02 09:16:43 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/02 09:11:36 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/01 17:59:57 | 000,008,704 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/01 16:47:21 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003Core.job
[2011/12/01 12:03:06 | 000,139,870 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/12/01 09:01:02 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Scan and Repair.job
[2011/11/30 22:48:32 | 001,551,028 | —- | M] () – C:\Documents and Settings\user\My Documents\More Walmart martians!!.zip
[2011/11/30 22:47:11 | 000,106,556 | —- | M] () – C:\Documents and Settings\user\My Documents\Selling my Stuff!.jpg
[2011/11/30 20:03:10 | 000,619,190 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/11/29 19:30:06 | 000,000,555 | —- | M] () – C:\Documents and Settings\user\Desktop\SopCast.lnk
[2011/11/29 16:28:22 | 000,000,513 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to MDHC Brief! 001.lnk
[2011/11/28 23:57:13 | 000,021,779 | —- | M] () – C:\Documents and Settings\user\Desktop\KINDLEFIRE COMPARISONS..odt
[2011/11/27 23:51:44 | 008,143,920 | —- | M] (AVG ) – C:\Documents and Settings\user\Desktop\avg_pct_stf_all_2012_26_c3.exe
[2011/11/27 15:32:34 | 005,944,736 | —- | M] () – C:\Documents and Settings\user\Desktop\Setup-SopCast-3.4.0-2011-6-9.exe
[2011/11/27 13:03:54 | 000,010,090 | —- | M] () – C:\Documents and Settings\user\Desktop\PDF_writer.asp.htm
[2011/11/27 13:03:33 | 000,007,430 | —- | M] () – C:\Documents and Settings\user\Desktop\PDF-reader.asp.htm
[2011/11/27 10:05:20 | 000,000,742 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/27 10:05:20 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/11/26 17:41:06 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/25 15:01:06 | 000,000,000 | —- | M] () – C:\Documents and Settings\user\defogger_reenable
[2011/11/25 14:46:18 | 001,266,688 | —- | M] () – C:\Documents and Settings\user\My Documents\simpleadblock1.1.0.msi
[2011/11/25 14:21:47 | 001,593,184 | —- | M] () – C:\Documents and Settings\user\My Documents\AutoRuns SCAN RESULT..arn
[2011/11/25 13:49:04 | 000,000,803 | —- | M] () – C:\Documents and Settings\user\Desktop\Internet Explorer.lnk
[2011/11/25 10:48:09 | 000,000,815 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/11/24 17:32:34 | 001,247,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\LIVE WRITER-setup-web.exe
[2011/11/24 15:20:10 | 632,644,498 | —- | M] () – C:\Documents and Settings\user\My Documents\Drive_C.dat
[2011/11/24 15:20:10 | 000,315,311 | —- | M] () – C:\Documents and Settings\user\My Documents\Drive_C.xml
[2011/11/24 11:10:23 | 000,067,188 | —- | M] () – C:\Documents and Settings\user\My Documents\priloha.jpg
[2011/11/23 23:18:12 | 000,000,580 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to Paul clifford Stuff.lnk
[2011/11/23 15:59:43 | 000,000,790 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\DriveImage XML.lnk
[2011/11/23 15:59:43 | 000,000,772 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DriveImage XML.lnk
[2011/11/23 15:06:00 | 000,000,932 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to RootRepeal (3).lnk
[2011/11/23 13:31:16 | 000,000,720 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2011/11/23 12:46:50 | 015,492,608 | —- | M] (Luis Cobian, CobianSoft) – C:\Documents and Settings\user\My Documents\Cobian Backup - cbSetup.exe
[2011/11/23 09:20:09 | 001,547,478 | —- | M] () – C:\Documents and Settings\user\Desktop\tdsskiller.zip
[2011/11/22 13:31:01 | 009,024,987 | —- | M] () – C:\Documents and Settings\user\My Documents\=iso-8859-2Qstript=FDz1.wmv=
[2011/11/22 13:29:14 | 000,806,299 | —- | M] () – C:\Documents and Settings\user\My Documents\DSC00576.jpg
[2011/11/22 09:21:46 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/11/22 09:18:26 | 001,690,626 | —- | M] () – C:\Documents and Settings\user\My Documents\MaliarHitler.pps
[2011/11/22 09:17:33 | 001,539,584 | —- | M] () – C:\Documents and Settings\user\My Documents\=iso-8859-2QPap=EDr=5Fa=5FIndi=E1ni.pps=
[2011/11/21 12:22:12 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\ms-eissentialsl.exe
[2011/11/21 11:48:03 | 000,002,277 | —- | M] () – C:\Documents and Settings\user\Desktop\Google Chrome.lnk
[2011/11/21 11:48:03 | 000,002,255 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/19 10:14:26 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/18 16:16:04 | 000,000,494 | —- | M] () – C:\Documents and Settings\user\My Documents\Shortcut to HijackThis.lnk
[2011/11/18 10:26:40 | 000,018,356 | —- | M] () – C:\Documents and Settings\user\Desktop\wplockup(2).zip
[2011/11/18 10:11:05 | 000,413,522 | —- | M] () – C:\Documents and Settings\user\Desktop\SEOReport.zip
[2011/11/17 23:52:07 | 002,913,158 | —- | M] () – C:\Documents and Settings\user\Desktop\Link Juice download.php
[2011/11/17 23:51:15 | 002,913,156 | —- | M] () – C:\Documents and Settings\user\Desktop\LinkJuiceForce_4ec549d066db8.pdf
[2011/11/17 17:57:03 | 000,000,934 | —- | M] () – C:\Documents and Settings\user\Desktop\PDF Reader - Writer.htm
[2011/11/16 09:48:41 | 001,634,707 | —- | M] () – C:\Documents and Settings\user\My Documents\Irish Bungee Jumping..wmv
[2011/11/15 16:07:54 | 000,024,580 | —- | M] () – C:\Documents and Settings\user\Desktop\DS File Steve Miranda.DS_Store
[2011/11/15 14:11:59 | 005,610,886 | —- | M] () – C:\Documents and Settings\user\My Documents\MissUSA.wmv
[2011/11/15 09:14:01 | 000,036,190 | —- | M] () – C:\Documents and Settings\user\My Documents\kdesanachadzaSR.jpg
[2011/11/15 09:13:18 | 000,101,193 | —- | M] () – C:\Documents and Settings\user\My Documents\Taktobude!(AL).jpg
[2011/11/14 21:19:24 | 000,036,213 | —- | M] () – C:\Documents and Settings\user\My Documents\Q F P Synopsis.odt
[2011/11/14 16:56:29 | 000,000,026 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2011/11/14 10:28:54 | 000,581,298 | —- | M] () – C:\Documents and Settings\user\My Documents\Bread pics..odt
[2011/11/13 15:09:30 | 000,000,376 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to FINAL DRAFT STUFF 2.lnk
[2011/11/13 13:33:53 | 000,001,619 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2011/11/13 13:33:53 | 000,001,611 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/11/12 13:03:44 | 000,735,550 | —- | M] () – C:\Documents and Settings\user\Desktop\NoBSBacklinksWSO.zip
[2011/11/12 12:35:35 | 026,864,760 | —- | M] (Nitro PDF Software) – C:\Documents and Settings\user\Desktop\nitro_pdf_reader.exe
[2011/11/12 12:31:09 | 000,000,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2011/11/12 12:30:58 | 000,000,314 | —- | M] () – C:\WINDOWS\primopdf.ini
[2011/11/12 09:33:24 | 000,338,724 | —- | M] () – C:\Documents and Settings\user\My Documents\duchod.zip
[2011/11/12 09:31:55 | 003,700,736 | —- | M] () – C:\Documents and Settings\user\My Documents\Specsavers_Sauna_-_YouTube.mpg
[2011/11/12 09:31:09 | 000,055,847 | —- | M] () – C:\Documents and Settings\user\My Documents\stres.jpg
[2011/11/12 09:27:44 | 003,816,151 | —- | M] () – C:\Documents and Settings\user\My Documents\PowerfulPeeingBoy.wmv
[2011/11/12 09:25:46 | 000,705,802 | —- | M] () – C:\Documents and Settings\user\My Documents\Kecupy1.zip
[2011/11/12 09:24:37 | 006,488,576 | —- | M] () – C:\Documents and Settings\user\My Documents\Vsechnovbile.pps
[2011/11/11 17:38:49 | 007,549,704 | —- | M] () – C:\Documents and Settings\user\Desktop\InternationalPrimoPDF.exe
[2011/11/11 16:59:26 | 002,980,585 | —- | M] () – C:\Documents and Settings\user\My Documents\Ebook compiler.zip
[2011/11/10 17:00:31 | 000,146,180 | —- | M] () – C:\Documents and Settings\user\Desktop\What shows when you click on the Word admin in Blog Recent Comments.JPG
[2011/11/10 11:25:49 | 000,011,873 | —- | M] () – C:\Documents and Settings\user\My Documents\Letter to Adam, re Paul Richardson..odt
[2011/11/09 14:53:48 | 000,001,191 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to Image4.lnk
[2011/11/09 14:53:29 | 000,001,298 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to RGSRMasterPlan-December2010.lnk
[2011/11/09 14:53:09 | 000,001,423 | —- | M] () – C:\Documents and Settings\user\My Documents\Shortcut to CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.lnk
[2011/11/09 13:52:10 | 006,520,754 | —- | M] () – C:\Documents and Settings\user\My Documents\CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.zip
[2011/11/08 16:20:33 | 000,008,752 | —- | M] () – C:\Documents and Settings\user\My Documents\Final Draft Courier example..odt
[2011/11/08 15:08:49 | 000,001,224 | —- | M] () – C:\Documents and Settings\user\My Documents\untitled-[2]
[2011/11/08 09:53:10 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/07 23:03:36 | 000,422,019 | —- | M] () – C:\Documents and Settings\user\My Documents\image001111.zip
[2011/11/07 22:55:08 | 005,356,032 | —- | M] () – C:\Documents and Settings\user\My Documents\snow.pps
[2011/11/07 09:51:17 | 003,812,177 | —- | M] () – C:\Documents and Settings\user\My Documents\RONALDO LEAVES UT'D-msg-31883-9.zip
[2011/11/07 09:05:23 | 005,086,387 | —- | M] () – C:\Documents and Settings\user\My Documents\Probeerditeensa.zip
[2011/11/04 08:57:48 | 000,143,603 | —- | M] () – C:\Documents and Settings\user\My Documents\IKEAverkauftAutos.pdf
[2011/11/04 08:56:19 | 001,435,756 | —- | M] () – C:\Documents and Settings\user\My Documents\KarateBloopers.mpe
[2011/11/04 08:54:51 | 002,166,784 | —- | M] () – C:\Documents and Settings\user\My Documents\Cedulebezkomentaoe.pps
[2011/11/03 22:46:28 | 000,218,220 | —- | M] () – C:\Documents and Settings\user\Desktop\MalwareBytes Scan result!.JPG
[2011/11/03 17:49:22 | 000,001,023 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 13:37:36 | 000,181,672 | —- | M] () – C:\Documents and Settings\user\Desktop\Hostgator Support history..JPG
[2011/11/03 08:31:49 | 001,182,208 | —- | M] () – C:\Documents and Settings\user\My Documents\Pro_sikovne_ruce.pps
[2011/11/03 08:30:41 | 001,800,458 | —- | M] () – C:\Documents and Settings\user\My Documents\image001.zip
[2011/11/03 08:28:45 | 000,093,264 | —- | M] () – C:\Documents and Settings\user\My Documents\image001.bmp
[2011/11/02 23:25:45 | 001,748,286 | —- | M] () – C:\Documents and Settings\user\Desktop\AutoRuns result.arn
[2011/11/02 18:06:02 | 001,748,286 | —- | M] () – C:\Documents and Settings\user\Desktop\New Autorun for AVG..arn
[2011/11/02 17:05:08 | 000,204,589 | —- | M] () – C:\Documents and Settings\user\Desktop\AVG Screenshot..JPG
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/30 22:48:20 | 001,551,028 | —- | C] () – C:\Documents and Settings\user\My Documents\More Walmart martians!!.zip
[2011/11/30 22:47:10 | 000,106,556 | —- | C] () – C:\Documents and Settings\user\My Documents\Selling my Stuff!.jpg
[2011/11/29 16:28:22 | 000,000,513 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to MDHC Brief! 001.lnk
[2011/11/28 23:40:26 | 000,021,779 | —- | C] () – C:\Documents and Settings\user\Desktop\KINDLEFIRE COMPARISONS..odt
[2011/11/27 15:33:01 | 005,944,736 | —- | C] () – C:\Documents and Settings\user\Desktop\Setup-SopCast-3.4.0-2011-6-9.exe
[2011/11/27 13:03:53 | 000,010,090 | —- | C] () – C:\Documents and Settings\user\Desktop\PDF_writer.asp.htm
[2011/11/27 13:03:31 | 000,007,430 | —- | C] () – C:\Documents and Settings\user\Desktop\PDF-reader.asp.htm
[2011/11/27 10:05:20 | 000,000,742 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/27 10:05:20 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/11/27 10:05:19 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/25 15:01:06 | 000,000,000 | —- | C] () – C:\Documents and Settings\user\defogger_reenable
[2011/11/25 14:51:29 | 001,593,184 | —- | C] () – C:\Documents and Settings\user\My Documents\AutoRuns SCAN RESULT..arn
[2011/11/25 14:50:51 | 001,266,688 | —- | C] () – C:\Documents and Settings\user\My Documents\simpleadblock1.1.0.msi
[2011/11/25 13:49:04 | 000,000,803 | —- | C] () – C:\Documents and Settings\user\Desktop\Internet Explorer.lnk
[2011/11/25 10:48:09 | 000,000,803 | —- | C] () – C:\Documents and Settings\user\Start Menu\Programs\Internet Explorer.lnk
[2011/11/24 15:18:02 | 632,644,498 | —- | C] () – C:\Documents and Settings\user\My Documents\Drive_C.dat
[2011/11/24 15:18:02 | 000,315,311 | —- | C] () – C:\Documents and Settings\user\My Documents\Drive_C.xml
[2011/11/23 23:18:12 | 000,000,580 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to Paul clifford Stuff.lnk
[2011/11/23 15:59:43 | 000,000,790 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\DriveImage XML.lnk
[2011/11/23 15:59:43 | 000,000,772 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DriveImage XML.lnk
[2011/11/23 15:06:00 | 000,000,932 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to RootRepeal (3).lnk
[2011/11/23 13:31:16 | 000,000,720 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2011/11/22 13:29:55 | 009,024,987 | —- | C] () – C:\Documents and Settings\user\My Documents\=iso-8859-2Qstript=FDz1.wmv=
[2011/11/22 13:29:08 | 000,806,299 | —- | C] () – C:\Documents and Settings\user\My Documents\DSC00576.jpg
[2011/11/22 09:18:14 | 001,690,626 | —- | C] () – C:\Documents and Settings\user\My Documents\MaliarHitler.pps
[2011/11/22 09:17:22 | 001,539,584 | —- | C] () – C:\Documents and Settings\user\My Documents\=iso-8859-2QPap=EDr=5Fa=5FIndi=E1ni.pps=
[2011/11/21 15:46:11 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/21 15:40:54 | 000,002,198 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/11/21 15:40:21 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/18 10:26:40 | 000,018,356 | —- | C] () – C:\Documents and Settings\user\Desktop\wplockup(2).zip
[2011/11/18 10:11:03 | 000,413,522 | —- | C] () – C:\Documents and Settings\user\Desktop\SEOReport.zip
[2011/11/17 23:51:55 | 002,913,158 | —- | C] () – C:\Documents and Settings\user\Desktop\Link Juice download.php
[2011/11/17 23:51:12 | 002,913,156 | —- | C] () – C:\Documents and Settings\user\Desktop\LinkJuiceForce_4ec549d066db8.pdf
[2011/11/17 17:56:17 | 000,000,934 | —- | C] () – C:\Documents and Settings\user\Desktop\PDF Reader - Writer.htm
[2011/11/17 10:05:40 | 001,547,478 | —- | C] () – C:\Documents and Settings\user\Desktop\tdsskiller.zip
[2011/11/16 09:48:30 | 001,634,707 | —- | C] () – C:\Documents and Settings\user\My Documents\Irish Bungee Jumping..wmv
[2011/11/15 16:07:54 | 000,024,580 | —- | C] () – C:\Documents and Settings\user\Desktop\DS File Steve Miranda.DS_Store
[2011/11/15 14:11:21 | 005,610,886 | —- | C] () – C:\Documents and Settings\user\My Documents\MissUSA.wmv
[2011/11/15 09:14:01 | 000,036,190 | —- | C] () – C:\Documents and Settings\user\My Documents\kdesanachadzaSR.jpg
[2011/11/15 09:13:16 | 000,101,193 | —- | C] () – C:\Documents and Settings\user\My Documents\Taktobude!(AL).jpg
[2011/11/14 21:19:23 | 000,036,213 | —- | C] () – C:\Documents and Settings\user\My Documents\Q F P Synopsis.odt
[2011/11/14 16:56:13 | 000,000,026 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2011/11/14 10:28:53 | 000,581,298 | —- | C] () – C:\Documents and Settings\user\My Documents\Bread pics..odt
[2011/11/13 15:09:30 | 000,000,376 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to FINAL DRAFT STUFF 2.lnk
[2011/11/13 10:27:38 | 000,001,619 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2011/11/13 10:27:38 | 000,001,611 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/11/12 13:32:08 | 002,980,585 | —- | C] () – C:\Documents and Settings\user\My Documents\Ebook compiler.zip
[2011/11/12 13:30:22 | 000,001,423 | —- | C] () – C:\Documents and Settings\user\My Documents\Shortcut to CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.lnk
[2011/11/12 13:04:20 | 000,735,550 | —- | C] () – C:\Documents and Settings\user\Desktop\NoBSBacklinksWSO.zip
[2011/11/12 09:33:21 | 000,338,724 | —- | C] () – C:\Documents and Settings\user\My Documents\duchod.zip
[2011/11/12 09:31:31 | 003,700,736 | —- | C] () – C:\Documents and Settings\user\My Documents\Specsavers_Sauna_-_YouTube.mpg
[2011/11/12 09:31:08 | 000,055,847 | —- | C] () – C:\Documents and Settings\user\My Documents\stres.jpg
[2011/11/12 09:27:19 | 003,816,151 | —- | C] () – C:\Documents and Settings\user\My Documents\PowerfulPeeingBoy.wmv
[2011/11/12 09:25:41 | 000,705,802 | —- | C] () – C:\Documents and Settings\user\My Documents\Kecupy1.zip
[2011/11/12 09:23:55 | 006,488,576 | —- | C] () – C:\Documents and Settings\user\My Documents\Vsechnovbile.pps
[2011/11/11 17:39:46 | 000,000,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2011/11/11 17:39:38 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2011/11/11 17:38:39 | 007,549,704 | —- | C] () – C:\Documents and Settings\user\Desktop\InternationalPrimoPDF.exe
[2011/11/10 17:00:31 | 000,146,180 | —- | C] () – C:\Documents and Settings\user\Desktop\What shows when you click on the Word admin in Blog Recent Comments.JPG
[2011/11/10 16:43:31 | 000,002,277 | —- | C] () – C:\Documents and Settings\user\Desktop\Google Chrome.lnk
[2011/11/10 16:43:31 | 000,002,255 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/10 16:42:45 | 000,000,974 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003UA.job
[2011/11/10 16:42:45 | 000,000,922 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003Core.job
[2011/11/10 11:25:49 | 000,011,873 | —- | C] () – C:\Documents and Settings\user\My Documents\Letter to Adam, re Paul Richardson..odt
[2011/11/09 15:10:13 | 000,155,962 | —- | C] () – C:\Documents and Settings\user\My Documents\WW2 SPAM on my Blog site.JPG
[2011/11/09 14:53:48 | 000,001,191 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to Image4.lnk
[2011/11/09 14:53:29 | 000,001,298 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to RGSRMasterPlan-December2010.lnk
[2011/11/09 13:51:27 | 006,520,754 | —- | C] () – C:\Documents and Settings\user\My Documents\CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.zip
[2011/11/08 16:20:32 | 000,008,752 | —- | C] () – C:\Documents and Settings\user\My Documents\Final Draft Courier example..odt
[2011/11/08 15:08:49 | 000,001,224 | —- | C] () – C:\Documents and Settings\user\My Documents\untitled-[2]
[2011/11/07 23:03:32 | 000,422,019 | —- | C] () – C:\Documents and Settings\user\My Documents\image001111.zip
[2011/11/07 22:54:29 | 005,356,032 | —- | C] () – C:\Documents and Settings\user\My Documents\snow.pps
[2011/11/07 09:50:51 | 003,812,177 | —- | C] () – C:\Documents and Settings\user\My Documents\RONALDO LEAVES UT'D-msg-31883-9.zip
[2011/11/07 09:04:47 | 005,086,387 | —- | C] () – C:\Documents and Settings\user\My Documents\Probeerditeensa.zip
[2011/11/04 08:57:45 | 000,143,603 | —- | C] () – C:\Documents and Settings\user\My Documents\IKEAverkauftAutos.pdf
[2011/11/04 08:56:10 | 001,435,756 | —- | C] () – C:\Documents and Settings\user\My Documents\KarateBloopers.mpe
[2011/11/04 08:54:36 | 002,166,784 | —- | C] () – C:\Documents and Settings\user\My Documents\Cedulebezkomentaoe.pps
[2011/11/03 22:46:28 | 000,218,220 | —- | C] () – C:\Documents and Settings\user\Desktop\MalwareBytes Scan result!.JPG
[2011/11/03 17:49:22 | 000,001,023 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 13:37:36 | 000,181,672 | —- | C] () – C:\Documents and Settings\user\Desktop\Hostgator Support history..JPG
[2011/11/03 08:31:41 | 001,182,208 | —- | C] () – C:\Documents and Settings\user\My Documents\Pro_sikovne_ruce.pps
[2011/11/03 08:30:30 | 001,800,458 | —- | C] () – C:\Documents and Settings\user\My Documents\image001.zip
[2011/11/03 08:28:44 | 000,093,264 | —- | C] () – C:\Documents and Settings\user\My Documents\image001.bmp
[2011/11/02 23:25:44 | 001,748,286 | —- | C] () – C:\Documents and Settings\user\Desktop\AutoRuns result.arn
[2011/11/02 18:06:00 | 001,748,286 | —- | C] () – C:\Documents and Settings\user\Desktop\New Autorun for AVG..arn
[2011/11/02 17:05:08 | 000,204,589 | —- | C] () – C:\Documents and Settings\user\Desktop\AVG Screenshot..JPG
[2011/09/17 23:08:26 | 000,000,021 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
[2011/09/07 11:47:03 | 000,008,704 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/31 11:23:26 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/21 13:53:22 | 000,110,413 | —- | C] () – C:\WINDOWS\hpoins11.dat
[2011/07/21 13:53:10 | 000,006,947 | —- | C] () – C:\WINDOWS\hpomdl11.dat
[2011/07/17 17:58:18 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2011/02/10 04:03:48 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2009/10/25 21:51:13 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\FSRremoC.DLL
[2009/10/25 21:51:13 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\FSRremoS.EXE
[2008/11/28 22:01:58 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/11/28 21:55:59 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/11/28 13:32:04 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/11/28 13:30:59 | 000,129,296 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/02/03 07:59:04 | 000,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/03/21 23:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 23:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 10:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 10:00:00 | 000,502,682 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 10:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 10:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 10:00:00 | 000,086,766 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 10:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 10:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 10:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 10:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 10:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/10/17 22:11:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/11/19 09:01:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/20 08:19:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/11/13 16:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Final Draft
[2011/12/02 12:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/10/25 15:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/12/02 13:53:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/31 11:37:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/10/18 15:13:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/02 09:15:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2011/11/24 16:08:19 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AVG
[2011/10/17 21:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AVG2012
[2011/08/13 14:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Bandoo
[2011/11/23 12:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ElevatedDiagnostics
[2011/11/13 16:29:10 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Final Draft
[2011/08/01 17:04:38 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\OpenCandy
[2011/07/16 17:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\OpenOffice.org
[2011/11/12 12:32:30 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\PrimoPDF
[2011/10/25 15:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\RoboForm
[2011/08/27 16:54:25 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\searchquband
[2011/09/23 15:40:11 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Serif
[2011/12/02 10:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Simple Adblock
[2009/02/26 00:29:47 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Windows Desktop Search
[2011/07/17 14:56:48 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Windows Search
[2011/12/01 09:01:02 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Scan and Repair.job
[2011/12/02 12:34:27 | 000,000,386 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Start On user Logon.job
[2011/12/02 12:34:28 | 000,000,616 | -H– | M] () – C:\WINDOWS\Tasks\ConfigExec.job
[2011/12/02 12:24:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\Tasks\DataUpload.job
[2011/12/02 09:16:43 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/11/28 21:59:11 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/22 12:47:14 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/11/28 21:59:11 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 07:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 07:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2011/07/31 11:37:16 | 000,031,131 | —- | M] () – C:\install.log
[2007/11/07 07:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/11/28 21:59:11 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/11/28 21:59:11 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/02/25 21:44:57 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/02 09:11:33 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2011/11/12 13:27:57 | 000,099,574 | —- | M] () – C:\TDSSKiller.2.6.18.0_12.11.2011_13.25.50_log.txt
[2011/11/13 10:30:51 | 000,096,562 | —- | M] () – C:\TDSSKiller.2.6.18.0_13.11.2011_10.29.56_log.txt
[2011/11/17 10:05:17 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.18.0_17.11.2011_10.05.11_log.txt
[2011/11/17 10:07:42 | 000,049,100 | —- | M] () – C:\TDSSKiller.2.6.19.0_17.11.2011_10.07.18_log.txt
[2011/11/23 09:18:46 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.19.0_23.11.2011_09.17.55_log.txt
[2011/11/23 09:19:30 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.19.0_23.11.2011_09.19.23_log.txt
[2011/11/23 09:47:44 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.19.0_23.11.2011_09.47.39_log.txt
[2011/12/02 10:00:27 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.20.0_02.12.2011_10.00.21_log.txt
[2011/11/29 09:50:05 | 000,099,444 | —- | M] () – C:\TDSSKiller.2.6.20.0_29.11.2011_09.48.21_log.txt
[2011/12/02 10:04:19 | 000,099,946 | —- | M] () – C:\TDSSKiller.2.6.21.0_02.12.2011_10.02.49_log.txt
[2007/11/07 07:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/11/28 21:58:36 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 13:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/11/28 13:30:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/11/28 13:30:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/11/28 13:30:08 | 000,897,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/02/25 21:50:27 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/25 22:49:31 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/11/28 22:05:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/11/27 23:51:44 | 008,143,920 | —- | M] (AVG ) – C:\Documents and Settings\user\Desktop\avg_pct_stf_all_2012_26_c3.exe
[2005/02/16 11:06:00 | 000,218,112 | —- | M] (Soeperman Enterprises Ltd.) – C:\Documents and Settings\user\Desktop\HijackThis.exe
[2011/11/11 17:38:49 | 007,549,704 | —- | M] () – C:\Documents and Settings\user\Desktop\InternationalPrimoPDF.exe
[2011/11/24 17:32:34 | 001,247,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\LIVE WRITER-setup-web.exe
[2011/11/21 12:22:12 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\ms-eissentialsl.exe
[2011/11/12 12:35:35 | 026,864,760 | —- | M] (Nitro PDF Software) – C:\Documents and Settings\user\Desktop\nitro_pdf_reader.exe
[2011/12/02 13:38:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2011/11/27 15:32:34 | 005,944,736 | —- | M] () – C:\Documents and Settings\user\Desktop\Setup-SopCast-3.4.0-2011-6-9.exe
[2011/12/02 10:01:43 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\user\Desktop\TDSSKiller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2011/10/07 19:29:50 | 000,000,698 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb
[2011/06/13 21:13:08 | 000,000,786 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-26 17:41:48
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
I hope somone can help me with this, I've tried everything I know and not been able to remove this thing! I deleted any Bandoo stuff, via my add / remove programs panel, as I heard they were somehow connected. I also tried to remove it via the "Add Ons Management" route; however, the option to remove searchqu/406 appears as "grayed out" but not for anything else. Looks like this is a deliberate device to prevent it's removal. As per instructions, I'm pasting below both the Extras.txt and OTL files, hope you can help me get rid of this darned thing!
Best wishes
Ian
(END)
OTL Extras logfile created on: 02/12/2011 13:48:08 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.99 Gb Total Physical Memory | 2.07 Gb Available Physical Memory | 69.32% Memory free
3.57 Gb Paging File | 2.64 Gb Available in Paging File | 73.91% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.46 Gb Total Space | 214.44 Gb Free Space | 76.73% Space Free | Partition Type: NTFS
Drive E: | 465.65 Gb Total Space | 431.28 Gb Free Space | 92.62% Space Free | Partition Type: FAT32
Computer Name: USER-92C49880C3 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – (Microsoft Corporation)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\acs\AOLDial.exe" = C:\Program Files\Common Files\AOL\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialler – (America Online)
"C:\Program Files\Common Files\AOL\acs\AOLacsd.exe" = C:\Program Files\Common Files\AOL\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Services – (AOL LLC)
"C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.6\waol.exe" = C:\Program Files\AOL Desktop 9.6\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Veetle\Player\VeetleNet.exe" = C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet – ()
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00107ED7-7DB8-47CD-A50F-E2422D13298F}" = Serif WebPlus Starter Edition 3.0
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{16DABD39-A174-4C6B-A2C4-A492E64933C8}" = AVG 2012
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{54B19DCE-232F-45A3-80D9-2141DEDF6D8F}" = Simple Adblock
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5F1ECD36-0DFA-4C58-830B-0F089083407F}" = AVG 2012
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78D62D17-D970-42DA-B8CF-5E5576293B33}" = Final Draft 7
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}" = System Requirements Lab for Intel
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AI RoboForm" = RoboForm 7-6-1 (All Users)
"AOL Broadband Toolbar" = AOL Broadband Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AVG" = AVG 2012
"Belarc Advisor" = Belarc Advisor 8.2
"CobBackup8" = Cobian Backup 8
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MouseSuite98" = Mouse Suite
"Mozilla Firefox 8.0.1 (x86 en-GB)" = Mozilla Firefox 8.0.1 (x86 en-GB)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SopCast" = SopCast 3.4.0
"Veetle TV" = Veetle TV
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.1.11
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 29/11/2011 05:47:44 | Computer Name = USER-92C49880C3 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240022, P2 processdownloadresults, P3
download, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials
(edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 02/12/2011 05:18:19 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 06:13:27 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7000
Description = The MBAMSwissArmy service failed to start due to the following error:
%%2
Error - 02/12/2011 08:34:54 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:34:54 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 08:34:57 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:34:57 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 08:35:04 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:35:04 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
Error - 02/12/2011 08:40:04 | Computer Name = USER-92C49880C3 | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 02/12/2011 08:40:05 | Computer Name = USER-92C49880C3 | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%1058
< End of report >
OTL logfile created on: 02/12/2011 13:48:08 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.99 Gb Total Physical Memory | 2.07 Gb Available Physical Memory | 69.32% Memory free
3.57 Gb Paging File | 2.64 Gb Available in Paging File | 73.91% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 279.46 Gb Total Space | 214.44 Gb Free Space | 76.73% Space Free | Partition Type: NTFS
Drive E: | 465.65 Gb Total Space | 431.28 Gb Free Space | 92.62% Space Free | Partition Type: FAT32
Computer Name: USER-92C49880C3 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\user\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\acs\AOLacsd.exe (AOL LLC)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\ico.exe (Primax Electronics Ltd.)
PRC - C:\WINDOWS\system32\FSRremoS.EXE ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\{6c914a0b-b677-4a73-8a01-db8b914cc7bf}\components\RadioWMPCoreGecko8.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\WINDOWS\system32\Primomonnt.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\WINDOWS\system32\FSRremoS.EXE ()
========== Win32 Services (SafeList) ==========
SRV - (avgfws) – C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (MpKsl7aff1b0f) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A7A5C2B6-47A2-4F94-8272-CF7548D9C8A3}\MpKsl7aff1b0f.sys (Microsoft Corporation)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (CamDrL) Logitech QuickCam Pro 3000(CamDrl) – C:\WINDOWS\system32\drivers\Camdrl.sys (Logitech Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (pelusblf) – C:\WINDOWS\system32\drivers\pelusblf.sys (Primax Electronics Ltd.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (pelmouse) – C:\WINDOWS\system32\drivers\PELMOUSE.SYS (Primax Electronics Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {4a6e1b85-1193-4a2a-aab8-7417f275f18a} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E 06 EA CB EE B0 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {4a6e1b85-1193-4a2a-aab8-7417f275f18a} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "Softonic-EngUK_ Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3031756&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&appid;=102&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/11/22 09:21:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/10/25 15:47:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/27 10:05:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/12/02 09:17:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/12/02 09:18:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions
[2011/12/01 15:56:44 | 000,000,000 | —D | M] (Serif WebPlus Community Toolbar) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\{07364a98-eb02-4736-bc54-ebe437fccb87}
[2011/11/09 17:07:44 | 000,000,000 | —D | M] (Softonic-EngUK_ Community Toolbar) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\{6c914a0b-b677-4a73-8a01-db8b914cc7bf}
[2011/08/13 14:49:01 | 000,000,000 | —D | M] (Bandoo for Firefox) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\[removed]
[2011/12/01 15:56:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\extensions\trash
[2011/11/08 16:15:42 | 000,002,519 | —- | M] () – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\z3nmo6x1.default\searchplugins\Search_Results.xml
[2011/12/02 09:17:45 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/20 10:32:06 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/10/20 10:18:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\{C2B1F3AE-5CD5-49B7-8A0C-2C3BCBBBB294}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Z3NMO6X1.DEFAULT\EXTENSIONS\[removed]
[2011/11/21 04:21:46 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/21 01:23:17 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/21 01:09:48 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/21 01:23:17 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/21 01:23:17 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/05 13:08:57 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
[2011/11/08 16:15:42 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/11/21 01:23:17 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_0\npSkypeChromePlugin.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1829_0\plugins/avgnpss.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: AVG Safe Search = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\
O1 HOSTS File: ([2004/08/04 10:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (AOL Broadband Toolbar Loader) - {776a9d06-e178-4aa0-aee4-b4de3a64ad28} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~2\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SimpleAdblock Class) - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Common Files\Simple Adblock\SimpleAdblock.dll (Simple Adblock)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~2\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (AOL Broadband Toolbar) - {e6ed7f95-e571-4f81-8757-5eb11252703d} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Broadband Toolbar) - {E6ED7F95-E571-4F81-8757-5EB11252703D} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll (AOL)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1312112157\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.co.uk ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: aol.com ([mail] http in Trusted sites)
O15 - HKCU\..Trusted Domains: aol.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1302524918559 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s…el_4.4.24.0.cab (SysInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DE4DE603-F4F3-4AC7-922C-377CB5146A44}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - http://googleads.g.doubleclick.net/pagead/…AjIItI_WN72Tg5M
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/28 21:59:11 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{30ecadd0-d714-11e0-bcb0-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{30ecadd0-d714-11e0-bcb0-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{30ecadd0-d714-11e0-bcb0-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/02 13:38:08 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2011/12/02 12:32:33 | 000,000,000 | -HSD | C] – C:\Documents and Settings\user\Desktop\Temporary Internet Files
[2011/11/30 22:48:32 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\More Walmart martians!!
[2011/11/27 23:51:17 | 008,143,920 | —- | C] (AVG ) – C:\Documents and Settings\user\Desktop\avg_pct_stf_all_2012_26_c3.exe
[2011/11/26 10:13:44 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\BLEEPING COMPUTER STUFF
[2011/11/25 14:47:40 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Simple Adblock
[2011/11/25 14:47:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Simple Adblock
[2011/11/25 14:10:56 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\New Folder
[2011/11/25 14:09:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\New Folder (2)
[2011/11/25 10:33:48 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/11/24 17:32:29 | 001,247,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\LIVE WRITER-setup-web.exe
[2011/11/24 15:21:18 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\C - DRIVE - CLONE
[2011/11/24 14:07:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Cobian Backup 8
[2011/11/24 12:33:42 | 001,566,512 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\user\Desktop\TDSSKiller.exe
[2011/11/23 16:22:59 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\BACKUP CLONE OF C- DRIVE
[2011/11/23 16:22:50 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\AUTORUNS
[2011/11/23 15:59:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Runtime Software
[2011/11/23 15:58:50 | 000,000,000 | —D | C] – C:\Program Files\Runtime Software
[2011/11/23 14:17:35 | 000,000,000 | —D | C] – C:\Program Files\Cobian Backup 8
[2011/11/23 14:14:18 | 015,492,608 | —- | C] (Luis Cobian, CobianSoft) – C:\Documents and Settings\user\My Documents\Cobian Backup - cbSetup.exe
[2011/11/23 13:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Safe mirror
[2011/11/23 13:34:39 | 000,000,000 | —D | C] – C:\Program Files\Cobian Backup 10
[2011/11/23 12:55:15 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\ElevatedDiagnostics
[2011/11/21 15:44:03 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/11/21 15:41:13 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2011/11/21 15:41:13 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2011/11/21 15:40:03 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/11/21 12:22:09 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\ms-eissentialsl.exe
[2011/11/18 16:23:27 | 000,218,112 | —- | C] (Soeperman Enterprises Ltd.) – C:\Documents and Settings\user\Desktop\HijackThis.exe
[2011/11/18 10:27:09 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2011/11/17 10:06:43 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\tdsskiller
[2011/11/16 12:36:17 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\DESKTOP TEMP INTERNET FILES
[2011/11/13 16:29:10 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Final Draft
[2011/11/13 15:03:26 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\FINAL DRAFT STUFF
[2011/11/13 14:45:15 | 016,537,808 | —- | C] (Nullsoft, Inc.) – C:\Documents and Settings\user\My Documents\winamp5621_full_emusic-7plus_all.exe
[2011/11/13 13:34:22 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\McAfee
[2011/11/13 13:33:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2011/11/13 10:27:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/11/13 10:27:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2011/11/13 10:27:37 | 000,000,000 | —D | C] – C:\Program Files\McAfee Security Scan
[2011/11/12 12:35:22 | 026,864,760 | —- | C] (Nitro PDF Software) – C:\Documents and Settings\user\Desktop\nitro_pdf_reader.exe
[2011/11/12 12:32:30 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\PrimoPDF
[2011/11/12 09:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\duchod
[2011/11/12 09:25:46 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\Kecupy1
[2011/11/11 17:39:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PrimoPDF
[2011/11/11 17:39:34 | 000,000,000 | —D | C] – C:\Program Files\Nitro PDF
[2011/11/11 17:00:52 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\Ebook compiler
[2011/11/10 16:43:27 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Start Menu\Programs\Google Chrome
[2011/11/09 15:09:04 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2011/11/09 13:52:10 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11
[2011/11/08 15:50:37 | 000,000,000 | —D | C] – C:\Program Files\FoxTabFLVPlayer
[2011/11/07 23:03:36 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\image001111
[2011/11/07 09:51:18 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\RONALDO LEAVES UT'D-msg-31883-9
[2011/11/07 09:05:23 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\Probeerditeensa
[2011/11/05 14:14:04 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\Scott Blanchard Stuff
[2011/11/05 13:09:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\~0
[2011/11/03 17:49:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/03 17:49:15 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/03 08:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\image001
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/02 13:47:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003UA.job
[2011/12/02 13:38:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2011/12/02 12:34:30 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/02 12:34:28 | 000,000,616 | -H– | M] () – C:\WINDOWS\tasks\ConfigExec.job
[2011/12/02 12:34:27 | 000,000,386 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On user Logon.job
[2011/12/02 12:24:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\tasks\DataUpload.job
[2011/12/02 12:03:53 | 111,238,080 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/02 10:04:53 | 000,002,198 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/12/02 10:01:43 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\user\Desktop\TDSSKiller.exe
[2011/12/02 09:16:43 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/02 09:11:36 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/01 17:59:57 | 000,008,704 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/01 16:47:21 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003Core.job
[2011/12/01 12:03:06 | 000,139,870 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/12/01 09:01:02 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Scan and Repair.job
[2011/11/30 22:48:32 | 001,551,028 | —- | M] () – C:\Documents and Settings\user\My Documents\More Walmart martians!!.zip
[2011/11/30 22:47:11 | 000,106,556 | —- | M] () – C:\Documents and Settings\user\My Documents\Selling my Stuff!.jpg
[2011/11/30 20:03:10 | 000,619,190 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/11/29 19:30:06 | 000,000,555 | —- | M] () – C:\Documents and Settings\user\Desktop\SopCast.lnk
[2011/11/29 16:28:22 | 000,000,513 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to MDHC Brief! 001.lnk
[2011/11/28 23:57:13 | 000,021,779 | —- | M] () – C:\Documents and Settings\user\Desktop\KINDLEFIRE COMPARISONS..odt
[2011/11/27 23:51:44 | 008,143,920 | —- | M] (AVG ) – C:\Documents and Settings\user\Desktop\avg_pct_stf_all_2012_26_c3.exe
[2011/11/27 15:32:34 | 005,944,736 | —- | M] () – C:\Documents and Settings\user\Desktop\Setup-SopCast-3.4.0-2011-6-9.exe
[2011/11/27 13:03:54 | 000,010,090 | —- | M] () – C:\Documents and Settings\user\Desktop\PDF_writer.asp.htm
[2011/11/27 13:03:33 | 000,007,430 | —- | M] () – C:\Documents and Settings\user\Desktop\PDF-reader.asp.htm
[2011/11/27 10:05:20 | 000,000,742 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/27 10:05:20 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/11/26 17:41:06 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/25 15:01:06 | 000,000,000 | —- | M] () – C:\Documents and Settings\user\defogger_reenable
[2011/11/25 14:46:18 | 001,266,688 | —- | M] () – C:\Documents and Settings\user\My Documents\simpleadblock1.1.0.msi
[2011/11/25 14:21:47 | 001,593,184 | —- | M] () – C:\Documents and Settings\user\My Documents\AutoRuns SCAN RESULT..arn
[2011/11/25 13:49:04 | 000,000,803 | —- | M] () – C:\Documents and Settings\user\Desktop\Internet Explorer.lnk
[2011/11/25 10:48:09 | 000,000,815 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/11/24 17:32:34 | 001,247,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\LIVE WRITER-setup-web.exe
[2011/11/24 15:20:10 | 632,644,498 | —- | M] () – C:\Documents and Settings\user\My Documents\Drive_C.dat
[2011/11/24 15:20:10 | 000,315,311 | —- | M] () – C:\Documents and Settings\user\My Documents\Drive_C.xml
[2011/11/24 11:10:23 | 000,067,188 | —- | M] () – C:\Documents and Settings\user\My Documents\priloha.jpg
[2011/11/23 23:18:12 | 000,000,580 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to Paul clifford Stuff.lnk
[2011/11/23 15:59:43 | 000,000,790 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\DriveImage XML.lnk
[2011/11/23 15:59:43 | 000,000,772 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DriveImage XML.lnk
[2011/11/23 15:06:00 | 000,000,932 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to RootRepeal (3).lnk
[2011/11/23 13:31:16 | 000,000,720 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2011/11/23 12:46:50 | 015,492,608 | —- | M] (Luis Cobian, CobianSoft) – C:\Documents and Settings\user\My Documents\Cobian Backup - cbSetup.exe
[2011/11/23 09:20:09 | 001,547,478 | —- | M] () – C:\Documents and Settings\user\Desktop\tdsskiller.zip
[2011/11/22 13:31:01 | 009,024,987 | —- | M] () – C:\Documents and Settings\user\My Documents\=iso-8859-2Qstript=FDz1.wmv=
[2011/11/22 13:29:14 | 000,806,299 | —- | M] () – C:\Documents and Settings\user\My Documents\DSC00576.jpg
[2011/11/22 09:21:46 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/11/22 09:18:26 | 001,690,626 | —- | M] () – C:\Documents and Settings\user\My Documents\MaliarHitler.pps
[2011/11/22 09:17:33 | 001,539,584 | —- | M] () – C:\Documents and Settings\user\My Documents\=iso-8859-2QPap=EDr=5Fa=5FIndi=E1ni.pps=
[2011/11/21 12:22:12 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\ms-eissentialsl.exe
[2011/11/21 11:48:03 | 000,002,277 | —- | M] () – C:\Documents and Settings\user\Desktop\Google Chrome.lnk
[2011/11/21 11:48:03 | 000,002,255 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/19 10:14:26 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/18 16:16:04 | 000,000,494 | —- | M] () – C:\Documents and Settings\user\My Documents\Shortcut to HijackThis.lnk
[2011/11/18 10:26:40 | 000,018,356 | —- | M] () – C:\Documents and Settings\user\Desktop\wplockup(2).zip
[2011/11/18 10:11:05 | 000,413,522 | —- | M] () – C:\Documents and Settings\user\Desktop\SEOReport.zip
[2011/11/17 23:52:07 | 002,913,158 | —- | M] () – C:\Documents and Settings\user\Desktop\Link Juice download.php
[2011/11/17 23:51:15 | 002,913,156 | —- | M] () – C:\Documents and Settings\user\Desktop\LinkJuiceForce_4ec549d066db8.pdf
[2011/11/17 17:57:03 | 000,000,934 | —- | M] () – C:\Documents and Settings\user\Desktop\PDF Reader - Writer.htm
[2011/11/16 09:48:41 | 001,634,707 | —- | M] () – C:\Documents and Settings\user\My Documents\Irish Bungee Jumping..wmv
[2011/11/15 16:07:54 | 000,024,580 | —- | M] () – C:\Documents and Settings\user\Desktop\DS File Steve Miranda.DS_Store
[2011/11/15 14:11:59 | 005,610,886 | —- | M] () – C:\Documents and Settings\user\My Documents\MissUSA.wmv
[2011/11/15 09:14:01 | 000,036,190 | —- | M] () – C:\Documents and Settings\user\My Documents\kdesanachadzaSR.jpg
[2011/11/15 09:13:18 | 000,101,193 | —- | M] () – C:\Documents and Settings\user\My Documents\Taktobude!(AL).jpg
[2011/11/14 21:19:24 | 000,036,213 | —- | M] () – C:\Documents and Settings\user\My Documents\Q F P Synopsis.odt
[2011/11/14 16:56:29 | 000,000,026 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2011/11/14 10:28:54 | 000,581,298 | —- | M] () – C:\Documents and Settings\user\My Documents\Bread pics..odt
[2011/11/13 15:09:30 | 000,000,376 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to FINAL DRAFT STUFF 2.lnk
[2011/11/13 13:33:53 | 000,001,619 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2011/11/13 13:33:53 | 000,001,611 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/11/12 13:03:44 | 000,735,550 | —- | M] () – C:\Documents and Settings\user\Desktop\NoBSBacklinksWSO.zip
[2011/11/12 12:35:35 | 026,864,760 | —- | M] (Nitro PDF Software) – C:\Documents and Settings\user\Desktop\nitro_pdf_reader.exe
[2011/11/12 12:31:09 | 000,000,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2011/11/12 12:30:58 | 000,000,314 | —- | M] () – C:\WINDOWS\primopdf.ini
[2011/11/12 09:33:24 | 000,338,724 | —- | M] () – C:\Documents and Settings\user\My Documents\duchod.zip
[2011/11/12 09:31:55 | 003,700,736 | —- | M] () – C:\Documents and Settings\user\My Documents\Specsavers_Sauna_-_YouTube.mpg
[2011/11/12 09:31:09 | 000,055,847 | —- | M] () – C:\Documents and Settings\user\My Documents\stres.jpg
[2011/11/12 09:27:44 | 003,816,151 | —- | M] () – C:\Documents and Settings\user\My Documents\PowerfulPeeingBoy.wmv
[2011/11/12 09:25:46 | 000,705,802 | —- | M] () – C:\Documents and Settings\user\My Documents\Kecupy1.zip
[2011/11/12 09:24:37 | 006,488,576 | —- | M] () – C:\Documents and Settings\user\My Documents\Vsechnovbile.pps
[2011/11/11 17:38:49 | 007,549,704 | —- | M] () – C:\Documents and Settings\user\Desktop\InternationalPrimoPDF.exe
[2011/11/11 16:59:26 | 002,980,585 | —- | M] () – C:\Documents and Settings\user\My Documents\Ebook compiler.zip
[2011/11/10 17:00:31 | 000,146,180 | —- | M] () – C:\Documents and Settings\user\Desktop\What shows when you click on the Word admin in Blog Recent Comments.JPG
[2011/11/10 11:25:49 | 000,011,873 | —- | M] () – C:\Documents and Settings\user\My Documents\Letter to Adam, re Paul Richardson..odt
[2011/11/09 14:53:48 | 000,001,191 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to Image4.lnk
[2011/11/09 14:53:29 | 000,001,298 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to RGSRMasterPlan-December2010.lnk
[2011/11/09 14:53:09 | 000,001,423 | —- | M] () – C:\Documents and Settings\user\My Documents\Shortcut to CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.lnk
[2011/11/09 13:52:10 | 006,520,754 | —- | M] () – C:\Documents and Settings\user\My Documents\CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.zip
[2011/11/08 16:20:33 | 000,008,752 | —- | M] () – C:\Documents and Settings\user\My Documents\Final Draft Courier example..odt
[2011/11/08 15:08:49 | 000,001,224 | —- | M] () – C:\Documents and Settings\user\My Documents\untitled-[2]
[2011/11/08 09:53:10 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/07 23:03:36 | 000,422,019 | —- | M] () – C:\Documents and Settings\user\My Documents\image001111.zip
[2011/11/07 22:55:08 | 005,356,032 | —- | M] () – C:\Documents and Settings\user\My Documents\snow.pps
[2011/11/07 09:51:17 | 003,812,177 | —- | M] () – C:\Documents and Settings\user\My Documents\RONALDO LEAVES UT'D-msg-31883-9.zip
[2011/11/07 09:05:23 | 005,086,387 | —- | M] () – C:\Documents and Settings\user\My Documents\Probeerditeensa.zip
[2011/11/04 08:57:48 | 000,143,603 | —- | M] () – C:\Documents and Settings\user\My Documents\IKEAverkauftAutos.pdf
[2011/11/04 08:56:19 | 001,435,756 | —- | M] () – C:\Documents and Settings\user\My Documents\KarateBloopers.mpe
[2011/11/04 08:54:51 | 002,166,784 | —- | M] () – C:\Documents and Settings\user\My Documents\Cedulebezkomentaoe.pps
[2011/11/03 22:46:28 | 000,218,220 | —- | M] () – C:\Documents and Settings\user\Desktop\MalwareBytes Scan result!.JPG
[2011/11/03 17:49:22 | 000,001,023 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 13:37:36 | 000,181,672 | —- | M] () – C:\Documents and Settings\user\Desktop\Hostgator Support history..JPG
[2011/11/03 08:31:49 | 001,182,208 | —- | M] () – C:\Documents and Settings\user\My Documents\Pro_sikovne_ruce.pps
[2011/11/03 08:30:41 | 001,800,458 | —- | M] () – C:\Documents and Settings\user\My Documents\image001.zip
[2011/11/03 08:28:45 | 000,093,264 | —- | M] () – C:\Documents and Settings\user\My Documents\image001.bmp
[2011/11/02 23:25:45 | 001,748,286 | —- | M] () – C:\Documents and Settings\user\Desktop\AutoRuns result.arn
[2011/11/02 18:06:02 | 001,748,286 | —- | M] () – C:\Documents and Settings\user\Desktop\New Autorun for AVG..arn
[2011/11/02 17:05:08 | 000,204,589 | —- | M] () – C:\Documents and Settings\user\Desktop\AVG Screenshot..JPG
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/30 22:48:20 | 001,551,028 | —- | C] () – C:\Documents and Settings\user\My Documents\More Walmart martians!!.zip
[2011/11/30 22:47:10 | 000,106,556 | —- | C] () – C:\Documents and Settings\user\My Documents\Selling my Stuff!.jpg
[2011/11/29 16:28:22 | 000,000,513 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to MDHC Brief! 001.lnk
[2011/11/28 23:40:26 | 000,021,779 | —- | C] () – C:\Documents and Settings\user\Desktop\KINDLEFIRE COMPARISONS..odt
[2011/11/27 15:33:01 | 005,944,736 | —- | C] () – C:\Documents and Settings\user\Desktop\Setup-SopCast-3.4.0-2011-6-9.exe
[2011/11/27 13:03:53 | 000,010,090 | —- | C] () – C:\Documents and Settings\user\Desktop\PDF_writer.asp.htm
[2011/11/27 13:03:31 | 000,007,430 | —- | C] () – C:\Documents and Settings\user\Desktop\PDF-reader.asp.htm
[2011/11/27 10:05:20 | 000,000,742 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/27 10:05:20 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/11/27 10:05:19 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/25 15:01:06 | 000,000,000 | —- | C] () – C:\Documents and Settings\user\defogger_reenable
[2011/11/25 14:51:29 | 001,593,184 | —- | C] () – C:\Documents and Settings\user\My Documents\AutoRuns SCAN RESULT..arn
[2011/11/25 14:50:51 | 001,266,688 | —- | C] () – C:\Documents and Settings\user\My Documents\simpleadblock1.1.0.msi
[2011/11/25 13:49:04 | 000,000,803 | —- | C] () – C:\Documents and Settings\user\Desktop\Internet Explorer.lnk
[2011/11/25 10:48:09 | 000,000,803 | —- | C] () – C:\Documents and Settings\user\Start Menu\Programs\Internet Explorer.lnk
[2011/11/24 15:18:02 | 632,644,498 | —- | C] () – C:\Documents and Settings\user\My Documents\Drive_C.dat
[2011/11/24 15:18:02 | 000,315,311 | —- | C] () – C:\Documents and Settings\user\My Documents\Drive_C.xml
[2011/11/23 23:18:12 | 000,000,580 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to Paul clifford Stuff.lnk
[2011/11/23 15:59:43 | 000,000,790 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\DriveImage XML.lnk
[2011/11/23 15:59:43 | 000,000,772 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DriveImage XML.lnk
[2011/11/23 15:06:00 | 000,000,932 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to RootRepeal (3).lnk
[2011/11/23 13:31:16 | 000,000,720 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2011/11/22 13:29:55 | 009,024,987 | —- | C] () – C:\Documents and Settings\user\My Documents\=iso-8859-2Qstript=FDz1.wmv=
[2011/11/22 13:29:08 | 000,806,299 | —- | C] () – C:\Documents and Settings\user\My Documents\DSC00576.jpg
[2011/11/22 09:18:14 | 001,690,626 | —- | C] () – C:\Documents and Settings\user\My Documents\MaliarHitler.pps
[2011/11/22 09:17:22 | 001,539,584 | —- | C] () – C:\Documents and Settings\user\My Documents\=iso-8859-2QPap=EDr=5Fa=5FIndi=E1ni.pps=
[2011/11/21 15:46:11 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/21 15:40:54 | 000,002,198 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/11/21 15:40:21 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/18 10:26:40 | 000,018,356 | —- | C] () – C:\Documents and Settings\user\Desktop\wplockup(2).zip
[2011/11/18 10:11:03 | 000,413,522 | —- | C] () – C:\Documents and Settings\user\Desktop\SEOReport.zip
[2011/11/17 23:51:55 | 002,913,158 | —- | C] () – C:\Documents and Settings\user\Desktop\Link Juice download.php
[2011/11/17 23:51:12 | 002,913,156 | —- | C] () – C:\Documents and Settings\user\Desktop\LinkJuiceForce_4ec549d066db8.pdf
[2011/11/17 17:56:17 | 000,000,934 | —- | C] () – C:\Documents and Settings\user\Desktop\PDF Reader - Writer.htm
[2011/11/17 10:05:40 | 001,547,478 | —- | C] () – C:\Documents and Settings\user\Desktop\tdsskiller.zip
[2011/11/16 09:48:30 | 001,634,707 | —- | C] () – C:\Documents and Settings\user\My Documents\Irish Bungee Jumping..wmv
[2011/11/15 16:07:54 | 000,024,580 | —- | C] () – C:\Documents and Settings\user\Desktop\DS File Steve Miranda.DS_Store
[2011/11/15 14:11:21 | 005,610,886 | —- | C] () – C:\Documents and Settings\user\My Documents\MissUSA.wmv
[2011/11/15 09:14:01 | 000,036,190 | —- | C] () – C:\Documents and Settings\user\My Documents\kdesanachadzaSR.jpg
[2011/11/15 09:13:16 | 000,101,193 | —- | C] () – C:\Documents and Settings\user\My Documents\Taktobude!(AL).jpg
[2011/11/14 21:19:23 | 000,036,213 | —- | C] () – C:\Documents and Settings\user\My Documents\Q F P Synopsis.odt
[2011/11/14 16:56:13 | 000,000,026 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2011/11/14 10:28:53 | 000,581,298 | —- | C] () – C:\Documents and Settings\user\My Documents\Bread pics..odt
[2011/11/13 15:09:30 | 000,000,376 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to FINAL DRAFT STUFF 2.lnk
[2011/11/13 10:27:38 | 000,001,619 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2011/11/13 10:27:38 | 000,001,611 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/11/12 13:32:08 | 002,980,585 | —- | C] () – C:\Documents and Settings\user\My Documents\Ebook compiler.zip
[2011/11/12 13:30:22 | 000,001,423 | —- | C] () – C:\Documents and Settings\user\My Documents\Shortcut to CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.lnk
[2011/11/12 13:04:20 | 000,735,550 | —- | C] () – C:\Documents and Settings\user\Desktop\NoBSBacklinksWSO.zip
[2011/11/12 09:33:21 | 000,338,724 | —- | C] () – C:\Documents and Settings\user\My Documents\duchod.zip
[2011/11/12 09:31:31 | 003,700,736 | —- | C] () – C:\Documents and Settings\user\My Documents\Specsavers_Sauna_-_YouTube.mpg
[2011/11/12 09:31:08 | 000,055,847 | —- | C] () – C:\Documents and Settings\user\My Documents\stres.jpg
[2011/11/12 09:27:19 | 003,816,151 | —- | C] () – C:\Documents and Settings\user\My Documents\PowerfulPeeingBoy.wmv
[2011/11/12 09:25:41 | 000,705,802 | —- | C] () – C:\Documents and Settings\user\My Documents\Kecupy1.zip
[2011/11/12 09:23:55 | 006,488,576 | —- | C] () – C:\Documents and Settings\user\My Documents\Vsechnovbile.pps
[2011/11/11 17:39:46 | 000,000,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2011/11/11 17:39:38 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2011/11/11 17:38:39 | 007,549,704 | —- | C] () – C:\Documents and Settings\user\Desktop\InternationalPrimoPDF.exe
[2011/11/10 17:00:31 | 000,146,180 | —- | C] () – C:\Documents and Settings\user\Desktop\What shows when you click on the Word admin in Blog Recent Comments.JPG
[2011/11/10 16:43:31 | 000,002,277 | —- | C] () – C:\Documents and Settings\user\Desktop\Google Chrome.lnk
[2011/11/10 16:43:31 | 000,002,255 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/10 16:42:45 | 000,000,974 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003UA.job
[2011/11/10 16:42:45 | 000,000,922 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-682003330-788750540-1003Core.job
[2011/11/10 11:25:49 | 000,011,873 | —- | C] () – C:\Documents and Settings\user\My Documents\Letter to Adam, re Paul Richardson..odt
[2011/11/09 15:10:13 | 000,155,962 | —- | C] () – C:\Documents and Settings\user\My Documents\WW2 SPAM on my Blog site.JPG
[2011/11/09 14:53:48 | 000,001,191 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to Image4.lnk
[2011/11/09 14:53:29 | 000,001,298 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to RGSRMasterPlan-December2010.lnk
[2011/11/09 13:51:27 | 006,520,754 | —- | C] () – C:\Documents and Settings\user\My Documents\CopyofCopyofREV4PMc-RGSRGolfCashFlowForecast-13OCT11.zip
[2011/11/08 16:20:32 | 000,008,752 | —- | C] () – C:\Documents and Settings\user\My Documents\Final Draft Courier example..odt
[2011/11/08 15:08:49 | 000,001,224 | —- | C] () – C:\Documents and Settings\user\My Documents\untitled-[2]
[2011/11/07 23:03:32 | 000,422,019 | —- | C] () – C:\Documents and Settings\user\My Documents\image001111.zip
[2011/11/07 22:54:29 | 005,356,032 | —- | C] () – C:\Documents and Settings\user\My Documents\snow.pps
[2011/11/07 09:50:51 | 003,812,177 | —- | C] () – C:\Documents and Settings\user\My Documents\RONALDO LEAVES UT'D-msg-31883-9.zip
[2011/11/07 09:04:47 | 005,086,387 | —- | C] () – C:\Documents and Settings\user\My Documents\Probeerditeensa.zip
[2011/11/04 08:57:45 | 000,143,603 | —- | C] () – C:\Documents and Settings\user\My Documents\IKEAverkauftAutos.pdf
[2011/11/04 08:56:10 | 001,435,756 | —- | C] () – C:\Documents and Settings\user\My Documents\KarateBloopers.mpe
[2011/11/04 08:54:36 | 002,166,784 | —- | C] () – C:\Documents and Settings\user\My Documents\Cedulebezkomentaoe.pps
[2011/11/03 22:46:28 | 000,218,220 | —- | C] () – C:\Documents and Settings\user\Desktop\MalwareBytes Scan result!.JPG
[2011/11/03 17:49:22 | 000,001,023 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 13:37:36 | 000,181,672 | —- | C] () – C:\Documents and Settings\user\Desktop\Hostgator Support history..JPG
[2011/11/03 08:31:41 | 001,182,208 | —- | C] () – C:\Documents and Settings\user\My Documents\Pro_sikovne_ruce.pps
[2011/11/03 08:30:30 | 001,800,458 | —- | C] () – C:\Documents and Settings\user\My Documents\image001.zip
[2011/11/03 08:28:44 | 000,093,264 | —- | C] () – C:\Documents and Settings\user\My Documents\image001.bmp
[2011/11/02 23:25:44 | 001,748,286 | —- | C] () – C:\Documents and Settings\user\Desktop\AutoRuns result.arn
[2011/11/02 18:06:00 | 001,748,286 | —- | C] () – C:\Documents and Settings\user\Desktop\New Autorun for AVG..arn
[2011/11/02 17:05:08 | 000,204,589 | —- | C] () – C:\Documents and Settings\user\Desktop\AVG Screenshot..JPG
[2011/09/17 23:08:26 | 000,000,021 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
[2011/09/07 11:47:03 | 000,008,704 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/31 11:23:26 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/21 13:53:22 | 000,110,413 | —- | C] () – C:\WINDOWS\hpoins11.dat
[2011/07/21 13:53:10 | 000,006,947 | —- | C] () – C:\WINDOWS\hpomdl11.dat
[2011/07/17 17:58:18 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2011/02/10 04:03:48 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2009/10/25 21:51:13 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\FSRremoC.DLL
[2009/10/25 21:51:13 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\FSRremoS.EXE
[2008/11/28 22:01:58 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/11/28 21:55:59 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/11/28 13:32:04 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/11/28 13:30:59 | 000,129,296 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/02/03 07:59:04 | 000,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/03/21 23:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 23:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 10:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 10:00:00 | 000,502,682 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 10:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 10:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 10:00:00 | 000,086,766 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 10:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 10:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 10:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 10:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 10:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/10/17 22:11:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/11/19 09:01:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/20 08:19:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/11/13 16:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Final Draft
[2011/12/02 12:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/10/25 15:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/12/02 13:53:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/31 11:37:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/10/18 15:13:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/02 09:15:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2011/11/24 16:08:19 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AVG
[2011/10/17 21:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AVG2012
[2011/08/13 14:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Bandoo
[2011/11/23 12:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ElevatedDiagnostics
[2011/11/13 16:29:10 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Final Draft
[2011/08/01 17:04:38 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\OpenCandy
[2011/07/16 17:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\OpenOffice.org
[2011/11/12 12:32:30 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\PrimoPDF
[2011/10/25 15:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\RoboForm
[2011/08/27 16:54:25 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\searchquband
[2011/09/23 15:40:11 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Serif
[2011/12/02 10:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Simple Adblock
[2009/02/26 00:29:47 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Windows Desktop Search
[2011/07/17 14:56:48 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Windows Search
[2011/12/01 09:01:02 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Scan and Repair.job
[2011/12/02 12:34:27 | 000,000,386 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Start On user Logon.job
[2011/12/02 12:34:28 | 000,000,616 | -H– | M] () – C:\WINDOWS\Tasks\ConfigExec.job
[2011/12/02 12:24:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\Tasks\DataUpload.job
[2011/12/02 09:16:43 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/11/28 21:59:11 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/22 12:47:14 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/11/28 21:59:11 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 07:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 07:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2011/07/31 11:37:16 | 000,031,131 | —- | M] () – C:\install.log
[2007/11/07 07:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/11/28 21:59:11 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/11/28 21:59:11 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/02/25 21:44:57 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/02 09:11:33 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2011/11/12 13:27:57 | 000,099,574 | —- | M] () – C:\TDSSKiller.2.6.18.0_12.11.2011_13.25.50_log.txt
[2011/11/13 10:30:51 | 000,096,562 | —- | M] () – C:\TDSSKiller.2.6.18.0_13.11.2011_10.29.56_log.txt
[2011/11/17 10:05:17 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.18.0_17.11.2011_10.05.11_log.txt
[2011/11/17 10:07:42 | 000,049,100 | —- | M] () – C:\TDSSKiller.2.6.19.0_17.11.2011_10.07.18_log.txt
[2011/11/23 09:18:46 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.19.0_23.11.2011_09.17.55_log.txt
[2011/11/23 09:19:30 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.19.0_23.11.2011_09.19.23_log.txt
[2011/11/23 09:47:44 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.19.0_23.11.2011_09.47.39_log.txt
[2011/12/02 10:00:27 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.20.0_02.12.2011_10.00.21_log.txt
[2011/11/29 09:50:05 | 000,099,444 | —- | M] () – C:\TDSSKiller.2.6.20.0_29.11.2011_09.48.21_log.txt
[2011/12/02 10:04:19 | 000,099,946 | —- | M] () – C:\TDSSKiller.2.6.21.0_02.12.2011_10.02.49_log.txt
[2007/11/07 07:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/11/28 21:58:36 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 13:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/11/28 13:30:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/11/28 13:30:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/11/28 13:30:08 | 000,897,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/02/25 21:50:27 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/25 22:49:31 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/11/28 22:05:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/11/27 23:51:44 | 008,143,920 | —- | M] (AVG ) – C:\Documents and Settings\user\Desktop\avg_pct_stf_all_2012_26_c3.exe
[2005/02/16 11:06:00 | 000,218,112 | —- | M] (Soeperman Enterprises Ltd.) – C:\Documents and Settings\user\Desktop\HijackThis.exe
[2011/11/11 17:38:49 | 007,549,704 | —- | M] () – C:\Documents and Settings\user\Desktop\InternationalPrimoPDF.exe
[2011/11/24 17:32:34 | 001,247,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\LIVE WRITER-setup-web.exe
[2011/11/21 12:22:12 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Desktop\ms-eissentialsl.exe
[2011/11/12 12:35:35 | 026,864,760 | —- | M] (Nitro PDF Software) – C:\Documents and Settings\user\Desktop\nitro_pdf_reader.exe
[2011/12/02 13:38:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2011/11/27 15:32:34 | 005,944,736 | —- | M] () – C:\Documents and Settings\user\Desktop\Setup-SopCast-3.4.0-2011-6-9.exe
[2011/12/02 10:01:43 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\user\Desktop\TDSSKiller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2011/10/07 19:29:50 | 000,000,698 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb
[2011/06/13 21:13:08 | 000,000,786 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-26 17:41:48
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >