Thankyou for your response here is the OTL.text file others to follow
OTL logfile created on: 6/30/2012 12:21:39 AM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\radiorentals\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.87 Gb Total Physical Memory | 2.93 Gb Available Physical Memory | 75.74% Memory free
7.73 Gb Paging File | 6.87 Gb Available in Paging File | 88.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.99 Gb Total Space | 197.56 Gb Free Space | 69.08% Space Free | Partition Type: NTFS
Computer Name: ALISON | User Name: radiorentals | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\radiorentals\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (.Net Main) – C:\Windows\SysNative\idle-Threads.exe ()
SRV:
64bit: - (.Net Security) – C:\Windows\SysNative\latch-Threads.exe ()
SRV:
64bit: - (.Net Crypt) – C:\Windows\SysNative\mutex-Threads.exe ()
SRV:
64bit: - (.Net Semaphore) – C:\Windows\SysNative\semaphore-Threads.exe ()
SRV:
64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:
64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:
64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:
64bit: - (ePowerSvc) – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:
64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Group)
SRV:
64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (vToolbarUpdater11.1.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (PassThru Service) – C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (IJPLMSVC) – C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (GREGService) – C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (usbvox) – C:\Windows\SysNative\Drivers\usbvox64.sys ()
DRV:
64bit: - (scssifilter) – C:\Windows\SysNative\drivers\scssifilter64.sys (Microsoft Corporation)
DRV:
64bit: - (usbmp3) – C:\Windows\SysNative\Drivers\usbmp364.sys ()
DRV:
64bit: - (usbwav) – C:\Windows\SysNative\Drivers\usbwav64.sys ()
DRV:
64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:
64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:
64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (Netaapl) – C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:
64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:
64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:
64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (htcnprot) – C:\Windows\SysNative\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV:
64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:
64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:
64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:
64bit: - (HTCAND64) – C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:
64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:
64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:
64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…d4z125a4562d204
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:
64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:
64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…d4z125a4562d204
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACGW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2438727
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchPage =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.imesh.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {F08555B0-9CC3-11D2-AA8E-000000000567} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?FORM=VIATDF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://search.babylon.com/?q={searchTerms}…0000017c4f4f1d2
IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" =
http://www.questscan.com/?prt=QstscanPB&am;…s={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…1I7ACGW_enAU382
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…1I7ACGW_enAU382
IE - HKCU\..\SearchScopes\{78FF7C5E-67BA-4E4A-B09E-84BFE0DF08D6}: "URL" =
http://websearch.ask.com/redirect?client=i…9B-8713DF73C198
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
http://isearch.avg.com/search?cid={544C5B4…mp;d=2012-06-14 21:30:50&v;=10.0.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" =
http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(B)
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2438727
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://search.imesh.net"
FF - prefs.js..extensions.enabledItems: [removed]:0.1
FF - prefs.js..keyword.URL: "
http://dts.search-results.com/sr?src=ffb&appid;=1157&systemid;=1&sr;=0&q;="
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\radiorentals\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\radiorentals\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\radiorentals\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4C0766D3-67A7-45a3-85A2-752F77312F32}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\coFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\ProgramData\CodecCheck\firefox [2011/07/12 17:16:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/20 17:51:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/06/14 23:15:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.7\ [2012/06/16 09:36:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 11:45:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/23 20:01:54 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 11:45:01 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/23 20:01:54 | 000,000,000 | —D | M]
[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions
[2010/08/16 10:12:12 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions\[removed]
[2010/09/20 05:42:40 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions\[removed]
[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions
[2012/05/17 17:03:07 | 000,000,000 | —D | M] (Wincore Mediabar) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0}
[2012/04/29 00:14:54 | 000,000,000 | —D | M] (wxDfast) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions\[removed]
[2012/03/20 13:52:38 | 000,002,205 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\alot-search.xml
[2011/06/08 13:47:03 | 000,002,574 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\askcom.xml
[2011/03/20 16:30:43 | 000,001,834 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\bing.xml
[2012/05/17 17:03:00 | 000,002,517 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\Search_Results.xml
[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/20 17:51:33 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011/07/12 17:16:19 | 000,000,000 | —D | M] ("Premiumplay Codec-C") – C:\PROGRAMDATA\CODECCHECK\FIREFOX
[2012/06/17 11:45:00 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/16 09:35:57 | 000,003,766 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/15 18:10:12 | 000,002,310 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/06/17 11:44:56 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/05/17 17:03:00 | 000,002,517 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2012/06/17 11:44:56 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url =
http://search.babylon.com/?q={searchTerms}…0000017c4f4f1d2
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:
64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:
64bit: - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\x64\BrowserConnection.dll (iMesh, Inc)
O2 - BHO: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll ()
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\BrowserConnection.dll (iMesh, Inc)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3:
64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:
64bit: - HKLM..\Run: [apvxdwin] File not found
O4:
64bit: - HKLM..\Run: [avgnt] File not found
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [Defender Pro Antiphishing Helper] File not found
O4:
64bit: - HKLM..\Run: [DPAgent] File not found
O4:
64bit: - HKLM..\Run: [G Data AntiVirus Tray Application] File not found
O4:
64bit: - HKLM..\Run: [GDFirewallTray] File not found
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [scaninicio] File not found
O4:
64bit: - HKLM..\Run: [UfSeAgnt.exe] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (iMesh, Inc)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [sound-card-recorder] "C:\Program Files (x86)\Phone Call Recorder\phonerec.exe" /tray File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Facebook Update] C:\Users\radiorentals\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [QcrJdlni] C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe ()
O4 - HKCU..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - Startup: C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4}
http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{113A12D7-D158-4CB4-ACCA-102DC7CDCA41}: DhcpNameServer = 10.143.147.147 10.143.147.148
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A37BEAB5-1E21-4CC3-B88C-EBF540245F4D}: DhcpNameServer = 10.0.0.138
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe) - C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe ()
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0b482776-a241-11df-b753-0017c4f4f1d2}\Shell - "" = AutoRun
O33 - MountPoints2\{0b482776-a241-11df-b753-0017c4f4f1d2}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0b48277a-a241-11df-b753-0017c4f4f1d2}\Shell - "" = AutoRun
O33 - MountPoints2\{0b48277a-a241-11df-b753-0017c4f4f1d2}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0b4827d7-a241-11df-b753-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{0b4827d7-a241-11df-b753-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0b4827d9-a241-11df-b753-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{0b4827d9-a241-11df-b753-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{36c224bf-1017-11e0-b63b-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{36c224bf-1017-11e0-b63b-705ab6e51266}\Shell\AutoRun\command - "" = E:\LGAutoRun.exe
O33 - MountPoints2\{6488bc11-b187-11df-9ea5-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{6488bc11-b187-11df-9ea5-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{6488bc13-b187-11df-9ea5-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{6488bc13-b187-11df-9ea5-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Program Files (x86)\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
========== Files/Folders - Created Within 30 Days ==========
[2012/06/29 21:55:38 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{1D12CC76-E393-4208-8086-8FA9461315AE}
[2012/06/29 21:55:26 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7090F71F-F744-41D4-B6EA-8D2FA7A51546}
[2012/06/29 19:30:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\ivawsleu
[2012/06/29 09:54:53 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7242A710-C0FF-4F05-9A9E-10A23C4C3D86}
[2012/06/29 09:54:41 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{97FE2437-8690-4D6A-9601-1E57E73DEB21}
[2012/06/28 21:54:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{D3C6DA99-E853-40BE-B699-6712ED42788C}
[2012/06/28 21:54:08 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{72C850ED-3BB0-437B-A45C-8B31CEF33650}
[2012/06/28 20:42:32 | 000,000,000 | —D | C] – C:\Windows\en
[2012/06/28 20:38:24 | 000,048,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fssfltr.sys
[2012/06/28 20:34:34 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B267C275-B16E-4491-8AC9-203953524CE6}
[2012/06/28 20:34:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5556EF6B-3D6E-47FE-9868-46AEC5A91B12}
[2012/06/28 20:27:50 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7071BD75-769C-48DB-9200-80FE6E61C2FF}
[2012/06/28 20:27:39 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{161234F5-C5DE-40D2-B4CC-6A706A3574DD}
[2012/06/28 20:27:29 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5C9FE7BE-3460-46C2-8CAE-0D90C229CEF9}
[2012/06/28 20:27:19 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0772D968-63BA-4EBD-BECE-2D23FF3754B4}
[2012/06/28 20:27:09 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{493293F5-1504-4A06-9967-69714447F5DE}
[2012/06/28 20:26:58 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B780D0E3-2C87-409B-8B58-A2A906867B08}
[2012/06/28 20:26:48 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{3FA523EB-7AC6-4972-8576-A37EAF9A11F0}
[2012/06/28 20:26:37 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{AD373357-F4B6-4B45-B686-611ED5D217B4}
[2012/06/28 20:26:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B126786E-4984-4264-A42D-740E2AE768D9}
[2012/06/28 20:26:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{D4E95DD4-F513-42EF-BF5D-D4BC143645CD}
[2012/06/28 20:26:03 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{59A0B056-AE70-4990-A32A-E89F3040441F}
[2012/06/28 20:25:51 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{A13B57FD-38E6-4F62-B7F1-F3ACE013257F}
[2012/06/26 11:26:17 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/26 11:26:17 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/26 11:26:16 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/26 11:25:52 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/26 11:25:52 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/26 11:25:51 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/23 23:47:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{4E726720-C554-4283-A849-CA5475D242AC}
[2012/06/23 23:46:54 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E50A0124-AAC8-457C-A735-8C85ACF8EA31}
[2012/06/22 10:01:32 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/22 10:01:32 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/20 08:54:04 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{6AB197A2-28B2-4E69-847F-F694D48E45E3}
[2012/06/20 08:53:47 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5135D699-CCC9-4549-B845-055C0111023A}
[2012/06/19 08:50:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{AE331330-AA36-48C6-B2C5-7680BA192E6E}
[2012/06/19 08:50:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\AVG Secure Search
[2012/06/19 08:02:39 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/19 08:02:38 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/19 08:02:36 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/19 08:02:36 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/19 08:02:32 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/19 08:02:31 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/19 08:02:30 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/06/19 08:02:30 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/06/19 08:02:24 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/06/19 08:02:24 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/06/19 08:02:23 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/06/19 08:02:22 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/19 08:02:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/17 13:18:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\FrostWire
[2012/06/17 13:18:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\.frostwire5
[2012/06/17 11:53:23 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/17 11:53:23 | 000,070,344 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/14 23:19:36 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{2D7818AA-162A-4C13-903C-357CFB4D96DD}
[2012/06/14 23:19:24 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{8E8555C9-14B3-4187-8553-143820D4C0D1}
[2012/06/14 21:39:58 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C9A65FDD-955A-414C-96C5-E9CE877B5B5C}
[2012/06/14 21:39:45 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0BCFC424-08A6-4AF6-9338-4E4BAAC527D3}
[2012/06/14 21:36:11 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/06/14 21:32:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Roaming\AVG2012
[2012/06/14 21:30:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2012/06/14 21:30:50 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/06/14 21:30:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2012/06/14 21:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2012/06/14 21:30:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/06/14 21:30:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2012/06/14 21:29:50 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/06/14 21:29:50 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2012/06/14 21:11:24 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/06/14 20:35:17 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/14 20:35:16 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/14 20:35:16 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/14 20:35:06 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/14 20:35:05 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/14 20:35:04 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/14 20:35:00 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/14 20:34:49 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/14 20:34:48 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/14 19:59:46 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\Macromedia
[2012/06/14 19:58:12 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{BFF4B682-D5CE-4A3F-B861-A0F09B9A2427}
[2012/06/14 19:58:01 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{457098C9-2E0E-4295-B50B-C06E7EF928B4}
[2012/06/13 15:49:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EE8E9369-85C1-47BC-AE01-FF139683E442}
[2012/06/13 15:48:50 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C1488EDD-755C-4470-99EE-88E72C3E290E}
[2012/06/12 17:06:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E824A145-8763-447D-9F45-46C9CAA71E5E}
[2012/06/12 17:06:06 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EB3E53B3-2DE9-4611-89E6-6EA0256CA12B}
[2012/06/11 10:28:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EA46E58B-C36F-4410-938F-F0EAEAC2B5FC}
[2012/06/11 10:28:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E310FE54-DBE4-490A-9BDD-6FF42249317F}
[2012/06/11 10:17:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FFE96526-1B05-4EBF-83C0-427C4DA84BBE}
[2012/06/11 10:17:17 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E1916FBA-BE68-4362-B3E9-D38350995F42}
[2012/06/07 19:55:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B7ED88FA-ED40-4768-978F-5F3D4F0DB258}
[2012/06/07 19:55:15 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FEB88999-E9E6-4303-8926-21A102576BAA}
[2012/06/05 17:04:02 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{ABBFA0E3-3214-476F-8EE9-B68AD36D745B}
[2012/06/05 17:03:52 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0961A955-3CC9-4D58-86FC-FA8F9C6DD163}
[2012/06/04 17:21:12 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{DEF1D142-FAD5-4582-AC55-7D8E0C32750E}
[2012/06/04 17:20:57 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{769BAC13-7A28-4954-8B10-032CBE6F122C}
[2012/06/04 17:11:18 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{51146BCB-FE36-48D0-9D33-55AC0FF3F254}
[2012/06/04 17:11:08 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FFA318A0-8120-49F4-B441-9B225EF2257B}
[2012/06/03 12:30:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0BF89684-C314-42D9-840E-13AC5421795A}
[2012/06/03 12:30:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C6483662-159B-4E94-92F7-418D9AEDED59}
[2012/06/02 15:58:35 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{01ABE5D9-8805-4DB0-853A-D28D32247E66}
[2012/06/02 15:58:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EF120D16-F395-4A2B-9E97-FFDB8C3302F6}
[2012/06/01 09:32:00 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0DC69B49-6DF3-4368-B23F-14B2C70C5413}
[2012/06/01 09:31:48 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{82B8ADA1-EAF3-480F-9C6F-8BFCAEEF3103}
[2012/04/19 23:59:20 | 007,760,687 | —- | C] (Boraxsoft) – C:\Users\radiorentals\AppData\Roaming\SetupGFD.exe
[2012/04/19 23:55:55 | 005,514,668 | —- | C] (LIGHTNING UK!) – C:\Users\radiorentals\AppData\Roaming\Imgburn.exe
[2012/04/19 23:55:04 | 005,082,084 | —- | C] (The Public) – C:\Users\radiorentals\AppData\Roaming\Avisynth.exe
========== Files - Modified Within 30 Days ==========
[2012/06/29 22:55:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/29 22:55:19 | 3113,254,912 | -HS- | M] () – C:\hiberfil.sys
[2012/06/29 22:54:31 | 000,104,047 | RHS- | M] () – C:\Windows\SysNative\masteraclini.enu
[2012/06/29 22:50:25 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/29 22:50:25 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/29 22:47:00 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/06/29 22:43:05 | 000,000,147 | RH– | M] () – C:\Windows\SysNative\masteraclbini.enu
[2012/06/29 22:42:17 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/29 22:41:08 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/29 21:24:02 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/29 21:02:16 | 000,000,512 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for radiorentals.job
[2012/06/29 19:30:24 | 000,092,172 | –S- | M] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe
[2012/06/29 19:30:24 | 000,092,172 | —- | M] () – C:\Users\radiorentals\0.37516256241763035.exe
[2012/06/29 19:06:02 | 000,000,956 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/06/29 08:47:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/29 07:11:36 | 100,783,635 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/29 07:10:20 | 000,137,616 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/28 22:06:00 | 000,000,934 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/23 22:42:29 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 22:42:28 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/19 08:46:48 | 000,441,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/19 08:24:57 | 000,749,420 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/19 08:24:57 | 000,627,138 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/19 08:24:57 | 000,111,676 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/15 07:33:24 | 000,002,438 | —- | M] () – C:\Users\radiorentals\Desktop\Google Chrome.lnk
[2012/06/14 21:30:58 | 000,000,932 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/14 21:30:31 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/06/14 21:30:31 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/06/03 08:19:46 | 000,038,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/03 08:19:42 | 000,057,880 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/03 08:19:42 | 000,044,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/03 08:19:23 | 000,701,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/03 08:15:31 | 002,622,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/03 08:15:08 | 000,099,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
========== Files Created - No Company Name ==========
[2012/06/29 19:30:25 | 000,092,172 | –S- | C] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe
[2012/06/29 19:30:22 | 000,092,172 | —- | C] () – C:\Users\radiorentals\0.37516256241763035.exe
[2012/06/29 07:11:36 | 100,783,635 | —- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/29 07:10:20 | 000,137,616 | —- | C] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/17 11:53:24 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/14 21:30:58 | 000,000,932 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/14 21:30:31 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/06/14 21:30:31 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/04/20 00:01:42 | 000,034,936 | —- | C] () – C:\Windows\SysWow64\uninstHelixYUV.exe
[2012/04/19 23:57:58 | 005,243,208 | —- | C] ( ) – C:\Users\radiorentals\AppData\Roaming\AvsP.exe
[2012/04/19 23:57:22 | 001,357,348 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\MatroskaSplitter.exe
[2012/04/19 23:57:18 | 000,117,723 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\yuvcodecs-1.3.exe
[2011/12/04 12:16:59 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/12/03 12:55:25 | 000,026,018 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\UserTile.png
[2011/08/07 17:54:08 | 000,012,712 | -HS- | C] () – C:\ProgramData\vydm2tkqc846qk5r2761qlb8ah15252rc05a0p
[2011/08/07 17:54:08 | 000,012,586 | -HS- | C] () – C:\Users\radiorentals\AppData\Local\vydm2tkqc846qk5r2761qlb8ah15252rc05a0p
[2010/12/04 17:52:04 | 000,000,100 | —- | C] () – C:\Users\radiorentals\AppData\Local\fusioncache.dat
[2010/12/04 17:47:31 | 000,749,200 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/01 18:24:37 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/09/30 10:07:56 | 008,007,680 | —- | C] ( ) – C:\Windows\SysWow64\Microsoft.mshtml.dll
[2010/09/30 10:07:55 | 000,126,976 | —- | C] ( ) – C:\Windows\SysWow64\Interop.SHDocVw.dll
[2010/06/09 11:57:47 | 000,000,946 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\wklnhst.dat
[2010/06/06 12:15:54 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
========== LOP Check ==========
[2011/12/06 07:24:47 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Alawar
[2012/06/14 23:14:53 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\AVG2012
[2012/03/15 18:10:07 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Babylon
[2010/12/10 16:58:04 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\BBB
[2012/04/17 20:07:50 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Canon
[2010/06/06 07:55:13 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Faerie Solitaire
[2012/04/18 15:14:14 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\FUJIFILM
[2010/06/26 15:51:41 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Gaijin Ent
[2010/11/12 20:09:49 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Gamelab
[2011/06/24 17:49:45 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\GetRightToGo
[2012/04/07 00:28:53 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\HTC
[2011/05/15 18:43:39 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Leadertech
[2011/12/08 22:21:25 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\monkey money
[2012/05/17 17:02:44 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\MusicNet
[2010/09/28 11:28:20 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\OpenOffice.org
[2010/06/05 11:15:02 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Packard Bell
[2011/12/08 19:54:32 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\PlayFirst
[2011/11/05 11:37:14 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Shareaza
[2010/06/05 09:31:41 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\SNS
[2010/06/09 11:57:48 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Template
[2010/09/28 11:28:20 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\TomTom
[2012/03/24 18:40:50 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Uniblue
[2011/12/11 12:03:57 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Virtual City
[2012/05/21 20:42:53 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\WildTangent
[2010/09/28 11:28:20 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\WildTangentv1002
[2012/01/03 11:15:44 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Windows Live Writer
[2012/06/28 22:06:00 | 000,000,934 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/29 19:06:02 | 000,000,956 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/03/10 01:10:17 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/04/01 15:06:26 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/08 01:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/08 01:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/08 01:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/06/29 22:55:19 | 3113,254,912 | -HS- | M] () – C:\hiberfil.sys
[2007/11/08 01:44:20 | 000,855,040 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/08 01:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/08 01:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/08 01:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/08 01:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/08 01:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/08 01:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/08 01:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/08 01:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/08 01:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/08 01:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/06/29 22:55:19 | 4151,009,280 | -HS- | M] () – C:\pagefile.sys
[2010/04/01 15:06:26 | 000,003,274 | —- | M] () – C:\RHDSetup.log
[2011/04/02 07:41:01 | 000,000,404 | —- | M] () – C:\rkill.log
[2010/04/01 15:06:26 | 000,005,902 | —- | M] () – C:\scramble.log
[2012/03/16 01:12:44 | 000,000,510 | —- | M] () – C:\settings.ini
[1999/12/31 23:00:08 | 000,000,895 | —- | M] () – C:\tmp1
[1999/12/31 23:00:10 | 000,000,128 | —- | M] () – C:\tmp2
[2012/03/15 18:10:19 | 000,000,237 | —- | M] () – C:\user.js
[2007/11/08 01:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/08 01:50:40 | 001,927,956 | —- | M] () – C:\VC_RED.cab
[2007/11/08 01:53:12 | 000,242,176 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 15:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 15:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 15:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 15:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 06:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 14:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/09/02 13:09:53 | 000,000,314 | -HS- | M] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/04/02 07:45:56 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\radiorentals\Desktop\mbam-setup-1.50.1.1100.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 180 bytes -> C:\ProgramData\Temp:CB0AACC9
@Alternate Data Stream - 16 bytes -> C:\Users\radiorentals\Downloads:Shareaza.GUID
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:1DA424AA
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >