Hi Robybel,
Oops, I did the 'full scan'.
Here is the full scan log. I'll post the 'quick scan log' in a minute.:
OTL logfile created on: 17/02/2013 14:23:05 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dennis\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.75 Gb Total Physical Memory | 2.44 Gb Available Physical Memory | 65.00% Memory free
7.68 Gb Paging File | 6.31 Gb Available in Paging File | 82.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.43 Gb Total Space | 13.81 Gb Free Space | 10.12% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 4.54 Gb Free Space | 45.40% Space Free | Partition Type: NTFS
Computer Name: DENNIS-PC | User Name: Dennis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
PRC - C:\Users\Dennis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oahlp.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions)
PRC - C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
PRC - C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\SiteSafety.dll ()
MOD - C:\Program Files\Steam\sdl.dll ()
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Perfect Uninstaller\Contextmenu.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll ()
MOD - C:\Program Files\Saitek\Software\SAICFG.dll ()
========== Services (SafeList) ==========
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (vToolbarUpdater14.1.7) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (CLPSLauncher) – C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (GeekBuddyRSP) – C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\Dennis\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (CFRMD) – C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (NETw4v32) – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (SaiNtBus) – C:\Windows\System32\drivers\SaiBus.sys (Saitek)
DRV - (SaiMini) – C:\Windows\System32\drivers\SaiMini.sys (Saitek)
DRV - (SaiH0461) – C:\Windows\System32\drivers\SaiH0461.sys (Saitek)
DRV - (ss_mdm) – C:\Windows\System32\drivers\ss_mdm.sys (MCCI)
DRV - (ss_mdfl) – C:\Windows\System32\drivers\ss_mdfl.sys (MCCI)
DRV - (ss_bus) – C:\Windows\System32\drivers\ss_bus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUK
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}:6.0.39
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {534EBA91-5C43-4711-AA70-5C4ECF671FED}:1.9.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.1.0.10 [2013/02/13 23:40:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/31 12:41:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/31 12:00:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{534EBA91-5C43-4711-AA70-5C4ECF671FED}: C:\Users\Dennis\AppData\Local\{534EBA91-5C43-4711-AA70-5C4ECF671FED}
[2009/02/17 20:25:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Extensions
[2012/11/27 20:07:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions
[2011/01/09 20:13:28 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
[2012/11/26 21:52:22 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/26 21:52:19 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2013/02/13 23:39:50 | 000,003,592 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/11/26 21:52:19 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/26 21:52:19 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/11/26 21:52:19 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/11/26 21:52:19 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/11/26 21:52:19 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - homepage:
http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url =
http://isearch.avg.com/search?cid={C0D01CC…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=dsp&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage:
http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: BitTorrent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: AVG Security Toolbar = C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\14.1.0.10_0\
O1 HOSTS File: ([2013/02/16 20:42:40 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BeNaughtyChat.lnk = C:\Program Files\BeNaughtyChat\BeNaughtyChat.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0}
http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1E45316-623A-47F4-AE3A-51183EE97AFA}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.1.7\ViProtocol.dll ()
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()
O18 - Protocol\Filter\x-sdch - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/17 00:09:27 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2013/02/08 16:59:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2013/02/08 16:59:27 | 000,031,768 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAnet.sys
[2013/02/08 16:59:27 | 000,027,648 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAmon.sys
[2013/02/08 16:59:22 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2013/02/08 15:44:57 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2013/02/08 15:43:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/02/08 15:43:03 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/02/08 15:43:02 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/02/08 15:41:18 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/02/08 15:28:21 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/08 15:27:47 | 000,477,616 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 15:27:47 | 000,473,520 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 15:27:47 | 000,158,128 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2013/02/08 15:27:47 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2013/02/08 15:27:47 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2013/02/07 19:30:38 | 002,322,184 | —- | C] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/07 19:15:22 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/07 19:15:22 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/02/04 22:32:28 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/04 22:32:23 | 000,000,000 | —D | C] – C:\JRT
[2013/02/04 22:24:15 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/04 21:56:17 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Avg2013
[2013/02/04 21:40:59 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:38:22 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/02 14:38:22 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/02 14:38:22 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/02 14:36:40 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/02 14:36:11 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/02/02 14:33:27 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\AVG Secure Search
[2013/02/02 14:33:20 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2013/02/02 14:33:12 | 000,033,112 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/02 14:33:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/02/02 14:33:06 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/02/02 14:06:27 | 005,029,149 | R— | C] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 19:58:25 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/01/31 12:00:07 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/30 18:37:10 | 000,000,000 | —D | C] – C:\Users\Dennis\Desktop\tdsskiller
[2013/01/28 20:44:36 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:30 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/01/22 17:40:14 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Macromedia
[2013/01/22 17:15:11 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/01/22 14:43:00 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\TuneUp Software
[2013/01/22 14:37:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\MFAData
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/01/22 14:30:23 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2013/01/22 14:29:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Comodo
[2013/01/22 14:29:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/01/22 14:29:41 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Comodo
[2013/01/22 14:29:19 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gdiplus.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/17 14:29:00 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2013/02/17 14:24:59 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/02/17 12:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 12:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 10:55:36 | 000,002,485 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
[2013/02/17 10:55:35 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2013/02/17 10:54:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/17 10:54:38 | 4024,479,744 | -HS- | M] () – C:\hiberfil.sys
[2013/02/16 20:42:40 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2013/02/13 23:39:44 | 000,033,112 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/12 23:07:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:55:09 | 000,000,876 | —- | M] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/08 15:27:34 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 15:27:34 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 15:27:34 | 000,158,128 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2013/02/08 15:27:34 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2013/02/08 15:27:34 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2013/02/07 19:30:42 | 002,322,184 | —- | M] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:16:33 | 000,000,932 | —- | M] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/06 21:38:09 | 000,198,144 | —- | M] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/04 21:41:01 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:06:36 | 005,029,149 | R— | M] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 12:40:02 | 000,580,235 | —- | M] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:52 | 002,195,061 | —- | M] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | M] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | M] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/28 20:44:53 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 17:15:11 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/01/22 17:15:11 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/01/22 14:30:04 | 000,001,926 | —- | M] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/01/22 14:29:19 | 001,700,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\gdiplus.dll
[2013/01/22 14:04:26 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2013/01/20 19:26:22 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/12 23:07:00 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:59:27 | 000,208,320 | —- | C] () – C:\Windows\System32\drivers\OADriver.sys
[2013/02/08 16:59:27 | 000,044,992 | —- | C] () – C:\Windows\System32\drivers\oahlp32.sys
[2013/02/08 16:55:09 | 000,000,876 | —- | C] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:16:33 | 000,000,932 | —- | C] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:13:36 | 4024,479,744 | -HS- | C] () – C:\hiberfil.sys
[2013/02/02 14:38:22 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/02 14:38:22 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/02 14:38:22 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/02 14:38:22 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/02 14:38:22 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/31 12:39:59 | 000,580,235 | —- | C] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:50 | 002,195,061 | —- | C] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | C] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | C] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/22 14:30:04 | 000,001,926 | —- | C] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2012/11/28 23:27:13 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2012/11/28 23:27:13 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/06/09 19:11:14 | 001,474,832 | —- | C] () – C:\Windows\System32\drivers\sfi.dat
[2009/12/02 13:22:04 | 000,000,063 | —- | C] () – C:\Users\Dennis\.structure
[2008/09/08 09:11:42 | 000,008,268 | —- | C] () – C:\Users\Dennis\AppData\Local\d3d9caps.dat
[2008/03/03 23:08:38 | 000,000,000 | —- | C] () – C:\Users\Dennis\AppData\Roaming\wklnhst.dat
[2008/02/28 20:47:38 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2008/02/28 19:54:26 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2008/02/28 18:58:55 | 000,198,144 | —- | C] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 12:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2011/01/21 15:46:32 | 011,582,464 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/03/03 04:36:24 | 000,615,424 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/01/19 07:36:49 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Sports Interactive:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\processPurchaseResponse.do_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Nationwide Internet banking signup_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi2.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi1.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Dell Webcam Center:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\bevestigingDVDpap_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\aBHbAwAALilM.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\__MACOSX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\tdsskiller:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\Scotland march 2012:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\New Folder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\[Classic, 1982] Taboo II (Dorothy LeMay, Honey Wilder).avi:Roxio EMC Stream
< End of report >
Short scan log:
OTL logfile created on: 17/02/2013 16:08:50 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dennis\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.75 Gb Total Physical Memory | 2.24 Gb Available Physical Memory | 59.81% Memory free
7.68 Gb Paging File | 6.22 Gb Available in Paging File | 81.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.43 Gb Total Space | 13.52 Gb Free Space | 9.91% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 4.54 Gb Free Space | 45.40% Space Free | Partition Type: NTFS
Computer Name: DENNIS-PC | User Name: Dennis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
PRC - C:\Users\Dennis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oahlp.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions)
PRC - C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
PRC - C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\SiteSafety.dll ()
MOD - C:\Program Files\Steam\sdl.dll ()
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Perfect Uninstaller\Contextmenu.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll ()
MOD - C:\Program Files\Saitek\Software\SAICFG.dll ()
========== Services (SafeList) ==========
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (vToolbarUpdater14.1.7) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (CLPSLauncher) – C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (GeekBuddyRSP) – C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\Dennis\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (CFRMD) – C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (NETw4v32) – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (SaiNtBus) – C:\Windows\System32\drivers\SaiBus.sys (Saitek)
DRV - (SaiMini) – C:\Windows\System32\drivers\SaiMini.sys (Saitek)
DRV - (SaiH0461) – C:\Windows\System32\drivers\SaiH0461.sys (Saitek)
DRV - (ss_mdm) – C:\Windows\System32\drivers\ss_mdm.sys (MCCI)
DRV - (ss_mdfl) – C:\Windows\System32\drivers\ss_mdfl.sys (MCCI)
DRV - (ss_bus) – C:\Windows\System32\drivers\ss_bus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUK
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}:6.0.39
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {534EBA91-5C43-4711-AA70-5C4ECF671FED}:1.9.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.1.0.10 [2013/02/13 23:40:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/31 12:41:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/31 12:00:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{534EBA91-5C43-4711-AA70-5C4ECF671FED}: C:\Users\Dennis\AppData\Local\{534EBA91-5C43-4711-AA70-5C4ECF671FED}
[2009/02/17 20:25:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Extensions
[2012/11/27 20:07:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions
[2011/01/09 20:13:28 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
[2012/11/26 21:52:22 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/26 21:52:19 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2013/02/13 23:39:50 | 000,003,592 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/11/26 21:52:19 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/26 21:52:19 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/11/26 21:52:19 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/11/26 21:52:19 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/11/26 21:52:19 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - homepage:
http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url =
http://isearch.avg.com/search?cid={C0D01CC…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=dsp&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage:
http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: BitTorrent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: AVG Security Toolbar = C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\14.1.0.10_0\
O1 HOSTS File: ([2013/02/16 20:42:40 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BeNaughtyChat.lnk = C:\Program Files\BeNaughtyChat\BeNaughtyChat.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0}
http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1E45316-623A-47F4-AE3A-51183EE97AFA}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.1.7\ViProtocol.dll ()
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()
O18 - Protocol\Filter\x-sdch - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/17 00:09:27 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2013/02/08 16:59:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2013/02/08 16:59:27 | 000,031,768 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAnet.sys
[2013/02/08 16:59:27 | 000,027,648 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAmon.sys
[2013/02/08 16:59:22 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2013/02/08 15:44:57 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2013/02/08 15:43:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/02/08 15:43:03 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/02/08 15:43:02 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/02/08 15:41:18 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/02/08 15:28:21 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/07 19:30:38 | 002,322,184 | —- | C] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/07 19:15:22 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/07 19:15:22 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/02/04 22:32:28 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/04 22:32:23 | 000,000,000 | —D | C] – C:\JRT
[2013/02/04 22:24:15 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/04 21:56:17 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Avg2013
[2013/02/04 21:40:59 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:38:22 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/02 14:38:22 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/02 14:38:22 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/02 14:36:40 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/02 14:36:11 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/02/02 14:33:27 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\AVG Secure Search
[2013/02/02 14:33:20 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2013/02/02 14:33:12 | 000,033,112 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/02 14:33:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/02/02 14:33:06 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/02/02 14:06:27 | 005,029,149 | R— | C] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 19:58:25 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/01/31 12:00:07 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/30 18:37:10 | 000,000,000 | —D | C] – C:\Users\Dennis\Desktop\tdsskiller
[2013/01/28 20:44:36 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:30 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/01/22 17:40:14 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Macromedia
[2013/01/22 14:43:00 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\TuneUp Software
[2013/01/22 14:37:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\MFAData
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/01/22 14:30:23 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2013/01/22 14:29:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Comodo
[2013/01/22 14:29:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/01/22 14:29:41 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Comodo
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/17 16:15:00 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/02/17 16:13:00 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2013/02/17 15:45:02 | 000,198,144 | —- | M] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/17 14:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 14:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 10:55:36 | 000,002,485 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
[2013/02/17 10:55:35 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2013/02/17 10:54:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/17 10:54:38 | 4024,479,744 | -HS- | M] () – C:\hiberfil.sys
[2013/02/16 20:42:40 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2013/02/13 23:39:44 | 000,033,112 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/12 23:07:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:55:09 | 000,000,876 | —- | M] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:30:42 | 002,322,184 | —- | M] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:16:33 | 000,000,932 | —- | M] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/04 21:41:01 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:06:36 | 005,029,149 | R— | M] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 12:40:02 | 000,580,235 | —- | M] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:52 | 002,195,061 | —- | M] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | M] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | M] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/28 20:44:53 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 14:30:04 | 000,001,926 | —- | M] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/01/22 14:04:26 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2013/01/20 19:26:22 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/12 23:07:00 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:59:27 | 000,208,320 | —- | C] () – C:\Windows\System32\drivers\OADriver.sys
[2013/02/08 16:59:27 | 000,044,992 | —- | C] () – C:\Windows\System32\drivers\oahlp32.sys
[2013/02/08 16:55:09 | 000,000,876 | —- | C] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:16:33 | 000,000,932 | —- | C] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:13:36 | 4024,479,744 | -HS- | C] () – C:\hiberfil.sys
[2013/02/02 14:38:22 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/02 14:38:22 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/02 14:38:22 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/02 14:38:22 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/02 14:38:22 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/31 12:39:59 | 000,580,235 | —- | C] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:50 | 002,195,061 | —- | C] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | C] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | C] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/22 14:30:04 | 000,001,926 | —- | C] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2012/11/28 23:27:13 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2012/11/28 23:27:13 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/06/09 19:11:14 | 001,474,832 | —- | C] () – C:\Windows\System32\drivers\sfi.dat
[2009/12/02 13:22:04 | 000,000,063 | —- | C] () – C:\Users\Dennis\.structure
[2008/09/08 09:11:42 | 000,008,268 | —- | C] () – C:\Users\Dennis\AppData\Local\d3d9caps.dat
[2008/03/03 23:08:38 | 000,000,000 | —- | C] () – C:\Users\Dennis\AppData\Roaming\wklnhst.dat
[2008/02/28 20:47:38 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2008/02/28 19:54:26 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2008/02/28 18:58:55 | 000,198,144 | —- | C] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 12:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2011/01/21 15:46:32 | 011,582,464 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/03/03 04:36:24 | 000,615,424 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/01/19 07:36:49 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/07/07 21:46:19 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Akigo
[2013/02/08 15:44:57 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2011/08/10 22:06:30 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\BeNaughtyChat
[2012/07/07 23:24:50 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Dropbox
[2013/02/08 17:02:22 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2008/04/04 16:24:01 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Panasonic
[2011/05/24 20:12:37 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\PCDr
[2012/07/24 21:33:02 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Sports Interactive
[2008/03/03 23:08:39 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Template
[2013/01/22 14:43:00 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\TuneUp Software
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Sports Interactive:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\processPurchaseResponse.do_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Nationwide Internet banking signup_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi2.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi1.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Dell Webcam Center:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\bevestigingDVDpap_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\aBHbAwAALilM.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\__MACOSX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\tdsskiller:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\Scotland march 2012:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\New Folder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\[Classic, 1982] Taboo II (Dorothy LeMay, Honey Wilder).avi:Roxio EMC Stream
< End of report >