Declan
Topic Starter
My daughter's Aspire One Netbook seems to have become seriously affected as the performance is terribly slow and pop-ups seem to have taken over the system.
The system itself runs with Vista, and has 1Gb memory, with 250 Gb HDD.
Please find the requested files attached.
Thank you in advance for any help.
OTL scan took about 30 seconds before it responded.
OTL.txt
OTL logfile created on: 19/06/2013 20:06:54 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.09 Mb Total Physical Memory | 491.77 Mb Available Physical Memory | 48.54% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.79 Gb Total Space | 167.98 Gb Free Space | 77.85% Space Free | Partition Type: NTFS
Drive D: | 4.00 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: FAT32
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10x_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - (vToolbarUpdater15.2.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (MWLService) – C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (RS_Service) – C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV - (GREGService) – C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (L1C) – system32\DRIVERS\L1C62x86.sys File not found
DRV - (GEARAspiWDM) – system32\DRIVERS\GEARAspiWDM.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (EUCR) – C:\Windows\System32\drivers\EUCR6SK.sys (ENE Technology Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (mwlPSDVDisk) – C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV - (mwlPSDNServ) – C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV - (mwlPSDFilter) – C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com/
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
IE - HKCU\..\SearchScopes\{37D5285D-E43C-4DF7-9108-533774FD7A78}: "URL" = http://websearch.ask.com/redirect?client=i…56-5309080391E3
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(B)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/06/08 22:22:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/06/08 22:22:15 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.conduit.com/?ctid=CT2269050&…amp;sspv=CHSB18
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaaooaijelonlmbcbjkocdnicdfmo\7.13.0.0_0\background/registryAccess.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\BetterCareerSearch_2b\bar\1.bin\NP2bStub.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\User\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: news.net = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmbbgcooaabknohabmoaikiakkoignai\1.0.12_0\
CHR - Extension: AVG Security Toolbar = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.2.0.5_0\
O1 HOSTS File: ([2013/06/17 01:30:43 | 000,449,637 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15435 more lines…
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll File not found
O2 - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{7ff70c81-f37a-4d7b-9d30-ba8ee8c80d5f} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKCU..\Run: [BreakingNews] C:\Program Files\BreakingNews\BreakingNews\DesktopContainer.exe File not found
O4 - HKCU..\Run: [MPOptimizer] "C:\Program Files\MaxPerforma Optimizer\MaxPerforma.exe" /scan File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37096400-4D72-41DD-B37B-C84267CD79C6}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{11bacb60-f4f8-11e0-b91d-18f46ac378bb}\Shell - "" = AutoRun
O33 - MountPoints2\{11bacb60-f4f8-11e0-b91d-18f46ac378bb}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{169b6e5a-5e4c-11e1-a61c-18f46ac378bb}\Shell - "" = AutoRun
O33 - MountPoints2\{169b6e5a-5e4c-11e1-a61c-18f46ac378bb}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{75e89618-ef1a-11e0-b73e-1c750835ad5b}\Shell - "" = AutoRun
O33 - MountPoints2\{75e89618-ef1a-11e0-b73e-1c750835ad5b}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{75e896b9-ef1a-11e0-b73e-1c750835ad5b}\Shell - "" = AutoRun
O33 - MountPoints2\{75e896b9-ef1a-11e0-b73e-1c750835ad5b}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/06/19 19:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/19 19:27:12 | 000,000,000 | —D | C] – C:\Users\User\Documents\My Received Files
[2013/06/18 22:49:41 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/06/18 22:49:41 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/06/18 22:49:40 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/06/18 22:49:40 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/06/18 22:49:39 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/06/18 22:49:39 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/06/18 22:49:39 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/06/18 22:49:39 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/06/18 22:49:39 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/18 22:49:38 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/18 22:49:38 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/18 22:49:38 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/06/18 22:49:37 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/06/18 22:49:37 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/06/18 22:49:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/06/18 22:49:37 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/06/18 22:49:37 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/06/18 22:49:36 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/06/18 22:49:36 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/06/18 22:49:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/06/18 22:49:36 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/06/18 22:49:36 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/06/18 22:49:35 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/18 22:49:35 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/06/18 22:49:35 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/06/18 22:49:34 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/06/18 22:49:34 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/06/18 22:49:34 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/06/18 22:49:34 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/06/18 22:49:34 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/06/18 22:49:34 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/06/18 22:49:34 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/06/18 22:49:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/06/18 22:49:34 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/06/18 22:49:33 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/06/18 22:49:33 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/06/18 22:47:25 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/06/18 22:47:25 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/06/18 22:47:25 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/06/18 22:47:25 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/18 22:47:24 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/06/18 22:47:24 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/06/18 22:47:24 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/06/18 22:47:24 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/06/18 22:47:24 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/06/18 22:47:24 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/06/18 22:47:24 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/06/18 22:47:24 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/06/18 22:47:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/06/18 22:47:23 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/06/18 22:47:23 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/06/18 22:47:23 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/06/17 20:54:50 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2013/06/17 20:54:47 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/06/17 19:09:46 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/06/17 19:08:16 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/06/17 19:05:54 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OxpsConverter.exe
[2013/06/17 19:05:41 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/06/17 19:05:31 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptdlg.dll
[2013/06/17 19:04:36 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/06/17 19:04:22 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/06/17 19:04:18 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certenc.dll
[2013/06/17 19:03:14 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2013/06/17 19:03:12 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcorehc.dll
[2013/06/17 19:03:09 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/06/17 19:01:40 | 003,913,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/06/17 19:01:39 | 003,968,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/06/17 19:00:49 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2013/06/17 19:00:47 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
[2013/06/17 19:00:38 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcore6.dll
[2013/06/17 19:00:38 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/06/17 18:59:57 | 000,101,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2013/06/17 18:59:56 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2013/06/17 18:52:33 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/17 18:50:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\AVG Secure Search
[2013/06/17 18:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/06/17 18:49:56 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/06/17 18:49:16 | 000,037,664 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/17 18:49:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/06/17 18:48:55 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/06/17 18:44:09 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/06/17 18:44:09 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/06/17 18:42:08 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Avg2013
[2013/06/17 06:47:45 | 000,000,000 | —D | C] – C:\9e856ef85da9b57ffd821680f163a2
[2013/06/17 05:47:58 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2013/06/17 05:47:57 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2013/06/17 05:19:38 | 000,000,000 | —D | C] – C:\Windows\System32\SPReview
[2013/06/17 05:18:04 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2013/06/16 23:46:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/06/16 22:45:20 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2013/06/16 22:33:15 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/06/16 22:32:47 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/14 12:58:13 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/06/14 12:58:13 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/06/14 12:57:16 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/06/14 12:57:16 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/06/14 12:56:41 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/06/14 12:56:39 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/06/14 12:56:39 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/06/14 12:56:03 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/06/14 12:56:03 | 000,262,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rstrui.exe
[2013/06/14 12:55:55 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/06/14 12:55:20 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2013/06/14 12:55:20 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnaddr.dll
[2013/06/14 12:54:48 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/06/14 12:53:27 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2013/06/14 12:51:46 | 000,240,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/06/14 12:51:46 | 000,187,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/06/14 12:51:38 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2013/06/14 12:51:36 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/06/14 12:51:36 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/06/14 12:50:54 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll
[2013/06/14 12:32:03 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browcli.dll
[2013/06/14 12:30:59 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\System32\fpb.rs
[2013/06/14 12:30:59 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\System32\oflc-nz.rs
[2013/06/14 12:30:59 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\System32\pegibbfc.rs
[2013/06/14 12:30:59 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\System32\csrr.rs
[2013/06/14 12:30:59 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\System32\cob-au.rs
[2013/06/14 12:30:59 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\System32\usk.rs
[2013/06/14 12:30:59 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\System32\grb.rs
[2013/06/14 12:30:59 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi.rs
[2013/06/14 12:30:59 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\System32\djctq.rs
[2013/06/14 12:30:58 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2013/06/14 12:30:58 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wpc.dll
[2013/06/14 12:30:58 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-pt.rs
[2013/06/14 12:30:56 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\System32\cero.rs
[2013/06/14 12:30:56 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\System32\esrb.rs
[2013/06/14 12:30:56 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\System32\oflc.rs
[2013/06/14 12:30:56 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-fi.rs
[2013/06/14 12:30:23 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2013/06/14 12:30:21 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2013/06/14 12:30:21 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2013/06/14 12:30:21 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrmemptylst.exe
[2013/06/14 12:30:17 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profprov.dll
[2013/06/14 12:30:16 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2013/06/14 12:29:39 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/06/14 12:28:51 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/06/11 22:14:09 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcore.dll
[2013/06/11 22:03:01 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2013/06/11 22:03:01 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2013/06/11 22:02:34 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2013/06/11 22:02:34 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2013/06/11 22:02:34 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2013/06/11 22:02:12 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2013/06/11 22:02:12 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2013/06/08 22:23:30 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/06/08 22:23:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\RealNetworks
[2013/06/08 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\RealNetworks
[2013/06/08 22:22:09 | 000,000,000 | —D | C] – C:\ProgramData\RealNetworks
[2013/06/08 22:21:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2013/06/08 22:21:34 | 000,201,872 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2013/06/08 22:21:22 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2013/06/08 22:21:22 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2013/06/08 22:21:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2013/06/08 22:21:18 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[2013/06/08 22:20:56 | 000,000,000 | —D | C] – C:\Program Files\Real
[2013/06/08 22:20:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Real
[2013/06/08 22:20:27 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/06/08 22:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2013/06/08 22:17:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DVDVideoSoft
[13 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/06/19 19:50:43 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/19 19:40:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/19 19:31:06 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000UA.job
[2013/06/19 19:31:05 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/19 19:24:49 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/19 19:17:26 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 19:17:26 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 19:10:36 | 796,729,344 | -HS- | M] () – C:\hiberfil.sys
[2013/06/18 22:49:41 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/06/18 22:49:41 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/06/18 22:49:40 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/06/18 22:49:40 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/06/18 22:49:40 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/18 22:49:39 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/18 22:49:39 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/06/18 22:49:39 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/06/18 22:49:39 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/06/18 22:49:39 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/06/18 22:49:38 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/18 22:49:38 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/06/18 22:49:37 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/06/18 22:49:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/06/18 22:49:37 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/06/18 22:49:37 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/06/18 22:49:37 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/06/18 22:49:37 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/06/18 22:49:36 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/06/18 22:49:36 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/18 22:49:36 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/06/18 22:49:36 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/06/18 22:49:36 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/06/18 22:49:35 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/06/18 22:49:35 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/06/18 22:49:35 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/06/18 22:49:34 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/06/18 22:49:34 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/06/18 22:49:34 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/06/18 22:49:34 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/06/18 22:49:34 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/06/18 22:49:34 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/06/18 22:49:34 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/06/18 22:49:34 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/06/18 22:49:34 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/06/18 22:49:34 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/06/18 22:49:33 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/06/18 22:47:25 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/06/18 22:47:25 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/06/18 22:47:25 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/06/18 22:47:25 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/06/18 22:47:25 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/18 22:47:24 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/06/18 22:47:24 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/06/18 22:47:24 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/06/18 22:47:24 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/06/18 22:47:24 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/06/18 22:47:24 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/06/18 22:47:24 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/06/18 22:47:24 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/06/18 22:47:24 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/06/18 22:47:23 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/06/18 22:47:23 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/06/18 22:31:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000Core.job
[2013/06/18 05:59:01 | 000,628,904 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/06/18 05:59:01 | 000,110,798 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/06/18 05:51:14 | 000,259,112 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/06/17 20:54:52 | 000,001,230 | —- | M] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/17 18:50:10 | 000,000,939 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/17 18:48:24 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/17 06:12:44 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msclmd.dll
[2013/06/17 01:30:43 | 000,449,637 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/06/17 01:25:59 | 000,000,065 | —- | M] () – C:\Windows\wininit.ini
[2013/06/16 23:46:37 | 000,001,224 | —- | M] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 22:33:18 | 000,000,973 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/11 20:49:23 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | M] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:54:21 | 000,002,329 | —- | M] () – C:\Users\User\Desktop\Google Chrome.lnk
[2013/06/08 22:22:23 | 000,001,242 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:34 | 000,201,872 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2013/06/08 22:21:22 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2013/06/08 22:21:22 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2013/06/08 22:21:18 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[13 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/06/18 22:49:34 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/06/17 20:54:52 | 000,001,230 | —- | C] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/17 18:50:10 | 000,000,939 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/17 01:25:59 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2013/06/16 23:46:37 | 000,001,224 | —- | C] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 23:34:06 | 000,161,736 | —- | C] () – C:\Program Files\2bres.dll
[2013/06/16 22:46:44 | 000,002,121 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/06/16 22:33:18 | 000,000,973 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/14 12:58:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/06/14 12:56:39 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/06/11 20:49:23 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | C] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:22:23 | 000,001,242 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:07 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/08 22:21:04 | 000,000,878 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/03 15:32:36 | 000,000,017 | —- | C] () – C:\Windows\System32\shortcut_ex.dat
[2012/01/13 23:37:54 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2011/07/21 15:23:43 | 000,003,584 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/19 19:46:28 | 000,001,940 | —- | C] () – C:\Users\User\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/15 21:00:39 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/17 10:24:14 | 000,131,984 | —- | C] () – C:\ProgramData\FullRemove.exe
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 05:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 13:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/06/17 18:52:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/16 22:32:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/08 22:17:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DVDVideoSoft
[2011/09/22 20:16:12 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
[2013/06/08 22:17:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\OpenCandy
[2011/12/21 18:39:41 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PlayFirst
[2012/03/13 18:13:53 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PriceGong
[2013/03/12 21:08:13 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SoftGrid Client
[2012/08/13 18:00:02 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tatara Systems
[2011/12/04 00:00:04 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tific
[2011/12/04 15:08:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TP
[2013/06/17 18:50:08 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TuneUp Software
[2011/10/05 10:32:19 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Vodafone
[2011/04/30 15:36:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/14 03:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2010/07/14 12:01:28 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2010/02/04 10:56:31 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2010/02/04 10:56:31 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2010/07/14 12:01:28 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/14 03:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\en-US\explorer.exe.mui
[2009/07/14 03:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui
< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/06/17 18:19:08 | 000,119,350 | —- | M] () MD5=03C5E925FD20453367E3C82732E2FD98 – C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
< MD5 for: IEXPLORE.EXE >
[2009/07/14 02:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2013/02/22 05:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_b104f0edc83023b1\iexplore.exe
[2011/12/16 09:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_b378134285f73a44\iexplore.exe
[2013/02/22 05:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_b183bdcce155df6c\iexplore.exe
[2011/08/20 05:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_b360a432860774ff\iexplore.exe
[2011/04/22 20:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_b398812085dee94a\iexplore.exe
[2013/05/17 00:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_b0e94f59c845c389\iexplore.exe
[2011/06/21 06:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_b3c2cf339f43b73b\iexplore.exe
[2011/11/05 05:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_b38fb3ae85e53510\iexplore.exe
[2012/02/29 12:02:06 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2011/06/21 06:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_b38113f685ef212c\iexplore.exe
[2013/05/16 23:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_b1d43d56e11a6501\iexplore.exe
[2011/11/05 05:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_b3d0781f9f391a91\iexplore.exe
[2011/02/24 06:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2011/12/16 10:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_b429fa439ef58435\iexplore.exe
[2010/11/20 13:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe
[2013/06/18 22:49:40 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF – C:\Program Files\Internet Explorer\iexplore.exe
[2013/06/18 22:49:40 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16618_none_ba64eabc65e5aa62\iexplore.exe
[2011/04/22 20:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_b3ffe0d59f14dce7\iexplore.exe
[2011/08/20 05:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_b40487279f125c2e\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2012/02/29 12:02:08 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/06/18 22:49:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/06/18 22:49:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/14 03:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/14 03:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/06/19 19:56:08 | 000,249,762 | —- | M] () MD5=8A325275D92E5956A7CC5016563ECE01 – C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
< MD5 for: SERVICES >
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/14 03:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/14 03:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/14 03:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/14 03:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: SERVICES.SBS >
[2011/03/01 08:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: WINLOGON.ADML >
[2009/07/14 03:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/07/14 12:01:28 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2010/07/14 12:01:28 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 13:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 13:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2009/07/14 03:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui
[2010/11/20 13:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 13:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-0D9AB72B.PF >
[2013/01/05 00:31:59 | 000,036,434 | —- | M] () MD5=36D4E65B25B563CE3B7FD6829F636BE5 – C:\Windows\Prefetch\WINLOGON.EXE-0D9AB72B.pf
< MD5 for: WINLOGON.MFL >
[2009/07/14 03:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/14 03:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/09/17 10:42:19 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/06/19 19:10:36 | 796,729,344 | -HS- | M] () – C:\hiberfil.sys
[2013/06/19 19:10:36 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2010/09/17 10:16:12 | 000,002,089 | —- | M] () – C:\RHDSetup.log
< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/11/20 13:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/17 01:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2011/10/04 08:48:57 | 000,161,736 | —- | M] () – C:\Program Files\2bres.dll
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is C0D2-1310
Directory of C:\
14/07/2009 05:53 Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
14/07/2009 05:53 Application Data [C:\ProgramData]
14/07/2009 05:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 05:53 Documents [C:\Users\Public\Documents]
14/07/2009 05:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 05:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
14/07/2009 05:53 All Users [C:\ProgramData]
14/07/2009 05:53 Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
14/07/2009 05:53 Application Data [C:\ProgramData]
14/07/2009 05:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 05:53 Documents [C:\Users\Public\Documents]
14/07/2009 05:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 05:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
14/07/2009 05:53 Application Data [C:\Users\Default\AppData\Roaming]
14/07/2009 05:53 Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
14/07/2009 05:53 Local Settings [C:\Users\Default\AppData\Local]
14/07/2009 05:53 My Documents [C:\Users\Default\Documents]
14/07/2009 05:53 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
14/07/2009 05:53 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
14/07/2009 05:53 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
14/07/2009 05:53 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
14/07/2009 05:53 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
14/07/2009 05:53 Application Data [C:\Users\Default\AppData\Local]
14/07/2009 05:53 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
14/07/2009 05:53 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
14/07/2009 05:53 My Music [C:\Users\Default\Music]
14/07/2009 05:53 My Pictures [C:\Users\Default\Pictures]
14/07/2009 05:53 My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
14/07/2009 05:53 My Music [C:\Users\Public\Music]
14/07/2009 05:53 My Pictures [C:\Users\Public\Pictures]
14/07/2009 05:53 My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\User
28/04/2011 15:53 Application Data [C:\Users\User\AppData\Roaming]
28/04/2011 15:53 Cookies [C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies]
28/04/2011 15:53 Local Settings [C:\Users\User\AppData\Local]
28/04/2011 15:53 My Documents [C:\Users\User\Documents]
28/04/2011 15:53 NetHood [C:\Users\User\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
28/04/2011 15:53 PrintHood [C:\Users\User\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
28/04/2011 15:53 Recent [C:\Users\User\AppData\Roaming\Microsoft\Windows\Recent]
28/04/2011 15:53 SendTo [C:\Users\User\AppData\Roaming\Microsoft\Windows\SendTo]
28/04/2011 15:53 Start Menu [C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu]
28/04/2011 15:53 Templates [C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\User\AppData\Local
28/04/2011 15:53 Application Data [C:\Users\User\AppData\Local]
28/04/2011 15:53 History [C:\Users\User\AppData\Local\Microsoft\Windows\History]
28/04/2011 15:53 Temporary Internet Files [C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\User\Documents
28/04/2011 15:53 My Music [C:\Users\User\Music]
28/04/2011 15:53 My Pictures [C:\Users\User\Pictures]
28/04/2011 15:53 My Videos [C:\Users\User\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 180,227,072,000 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/29 12:24:03 | 000,000,221 | -HS- | M] () – C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/06/19 19:50:43 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-06-18 21:57:24
========== Alternate Data Streams ==========
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:93EB7685
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:CDFF58FE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:E36F5B57
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1A60DE96
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:798A3728
< End of report >
Extras.
OTL Extras logfile created on: 19/06/2013 20:06:54 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.09 Mb Total Physical Memory | 491.77 Mb Available Physical Memory | 48.54% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.79 Gb Total Space | 167.98 Gb Free Space | 77.85% Space Free | Partition Type: NTFS
Drive D: | 4.00 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: FAT32
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{8D619BA9-CEB9-4CAF-A046-8D0996AFA3F7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{93261F4F-6F49-4F05-BD31-EEC1957E037A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D915D26-632E-4018-86D0-42E0CB68D960}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{13462FC8-47CF-4C6D-B4D8-DF6C74A5B01C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{17166C8E-0410-4825-83C0-C63F83068A6E}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{1FC90693-891B-4627-BCAA-714A3A4036F8}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{20A5C867-274F-42F1-9D16-16A2D07B9D9D}" = dir=in | app=c:\program files\acer\acer vcm\vc.exe |
"{4AE3F81D-6CFC-40C1-98A6-6B7F68688679}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{62E76F29-2A2E-460F-A037-EDF06D25DC76}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{7DD32618-6FCD-4636-A8C1-DB71EA48270B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{8846D206-31DA-4A63-BAEC-A071CBB2FAEC}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{9014FEEA-C54E-4606-9735-974B5DCF8E40}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{9381D105-D510-47B3-89A1-973B571DF66F}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{9E36EDD9-453A-479E-B839-8609260FB58E}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{A3B8FCEA-C3E3-45E6-868E-2BCAF746C86C}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{B03276C1-EC25-475A-8CE0-B3269AE46F1B}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{B94486ED-FC87-4682-9129-00E7ED1FC7F1}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C3B8AE6C-76EF-4813-AD58-19A233FF5A1F}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{D6007FF0-E302-4277-94AD-6649D4AC5171}" = dir=in | app=c:\program files\acer\acer vcm\rs_service.exe |
"{E08EBB58-1B16-4546-AEAA-67DC0D4E094A}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{EDCC8F7A-6059-4E5C-BF8C-8E543F7AD143}" = protocol=6 | dir=in | app=c:\program files\frostwire 5\frostwire.exe |
"{F8D6D454-84E4-4981-A1B8-53ACDC531102}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{FC58E259-A97E-4DBA-8EAE-B628A73E6929}" = protocol=17 | dir=in | app=c:\program files\frostwire 5\frostwire.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20C44F68-5CC1-4EF2-AC9F-744166861406}" = O2 Connection Manager
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java™ 6 Update 27
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2AE79B77-E3FA-4F9C-93D7-4FC643516D6A}" = AVG 2013
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}" = RealDownloader
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523281E5-91DD-49F5-9D85-954148F7596A}" = AndroidInstaller
"{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1" = Acer GameZone Console
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.192.810
"{D774186B-031F-4186-BC4D-B256B9831B85}" = AVG 2013
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"3B29FD3CCF1F5B855DA0C521597413EBABE97DFB" = ENE USB Card Reader Driver
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG" = AVG 2013
"CCleaner" = CCleaner
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{523281E5-91DD-49F5-9D85-954148F7596A}" = AndroidInstaller
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"LManager" = Launch Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"RealPlayer 16.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.94
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"ZTE USB Driver" = ZTE USB Driver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 16/06/2013 17:18:55 | Computer Name = User-PC | Source = CVHSVC | ID = 100
Description = Information only. (Patch task for {90140011-0066-0409-0000-0000000FF1CE}):
DownloadLatest Failed:
Error - 16/06/2013 17:18:55 | Computer Name = User-PC | Source = CVHSVC | ID = 100
Description = Information only. Error: Failed to make the SOAP Call HResult: 0x800c0005.
Exception caught while trying to report the Update Event
Error - 16/06/2013 17:50:22 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 16/06/2013 18:07:53 | Computer Name = User-PC | Source = VSS | ID = 8194
Description =
Error - 16/06/2013 18:11:10 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 16/06/2013 18:36:19 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 16/06/2013 20:03:37 | Computer Name = User-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.
Error - 16/06/2013 20:09:10 | Computer Name = User-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.
Error - 16/06/2013 20:09:41 | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 17/06/2013 00:55:42 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
[ System Events ]
Error - 19/01/2012 16:31:42 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 20/01/2012 07:40:13 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86
Error - 20/01/2012 10:10:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86
Error - 21/01/2012 10:16:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 22/01/2012 09:40:47 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 22/01/2012 16:19:30 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 22/01/2012 17:37:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 23/01/2012 13:46:01 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 24/01/2012 11:18:45 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86
Error - 25/01/2012 10:08:01 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
< End of report >
Hijack Reports and DDS to follow …
The system itself runs with Vista, and has 1Gb memory, with 250 Gb HDD.
Please find the requested files attached.
Thank you in advance for any help.
OTL scan took about 30 seconds before it responded.
OTL.txt
OTL logfile created on: 19/06/2013 20:06:54 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.09 Mb Total Physical Memory | 491.77 Mb Available Physical Memory | 48.54% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.79 Gb Total Space | 167.98 Gb Free Space | 77.85% Space Free | Partition Type: NTFS
Drive D: | 4.00 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: FAT32
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10x_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - (vToolbarUpdater15.2.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (MWLService) – C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (RS_Service) – C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV - (GREGService) – C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (L1C) – system32\DRIVERS\L1C62x86.sys File not found
DRV - (GEARAspiWDM) – system32\DRIVERS\GEARAspiWDM.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (EUCR) – C:\Windows\System32\drivers\EUCR6SK.sys (ENE Technology Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (mwlPSDVDisk) – C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV - (mwlPSDNServ) – C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV - (mwlPSDFilter) – C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com/
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
IE - HKCU\..\SearchScopes\{37D5285D-E43C-4DF7-9108-533774FD7A78}: "URL" = http://websearch.ask.com/redirect?client=i…56-5309080391E3
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(B)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/06/08 22:22:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/06/08 22:22:15 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.conduit.com/?ctid=CT2269050&…amp;sspv=CHSB18
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaaooaijelonlmbcbjkocdnicdfmo\7.13.0.0_0\background/registryAccess.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\BetterCareerSearch_2b\bar\1.bin\NP2bStub.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\User\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: news.net = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmbbgcooaabknohabmoaikiakkoignai\1.0.12_0\
CHR - Extension: AVG Security Toolbar = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.2.0.5_0\
O1 HOSTS File: ([2013/06/17 01:30:43 | 000,449,637 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15435 more lines…
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll File not found
O2 - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{7ff70c81-f37a-4d7b-9d30-ba8ee8c80d5f} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKCU..\Run: [BreakingNews] C:\Program Files\BreakingNews\BreakingNews\DesktopContainer.exe File not found
O4 - HKCU..\Run: [MPOptimizer] "C:\Program Files\MaxPerforma Optimizer\MaxPerforma.exe" /scan File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37096400-4D72-41DD-B37B-C84267CD79C6}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{11bacb60-f4f8-11e0-b91d-18f46ac378bb}\Shell - "" = AutoRun
O33 - MountPoints2\{11bacb60-f4f8-11e0-b91d-18f46ac378bb}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{169b6e5a-5e4c-11e1-a61c-18f46ac378bb}\Shell - "" = AutoRun
O33 - MountPoints2\{169b6e5a-5e4c-11e1-a61c-18f46ac378bb}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{75e89618-ef1a-11e0-b73e-1c750835ad5b}\Shell - "" = AutoRun
O33 - MountPoints2\{75e89618-ef1a-11e0-b73e-1c750835ad5b}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{75e896b9-ef1a-11e0-b73e-1c750835ad5b}\Shell - "" = AutoRun
O33 - MountPoints2\{75e896b9-ef1a-11e0-b73e-1c750835ad5b}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/06/19 19:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/19 19:27:12 | 000,000,000 | —D | C] – C:\Users\User\Documents\My Received Files
[2013/06/18 22:49:41 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/06/18 22:49:41 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/06/18 22:49:40 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/06/18 22:49:40 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/06/18 22:49:39 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/06/18 22:49:39 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/06/18 22:49:39 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/06/18 22:49:39 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/06/18 22:49:39 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/18 22:49:38 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/18 22:49:38 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/18 22:49:38 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/06/18 22:49:37 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/06/18 22:49:37 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/06/18 22:49:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/06/18 22:49:37 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/06/18 22:49:37 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/06/18 22:49:36 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/06/18 22:49:36 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/06/18 22:49:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/06/18 22:49:36 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/06/18 22:49:36 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/06/18 22:49:35 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/18 22:49:35 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/06/18 22:49:35 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/06/18 22:49:34 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/06/18 22:49:34 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/06/18 22:49:34 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/06/18 22:49:34 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/06/18 22:49:34 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/06/18 22:49:34 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/06/18 22:49:34 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/06/18 22:49:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/06/18 22:49:34 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/06/18 22:49:33 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/06/18 22:49:33 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/06/18 22:47:25 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/06/18 22:47:25 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/06/18 22:47:25 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/06/18 22:47:25 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/18 22:47:24 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/06/18 22:47:24 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/06/18 22:47:24 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/06/18 22:47:24 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/06/18 22:47:24 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/06/18 22:47:24 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/06/18 22:47:24 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/06/18 22:47:24 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/06/18 22:47:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/06/18 22:47:23 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/06/18 22:47:23 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/06/18 22:47:23 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/06/17 20:54:50 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2013/06/17 20:54:47 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2013/06/17 19:09:46 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/06/17 19:08:16 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/06/17 19:05:54 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OxpsConverter.exe
[2013/06/17 19:05:41 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/06/17 19:05:31 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptdlg.dll
[2013/06/17 19:04:36 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/06/17 19:04:22 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/06/17 19:04:18 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certenc.dll
[2013/06/17 19:03:14 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2013/06/17 19:03:12 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcorehc.dll
[2013/06/17 19:03:09 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/06/17 19:01:40 | 003,913,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/06/17 19:01:39 | 003,968,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/06/17 19:00:49 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2013/06/17 19:00:47 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
[2013/06/17 19:00:38 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcore6.dll
[2013/06/17 19:00:38 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/06/17 18:59:57 | 000,101,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2013/06/17 18:59:56 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2013/06/17 18:52:33 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/17 18:50:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\AVG Secure Search
[2013/06/17 18:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/06/17 18:49:56 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/06/17 18:49:16 | 000,037,664 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/17 18:49:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/06/17 18:48:55 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/06/17 18:44:09 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/06/17 18:44:09 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/06/17 18:42:08 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/06/17 18:36:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Avg2013
[2013/06/17 06:47:45 | 000,000,000 | —D | C] – C:\9e856ef85da9b57ffd821680f163a2
[2013/06/17 05:47:58 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2013/06/17 05:47:57 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2013/06/17 05:19:38 | 000,000,000 | —D | C] – C:\Windows\System32\SPReview
[2013/06/17 05:18:04 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2013/06/16 23:46:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/06/16 23:46:00 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/06/16 22:45:20 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2013/06/16 22:33:15 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/06/16 22:32:47 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/14 12:58:13 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/06/14 12:58:13 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/06/14 12:57:16 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/06/14 12:57:16 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/06/14 12:56:41 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/06/14 12:56:39 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/06/14 12:56:39 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/06/14 12:56:03 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/06/14 12:56:03 | 000,262,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rstrui.exe
[2013/06/14 12:55:55 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/06/14 12:55:20 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2013/06/14 12:55:20 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnaddr.dll
[2013/06/14 12:54:48 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/06/14 12:53:27 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2013/06/14 12:51:46 | 000,240,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/06/14 12:51:46 | 000,187,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/06/14 12:51:38 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2013/06/14 12:51:36 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/06/14 12:51:36 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/06/14 12:51:36 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/06/14 12:51:36 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/06/14 12:50:54 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll
[2013/06/14 12:32:03 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browcli.dll
[2013/06/14 12:30:59 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\System32\fpb.rs
[2013/06/14 12:30:59 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\System32\oflc-nz.rs
[2013/06/14 12:30:59 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\System32\pegibbfc.rs
[2013/06/14 12:30:59 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\System32\csrr.rs
[2013/06/14 12:30:59 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\System32\cob-au.rs
[2013/06/14 12:30:59 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\System32\usk.rs
[2013/06/14 12:30:59 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\System32\grb.rs
[2013/06/14 12:30:59 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi.rs
[2013/06/14 12:30:59 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\System32\djctq.rs
[2013/06/14 12:30:58 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2013/06/14 12:30:58 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wpc.dll
[2013/06/14 12:30:58 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-pt.rs
[2013/06/14 12:30:56 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\System32\cero.rs
[2013/06/14 12:30:56 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\System32\esrb.rs
[2013/06/14 12:30:56 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\System32\oflc.rs
[2013/06/14 12:30:56 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\System32\pegi-fi.rs
[2013/06/14 12:30:23 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2013/06/14 12:30:21 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2013/06/14 12:30:21 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2013/06/14 12:30:21 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrmemptylst.exe
[2013/06/14 12:30:17 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profprov.dll
[2013/06/14 12:30:16 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2013/06/14 12:29:39 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/06/14 12:28:51 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/06/11 22:14:09 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcore.dll
[2013/06/11 22:03:01 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2013/06/11 22:03:01 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2013/06/11 22:02:34 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2013/06/11 22:02:34 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2013/06/11 22:02:34 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2013/06/11 22:02:12 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2013/06/11 22:02:12 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2013/06/08 22:23:30 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/06/08 22:23:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\RealNetworks
[2013/06/08 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\RealNetworks
[2013/06/08 22:22:09 | 000,000,000 | —D | C] – C:\ProgramData\RealNetworks
[2013/06/08 22:21:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2013/06/08 22:21:34 | 000,201,872 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2013/06/08 22:21:22 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2013/06/08 22:21:22 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2013/06/08 22:21:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2013/06/08 22:21:18 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[2013/06/08 22:20:56 | 000,000,000 | —D | C] – C:\Program Files\Real
[2013/06/08 22:20:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Real
[2013/06/08 22:20:27 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/06/08 22:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2013/06/08 22:17:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DVDVideoSoft
[13 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/06/19 19:50:43 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/06/19 19:40:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/19 19:31:06 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000UA.job
[2013/06/19 19:31:05 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/19 19:24:49 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/19 19:17:26 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 19:17:26 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 19:10:36 | 796,729,344 | -HS- | M] () – C:\hiberfil.sys
[2013/06/18 22:49:41 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/06/18 22:49:41 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/06/18 22:49:40 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/06/18 22:49:40 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/06/18 22:49:40 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/18 22:49:39 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/18 22:49:39 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/06/18 22:49:39 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/06/18 22:49:39 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/06/18 22:49:39 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/06/18 22:49:38 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/18 22:49:38 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/06/18 22:49:37 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/06/18 22:49:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/06/18 22:49:37 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/06/18 22:49:37 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/06/18 22:49:37 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/06/18 22:49:37 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/06/18 22:49:36 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/06/18 22:49:36 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/06/18 22:49:36 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/06/18 22:49:36 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/06/18 22:49:36 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/06/18 22:49:35 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/06/18 22:49:35 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/06/18 22:49:35 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/06/18 22:49:34 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/06/18 22:49:34 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/06/18 22:49:34 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/06/18 22:49:34 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/06/18 22:49:34 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/06/18 22:49:34 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/06/18 22:49:34 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/06/18 22:49:34 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/06/18 22:49:34 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/06/18 22:49:34 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/06/18 22:49:33 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/06/18 22:47:25 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/06/18 22:47:25 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/06/18 22:47:25 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/06/18 22:47:25 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/06/18 22:47:25 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/18 22:47:25 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/18 22:47:25 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/18 22:47:25 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/18 22:47:24 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/06/18 22:47:24 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/06/18 22:47:24 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/06/18 22:47:24 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/06/18 22:47:24 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/06/18 22:47:24 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/06/18 22:47:24 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/06/18 22:47:24 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/06/18 22:47:24 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/06/18 22:47:23 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/06/18 22:47:23 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/06/18 22:31:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1724070015-2864343876-1984321240-1000Core.job
[2013/06/18 05:59:01 | 000,628,904 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/06/18 05:59:01 | 000,110,798 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/06/18 05:51:14 | 000,259,112 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/06/17 20:54:52 | 000,001,230 | —- | M] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/17 18:50:10 | 000,000,939 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/17 18:48:24 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/17 06:12:44 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msclmd.dll
[2013/06/17 01:30:43 | 000,449,637 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/06/17 01:25:59 | 000,000,065 | —- | M] () – C:\Windows\wininit.ini
[2013/06/16 23:46:37 | 000,001,224 | —- | M] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 22:33:18 | 000,000,973 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/11 20:49:23 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | M] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:54:21 | 000,002,329 | —- | M] () – C:\Users\User\Desktop\Google Chrome.lnk
[2013/06/08 22:22:23 | 000,001,242 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:34 | 000,201,872 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2013/06/08 22:21:22 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2013/06/08 22:21:22 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2013/06/08 22:21:18 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\System32\pncrt.dll
[13 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/06/18 22:49:34 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/06/17 20:54:52 | 000,001,230 | —- | C] () – C:\Users\User\Desktop\Revo Uninstaller.lnk
[2013/06/17 18:50:10 | 000,000,939 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/17 01:25:59 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2013/06/16 23:46:37 | 000,001,224 | —- | C] () – C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2013/06/16 23:34:06 | 000,161,736 | —- | C] () – C:\Program Files\2bres.dll
[2013/06/16 22:46:44 | 000,002,121 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/06/16 22:33:18 | 000,000,973 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/06/14 12:58:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/06/14 12:56:39 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/06/11 20:49:23 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2013/06/11 20:49:10 | 000,003,439 | —- | C] () – C:\Users\User\Documents\Marks CV.rtf
[2013/06/08 22:22:23 | 000,001,242 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2013/06/08 22:21:07 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/08 22:21:04 | 000,000,878 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/03 15:32:36 | 000,000,017 | —- | C] () – C:\Windows\System32\shortcut_ex.dat
[2012/01/13 23:37:54 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2011/07/21 15:23:43 | 000,003,584 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/19 19:46:28 | 000,001,940 | —- | C] () – C:\Users\User\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/15 21:00:39 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/17 10:24:14 | 000,131,984 | —- | C] () – C:\ProgramData\FullRemove.exe
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 05:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 13:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 02:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/06/17 18:52:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2013
[2013/06/16 22:32:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVSoftware
[2013/06/08 22:17:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DVDVideoSoft
[2011/09/22 20:16:12 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DVDVideoSoftIEHelpers
[2013/06/08 22:17:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\OpenCandy
[2011/12/21 18:39:41 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PlayFirst
[2012/03/13 18:13:53 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PriceGong
[2013/03/12 21:08:13 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SoftGrid Client
[2012/08/13 18:00:02 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tatara Systems
[2011/12/04 00:00:04 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tific
[2011/12/04 15:08:47 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TP
[2013/06/17 18:50:08 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TuneUp Software
[2011/10/05 10:32:19 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Vodafone
[2011/04/30 15:36:33 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/14 03:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 22:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2010/07/14 12:01:28 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2010/02/04 10:56:31 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2010/02/04 10:56:31 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2010/07/14 12:01:28 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/14 03:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\en-US\explorer.exe.mui
[2009/07/14 03:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui
< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/06/17 18:19:08 | 000,119,350 | —- | M] () MD5=03C5E925FD20453367E3C82732E2FD98 – C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
< MD5 for: IEXPLORE.EXE >
[2009/07/14 02:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2013/02/22 05:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_b104f0edc83023b1\iexplore.exe
[2011/12/16 09:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_b378134285f73a44\iexplore.exe
[2013/02/22 05:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_b183bdcce155df6c\iexplore.exe
[2011/08/20 05:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_b360a432860774ff\iexplore.exe
[2011/04/22 20:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_b398812085dee94a\iexplore.exe
[2013/05/17 00:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_b0e94f59c845c389\iexplore.exe
[2011/06/21 06:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_b3c2cf339f43b73b\iexplore.exe
[2011/11/05 05:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_b38fb3ae85e53510\iexplore.exe
[2012/02/29 12:02:06 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2011/06/21 06:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_b38113f685ef212c\iexplore.exe
[2013/05/16 23:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_b1d43d56e11a6501\iexplore.exe
[2011/11/05 05:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_b3d0781f9f391a91\iexplore.exe
[2011/02/24 06:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2011/12/16 10:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_b429fa439ef58435\iexplore.exe
[2010/11/20 13:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2011/02/24 06:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe
[2013/06/18 22:49:40 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF – C:\Program Files\Internet Explorer\iexplore.exe
[2013/06/18 22:49:40 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16618_none_ba64eabc65e5aa62\iexplore.exe
[2011/04/22 20:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_b3ffe0d59f14dce7\iexplore.exe
[2011/08/20 05:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_b40487279f125c2e\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2012/02/29 12:02:08 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/06/18 22:49:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/06/18 22:49:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/14 03:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/14 03:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/06/19 19:56:08 | 000,249,762 | —- | M] () MD5=8A325275D92E5956A7CC5016563ECE01 – C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
< MD5 for: SERVICES >
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 22:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/14 03:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/14 03:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 22:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/14 03:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/14 03:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 21:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: SERVICES.SBS >
[2011/03/01 08:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: WINLOGON.ADML >
[2009/07/14 03:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/07/14 12:01:28 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2010/07/14 12:01:28 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 13:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 13:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2009/07/14 03:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui
[2010/11/20 13:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 13:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-0D9AB72B.PF >
[2013/01/05 00:31:59 | 000,036,434 | —- | M] () MD5=36D4E65B25B563CE3B7FD6829F636BE5 – C:\Windows\Prefetch\WINLOGON.EXE-0D9AB72B.pf
< MD5 for: WINLOGON.MFL >
[2009/07/14 03:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/14 03:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 21:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/09/17 10:42:19 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/06/19 19:10:36 | 796,729,344 | -HS- | M] () – C:\hiberfil.sys
[2013/06/19 19:10:36 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2010/09/17 10:16:12 | 000,002,089 | —- | M] () – C:\RHDSetup.log
< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/11/20 13:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/17 01:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2011/10/04 08:48:57 | 000,161,736 | —- | M] () – C:\Program Files\2bres.dll
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is C0D2-1310
Directory of C:\
14/07/2009 05:53 Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
14/07/2009 05:53 Application Data [C:\ProgramData]
14/07/2009 05:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 05:53 Documents [C:\Users\Public\Documents]
14/07/2009 05:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 05:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
14/07/2009 05:53 All Users [C:\ProgramData]
14/07/2009 05:53 Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
14/07/2009 05:53 Application Data [C:\ProgramData]
14/07/2009 05:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 05:53 Documents [C:\Users\Public\Documents]
14/07/2009 05:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 05:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
14/07/2009 05:53 Application Data [C:\Users\Default\AppData\Roaming]
14/07/2009 05:53 Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
14/07/2009 05:53 Local Settings [C:\Users\Default\AppData\Local]
14/07/2009 05:53 My Documents [C:\Users\Default\Documents]
14/07/2009 05:53 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
14/07/2009 05:53 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
14/07/2009 05:53 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
14/07/2009 05:53 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
14/07/2009 05:53 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
14/07/2009 05:53 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
14/07/2009 05:53 Application Data [C:\Users\Default\AppData\Local]
14/07/2009 05:53 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
14/07/2009 05:53 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
14/07/2009 05:53 My Music [C:\Users\Default\Music]
14/07/2009 05:53 My Pictures [C:\Users\Default\Pictures]
14/07/2009 05:53 My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
14/07/2009 05:53 My Music [C:\Users\Public\Music]
14/07/2009 05:53 My Pictures [C:\Users\Public\Pictures]
14/07/2009 05:53 My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\User
28/04/2011 15:53 Application Data [C:\Users\User\AppData\Roaming]
28/04/2011 15:53 Cookies [C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies]
28/04/2011 15:53 Local Settings [C:\Users\User\AppData\Local]
28/04/2011 15:53 My Documents [C:\Users\User\Documents]
28/04/2011 15:53 NetHood [C:\Users\User\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
28/04/2011 15:53 PrintHood [C:\Users\User\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
28/04/2011 15:53 Recent [C:\Users\User\AppData\Roaming\Microsoft\Windows\Recent]
28/04/2011 15:53 SendTo [C:\Users\User\AppData\Roaming\Microsoft\Windows\SendTo]
28/04/2011 15:53 Start Menu [C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu]
28/04/2011 15:53 Templates [C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\User\AppData\Local
28/04/2011 15:53 Application Data [C:\Users\User\AppData\Local]
28/04/2011 15:53 History [C:\Users\User\AppData\Local\Microsoft\Windows\History]
28/04/2011 15:53 Temporary Internet Files [C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\User\Documents
28/04/2011 15:53 My Music [C:\Users\User\Music]
28/04/2011 15:53 My Pictures [C:\Users\User\Pictures]
28/04/2011 15:53 My Videos [C:\Users\User\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 180,227,072,000 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/29 12:24:03 | 000,000,221 | -HS- | M] () – C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/06/19 19:50:43 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-06-18 21:57:24
========== Alternate Data Streams ==========
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:93EB7685
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:CDFF58FE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:E36F5B57
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:1A60DE96
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:798A3728
< End of report >
Extras.
OTL Extras logfile created on: 19/06/2013 20:06:54 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16618)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.09 Mb Total Physical Memory | 491.77 Mb Available Physical Memory | 48.54% Memory free
1.99 Gb Paging File | 1.04 Gb Available in Paging File | 52.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.79 Gb Total Space | 167.98 Gb Free Space | 77.85% Space Free | Partition Type: NTFS
Drive D: | 4.00 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: FAT32
Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{8D619BA9-CEB9-4CAF-A046-8D0996AFA3F7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{93261F4F-6F49-4F05-BD31-EEC1957E037A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D915D26-632E-4018-86D0-42E0CB68D960}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{13462FC8-47CF-4C6D-B4D8-DF6C74A5B01C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{17166C8E-0410-4825-83C0-C63F83068A6E}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{1FC90693-891B-4627-BCAA-714A3A4036F8}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{20A5C867-274F-42F1-9D16-16A2D07B9D9D}" = dir=in | app=c:\program files\acer\acer vcm\vc.exe |
"{4AE3F81D-6CFC-40C1-98A6-6B7F68688679}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{62E76F29-2A2E-460F-A037-EDF06D25DC76}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{7DD32618-6FCD-4636-A8C1-DB71EA48270B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{8846D206-31DA-4A63-BAEC-A071CBB2FAEC}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{9014FEEA-C54E-4606-9735-974B5DCF8E40}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{9381D105-D510-47B3-89A1-973B571DF66F}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{9E36EDD9-453A-479E-B839-8609260FB58E}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{A3B8FCEA-C3E3-45E6-868E-2BCAF746C86C}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{B03276C1-EC25-475A-8CE0-B3269AE46F1B}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{B94486ED-FC87-4682-9129-00E7ED1FC7F1}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C3B8AE6C-76EF-4813-AD58-19A233FF5A1F}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
"{D6007FF0-E302-4277-94AD-6649D4AC5171}" = dir=in | app=c:\program files\acer\acer vcm\rs_service.exe |
"{E08EBB58-1B16-4546-AEAA-67DC0D4E094A}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{EDCC8F7A-6059-4E5C-BF8C-8E543F7AD143}" = protocol=6 | dir=in | app=c:\program files\frostwire 5\frostwire.exe |
"{F8D6D454-84E4-4981-A1B8-53ACDC531102}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{FC58E259-A97E-4DBA-8EAE-B628A73E6929}" = protocol=17 | dir=in | app=c:\program files\frostwire 5\frostwire.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20C44F68-5CC1-4EF2-AC9F-744166861406}" = O2 Connection Manager
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java™ 6 Update 27
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2AE79B77-E3FA-4F9C-93D7-4FC643516D6A}" = AVG 2013
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}" = RealDownloader
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523281E5-91DD-49F5-9D85-954148F7596A}" = AndroidInstaller
"{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1" = Acer GameZone Console
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.192.810
"{D774186B-031F-4186-BC4D-B256B9831B85}" = AVG 2013
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"3B29FD3CCF1F5B855DA0C521597413EBABE97DFB" = ENE USB Card Reader Driver
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG" = AVG 2013
"CCleaner" = CCleaner
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{523281E5-91DD-49F5-9D85-954148F7596A}" = AndroidInstaller
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"LManager" = Launch Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"RealPlayer 16.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.94
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"ZTE USB Driver" = ZTE USB Driver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 16/06/2013 17:18:55 | Computer Name = User-PC | Source = CVHSVC | ID = 100
Description = Information only. (Patch task for {90140011-0066-0409-0000-0000000FF1CE}):
DownloadLatest Failed:
Error - 16/06/2013 17:18:55 | Computer Name = User-PC | Source = CVHSVC | ID = 100
Description = Information only. Error: Failed to make the SOAP Call HResult: 0x800c0005.
Exception caught while trying to report the Update Event
Error - 16/06/2013 17:50:22 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 16/06/2013 18:07:53 | Computer Name = User-PC | Source = VSS | ID = 8194
Description =
Error - 16/06/2013 18:11:10 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 16/06/2013 18:36:19 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 16/06/2013 20:03:37 | Computer Name = User-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.
Error - 16/06/2013 20:09:10 | Computer Name = User-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.
Error - 16/06/2013 20:09:41 | Computer Name = User-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 17/06/2013 00:55:42 | Computer Name = User-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
[ System Events ]
Error - 19/01/2012 16:31:42 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 20/01/2012 07:40:13 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86
Error - 20/01/2012 10:10:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86
Error - 21/01/2012 10:16:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 22/01/2012 09:40:47 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 22/01/2012 16:19:30 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 22/01/2012 17:37:54 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 23/01/2012 13:46:01 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
Error - 24/01/2012 11:18:45 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86
Error - 25/01/2012 10:08:01 | Computer Name = User-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
BHDrvx86 cdrom
< End of report >
Hijack Reports and DDS to follow …