OTL logfile created on: 11/11/2011 3:10:37 PM - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Zoltan\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.97 Gb Total Physical Memory | 1.62 Gb Available Physical Memory | 54.66% Memory free 6.13 Gb Paging File | 4.73 Gb Available in Paging File | 77.19% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 116.44 Gb Total Space | 95.03 Gb Free Space | 81.61% Space Free | Partition Type: NTFS Drive D: | 104.72 Gb Total Space | 104.62 Gb Free Space | 99.90% Space Free | Partition Type: NTFS Computer Name: CORVETTEZR1 | User Name: Zoltan | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011/11/11 14:39:01 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Zoltan\Desktop\OTL.exe PRC - [2011/11/11 13:40:52 | 000,307,376 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe PRC - [2011/11/11 13:33:51 | 000,246,624 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe PRC - [2011/11/11 13:33:51 | 000,218,464 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe PRC - [2011/10/24 20:29:16 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe PRC - [2011/10/18 06:14:54 | 001,229,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe PRC - [2009/08/23 22:32:00 | 003,054,136 | ---- | M] (ASUS) -- C:\Windows\AsScrPro.exe PRC - [2009/08/23 21:42:38 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009/03/22 23:52:13 | 017,149,952 | ---- | M] (VIA) -- C:\Program Files\VIA\VIAudioi\VDeck\VDECK.EXE PRC - [2009/03/20 20:37:18 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATK Hotkey\HControl.exe PRC - [2009/03/18 15:54:58 | 000,154,168 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe PRC - [2009/03/06 04:44:49 | 000,424,352 | ---- | M] (ELAN Microelectronic Corp.) -- C:\Program Files\Elantech\ETDCtrl.exe PRC - [2009/03/04 10:26:24 | 008,392,704 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe PRC - [2009/02/06 16:13:16 | 001,593,344 | ---- | M] () -- C:\Program Files\ASUS\Wireless Console 3\wcourier.exe PRC - [2008/12/29 10:21:02 | 000,159,744 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATK Media\DMedia.exe PRC - [2008/12/22 17:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATK Hotkey\WDC.exe PRC - [2008/12/09 15:00:58 | 000,297,528 | ---- | M] (ASUS) -- C:\Program Files\ASUS\SmartLogon\sensorsrv.exe PRC - [2008/11/26 19:54:00 | 000,211,512 | ---- | M] (ATK) -- C:\Program Files\P4G\BatteryLife.exe PRC - [2008/09/30 23:02:48 | 000,851,968 | ---- | M] (ATK) -- C:\Program Files\ASUS\Splendid\ACMON.exe PRC - [2008/09/30 15:17:32 | 000,237,568 | ---- | M] (AlcorMicro Co., Ltd.) -- C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe PRC - [2008/08/18 11:27:32 | 000,117,304 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe PRC - [2008/08/18 10:56:22 | 000,098,304 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe PRC - [2008/08/13 21:00:08 | 000,113,208 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe PRC - [2008/08/13 20:59:52 | 000,100,920 | ---- | M] () -- C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe PRC - [2008/08/13 16:21:56 | 002,482,176 | ---- | M] (ASUS) -- C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe PRC - [2008/07/18 19:52:16 | 000,104,936 | ---- | M] (CyberLink) -- C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe PRC - [2008/03/31 23:09:30 | 000,266,240 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe PRC - [2008/03/31 02:55:48 | 000,225,280 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe PRC - [2008/01/20 19:24:54 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe PRC - [2007/11/30 11:20:44 | 000,051,768 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe PRC - [2007/08/08 00:08:40 | 000,094,208 | ---- | M] () -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe PRC - [2005/07/06 15:43:42 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\Windows\System32\ACEngSvr.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011/11/11 13:33:51 | 001,451,336 | ---- | M] () -- C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll MOD - [2011/11/11 13:33:51 | 000,218,464 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe MOD - [2009/01/06 02:11:43 | 000,090,112 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\DTS2APOAPI.DLL MOD - [2008/10/30 15:37:04 | 000,015,360 | ---- | M] () -- C:\Program Files\P4G\OvrClk.dll MOD - [2008/08/27 16:32:36 | 000,619,816 | ---- | M] () -- C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll MOD - [2008/08/20 15:49:56 | 000,016,384 | ---- | M] () -- C:\Program Files\P4G\DevMng.dll MOD - [2008/06/09 09:55:08 | 000,013,096 | ---- | M] () -- C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll MOD - [2008/03/17 02:49:59 | 000,069,632 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\QSAPOAPI.DLL MOD - [2008/02/13 22:56:59 | 000,094,208 | ---- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\VMICAPI.DLL MOD - [2007/11/30 11:20:44 | 000,051,768 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe MOD - [2007/11/12 15:41:50 | 000,106,496 | ---- | M] () -- C:\Program Files\ASUS\ATK Hotkey\MsgTran.dll MOD - [2007/06/15 10:28:36 | 000,147,456 | ---- | M] () -- C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll MOD - [2007/06/01 17:08:18 | 000,143,360 | ---- | M] () -- C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll MOD - [2007/03/09 16:16:52 | 000,106,496 | ---- | M] () -- C:\Program Files\ATKGFNEX\AGFNEX.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- -- (Norton Internet Security) SRV - [2011/11/11 13:33:51 | 000,246,624 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe -- (vToolbarUpdater) SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent) SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd) SRV - [2009/08/23 21:37:43 | 000,110,576 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\ProgramData\Partner\partner.exe -- (Partner Service) SRV - [2008/08/13 20:59:52 | 000,100,920 | ---- | M] () [Auto | Running] -- C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService) SRV - [2008/03/31 02:55:48 | 000,225,280 | ---- | M] (ASUSTek Computer Inc.) [Auto | Running] -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe -- (ADSMService) SRV - [2008/01/20 19:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007/08/08 00:08:40 | 000,094,208 | ---- | M] () [Auto | Running] -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2011/10/04 06:21:16 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim) DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86) DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2011/07/11 01:14:02 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter) DRV - [2011/07/11 01:14:00 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH) DRV - [2011/07/11 01:13:58 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver) DRV - [2009/08/23 22:29:00 | 000,030,264 | ---- | M] (ASUSTek Computer Inc) [File_System | Boot | Running] -- C:\Windows\System32\drivers\AsDsm.sys -- (AsDsm) DRV - [2009/03/19 23:21:37 | 000,984,064 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV - [2009/01/14 12:51:50 | 000,230,952 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SRS_PremiumSound_i386.sys -- (SRS_PremiumSound_Service) DRV - [2008/12/24 01:39:43 | 000,014,392 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2008/12/20 00:01:46 | 001,093,120 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008/12/15 23:05:37 | 000,048,128 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1E60x86.sys -- (L1E) DRV - [2008/11/04 10:15:59 | 001,753,984 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC) DRV - [2008/11/03 00:03:27 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr) DRV - [2008/05/29 09:21:04 | 000,015,416 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\lullaby.sys -- (lullaby) DRV - [2008/05/23 17:25:42 | 000,131,000 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) DRV - [2007/07/24 11:09:04 | 000,013,880 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ATKGFNEX\ASMMAP.sys -- (ASMMAP) DRV - [2006/11/02 00:41:49 | 001,010,560 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/11/11 13:33:56 | 000,000,000 | ---D | M] O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll (Google Inc.) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll () O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found. O4 - HKLM..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe (ATK) O4 - HKLM..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.) O4 - HKLM..\Run: [AmIcoSinglun] C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.) O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe () O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe (ASUS) O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUS) O4 - HKLM..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS) O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [DisableS3S4] c:\DisableS3S4.cmd File not found O4 - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.) O4 - HKLM..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe () O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files\ASUS\Wireless Console 3\wcourier.exe () O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 199.185.220.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6123B054-5316-45E3-BA5B-3B0A737D36EC}: DhcpNameServer = 192.168.1.254 199.185.220.254 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll () O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011/11/11 15:09:21 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\Desktop\New Folder [2011/11/11 14:39:00 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Zoltan\Desktop\OTL.exe [2011/11/11 13:58:35 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2011/11/11 13:56:16 | 000,000,000 | -H-D | C] -- C:\$AVG [2011/11/11 13:43:47 | 000,044,544 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\agremove.exe [2011/11/11 13:38:05 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Roaming\AVG2012 [2011/11/11 13:33:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012 [2011/11/11 13:33:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search [2011/11/11 13:33:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2011/11/11 13:33:50 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search [2011/11/11 13:33:32 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012 [2011/11/11 13:33:32 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG [2011/11/11 13:33:20 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2011/11/11 13:29:19 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2011/11/11 13:28:51 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2011/11/11 13:28:11 | 002,421,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll [2011/11/11 13:28:11 | 000,044,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll [2011/11/11 13:28:04 | 000,575,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll [2011/11/11 13:28:04 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll [2011/11/11 13:28:04 | 000,035,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll [2011/11/11 13:28:02 | 000,171,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll [2011/11/11 13:28:02 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe [2011/11/11 13:26:51 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Roaming\Google [2011/11/11 13:26:51 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Local\Google [2011/11/11 13:16:25 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Local\Power2Go [2011/11/11 13:16:08 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011/11/11 13:16:08 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Searches [2011/11/11 13:16:08 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011/11/11 13:16:01 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Roaming\Identities [2011/11/11 13:16:00 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Contacts [2011/11/11 13:15:29 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Local\VirtualStore [2011/11/11 13:14:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2011/11/11 13:13:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in [2011/11/11 13:13:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office Outlook Connector [2011/11/11 13:13:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE [2011/11/11 13:13:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework [2011/11/11 13:12:56 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll [2011/11/11 13:12:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition [2011/11/11 13:12:15 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft [2011/11/11 13:12:07 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft [2011/11/11 13:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive [2011/11/11 13:11:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live [2011/11/11 13:11:48 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live [2011/11/11 13:10:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live [2011/11/11 13:09:14 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Roaming\Macromedia [2011/11/11 13:09:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR [2011/11/11 13:09:14 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Roaming\Adobe [2011/11/11 13:08:53 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2011/11/11 13:08:44 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Local\Adobe [2011/11/11 13:07:20 | 000,000,000 | --SD | C] -- C:\Users\Zoltan\AppData\Roaming\Microsoft [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Videos [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Saved Games [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Pictures [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Music [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Links [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Favorites [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Downloads [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Documents [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\Desktop [2011/11/11 13:07:20 | 000,000,000 | R--D | C] -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\AppData\Local\Temporary Internet Files [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Templates [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Start Menu [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\SendTo [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Recent [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\PrintHood [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\NetHood [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Documents\My Videos [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Documents\My Pictures [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Documents\My Music [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\My Documents [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Local Settings [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\AppData\Local\History [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Cookies [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\Application Data [2011/11/11 13:07:20 | 000,000,000 | -HSD | C] -- C:\Users\Zoltan\AppData\Local\Application Data [2011/11/11 13:07:20 | 000,000,000 | -H-D | C] -- C:\Users\Zoltan\AppData [2011/11/11 13:07:20 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Local\Temp [2011/11/11 13:07:20 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Local\Microsoft [2011/11/11 13:07:20 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Roaming\Media Center Programs [2011/11/11 13:07:20 | 000,000,000 | ---D | C] -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite [2011/10/17 10:43:03 | 000,009,728 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\wceprv.dll [2011/10/17 10:43:02 | 000,034,816 | ---- | C] (Absolute Software Corporation) -- C:\Windows\System32\identprv.dll [2008/11/04 10:13:59 | 000,176,128 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll [2008/11/03 00:03:27 | 000,013,880 | ---- | C] ( ) -- C:\Windows\System32\drivers\kbfiltr.sys [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011/11/11 14:40:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/11/11 14:39:01 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Zoltan\Desktop\OTL.exe [2011/11/11 14:05:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011/11/11 13:49:53 | 000,667,686 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2011/11/11 13:49:53 | 000,665,410 | ---- | M] () -- C:\Windows\System32\perfh00A.dat [2011/11/11 13:49:53 | 000,595,684 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011/11/11 13:49:53 | 000,336,828 | ---- | M] () -- C:\Windows\System32\prfh0404.dat [2011/11/11 13:49:53 | 000,129,298 | ---- | M] () -- C:\Windows\System32\perfc00A.dat [2011/11/11 13:49:53 | 000,123,076 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2011/11/11 13:49:53 | 000,101,350 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011/11/11 13:49:53 | 000,101,188 | ---- | M] () -- C:\Windows\System32\prfc0404.dat [2011/11/11 13:43:51 | 000,044,544 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\agremove.exe [2011/11/11 13:42:32 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe [2011/11/11 13:42:29 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/11/11 13:42:16 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011/11/11 13:42:16 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011/11/11 13:41:54 | 3184,615,424 | -HS- | M] () -- C:\hiberfil.sys [2011/11/11 13:41:20 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2011/11/11 13:39:31 | 070,995,275 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm [2011/11/11 13:35:48 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\1043_ASUSTeK_K40IJ.alu [2011/11/11 13:33:56 | 000,000,849 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011/11/11 13:26:52 | 000,000,950 | ---- | M] () -- C:\Users\Zoltan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/11/11 13:09:02 | 000,001,894 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2011/11/11 13:03:00 | 000,047,092 | ---- | M] () -- C:\Windows\System32\license.rtf [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011/11/11 13:39:31 | 070,995,275 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm [2011/11/11 13:35:48 | 000,000,000 | ---- | C] () -- C:\Windows\System32\drivers\1043_ASUSTeK_K40IJ.alu [2011/11/11 13:33:56 | 000,000,849 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011/11/11 13:30:32 | 000,000,886 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/11/11 13:30:32 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/11/11 13:26:52 | 000,000,950 | ---- | C] () -- C:\Users\Zoltan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/11/11 13:16:14 | 000,000,956 | ---- | C] () -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011/11/11 13:16:07 | 000,000,951 | ---- | C] () -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [2011/11/11 13:16:00 | 000,000,922 | ---- | C] () -- C:\Users\Zoltan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk [2011/11/11 13:09:23 | 000,000,893 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk [2011/11/11 13:09:02 | 000,001,894 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2011/11/11 13:09:01 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk [2011/11/11 13:07:20 | 000,000,258 | ---- | C] () -- C:\Users\Zoltan\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk [2011/11/11 13:07:20 | 000,000,240 | ---- | C] () -- C:\Users\Zoltan\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk [2011/11/11 13:02:21 | 3184,615,424 | -HS- | C] () -- C:\hiberfil.sys [2009/08/23 22:38:40 | 000,045,056 | ---- | C] () -- C:\Windows\System32\acovcnt.exe [2009/08/23 22:32:06 | 000,047,672 | ---- | C] () -- C:\Windows\AsScrProlog.exe [2009/08/23 22:31:33 | 000,230,952 | ---- | C] () -- C:\Windows\System32\drivers\SRS_PremiumSound_i386.sys [2009/08/23 22:29:09 | 000,057,344 | ---- | C] () -- C:\Windows\System32\LogonStart.dll [2009/08/23 22:26:43 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll [2009/08/23 21:31:35 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009/08/23 21:31:35 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2009/02/25 20:38:39 | 000,982,196 | ---- | C] () -- C:\Windows\System32\igkrng500.bin [2009/02/25 20:38:39 | 000,417,344 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin [2009/02/25 20:38:39 | 000,139,824 | ---- | C] () -- C:\Windows\System32\igfcg500.bin [2009/02/25 20:38:39 | 000,097,448 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin [2008/12/23 13:36:14 | 000,106,496 | ---- | C] () -- C:\Program Files\Common Files\CPInstallAction.dll [2008/11/04 10:15:59 | 001,753,984 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys [2008/11/04 10:13:59 | 000,028,672 | ---- | C] () -- C:\Windows\System32\drivers\sncduvc.sys [2008/11/04 10:13:59 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini [2008/05/22 08:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files\Common Files\banner.jpg [2008/04/14 07:39:33 | 000,000,010 | ---- | C] () -- C:\Windows\System32\ABLKSR.ini [2008/04/13 21:40:34 | 000,336,828 | ---- | C] () -- C:\Windows\System32\prfh0404.dat [2008/04/13 21:40:34 | 000,116,540 | ---- | C] () -- C:\Windows\System32\prfi0404.dat [2008/04/13 21:40:34 | 000,101,188 | ---- | C] () -- C:\Windows\System32\prfc0404.dat [2008/04/13 21:40:34 | 000,030,674 | ---- | C] () -- C:\Windows\System32\prfd0404.dat [2008/04/13 21:27:38 | 000,667,686 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2008/04/13 21:27:38 | 000,340,236 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2008/04/13 21:27:38 | 000,123,076 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2008/04/13 21:27:38 | 000,037,390 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2008/04/13 21:23:00 | 000,665,410 | ---- | C] () -- C:\Windows\System32\perfh00A.dat [2008/04/13 21:23:00 | 000,336,930 | ---- | C] () -- C:\Windows\System32\perfi00A.dat [2008/04/13 21:23:00 | 000,129,298 | ---- | C] () -- C:\Windows\System32\perfc00A.dat [2008/04/13 21:23:00 | 000,040,258 | ---- | C] () -- C:\Windows\System32\perfd00A.dat [2008/04/13 20:50:59 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2008/01/20 19:24:45 | 000,642,560 | ---- | C] () -- C:\Windows\System32\autochk.exe [2006/11/02 05:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006/11/02 05:47:37 | 000,409,896 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 03:33:01 | 000,595,684 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 03:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 03:33:01 | 000,101,350 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 03:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 03:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 01:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 01:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 00:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat < End of report >