:Commands [CreateRestorePoint] :OTL SRV - [2013/11/19 20:54:20 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe -- (avgwd) SRV - [2013/07/04 09:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- C:\Program Files\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent) IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...r=971255584&ir= IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-se...913_c1&tsp=5010 O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - File not found O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - File not found O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - File not found O4 - HKLM..\Run: [AML Registry Cleaner] File not found O4 - HKLM..\Run: [KernelFaultCheck] File not found O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) O32 - AutoRun File - [2011/12/19 09:00:07 | 000,000,040 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] [1999/10/25 04:53:58 | 000,015,917 | ---- | C] () -- C:\WINDOWS\Sage.ini [1998/03/25 19:12:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SgHmZLib.dll [2013/05/09 10:03:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Babylon [2004/06/09 05:57:12 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Install.exe [2013/01/23 04:09:57 | 000,000,374 | ---- | M] () -- C:\WINDOWS\Tasks\ROC_REG_JAN_DELETE.job [2013/07/24 07:20:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer [2013/09/19 07:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2014/02/25 04:30:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TEMP\Local Settings\Application Data\Avg2013 [2013/01/23 04:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG January 2013 Campaign :Files C:\Program Files\AVG :Commands [EMPTYTEMP]