My son has terorized this PC and now not only slowing down issue has come up,
but today after I signed in to my online banking website, a new window came up on the main screen
with Cash Edge logo (unknown to me) stating new security measures for me to enter additional personal information.
Somehow this 'malware' knew when to collect information.
I also have redirecting websites at times, as I realize status bar trying to load even a website I am on is static.
ALSO when I look up on TASK MANAGER on win 7, there are several svchost.exe files running, is this also an indication of also some sort of Virus or Malware?
I have done couple of things myself before writing this note:
*I have uninstalled Java from this computer
*I have deleted some of the registry entries relating to Java Runtime (as far as I could tell)
*When I was listing files as per newly created files, this file running as a process called "rizote.exe" got my attention
I stopped the process from Task Manager, and then found any associated entries in REGISTRY and deleted them, I also deleted the actual
file from its physical location in the computer (RELATING TO THIS I AM ALSO ATTACHING A SCREEN SHOT OF THE INFO)
*I use old version of ATF cleaner, although it's not a 64bit version I used that to clean some of the Temp files.
Anyways here is my OTL LOG
-------------------------------------------------------------------------------------------------------------------
OTL logfile created on: 3/1/2012 5:02:57 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Users\Arda\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.93 Gb Total Physical Memory | 6.57 Gb Available Physical Memory | 82.81% Memory free
15.93 Gb Paging File | 14.55 Gb Available in Paging File | 91.34% Paging File free
Paging file location(s): f:\pagefile.sys 8192 8192 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 141.92 Gb Total Space | 23.84 Gb Free Space | 16.80% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 31.37 Gb Free Space | 10.52% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 295.64 Gb Free Space | 99.18% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 106.81 Gb Free Space | 11.47% Space Free | Partition Type: NTFS
Computer Name: ATILIO | User Name: Arda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/01 17:02:23 | 000,584,704 | ---- | M] (OldTimer Tools) -- C:\Users\Arda\Desktop\OTL.exe
PRC - [2012/01/26 09:39:06 | 002,077,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG9\avgtray.exe
PRC - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/03/30 01:05:00 | 000,393,616 | ---- | M] (KORG Inc.) -- C:\Program Files (x86)\KORG USB-MIDI Driver\EsHelper2.exe
PRC - [2011/01/05 09:52:43 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG9\avgcsrvx.exe
PRC - [2010/09/22 03:00:06 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010/09/18 04:11:03 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG9\avgemc.exe
PRC - [2010/09/18 04:11:01 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG9\avgwdsvc.exe
PRC - [2009/12/03 10:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
PRC - [2009/07/29 03:28:40 | 000,252,424 | ---- | M] (Avid Technology, Inc.) -- C:\Windows\SysWOW64\MAFWTray.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/02 11:41:38 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2010/09/22 03:00:06 | 001,016,280 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012/02/07 15:12:04 | 000,097,552 | ---- | M] (SANDBOXIE L.T.D) [Auto | Stopped] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 17:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/09/18 04:11:03 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/09/18 04:11:01 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 02:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 13:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/02/23 15:07:24 | 000,153,088 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Stopped] -- C:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV:64bit: - [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/09/14 16:36:10 | 000,057,480 | ---- | M] (NetFilterSDK.com) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\networx.sys -- (networx)
DRV:64bit: - [2011/09/12 08:50:33 | 000,035,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (AvgMfx64)
DRV:64bit: - [2011/07/07 08:42:38 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2011/05/05 07:21:08 | 000,317,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (AvgTdiA)
DRV:64bit: - [2011/03/30 01:13:00 | 000,033,656 | ---- | M] (KORG INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\KORGUM64.SYS -- (KORGUMDS)
DRV:64bit: - [2011/01/05 09:52:43 | 000,269,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (AvgLdx64)
DRV:64bit: - [2010/09/19 04:31:40 | 000,502,256 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010/09/18 01:46:04 | 000,070,424 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®
DRV:64bit: - [2010/03/10 05:16:36 | 000,029,720 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ivusb.sys -- (ivusb)
DRV:64bit: - [2009/11/18 21:43:48 | 000,037,392 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hotcore3.sys -- (hotcore3)
DRV:64bit: - [2009/07/29 03:28:24 | 000,231,944 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mafw.sys -- (MAFW)
DRV:64bit: - [2009/07/13 17:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 17:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/08 16:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/10 12:35:20 | 000,278,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1e6032e.sys -- (e1express) Intel®
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/02/13 00:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007/05/14 15:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV - [2009/07/13 17:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://tr.msn.com/iat/us_tr.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4C 3D F1 64 19 57 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files (x86)\vshare.tv_Bar\prxtbvsha.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {5109A31D-1C4D-42AB-84D7-E50331A0460B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{5109A31D-1C4D-42AB-84D7-E50331A0460B}: "URL" = http://www.google.co...age={startPage}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2818425
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8118
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [email protected]:0.1.2008d
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:0.1
FF - prefs.js..extensions.enabledItems: [email protected]:2.0.0
FF - prefs.js..extensions.enabledItems: [email protected]:0.9
FF - prefs.js..extensions.enabledItems: [email protected]:1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.5
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/06 18:18:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/01/06 18:18:26 | 000,000,000 | ---D | M]
[2011/01/07 16:04:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Arda\AppData\Roaming\mozilla\Extensions
[2011/01/07 16:04:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Arda\AppData\Roaming\mozilla\Extensions\[email protected]
[2012/03/01 12:36:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Arda\AppData\Roaming\mozilla\Firefox\Profiles\5yuxskvy.default\extensions
[2011/09/06 10:48:05 | 000,000,000 | ---D | M] (vshare.tv Bar Community Toolbar) -- C:\Users\Arda\AppData\Roaming\mozilla\Firefox\Profiles\5yuxskvy.default\extensions\{7aeb3efd-e564-43f1-b658-5058a7c5743b}
[2012/02/08 09:58:15 | 000,000,000 | ---D | M] (View Cookies) -- C:\Users\Arda\AppData\Roaming\mozilla\Firefox\Profiles\5yuxskvy.default\extensions\{8F6A6FD9-0619-459f-B9D0-81DE065D4E21}
[2012/02/08 10:20:54 | 000,000,000 | ---D | M] (Cookies Manager+) -- C:\Users\Arda\AppData\Roaming\mozilla\Firefox\Profiles\5yuxskvy.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
[2012/02/08 10:14:05 | 000,000,000 | ---D | M] (Edit Cookies) -- C:\Users\Arda\AppData\Roaming\mozilla\Firefox\Profiles\5yuxskvy.default\extensions\{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}
[2012/02/21 22:37:39 | 000,000,000 | ---D | M] (DeSopa) -- C:\Users\Arda\AppData\Roaming\mozilla\Firefox\Profiles\5yuxskvy.default\extensions\[email protected]
[2011/09/17 11:53:50 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Arda\AppData\Roaming\mozilla\Firefox\Profiles\5yuxskvy.default\extensions\[email protected]
[2012/03/01 13:02:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/07 16:03:42 | 000,000,000 | ---D | M] (Timezone Definitions for Mozilla Calendar) -- C:\PROGRAM FILES (X86)\CELTX\EXTENSIONS\[email protected]
[2011/01/07 16:03:42 | 000,000,000 | ---D | M] (Default Shot Palette) -- C:\PROGRAM FILES (X86)\CELTX\EXTENSIONS\[email protected]
[2011/01/07 16:03:42 | 000,000,000 | ---D | M] (MSN-Smileys) -- C:\PROGRAM FILES (X86)\CELTX\EXTENSIONS\[email protected]
[2011/01/07 16:03:42 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\PROGRAM FILES (X86)\CELTX\EXTENSIONS\[email protected]
[2011/01/07 16:03:42 | 000,000,000 | ---D | M] (Blackened) -- C:\PROGRAM FILES (X86)\CELTX\EXTENSIONS\[email protected]
[2011/01/07 16:03:42 | 000,000,000 | ---D | M] (Depth) -- C:\PROGRAM FILES (X86)\CELTX\EXTENSIONS\[email protected]
[2011/01/07 16:03:42 | 000,000,000 | ---D | M] (Minimal) -- C:\PROGRAM FILES (X86)\CELTX\EXTENSIONS\[email protected]
[2011/11/05 19:47:12 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/06/09 03:41:48 | 000,081,920 | ---- | M] (vShare.tv ) -- C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
O1 HOSTS File: ([2012/03/01 16:44:05 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (vshare.tv Bar Toolbar) - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files (x86)\vshare.tv_Bar\prxtbvsha.dll (Conduit Ltd.)
O2 - BHO: (CutePDF Form Filler Helper) - {D41289F2-69C6-417B-897E-C653D677CBAF} - C:\Program Files (x86)\CutePDF Pro\CPFillerCo.dll (Acro Software Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (vshare.tv Bar Toolbar) - {7aeb3efd-e564-43f1-b658-5058a7c5743b} - C:\Program Files (x86)\vshare.tv_Bar\prxtbvsha.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (vshare.tv Bar Toolbar) - {7AEB3EFD-E564-43F1-B658-5058A7C5743B} - C:\Program Files (x86)\vshare.tv_Bar\prxtbvsha.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [NetWorx] C:\Program Files\NetWorx\networx.exe (SoftPerfect Research)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [KORG USB-MIDI Driver] C:\Program Files (x86)\KORG USB-MIDI Driver\EsHelper2.exe (KORG Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [M-Audio Taskbar Icon] C:\Windows\SysWOW64\MAFWTray.exe (Avid Technology, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [EPSON NX620 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGAA.EXE /FU "C:\Users\Arda\AppData\Local\Temp\E_S1DA6.tmp" /EF "HKCU" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 [2012/02/29 12:28:58 | 000,000,000 | ---D | M]
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D6DBE389-51AE-429E-9D3B-63A380DA6574}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\Windows\system32\OGPDFLoader.dll) - C:\Windows\SysWOW64\OGPDFLoader.dll (Armjisoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1061926c-c596-11df-bd03-001cc01db0f9}\Shell - "" = AutoRun
O33 - MountPoints2\{1061926c-c596-11df-bd03-001cc01db0f9}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{10619286-c596-11df-bd03-001cc01db0f9}\Shell - "" = AutoRun
O33 - MountPoints2\{10619286-c596-11df-bd03-001cc01db0f9}\Shell\AutoRun\command - "" = "I:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/01 17:02:23 | 000,584,704 | ---- | C] (OldTimer Tools) -- C:\Users\Arda\Desktop\OTL.exe
[2012/03/01 16:52:45 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\tdsskiller
[2012/03/01 16:51:01 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\GooredFix Backups
[2012/03/01 16:50:29 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Users\Arda\Desktop\GooredFix.exe
[2012/03/01 16:44:05 | 000,000,000 | ---D | C] -- C:\_OTM
[2012/03/01 16:42:40 | 000,523,264 | ---- | C] (OldTimer Tools) -- C:\Users\Arda\Desktop\OTM.exe
[2012/03/01 16:42:15 | 000,000,000 | ---D | C] -- C:\REGISTRY BACKUP 2012
[2012/03/01 16:41:24 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\erunt
[2012/03/01 12:43:36 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Roaming\Malwarebytes
[2012/03/01 12:43:31 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/03/01 12:43:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/01 12:43:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/03/01 12:43:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/03/01 12:42:52 | 009,502,424 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Arda\Desktop\mbam--setup-1.60.1.1000.exe
[2012/02/29 22:44:58 | 000,000,000 | ---D | C] -- C:\Users\Arda\Documents\CutePDF
[2012/02/29 22:44:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
[2012/02/29 22:44:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CutePDF Pro
[2012/02/29 22:23:55 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\portfolio
[2012/02/29 12:28:54 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\2
[2012/02/29 12:23:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Armjisoft
[2012/02/29 12:23:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Armjisoft
[2012/02/29 12:23:14 | 009,519,348 | ---- | C] (Armjisoft Corporation) -- C:\Users\Arda\Desktop\PDFOwnerguardPersonalSetup.exe
[2012/02/29 11:20:58 | 015,644,488 | ---- | C] (Solid Documents, LLC) -- C:\Users\Arda\Desktop\solidpdfcreator.exe
[2012/02/29 01:07:54 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\elegant-cv-resume-html-template
[2012/02/28 17:13:27 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\Fonts
[2012/02/28 17:13:19 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\Collection Of Nick's Fonts
[2012/02/28 17:11:58 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\Topaz Star Effects 1.1 for Adobe Photoshop
[2012/02/28 17:07:25 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\MediaLoot Graphic Design - Huge Bundle
[2012/02/28 08:30:31 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Local\{6F96A69C-D429-4480-887C-171B47DE9623}
[2012/02/28 08:30:20 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Local\{91F2303A-537D-4961-82AB-C9B5C0C45228}
[2012/02/27 06:14:23 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Local\{1E2A3DD1-8AE9-49F1-AA7E-2F8AFA61B255}
[2012/02/27 06:14:11 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Local\{137F6546-CB3F-4CF9-A09D-81E9D2F89612}
[2012/02/27 05:39:10 | 000,000,000 | ---D | C] -- C:\Users\Arda\Documents\Fonts
[2012/02/27 05:37:36 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Local\FontCreator
[2012/02/27 05:37:17 | 001,078,504 | ---- | C] (High-Logic B.V.) -- C:\Windows\SysWow64\FontInstaller2.dll
[2012/02/27 05:37:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\High-Logic FontCreator
[2012/02/27 05:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\High-Logic FontCreator
[2012/02/27 05:37:17 | 000,000,000 | ---D | C] -- C:\Users\Arda\Documents\FontCreator
[2012/02/27 05:37:17 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Roaming\FontCreator
[2012/02/24 12:58:58 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Local\TechSmith
[2012/02/24 12:58:14 | 000,000,000 | ---D | C] -- C:\Users\Arda\Documents\Camtasia Studio
[2012/02/24 12:58:01 | 000,000,000 | ---D | C] -- C:\Windows\XSxS
[2012/02/24 12:58:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xenocode
[2012/02/24 09:06:11 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\BR
[2012/02/23 19:06:16 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Roaming\Adobe Mini Bridge CS5
[2012/02/23 15:23:37 | 000,000,000 | ---D | C] -- C:\Users\Arda\Documents\Studio One
[2012/02/23 15:18:19 | 000,000,000 | R--D | C] -- C:\Sandbox
[2012/02/23 15:00:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
[2012/02/23 14:53:16 | 000,000,000 | ---D | C] -- C:\Program Files\Sandboxie
[2012/02/23 13:48:35 | 000,000,000 | ---D | C] -- C:\ProgramData\PreSonus
[2012/02/23 13:48:34 | 000,000,000 | ---D | C] -- C:\Users\Arda\AppData\Roaming\PreSonus
[2012/02/23 13:47:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Propellerhead Software
[2012/02/23 13:47:40 | 000,000,000 | ---D | C] -- C:\Program Files\PreSonus
[2012/02/22 13:13:14 | 000,000,000 | ---D | C] -- C:\Users\Arda\Desktop\TEMP
[2012/02/17 10:33:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JDownloader
[2012/02/06 18:48:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KORG USB-MIDI Driver
[2012/02/06 18:48:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KORG
========== Files - Modified Within 30 Days ==========
[2012/03/01 17:02:23 | 000,584,704 | ---- | M] (OldTimer Tools) -- C:\Users\Arda\Desktop\OTL.exe
[2012/03/01 16:54:35 | 000,014,256 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 16:54:35 | 000,014,256 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 16:52:17 | 002,045,015 | ---- | M] () -- C:\Users\Arda\Desktop\tdsskiller.zip
[2012/03/01 16:50:30 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Users\Arda\Desktop\GooredFix.exe
[2012/03/01 16:47:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/01 16:44:05 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2012/03/01 16:42:40 | 000,523,264 | ---- | M] (OldTimer Tools) -- C:\Users\Arda\Desktop\OTM.exe
[2012/03/01 16:40:58 | 000,513,320 | ---- | M] () -- C:\Users\Arda\Desktop\erunt.zip
[2012/03/01 16:27:37 | 000,002,248 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2012/03/01 15:50:04 | 000,027,032 | ---- | M] () -- C:\Users\Arda\Desktop\March 1st, 2012 AVG SCAN.csv
[2012/03/01 14:24:03 | 000,363,344 | ---- | M] () -- C:\Users\Arda\Desktop\restore.jpg
[2012/03/01 13:54:57 | 000,658,465 | ---- | M] () -- C:\Users\Arda\Desktop\rizote.jpg
[2012/03/01 12:43:32 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/01 12:42:55 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Arda\Desktop\mbam--setup-1.60.1.1000.exe
[2012/03/01 08:08:31 | 093,721,623 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm
[2012/02/29 23:04:20 | 000,072,472 | ---- | M] () -- C:\Users\Arda\Desktop\Brogan Terrell Resume.pdf
[2012/02/29 22:59:32 | 001,979,694 | ---- | M] () -- C:\Users\Arda\Desktop\Brogan Terrell portfolio copy.pdf
[2012/02/29 14:43:18 | 000,199,512 | ---- | M] () -- C:\Users\Arda\Desktop\Filepost 29 Feb 2012.pdf
[2012/02/29 12:40:05 | 000,030,100 | ---- | M] () -- C:\Users\Arda\Desktop\Brogan Terrell.pdf
[2012/02/29 12:36:22 | 026,136,068 | ---- | M] () -- C:\Users\Arda\Desktop\Solid.PDF.Creator.Plus.v7.2.build.633.incl.patch.DA.zip
[2012/02/29 12:23:48 | 000,001,260 | ---- | M] () -- C:\Users\Public\Desktop\PDF OwnerGuard Personal.lnk
[2012/02/29 12:23:27 | 009,519,348 | ---- | M] (Armjisoft Corporation) -- C:\Users\Arda\Desktop\PDFOwnerguardPersonalSetup.exe
[2012/02/29 11:21:07 | 015,644,488 | ---- | M] (Solid Documents, LLC) -- C:\Users\Arda\Desktop\solidpdfcreator.exe
[2012/02/29 10:58:34 | 000,239,930 | ---- | M] () -- C:\Users\Arda\Desktop\2.ai
[2012/02/29 10:32:04 | 004,987,024 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/29 01:20:47 | 005,047,136 | ---- | M] () -- C:\Users\Arda\Desktop\moondog.psd
[2012/02/28 22:04:05 | 001,900,400 | ---- | M] () -- C:\Users\Arda\Desktop\elegant-cv-resume-html-template.zip
[2012/02/27 05:37:18 | 000,001,224 | ---- | M] () -- C:\Users\Arda\Desktop\High-Logic FontCreator.lnk
[2012/02/27 05:34:27 | 009,921,906 | ---- | M] () -- C:\Users\Arda\Desktop\High-Logic.FontCreator.Professional.Edition.6.5.rar
[2012/02/24 18:39:30 | 003,740,744 | ---- | M] () -- C:\Users\Arda\Desktop\moondog font.psd
[2012/02/23 19:31:25 | 009,625,925 | ---- | M] () -- C:\Users\Arda\Desktop\IMG_2279.psd
[2012/02/23 18:07:44 | 000,001,072 | ---- | M] () -- C:\Users\Arda\Desktop\Documents.lnk
[2012/02/23 17:32:25 | 000,284,803 | ---- | M] () -- C:\Users\Arda\Desktop\Stanislavski. system.pdf
[2012/02/23 15:32:48 | 000,001,002 | ---- | M] () -- C:\Users\Arda\Desktop\Sandboxed Web Browser.lnk
[2012/02/23 15:28:01 | 000,000,016 | ---- | M] () -- C:\Users\Arda\AppData\Roaming\msregsvv.dll
[2012/02/23 15:28:01 | 000,000,016 | ---- | M] () -- C:\ProgramData\autobk.inc
[2012/02/23 15:23:13 | 000,307,987 | ---- | M] () -- C:\Users\Arda\Desktop\presonus install 2.jpg
[2012/02/23 15:22:49 | 000,318,298 | ---- | M] () -- C:\Users\Arda\Desktop\presonus install 1.jpg
[2012/02/23 15:19:25 | 000,000,624 | ---- | M] () -- C:\Users\Arda\Desktop\Studio One 2 Professional.license
[2012/02/23 14:50:01 | 001,786,766 | ---- | M] () -- C:\Users\Arda\Desktop\IMG_2279.JPG
[2012/02/23 13:47:48 | 000,001,001 | ---- | M] () -- C:\Users\Public\Desktop\Studio One 2 x64.lnk
[2012/02/23 00:15:02 | 000,359,760 | ---- | M] () -- C:\Users\Arda\Desktop\bill Arda.pdf
[2012/02/17 10:33:53 | 000,002,037 | ---- | M] () -- C:\Users\Arda\Desktop\JDownloader.lnk
[2012/02/17 10:33:53 | 000,002,001 | ---- | M] () -- C:\Users\Arda\Application Data\Microsoft\Internet Explorer\Quick Launch\JDownloader.lnk
[2012/02/08 16:51:29 | 000,001,440 | ---- | M] () -- C:\Users\Arda\Desktop\Firefox - Profiles.lnk
[2012/02/06 12:49:32 | 000,000,146 | ---- | M] () -- C:\Users\Arda\Desktop\SOUND.lnk
[2012/02/05 19:48:46 | 000,778,150 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/05 19:48:46 | 000,659,580 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/02/05 19:48:46 | 000,120,508 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/02/01 19:00:25 | 000,000,410 | ---- | M] () -- C:\Windows\tasks\Defrag Winner Schedule.job
========== Files Created - No Company Name ==========
[2012/03/01 16:52:00 | 002,045,015 | ---- | C] () -- C:\Users\Arda\Desktop\tdsskiller.zip
[2012/03/01 16:40:54 | 000,513,320 | ---- | C] () -- C:\Users\Arda\Desktop\erunt.zip
[2012/03/01 14:29:03 | 000,027,032 | ---- | C] () -- C:\Users\Arda\Desktop\March 1st, 2012 AVG SCAN.csv
[2012/03/01 14:24:03 | 000,363,344 | ---- | C] () -- C:\Users\Arda\Desktop\restore.jpg
[2012/03/01 13:54:56 | 000,658,465 | ---- | C] () -- C:\Users\Arda\Desktop\rizote.jpg
[2012/03/01 12:43:32 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/29 23:04:20 | 000,072,472 | ---- | C] () -- C:\Users\Arda\Desktop\Brogan Terrell Resume.pdf
[2012/02/29 23:03:20 | 001,979,694 | ---- | C] () -- C:\Users\Arda\Desktop\Brogan Terrell portfolio copy.pdf
[2012/02/29 14:43:18 | 000,199,512 | ---- | C] () -- C:\Users\Arda\Desktop\Filepost 29 Feb 2012.pdf
[2012/02/29 12:23:48 | 000,001,260 | ---- | C] () -- C:\Users\Public\Desktop\PDF OwnerGuard Personal.lnk
[2012/02/29 11:38:08 | 026,136,068 | ---- | C] () -- C:\Users\Arda\Desktop\Solid.PDF.Creator.Plus.v7.2.build.633.incl.patch.DA.zip
[2012/02/29 01:03:45 | 000,030,100 | ---- | C] () -- C:\Users\Arda\Desktop\Brogan Terrell.pdf
[2012/02/28 23:05:02 | 000,239,930 | ---- | C] () -- C:\Users\Arda\Desktop\2.ai
[2012/02/28 22:03:58 | 001,900,400 | ---- | C] () -- C:\Users\Arda\Desktop\elegant-cv-resume-html-template.zip
[2012/02/27 05:37:18 | 000,001,224 | ---- | C] () -- C:\Users\Arda\Desktop\High-Logic FontCreator.lnk
[2012/02/27 05:33:21 | 009,921,906 | ---- | C] () -- C:\Users\Arda\Desktop\High-Logic.FontCreator.Professional.Edition.6.5.rar
[2012/02/24 18:30:52 | 003,740,744 | ---- | C] () -- C:\Users\Arda\Desktop\moondog font.psd
[2012/02/23 19:31:25 | 009,625,925 | ---- | C] () -- C:\Users\Arda\Desktop\IMG_2279.psd
[2012/02/23 19:03:55 | 005,047,136 | ---- | C] () -- C:\Users\Arda\Desktop\moondog.psd
[2012/02/23 18:20:09 | 001,786,766 | ---- | C] () -- C:\Users\Arda\Desktop\IMG_2279.JPG
[2012/02/23 18:07:44 | 000,001,072 | ---- | C] () -- C:\Users\Arda\Desktop\Documents.lnk
[2012/02/23 17:32:25 | 000,284,803 | ---- | C] () -- C:\Users\Arda\Desktop\Stanislavski. system.pdf
[2012/02/23 15:23:13 | 000,307,987 | ---- | C] () -- C:\Users\Arda\Desktop\presonus install 2.jpg
[2012/02/23 15:22:49 | 000,318,298 | ---- | C] () -- C:\Users\Arda\Desktop\presonus install 1.jpg
[2012/02/23 15:19:25 | 000,000,624 | ---- | C] () -- C:\Users\Arda\Desktop\Studio One 2 Professional.license
[2012/02/23 14:53:35 | 000,001,002 | ---- | C] () -- C:\Users\Arda\Desktop\Sandboxed Web Browser.lnk
[2012/02/23 14:53:33 | 000,002,248 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2012/02/23 13:47:48 | 000,001,013 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Studio One 2 x64.lnk
[2012/02/23 13:47:48 | 000,001,001 | ---- | C] () -- C:\Users\Public\Desktop\Studio One 2 x64.lnk
[2012/02/23 00:15:02 | 000,359,760 | ---- | C] () -- C:\Users\Arda\Desktop\bill Arda.pdf
[2012/02/17 10:33:53 | 000,002,037 | ---- | C] () -- C:\Users\Arda\Desktop\JDownloader.lnk
[2012/02/17 10:33:53 | 000,002,001 | ---- | C] () -- C:\Users\Arda\Application Data\Microsoft\Internet Explorer\Quick Launch\JDownloader.lnk
[2012/02/17 10:33:48 | 000,002,001 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012/02/17 10:33:48 | 000,001,945 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2012/02/17 10:33:48 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012/02/08 16:51:29 | 000,001,440 | ---- | C] () -- C:\Users\Arda\Desktop\Firefox - Profiles.lnk
[2012/02/06 19:01:32 | 000,002,299 | ---- | C] () -- C:\Users\Arda\Desktop\Vyzex MPK25.lnk
[2012/02/06 12:49:32 | 000,000,146 | ---- | C] () -- C:\Users\Arda\Desktop\SOUND.lnk
[2012/01/09 17:17:28 | 000,005,632 | ---- | C] () -- C:\Users\Arda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/09 17:13:44 | 000,129,024 | ---- | C] () -- C:\Windows\SysWow64\AVERM.dll
[2012/01/09 17:13:44 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\AVEQT.dll
[2012/01/06 18:25:25 | 000,000,016 | ---- | C] () -- C:\Users\Arda\AppData\Roaming\msregsvv.dll
[2012/01/06 18:25:25 | 000,000,016 | ---- | C] () -- C:\ProgramData\autobk.inc
[2011/12/08 13:41:04 | 000,771,962 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/14 07:42:35 | 000,001,189 | ---- | C] () -- C:\Users\Arda\AppData\Roaming\vso_ts_preview.xml
[2011/06/21 11:18:32 | 000,001,456 | ---- | C] () -- C:\Users\Arda\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/01/13 20:54:06 | 000,073,220 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/01/13 20:54:06 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2011/01/13 20:54:06 | 000,029,114 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2011/01/13 20:54:06 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2011/01/13 20:54:06 | 000,021,021 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2011/01/13 20:54:06 | 000,015,670 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2011/01/13 20:54:06 | 000,013,280 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2011/01/13 20:54:06 | 000,010,673 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2011/01/13 20:54:06 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2011/01/13 20:54:06 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/01/13 20:54:06 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/01/13 20:54:06 | 000,001,137 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/01/13 20:54:06 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/01/13 20:54:06 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/01/13 20:54:06 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/01/13 20:54:06 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2011/01/13 20:52:05 | 000,000,079 | ---- | C] () -- C:\Windows\ENX625.ini
[2010/09/21 04:22:44 | 000,000,026 | -H-- | C] () -- C:\ProgramData\.811261211181235583101118113995
[2010/09/19 03:31:02 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
========== LOP Check ==========
[2010/09/18 04:14:54 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\AVG9
[2011/02/11 09:37:17 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/19 04:37:12 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\DAEMON Tools Lite
[2011/03/16 19:01:42 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Epson
[2010/09/21 04:23:29 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Final Draft
[2012/02/27 05:39:41 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\FontCreator
[2011/01/07 16:04:31 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Greyfirst
[2012/01/06 18:31:12 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\IK Multimedia
[2011/01/13 20:59:08 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Leadertech
[2012/01/06 15:33:25 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\NCH Swift Sound
[2011/01/29 14:45:45 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\PACE Anti-Piracy
[2012/02/23 13:48:34 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\PreSonus
[2012/01/17 16:36:07 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Sports Interactive
[2011/01/29 14:48:17 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/10/06 10:23:40 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Steinberg
[2010/09/26 07:45:48 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\TeraCopy
[2012/01/10 10:35:26 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Total Media Converter
[2012/02/29 22:32:28 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\uTorrent
[2012/01/31 16:39:22 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Vso
[2011/10/06 10:23:40 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\VST3 Presets
[2011/12/20 11:33:42 | 000,000,000 | ---D | M] -- C:\Users\Arda\AppData\Roaming\Windows Live Writer
[2012/02/01 19:00:25 | 000,000,410 | ---- | M] () -- C:\Windows\Tasks\Defrag Winner Schedule.job
[2012/03/01 16:24:01 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Edited by jason richards, 01 March 2012 - 08:17 PM.