Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

3\LXCGTime.dll message keeps coming when i turn on my laptop


  • Please log in to reply

#1
imsmilingwithu

imsmilingwithu

    New Member

  • Member
  • Pip
  • 2 posts
hello,
i hope you can help me i went to your malware site & downloaded the otl & then i did the otl scan. my computer shuts down & blue screen comes up saying that windows has been infected & must shut the pc to protect it. then it turns on in safe mode. i have norton anti virus & it says all is well after scan. i got 1 dialogue box which said the microsoft silverlight file is corrupted. then pc went blue with a lot of words & then shut down & then turned on in safe mode.



OTL logfile created on: 5/30/2012 12:26:10 AM - Run 1
OTL by OldTimer - Version 3.2.44.0 Folder = C:\Users\Robbin\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.79 Gb Available Physical Memory | 39.72% Memory free
4.00 Gb Paging File | 2.36 Gb Available in Paging File | 58.97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 404.15 Gb Free Space | 86.79% Space Free | Partition Type: NTFS

Computer Name: ROBBIN-DV9 | User Name: Robbin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/05/30 00:24:28 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Robbin\Downloads\OTL.exe
PRC - [2012/05/24 01:55:37 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2012/02/20 11:18:28 | 000,240,408 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\SeaPort.EXE
PRC - [2012/02/20 11:18:28 | 000,193,816 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BBSvc.EXE
PRC - [2012/01/31 16:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2012/01/17 21:03:24 | 002,339,168 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgtray.exe
PRC - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/02/10 10:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 08:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
PRC - [2011/02/08 08:32:42 | 000,750,432 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgam.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/04/30 02:57:42 | 000,103,344 | ---- | M] (Lexmark International Inc.) -- C:\Program Files (x86)\Lexmark 2300 Series\ezprint.exe
PRC - [2007/04/30 02:55:32 | 000,205,744 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files (x86)\Lexmark 2300 Series\lxcgmon.exe


========== Modules (No Company Name) ==========

MOD - [2012/05/22 21:56:50 | 000,441,880 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppgooglenaclpluginchrome.dll
MOD - [2012/05/22 21:56:49 | 003,922,456 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
MOD - [2012/05/22 21:55:35 | 000,553,496 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\libglesv2.dll
MOD - [2012/05/22 21:55:33 | 000,117,784 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\libegl.dll
MOD - [2012/05/22 21:55:24 | 000,134,696 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\avutil-51.dll
MOD - [2012/05/22 21:55:23 | 000,250,408 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\avformat-54.dll
MOD - [2012/05/22 21:55:21 | 002,375,720 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\avcodec-54.dll
MOD - [2012/05/22 21:06:23 | 008,743,584 | ---- | M] () -- C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
MOD - [2012/02/22 20:49:56 | 000,921,600 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2011/02/10 10:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
MOD - [2009/06/17 15:40:16 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
MOD - [2009/06/17 15:40:16 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
MOD - [2009/06/17 15:40:16 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2009/01/12 17:50:42 | 000,259,480 | ---- | M] () -- C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
MOD - [2009/01/12 17:50:42 | 000,120,216 | ---- | M] () -- C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
MOD - [2009/01/12 17:50:42 | 000,038,184 | ---- | M] () -- C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
MOD - [2009/01/12 17:50:40 | 000,345,384 | ---- | M] () -- C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
MOD - [2005/12/13 19:52:02 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2300 Series\lxcgdrec.dll
MOD - [2005/06/14 21:08:28 | 000,196,608 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2300 Series\iptk.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/11/20 09:26:50 | 000,084,992 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Mcx2Svc.dll -- (Mcx2Svc)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/10/16 18:06:40 | 001,039,360 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxducoms.exe -- (lxdu_device)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:41:27 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2007/04/30 02:55:08 | 000,566,704 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxcgcoms.exe -- (lxcg_device)
SRV - [2012/05/18 11:59:48 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/02/20 11:18:28 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012/02/20 11:18:28 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BBSvc.EXE -- (BBSvc)
SRV - [2012/01/31 16:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/02/08 08:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/03/18 16:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/07/13 21:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/10 16:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2009/04/29 06:21:18 | 000,436,736 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/04/30 02:54:44 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysWOW64\lxcgcoms.exe -- (lxcg_device)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/05/27 22:05:26 | 000,118,864 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV:64bit: - [2011/05/13 18:37:54 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2011/04/05 03:59:54 | 000,377,936 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2011/03/16 19:03:18 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/01 17:25:18 | 000,041,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011/02/22 11:12:46 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV:64bit: - [2011/02/10 10:53:34 | 000,029,264 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV:64bit: - [2011/01/07 09:41:44 | 000,304,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 07:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/20 05:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/20 05:26:11 | 000,328,192 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\udfs.sys -- (udfs)
DRV:64bit: - [2010/05/28 01:32:56 | 000,320,560 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,024,144 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\crcdisk.sys -- (crcdisk)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\ws2ifsl.sys -- (ws2ifsl)
DRV:64bit: - [2009/07/13 19:19:47 | 000,092,160 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cdfs.sys -- (cdfs)
DRV:64bit: - [2009/07/08 03:45:50 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/06/25 18:04:20 | 000,067,584 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimmpx64.sys -- (rimmptsk)
DRV:64bit: - [2009/06/25 17:38:52 | 000,057,856 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpx64.sys -- (rismxdp)
DRV:64bit: - [2009/06/25 17:13:44 | 000,055,296 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimspx64.sys -- (rimsptsk)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/04/29 06:21:08 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\XAudio64.sys -- (XAudio)
DRV:64bit: - [2009/02/12 17:24:56 | 001,485,824 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_DPV.sys -- (HSF_DPV)
DRV:64bit: - [2009/02/12 17:20:56 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAXHWAZL.sys -- (CAXHWAZL)
DRV:64bit: - [2009/02/12 17:19:34 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_CNXT.sys -- (winachsf)
DRV:64bit: - [2008/03/04 11:32:46 | 000,222,720 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2007/07/11 05:30:34 | 000,009,088 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV:64bit: - [2006/06/18 01:27:24 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mdmxsdk.sys -- (mdmxsdk)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox...tb_id&%language
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 8B 2A 37 A0 7E CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{A43A0FDC-56DB-4E85-A013-6FBBFC7EC74F}: "URL" = http://www.google.co...q={searchTerms}
IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://toolbar.inbox...id=80141&lng=en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Robbin\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Robbin\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2012/02/03 13:41:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/05/24 01:56:08 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Robbin\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Robbin\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: YouTube = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\
CHR - Extension: Skype Click to Call = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: HP Product Detection Plugin = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnhbepgnjnaoahohppnffanmkjkjoglp\1.0.15.0_0\
CHR - Extension: Gmail = C:\Users\Robbin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark 2300 Series\ezprint.exe (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [LXCGCATS] rundll32 \3\LXCGtime.dll,RunDLLEntry File not found
O4:64bit: - HKLM..\Run: [lxcgmon.exe] C:\Program Files (x86)\Lexmark 2300 Series\lxcgmon.exe (Lexmark International, Inc.)
O4:64bit: - HKLM..\Run: [PCHealthBoost] "C:\Program Files (x86)\PC HealthBoost\PCHealthBoost.exe" /s File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [cdloader] C:\Users\Robbin\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: magicjack.com ([data] https in Trusted sites)
O15 - HKCU\..Trusted Domains: magicjack.com ([my] https in Trusted sites)
O15 - HKCU\..Trusted Domains: talk4free.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: talk4free.com ([reg] https in Trusted sites)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3F51001F-7C25-42E9-A680-B901C2564541}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgchsva.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/05/30 00:15:19 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{2D378E4B-D6DF-4F52-89D5-F955EBEF0381}
[2012/05/30 00:14:59 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{18323B37-143A-465F-99EB-7746FA6B4131}
[2012/05/29 22:03:09 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{AB8F941A-635F-400B-ABB1-F9F7B6C99F29}
[2012/05/29 22:02:58 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{58DA0D6D-8DDF-4841-A4B4-9655B181141D}
[2012/05/29 20:55:14 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{AADF53D2-455F-47D1-A827-48BC513D3F4A}
[2012/05/29 20:55:03 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{83F674B6-AABD-41E1-8FD0-592D64246245}
[2012/05/29 20:48:41 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Roaming\ApplicationData
[2012/05/29 20:33:55 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{20351CC3-FA16-4B8C-BF28-84654862A387}
[2012/05/29 20:33:42 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{FE8A647A-ACDB-41B8-9D73-11304F270787}
[2012/05/29 20:31:12 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{118300D7-7D6F-4FB7-8878-23C3F455F3BE}
[2012/05/29 20:30:55 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{08621079-05B4-46DF-B878-21D98236DAE4}
[2012/05/29 19:26:33 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{BBA36D97-25F0-4450-A5DF-9175698246EF}
[2012/05/29 19:26:23 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{5330C3E8-3E37-482B-AB40-F6F26B762362}
[2012/05/29 19:02:47 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F8B22D43-C853-4E59-AB8F-29B55CF519EC}
[2012/05/29 19:02:37 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F5C18A96-E8AB-4DBA-B67B-A03DD77B9FC5}
[2012/05/29 18:57:01 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{C352870F-FCD0-4B35-BDC7-ADB75C20C9B5}
[2012/05/29 18:56:49 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{FC0CA7D5-48A6-48A2-9FFD-91B09370EEFF}
[2012/05/29 16:33:28 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{159FCD97-1255-4099-9919-95F4181E9CA2}
[2012/05/29 16:33:14 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{1C72AA00-5D8B-4166-825F-C9F79B7DE6D4}
[2012/05/29 13:17:08 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/05/29 12:42:39 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{290FE114-B9C4-4AE1-8ABB-43A16762920F}
[2012/05/29 12:42:26 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{813F724E-4099-4C8D-8EE8-1FB9A624296E}
[2012/05/28 14:57:04 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{38533EFE-90A5-450C-9DAE-C3EA21C2D0E4}
[2012/05/28 14:56:47 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{B4F77C13-1C2C-42C7-931A-88E2BDAF4005}
[2012/05/28 14:52:39 | 000,000,000 | ---D | C] -- C:\PFiles
[2012/05/28 14:47:17 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D82FCE2A-4C62-4A69-8CB1-299BDC5B4885}
[2012/05/28 14:46:58 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{B518639B-E44A-469F-A02A-69D6FDB28F67}
[2012/05/28 05:12:25 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D6AD5BC8-2661-42E7-A24F-A6CF20EB1C9D}
[2012/05/28 05:12:08 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E9C495B6-C96D-4E57-9256-D9413EE978DA}
[2012/05/28 00:49:07 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D7AF4BFA-0DE3-4949-91C4-4D136BD4FC60}
[2012/05/27 19:35:44 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{9AEACE27-763A-4C5D-B2DA-B0DE1A08BB68}
[2012/05/27 19:35:31 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{3F859A45-64A9-4F6B-973C-6548753A6956}
[2012/05/27 17:45:59 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F066C827-2856-4E88-874B-A9B0F1C5B652}
[2012/05/27 14:02:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2012/05/27 14:02:49 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Roaming\Yahoo!
[2012/05/27 14:02:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
[2012/05/27 14:02:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2012/05/27 14:00:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo!
[2012/05/27 13:46:44 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{4DB808BD-E3FD-49B2-869C-524123A03983}
[2012/05/27 13:46:34 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E41E4E27-F66B-4459-817D-207C534ECF83}
[2012/05/26 23:35:03 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{9F44FC8B-E5CB-4AA0-B659-EE1F282520FE}
[2012/05/26 23:34:52 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{27484CF1-E9A5-46E6-837F-95CFB144606C}
[2012/05/26 22:37:46 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{29FB3AC5-2D98-4D4B-84DC-05731167E60C}
[2012/05/26 22:37:36 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{65DEF9F4-F5D4-487D-8820-DA7EF97D98B3}
[2012/05/26 16:23:51 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F0CF59FF-7C7C-4385-9681-676383E41159}
[2012/05/26 16:23:30 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{A3618685-DCB8-4F50-B317-A687E007754E}
[2012/05/26 13:43:02 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{739C5117-4675-4C3E-B30E-1D3C4AFFB7CC}
[2012/05/26 13:42:50 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{07F74073-DCB4-464B-8236-879A0202858A}
[2012/05/25 20:53:16 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{1952FAB3-68E0-4C11-B39E-027763751F55}
[2012/05/25 20:53:03 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{DBED1D93-D813-484C-A0A4-D39A3DC58711}
[2012/05/25 13:57:32 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{11416B1F-F26F-454D-B9C0-B3B842F6957A}
[2012/05/25 13:57:20 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{DFF57FAF-7F8E-4137-8ADE-776D6F707A92}
[2012/05/25 02:12:41 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{69595B66-15EE-4BFF-AC95-3E4EA29B6DF3}
[2012/05/25 02:12:30 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{1D7D741B-69BE-49E7-9942-ED3179094944}
[2012/05/25 00:27:34 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{7C1E254A-54DB-44FD-9767-BFBE89EA5855}
[2012/05/25 00:27:18 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{7C9A3EAD-5982-4E0C-B99E-2075EFFB9451}
[2012/05/24 21:04:13 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{BC3A4034-59D6-4754-8E39-E34B29D5EF06}
[2012/05/24 21:03:58 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{2CCF8F5B-F3FB-42A2-9184-A2D93E32D42A}
[2012/05/24 15:07:17 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{7C3F1591-6240-452A-A53B-5ED50B170E9E}
[2012/05/24 15:07:07 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{296545F2-1EE6-45C6-8CAC-231D5F6F8C7E}
[2012/05/24 13:25:11 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{398DF2E0-5F27-4173-9963-6D04AA76ECE9}
[2012/05/24 13:25:00 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{5C24476E-C48F-4387-A235-021BA829ED65}
[2012/05/24 12:02:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2012/05/24 12:02:19 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
[2012/05/24 12:02:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64
[2012/05/24 12:02:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Security Scan
[2012/05/24 12:02:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64\0307020.005
[2012/05/24 12:02:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2012/05/24 11:58:33 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{740DECCB-D9CD-465C-B13D-625101929981}
[2012/05/24 11:58:23 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{66DCFB61-5745-4AAB-8F88-2C12807DB61D}
[2012/05/24 01:56:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2012/05/24 01:55:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2012/05/24 01:54:37 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\Real
[2012/05/23 11:21:06 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{208883E1-CAC4-4B48-8D46-6288C88BC95F}
[2012/05/23 11:20:52 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{CD6C7D9E-174A-47DB-867B-B2F3FD2EE152}
[2012/05/23 01:46:26 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{697EBD22-B8FA-4B7D-B299-7007F721F1EA}
[2012/05/23 01:46:09 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{3CB4E2FF-9777-4402-B8C2-C4FF60D3F78A}
[2012/05/20 20:31:46 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{4C09198B-0BD1-414A-96AE-65233FD40C4C}
[2012/05/20 20:31:35 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{873E7AA9-8E8A-41CA-B5D0-434D69AEBE92}
[2012/05/19 15:32:16 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E40527B5-6F7F-41E0-B520-4FF5B52B3D31}
[2012/05/19 15:31:55 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{0346AC20-1267-48E8-BCFF-F406D9A95E7C}
[2012/05/18 11:59:42 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{3A076C38-B5B0-45E3-A422-2A1368BFC06D}
[2012/05/18 11:59:24 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{DF41A86D-0C05-4256-9290-BD8B47911C14}
[2012/05/17 10:19:11 | 000,000,000 | R--D | C] -- C:\Users\Robbin\Documents\Scanned Documents
[2012/05/17 10:19:10 | 000,000,000 | ---D | C] -- C:\Users\Robbin\Documents\Fax
[2012/05/17 10:11:34 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{575D1DB3-67DA-485B-BD45-CA47BFCC366A}
[2012/05/17 10:11:06 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F6416B23-4D4E-4D19-A5D7-8C184C9D93D0}
[2012/05/17 09:26:46 | 000,000,000 | ---D | C] -- C:\Users\Robbin\job1
[2012/05/17 09:22:09 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{36ADF53B-2657-4B54-8F0C-A55C4F56289B}
[2012/05/16 19:42:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrandBilliards
[2012/05/16 19:39:31 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{982EB58C-F16C-427C-BB2C-F52576C51515}
[2012/05/16 19:39:17 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{332AAD06-0818-46E4-8D11-B4CD6144484B}
[2012/05/16 19:35:11 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D87DB762-28C8-4B2E-88A7-0D37DECDEB6D}
[2012/05/16 19:35:00 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{A009CE29-6FE7-482A-866A-829740A44FC6}
[2012/05/16 14:27:07 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2012/05/16 14:17:45 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{32D56BAE-C9DC-48FF-B117-331032511524}
[2012/05/16 14:17:33 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{74BE1FF0-6981-4EBF-B7DB-A527293CAB28}
[2012/05/15 22:30:50 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{39F13602-62DA-40B1-97C9-19A26693C670}
[2012/05/15 22:30:37 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E39E9A85-B29E-43D2-B83D-59CF2E494120}
[2012/05/14 18:00:57 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D180DC0C-A7F0-4FFA-8D8C-ED15C190F911}
[2012/05/14 18:00:42 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D2F8DCCD-B4B5-4092-BEC1-CFCFF2DDCC2B}
[2012/05/14 15:37:44 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{55D3A9D4-5B7A-4858-81B2-D67C79122192}
[2012/05/14 15:37:33 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{20B6A99D-7AD2-49A0-8780-28A5F9F3CF1C}
[2012/05/14 11:24:36 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{23D7C6D3-3B66-4B51-B524-57009EFCF9E4}
[2012/05/14 11:24:23 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{49F28A3D-563D-47EF-83F5-EFEF93A4313B}
[2012/05/13 18:18:46 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{DDF98407-C2CB-4DC8-A221-DD01B581B9D6}
[2012/05/13 18:18:35 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{EC3B84A6-49EE-4B73-8BF6-FDDEDC50A34B}
[2012/05/13 17:28:20 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E9D5E5D0-56E4-4F20-8180-4ECCB70C34D9}
[2012/05/13 17:28:10 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{B9521B4F-D946-41E4-820A-252BFCFAFE9F}
[2012/05/13 14:20:15 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{C56B5478-6390-4081-956E-F8CEEC90425C}
[2012/05/13 14:20:04 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{39C376A0-D6C5-461E-9C36-116C7D4A7397}
[2012/05/13 04:18:50 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{9579E903-DF7F-4BA4-8093-8594C10B298B}
[2012/05/13 04:18:38 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{285EC7D8-BF89-4AAD-B7AA-2F3170AD5248}
[2012/05/13 04:16:08 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D7E53113-3F13-4B7A-BD24-66A398F10CB0}
[2012/05/13 04:15:56 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{114C4FFA-EFFA-42F6-BFFF-F5A85C277A33}
[2012/05/12 13:31:19 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{B42E66A1-763D-4BBD-B427-0310DCDC00B2}
[2012/05/12 13:31:08 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E1BB1B17-B4F4-4D1E-997B-843C5F4E0846}
[2012/05/12 11:19:43 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{041EA7A3-442E-4F5A-9B83-1692C2C1655C}
[2012/05/12 11:19:33 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{2E8CD096-3488-4C03-9C6E-300C70C8E0D1}
[2012/05/12 10:40:32 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{4F8399EE-00B9-4FED-B3BD-C0082D415FF0}
[2012/05/12 10:40:21 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{91F952AC-425F-485E-8BD5-74F7FAC49943}
[2012/05/12 02:12:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/12 02:11:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/05/12 02:11:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/05/11 22:12:00 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{6D749784-2624-42F2-9495-E011A6320B23}
[2012/05/11 22:11:49 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F1655635-F67F-4812-82D5-50D0D61BF5F9}
[2012/05/11 21:50:31 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{A5A19864-4749-4B38-A5AC-69B099D88A8B}
[2012/05/11 21:50:20 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{89D95B8A-5D19-47BF-B132-248D97F0BBB9}
[2012/05/11 09:05:38 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{BB9A5883-F0D3-499A-AD83-D704A1948620}
[2012/05/11 09:05:26 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{3ECF5EFE-072D-4F6B-894C-30D30088E11B}
[2012/05/11 04:35:15 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{3E1BD955-F04F-436C-B861-999193BCBC1B}
[2012/05/11 04:35:02 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{87007933-9700-40B8-A359-D9EA9C87AAE6}
[2012/05/10 23:42:59 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{AE8EB334-6F73-484D-8104-08E53BA0742B}
[2012/05/10 23:42:48 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{3371220F-378B-44E3-804A-0593F0F418BA}
[2012/05/10 17:51:13 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{28B63227-A634-4941-8BC3-FF9720472AA6}
[2012/05/10 17:51:01 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{4C6A4DA6-8F62-4661-AA93-823FF4AF7640}
[2012/05/10 13:30:48 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{FC69A22E-9AB2-4AF7-9C55-30F3CC7E73C5}
[2012/05/10 13:30:34 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D1FCA4CD-B1A1-4E54-A09D-07D2C7F9BE83}
[2012/05/10 03:02:19 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{FA1ED0AE-FA00-4EB3-8C39-CDD42A79A3DF}
[2012/05/09 21:24:54 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{67FE9DEA-3B0C-480A-8C94-6CB21E6CA838}
[2012/05/09 21:24:43 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{9A136C1A-1A11-4624-8187-E0E1D6FBA548}
[2012/05/08 13:52:06 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{0BAF18C6-C889-487F-894E-3EE46C9B28B4}
[2012/05/08 13:51:47 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{98D73E43-24F7-4BA7-A60B-FA09B6007439}
[2012/05/08 07:35:00 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{7CAE7F84-127C-4EF3-80FE-2865BF70BB37}
[2012/05/08 07:34:49 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{9FE6CE06-ACA0-4D0C-829A-7104DC993D0A}
[2012/05/07 18:08:58 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{FDA024BA-7B6E-437A-890A-BE4591CDBB44}
[2012/05/07 18:08:42 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{195BA6B3-4258-4E14-A701-567377402037}
[2012/05/07 13:14:47 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{BEE3966F-5EF0-4A4C-B608-D6FF7A6C7344}
[2012/05/07 13:14:24 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{3AE80987-125A-4CCC-8FCF-1AD6F9619D1F}
[2012/05/07 11:55:56 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{54015147-12BD-4969-9360-02D1818EBD9C}
[2012/05/07 11:55:45 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F5EF9730-F02A-4CC9-A193-67F60C5628CE}
[2012/05/06 19:01:08 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{93A5DB81-B365-4775-A407-F9355F8BBB5C}
[2012/05/06 19:00:57 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F49AFCF7-13A6-4E5C-9499-017D30C9910F}
[2012/05/06 14:21:40 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{24FE7B6E-6555-446F-911F-CFFD0FB0D04D}
[2012/05/06 14:21:28 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{8B255698-6784-4E79-8017-9A3BEC5B7244}
[2012/05/06 01:42:53 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F8A1054D-8A1F-4DF9-8DEF-2C83AA27EC2B}
[2012/05/06 01:42:30 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{33F0B3EF-FB84-4415-AD44-863B4BFAF591}
[2012/05/05 22:14:54 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D60145AB-8D1C-492E-B046-DE0CBACBCE20}
[2012/05/05 22:14:32 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{108CF44A-F223-42DC-AEDA-DE7ABB274E45}
[2012/05/05 21:46:51 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E28A5A71-F687-465D-8279-750090E7D83F}
[2012/05/05 21:46:29 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{4DC981B0-C519-40BE-ACA1-2051FD050128}
[2012/05/05 20:15:08 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{FF0AF725-BA50-49B4-B4BC-B486D97BCE86}
[2012/05/05 20:14:57 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D2D22C29-EC83-4EE6-86FB-1A85D867FFC2}
[2012/05/05 19:45:37 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{4ED83F72-CB9A-4EF9-9E10-68EA188D4F55}
[2012/05/05 19:45:26 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D72738A6-407A-4BE5-B958-58D0A0F20E59}
[2012/05/05 18:39:01 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{377EE356-7BF8-443A-B462-D3B3587B0B24}
[2012/05/05 18:38:51 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{10546B2B-A812-491B-B332-B0EE3194D5C5}
[2012/05/05 14:07:48 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{9AD0EB1B-CDAD-468B-A83A-CE9DC50A4B7C}
[2012/05/05 14:07:37 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D04AB5D8-1777-4B71-B6C2-01C3CAAD33DA}
[2012/05/05 12:32:52 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{7979A1E6-3A2F-46AC-BF1A-94A39C337279}
[2012/05/05 12:32:34 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{7A416928-0137-4390-B6C5-FA6ED09086FB}
[2012/05/05 02:46:06 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{ED8E9621-6FB2-460C-9204-7090EC2773B8}
[2012/05/05 02:45:56 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{A41CEE35-BB58-4087-B7D0-73B1EB6385FB}
[2012/05/04 21:21:08 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{96A75FB3-0AD3-47BF-BA00-C189A4DB2F9F}
[2012/05/04 21:20:56 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{BD9B9EAE-704B-4E05-B9C2-00BB4D83EE69}
[2012/05/04 13:57:40 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{E9A5847E-7885-4B52-A29C-9C5A3EF344F0}
[2012/05/04 13:57:29 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{1428831C-C0E2-4439-8DE3-2343C8026505}
[2012/05/04 09:39:54 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{B0C7EA4B-CF7E-48F6-B0B0-AE0717D3F65D}
[2012/05/04 09:39:43 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D6D74546-F0B4-4A67-9D5D-6DFD43AFB709}
[2012/05/03 22:43:10 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{2EF4363F-CD18-4209-8F53-5E7BC8D2C4E4}
[2012/05/03 22:42:59 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{BCAC90DF-2323-4461-8021-52EB0B1F4F06}
[2012/05/03 17:45:30 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{B064BF8C-0797-46E1-8712-73AF58AA49A9}
[2012/05/03 17:45:17 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{F99753FB-3502-4E5A-8651-1A0872F9A955}
[2012/05/03 13:21:12 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{C31DCF9B-E0FE-4943-A23B-D5D845555837}
[2012/05/03 13:21:01 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{D9CA0B3F-C065-4869-9027-46E453924E2E}
[2012/05/02 09:17:41 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{C472C99E-1C2B-4FD7-8288-070A5F7C983D}
[2012/05/02 09:17:28 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{AA48A655-AE9E-480C-BAA9-4059F7C1F44C}
[2012/05/02 00:01:41 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{2A5EA4F0-7309-42E8-B3BF-5CBD9DB98F3B}
[2012/05/02 00:01:27 | 000,000,000 | ---D | C] -- C:\Users\Robbin\AppData\Local\{70594C0E-C421-4E01-8401-9B4AE9A881E1}
[2012/02/03 13:33:18 | 003,063,561 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\MobileTV.exe
[2012/02/03 13:33:16 | 002,989,660 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\DVD.exe
[2012/02/03 13:33:14 | 002,864,396 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\MPV.exe
[2012/02/03 13:33:14 | 002,331,174 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\Karaoke.exe
[2012/02/03 13:33:13 | 002,231,606 | ---- | C] (Macromedia, Inc.) -- C:\ProgramData\Games.exe

========== Files - Modified Within 30 Days ==========

[2012/05/30 00:25:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1907791719-2269733499-3100609571-1000UA.job
[2012/05/30 00:22:01 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/30 00:22:01 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/30 00:14:27 | 000,000,753 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2012/05/30 00:14:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/05/30 00:14:00 | 1609,814,016 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/30 00:03:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/29 22:01:40 | 244,326,171 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/05/29 18:40:56 | 099,458,398 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/05/29 18:40:05 | 000,472,191 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/05/27 14:02:25 | 000,001,165 | ---- | M] () -- C:\Users\Robbin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2012/05/27 14:02:25 | 000,001,141 | ---- | M] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2012/05/25 03:25:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1907791719-2269733499-3100609571-1000Core.job
[2012/05/24 13:24:08 | 000,000,450 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Robbin.job
[2012/05/24 12:54:54 | 000,000,132 | ---- | M] () -- C:\Windows\system32err.xml
[2012/05/24 12:02:22 | 000,001,343 | ---- | M] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2012/05/24 01:56:32 | 000,001,046 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012/05/24 01:55:41 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2012/05/23 23:29:54 | 000,002,368 | ---- | M] () -- C:\Users\Robbin\Desktop\Google Chrome.lnk
[2012/05/16 19:42:25 | 000,001,007 | ---- | M] () -- C:\Users\Robbin\Desktop\GrandBilliards.lnk
[2012/05/11 09:04:10 | 000,416,816 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/11 04:53:51 | 002,026,446 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/11 04:53:51 | 000,647,508 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2012/05/11 04:53:51 | 000,624,178 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/05/11 04:53:51 | 000,442,656 | ---- | M] () -- C:\Windows\SysNative\perfh001.dat
[2012/05/11 04:53:51 | 000,110,926 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2012/05/11 04:53:51 | 000,106,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/05/11 04:53:51 | 000,079,118 | ---- | M] () -- C:\Windows\SysNative\perfc001.dat
[2012/05/10 17:50:56 | 000,000,996 | ---- | M] () -- C:\Users\Robbin\Desktop\magicJack.lnk
[2012/05/02 00:00:28 | 000,000,366 | ---- | M] () -- C:\Windows\tasks\Driver Robot.job

========== Files Created - No Company Name ==========

[2012/05/27 14:02:25 | 000,001,165 | ---- | C] () -- C:\Users\Robbin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2012/05/27 14:02:25 | 000,001,141 | ---- | C] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2012/05/24 12:54:49 | 000,000,132 | ---- | C] () -- C:\Windows\system32err.xml
[2012/05/24 12:02:24 | 000,000,450 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Robbin.job
[2012/05/24 12:02:22 | 000,001,343 | ---- | C] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2012/05/24 12:02:19 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NSSx64\0307020.005\isolate.ini
[2012/05/24 01:56:32 | 000,001,046 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012/05/18 11:59:53 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/16 19:42:25 | 000,001,007 | ---- | C] () -- C:\Users\Robbin\Desktop\GrandBilliards.lnk
[2012/01/26 19:57:02 | 000,000,753 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2011/12/19 22:13:31 | 001,036,288 | ---- | C] () -- C:\Windows\SysWow64\lxdudrs.dll
[2011/12/19 22:13:31 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\lxducaps.dll
[2011/12/19 22:13:31 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\lxducnv4.dll
[2011/12/01 04:27:26 | 000,413,696 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcginpa.dll
[2011/12/01 04:27:26 | 000,397,312 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgiesc.dll
[2011/12/01 04:27:26 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\lxcgcomx.dll
[2011/12/01 04:27:26 | 000,274,432 | ---- | C] () -- C:\Windows\SysWow64\lxcginst.dll
[2011/12/01 04:27:25 | 001,224,704 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgserv.dll
[2011/12/01 04:27:25 | 000,995,328 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgusb1.dll
[2011/12/01 04:27:25 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgpmui.dll
[2011/12/01 04:27:24 | 000,696,320 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcghbn3.dll
[2011/12/01 04:27:24 | 000,585,728 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcglmpm.dll
[2011/12/01 04:27:24 | 000,385,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgih.exe
[2011/12/01 04:27:24 | 000,181,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgppls.exe
[2011/12/01 04:27:24 | 000,163,840 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgprox.dll
[2011/12/01 04:27:24 | 000,094,208 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgpplc.dll
[2011/12/01 04:27:23 | 000,684,032 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgcomc.dll
[2011/12/01 04:27:23 | 000,537,520 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgcoms.exe
[2011/12/01 04:27:23 | 000,421,888 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgcomm.dll
[2011/12/01 04:27:23 | 000,381,872 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcgcfg.exe
[2011/09/29 16:00:46 | 000,000,040 | ---- | C] () -- C:\Windows\SysWow64\d3d9prs.dat

========== LOP Check ==========

[2012/05/29 20:51:44 | 000,000,000 | ---D | M] -- C:\Users\Robbin\AppData\Roaming\ApplicationData
[2011/08/28 09:43:29 | 000,000,000 | ---D | M] -- C:\Users\Robbin\AppData\Roaming\AVG10
[2012/05/10 17:51:02 | 000,000,000 | ---D | M] -- C:\Users\Robbin\AppData\Roaming\mjusbsp
[2011/10/04 04:33:10 | 000,000,000 | ---D | M] -- C:\Users\Robbin\AppData\Roaming\Windows Live Writer
[2012/05/02 00:00:28 | 000,000,366 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job
[2012/05/25 02:11:22 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
Hello and welcome to Geekstogo!

We apologize for the delay in responding to your request for help.
If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

If you haven't done so yet, please go to Malware and Spyware Cleaning Guide and follow the steps instructed there. If you have already done this, we still need a new log to see what has changed since you originally posted your problem.

We need to create an OTL Report
Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the box that says Scan All Users.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic.

In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. I suggest you do this and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP