I noticed some slowdowns with with the Internet (CPU running at 100%) and several tabs of untrusted site showing up.
I have done several full scan with AVG Free 20145 and I keep getting results stating
Trojan horse Generic_r/EJI emanating from various files in Windows\SysWOW64. Some of the infections are able to be secured while others say the Element Can Not Be Found. After removing the items, subsequent scans still have the same infections.If I disconnect the internet cable the system seems to go back to normal.
I also noticed strange processes active in my taskmgr including ctfmon, dllhost, fixmapi, dvdupgdr, and others even though it goes not seem the process is actually active. I force close the processes, but they return again in a few minutes.
I downloaded and ran OTL Tool. The logs are attached below. Please let me know what I can do.
OTL logfile created on: 1/4/2015 1:59:56 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Norm\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.75 Gb Total Physical Memory | 5.43 Gb Available Physical Memory | 70.01% Memory free
15.50 Gb Paging File | 12.80 Gb Available in Paging File | 82.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 708.16 Gb Free Space | 76.02% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 166.59 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 488.71 Mb Total Space | 449.03 Mb Free Space | 91.88% Space Free | Partition Type: FAT
Drive F: | 372.61 Gb Total Space | 136.59 Gb Free Space | 36.66% Space Free | Partition Type: NTFS
Computer Name: NORM-PC | User Name: Norm | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found --
PRC - [2015/01/04 13:56:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Norm\Desktop\OTL.exe
PRC - [2014/12/18 09:54:30 | 003,432,976 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
PRC - [2014/12/18 09:51:32 | 001,486,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
PRC - [2014/12/18 09:51:14 | 003,667,472 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgui.exe
PRC - [2014/12/18 09:45:26 | 000,298,080 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
PRC - [2014/12/05 20:50:53 | 000,856,904 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/12/03 01:31:16 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/11/13 22:17:33 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
PRC - [2014/11/06 10:29:26 | 000,602,880 | ---- | M] (NETGEAR Inc.) -- C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe
PRC - [2014/11/06 10:28:44 | 000,105,216 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
PRC - [2014/10/21 17:52:24 | 022,869,088 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe
PRC - [2014/09/18 18:16:34 | 000,014,624 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2014/08/12 06:36:02 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWOW64\java.exe
PRC - [2014/06/05 03:19:38 | 000,093,040 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2014/03/11 22:36:06 | 000,247,968 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
PRC - [2014/03/05 12:02:46 | 001,470,280 | R--- | M] (ACD Systems) -- C:\Program Files (x86)\ACD Systems\ACDSee\17.0\acdIDInTouch2.exe
PRC - [2012/09/20 16:57:02 | 004,139,008 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\USB Control Center\Control Center.exe
PRC - [2011/11/17 01:36:22 | 001,231,472 | ---- | M] (ACD Systems) -- C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe
PRC - [2010/02/08 13:43:20 | 001,916,248 | ---- | M] (Smith Micro Software, Inc.) -- C:\Program Files (x86)\Smith Micro\StuffIt 2010\ArcNameService.exe
PRC - [2008/12/12 17:06:40 | 000,642,856 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2008/12/12 17:06:40 | 000,642,856 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
PRC - [2008/11/13 14:43:49 | 000,204,800 | ---- | M] () -- C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe
PRC - [2007/09/10 23:45:04 | 000,124,832 | ---- | M] () -- C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
PRC - [2006/10/12 14:57:08 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe
========== Modules (No Company Name) ==========
MOD - [2015/01/04 08:21:21 | 001,160,704 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\_ssl.pyd
MOD - [2015/01/04 08:21:21 | 000,805,888 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._gdi_.pyd
MOD - [2015/01/04 08:21:21 | 000,110,080 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\PyWinTypes27.dll
MOD - [2015/01/04 08:21:21 | 000,027,136 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\_multiprocessing.pyd
MOD - [2015/01/04 08:21:21 | 000,007,168 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\hashobjs_ext.pyd
MOD - [2015/01/04 08:21:20 | 000,713,216 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\_hashlib.pyd
MOD - [2015/01/04 08:21:19 | 001,062,400 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._controls_.pyd
MOD - [2015/01/04 08:21:19 | 000,811,008 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._windows_.pyd
MOD - [2015/01/04 08:21:19 | 000,070,656 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._html2.pyd
MOD - [2015/01/04 08:21:19 | 000,025,600 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32pdh.pyd
MOD - [2015/01/04 08:21:19 | 000,024,064 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32pipe.pyd
MOD - [2015/01/04 08:21:18 | 000,686,080 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\unicodedata.pyd
MOD - [2015/01/04 08:21:18 | 000,127,488 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\pyexpat.pyd
MOD - [2015/01/04 08:21:18 | 000,108,544 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32security.pyd
MOD - [2015/01/04 08:21:18 | 000,045,568 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\_socket.pyd
MOD - [2015/01/04 08:21:18 | 000,038,912 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32inet.pyd
MOD - [2015/01/04 08:21:18 | 000,018,432 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32event.pyd
MOD - [2015/01/04 08:21:18 | 000,017,408 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32profile.pyd
MOD - [2015/01/04 08:21:18 | 000,010,240 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\select.pyd
MOD - [2015/01/04 08:21:17 | 000,525,640 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\windows._lib_cacheinvalidation.pyd
MOD - [2015/01/04 08:21:17 | 000,167,936 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32gui.pyd
MOD - [2015/01/04 08:21:17 | 000,119,808 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32file.pyd
MOD - [2015/01/04 08:21:16 | 000,128,512 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\_elementtree.pyd
MOD - [2015/01/04 08:21:16 | 000,087,552 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\_ctypes.pyd
MOD - [2015/01/04 08:21:14 | 000,098,816 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32api.pyd
MOD - [2015/01/04 08:21:13 | 000,557,056 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\pysqlite2._sqlite.pyd
MOD - [2015/01/04 08:21:13 | 000,320,512 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32com.shell.shell.pyd
MOD - [2015/01/04 08:21:13 | 000,022,528 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32ts.pyd
MOD - [2015/01/04 08:21:12 | 001,175,040 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._core_.pyd
MOD - [2015/01/04 08:21:12 | 000,364,544 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\pythoncom27.dll
MOD - [2015/01/04 08:21:11 | 000,735,232 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._misc_.pyd
MOD - [2015/01/04 08:21:11 | 000,078,336 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._animate.pyd
MOD - [2015/01/04 08:21:11 | 000,011,264 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32crypt.pyd
MOD - [2015/01/04 08:21:10 | 000,122,368 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\wx._wizard.pyd
MOD - [2015/01/04 08:21:09 | 000,035,840 | ---- | M] () -- C:\Users\Norm\AppData\Local\Temp\_MEI41442\win32process.pyd
MOD - [2014/12/05 20:50:46 | 001,077,064 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll
MOD - [2014/12/05 20:50:45 | 000,211,272 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll
MOD - [2014/11/17 04:46:22 | 000,639,488 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll
MOD - [2014/11/17 02:00:34 | 001,056,768 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll
MOD - [2014/11/17 01:21:08 | 010,374,656 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll
MOD - [2014/11/17 01:18:32 | 002,496,512 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll
MOD - [2014/11/14 05:53:22 | 006,499,840 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll
MOD - [2014/11/10 04:55:06 | 001,686,016 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll
MOD - [2014/11/07 04:13:32 | 002,475,520 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_MyMedia.dll
MOD - [2014/11/06 10:28:44 | 000,105,216 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
MOD - [2014/11/06 04:39:44 | 000,200,192 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll
MOD - [2014/11/05 03:01:04 | 000,458,752 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll
MOD - [2014/11/05 03:00:24 | 000,435,712 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll
MOD - [2014/11/05 02:59:24 | 000,642,048 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll
MOD - [2014/11/05 02:58:54 | 000,889,344 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll
MOD - [2014/11/05 02:51:50 | 001,191,424 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll
MOD - [2014/11/05 02:37:06 | 000,632,832 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll
MOD - [2014/11/05 02:36:18 | 000,192,512 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll
MOD - [2014/11/03 03:23:18 | 000,143,360 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll
MOD - [2014/09/11 03:39:34 | 000,144,896 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll
MOD - [2014/09/04 01:00:44 | 000,136,704 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll
MOD - [2014/09/04 01:00:34 | 000,066,560 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll
MOD - [2014/09/04 01:00:28 | 000,074,240 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll
MOD - [2014/09/04 01:00:20 | 000,072,192 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.dll
MOD - [2014/06/29 21:33:52 | 000,046,080 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll
MOD - [2014/06/29 21:05:12 | 001,183,232 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\qwt.dll
MOD - [2014/06/29 20:55:38 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll
MOD - [2014/06/29 20:55:00 | 000,081,408 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll
MOD - [2014/06/18 21:22:04 | 002,177,405 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\drivers\libntgr_api.dll
MOD - [2013/09/28 20:14:20 | 001,233,408 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\platforms\qwindows.dll
MOD - [2013/09/28 20:14:06 | 003,369,922 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\icuin51.dll
MOD - [2013/09/28 20:14:06 | 001,978,690 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\icuuc51.dll
MOD - [2013/09/28 20:14:04 | 022,378,434 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\icudt51.dll
MOD - [2013/09/28 20:13:48 | 000,989,805 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\libstdc++-6.dll
MOD - [2013/09/28 20:13:48 | 000,544,817 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll
MOD - [2013/09/28 20:13:48 | 000,261,120 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qjpeg.dll
MOD - [2013/09/28 20:13:48 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qico.dll
MOD - [2013/09/28 20:13:48 | 000,051,200 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qgif.dll
MOD - [2013/09/28 20:13:48 | 000,046,080 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qsvg.dll
MOD - [2013/09/28 20:13:48 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\printsupport\windowsprintersupport.dll
MOD - [2013/01/16 11:58:54 | 008,626,176 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
MOD - [2013/01/16 11:58:52 | 000,212,992 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2013/01/16 11:58:50 | 002,408,448 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
MOD - [2012/10/15 15:28:38 | 002,286,592 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\libvlccore.dll
MOD - [2012/10/15 15:28:30 | 000,051,200 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libwaveout_plugin.dll
MOD - [2012/10/15 15:28:30 | 000,049,664 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libaout_directx_plugin.dll
MOD - [2012/10/15 15:28:04 | 000,070,144 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\plugins\video_output\libdirectx_plugin.dll
MOD - [2012/10/15 15:28:02 | 000,219,648 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\plugins\access\libdshow_plugin.dll
MOD - [2012/10/15 15:27:56 | 000,111,616 | ---- | M] () -- C:\Program Files (x86)\NETGEAR Genie\bin\libvlc.dll
MOD - [2012/09/20 16:57:02 | 004,139,008 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\USB Control Center\Control Center.exe
MOD - [2008/12/12 17:11:26 | 000,148,480 | ---- | M] () -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\CAntiVirusCOM.dll
MOD - [2008/12/12 17:11:26 | 000,097,280 | ---- | M] () -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\CFirewallCOM.dll
========== Services (SafeList) ==========
SRV:64bit: - [2014/11/21 21:35:29 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/07/03 15:19:06 | 000,263,168 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\BCL Technologies\easyConverter SDK 3\Common\becldr.exe -- (becldr3Service)
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2011/04/20 01:04:20 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2014/12/30 22:20:49 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/12/18 10:00:17 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/12/18 09:54:30 | 003,432,976 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2014/12/18 09:51:32 | 001,486,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2015\avgfws.exe -- (avgfws)
SRV - [2014/12/18 09:45:26 | 000,298,080 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe -- (avgwd)
SRV - [2014/12/03 01:31:16 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/11/24 12:48:34 | 002,604,856 | ---- | M] (AVG Technologies) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2014/11/06 10:29:36 | 000,232,192 | ---- | M] (NETGEAR) [Auto | Running] -- C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe -- (NETGEARGenieDaemon)
SRV - [2014/11/04 17:40:02 | 005,795,120 | ---- | M] (MediaMall Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\MediaMall\MediaMallServer.exe -- (MediaMall Server)
SRV - [2014/09/18 18:16:34 | 000,014,624 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2014/06/05 03:19:38 | 000,093,040 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2014/03/20 17:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/03/11 22:36:06 | 000,247,968 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE -- (BBUpdate)
SRV - [2014/03/11 22:36:06 | 000,193,696 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE -- (BBSvc)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/04/18 10:06:42 | 000,737,616 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/03/25 20:15:04 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/10/07 12:39:52 | 000,234,784 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Program Files (x86)\AirPrint\airprint.exe -- (AirPrint)
SRV - [2010/02/08 13:43:20 | 001,916,248 | ---- | M] (Smith Micro Software, Inc.) [Auto | Running] -- C:\Program Files (x86)\Smith Micro\StuffIt 2010\ArcNameService.exe -- (Stuffit Archive Name Service)
SRV - [2008/12/12 17:06:40 | 000,642,856 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2008/11/13 14:43:49 | 000,204,800 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe -- (LinksysUpdater)
SRV - [2007/09/10 23:45:04 | 000,124,832 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor6.0)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014/12/08 21:24:26 | 000,260,888 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2014/11/18 21:42:04 | 000,203,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2014/11/18 16:30:19 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2014/10/10 15:14:32 | 000,274,200 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2014/10/05 20:41:40 | 000,124,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2014/08/28 20:47:24 | 000,243,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2014/07/28 13:52:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/07/18 14:53:26 | 000,313,624 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2014/06/18 20:03:34 | 000,153,368 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2014/06/18 20:03:20 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2013/10/01 21:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/09/26 09:44:54 | 000,057,144 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)
DRV:64bit: - [2012/10/17 13:53:46 | 000,026,112 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2012/08/23 09:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/08/13 14:05:58 | 000,183,584 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NetgearUDSTcpBus.sys -- (NetgearUDSTcpBus)
DRV:64bit: - [2012/08/13 14:03:32 | 000,107,296 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NetgearUDSMBus.sys -- (NetgearUDSMBus)
DRV:64bit: - [2012/04/18 14:05:16 | 000,019,304 | ---- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\grmnusb.sys -- (grmnusb)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/04/20 01:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2011/04/20 01:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/04/20 00:22:34 | 000,306,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/03/25 20:13:15 | 000,052,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/07 13:35:06 | 000,028,528 | ---- | M] (MediaMall Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\povrtdev.sys -- (msvad_simple)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/04/14 00:01:44 | 000,054,824 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/03/01 22:05:32 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2008/12/12 17:05:18 | 000,033,072 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\purendis.sys -- (purendis)
DRV:64bit: - [2008/12/12 17:05:18 | 000,031,536 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\pnarp.sys -- (pnarp)
DRV - [2014/11/24 12:31:18 | 000,014,112 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2014/07/01 12:37:56 | 000,020,872 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\DrvAgent64.SYS -- (DrvAgent64)
DRV - [2012/06/15 13:04:00 | 000,092,160 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\NetgearUDSMBus.sys -- (NetgearUDSMBus)
DRV - [2012/06/15 13:02:58 | 000,153,600 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\NetgearUDSTcpBus.sys -- (NetgearUDSTcpBus)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {F277C811-E1FF-46A7-95F9-1127EB5F3940}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 33 BF 17 A0 1F EB CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..CT3294791.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultEngine: "Yahoo"
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaultthis.engineName: "Vafmusic2 Customized Web Search"
FF - prefs.js..browser.search.isUS: true
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-oc"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-oc"
FF - prefs.js..browser.search.param.yahoo-type: ""
FF - prefs.js..browser.search.selectedEngine: "Vosteran"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: support%40ancestry.com:1.0.0.1
FF - prefs.js..extensions.enabledAddons: playonplugin%40playon.tv:1.0
FF - prefs.js..extensions.enabledAddons: %7B9D6218B8-03C7-4b91-AA43-680B305DD35C%7D:3.3.2
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.9.10
FF - prefs.js..extensions.enabledAddons: b1ac2ff7-8e51-4bb6-8bf8-87f1d567919a%404bb97481-aead-4c2e-a62b-e25e264651bb.com:0.95.133
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:34.0.5
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@playon.tv/PlayOnToolbar: C:\Program Files (x86)\MediaMall\toolbar\npVT.dll (MediaMall Technologies, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6311158d-1248-4c22-b80e-0fce899a0c7c}: C:\Program Files (x86)\Mozilla Firefox\extensions\{6311158d-1248-4c22-b80e-0fce899a0c7c}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/12/18 10:00:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.3.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2014/12/17 15:50:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files (x86)\AVG\AVG2012\Thunderbird\
[2011/03/26 21:29:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Extensions
[2011/03/26 21:29:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/03/25 19:22:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Extensions\
[email protected]
[2015/01/03 13:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions
[2014/10/24 08:43:49 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2014/11/13 09:44:32 | 000,000,000 | ---D | M] (Vafmusic2) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\{7f3f960e-a836-45ca-8911-0accb522246e}
[2015/01/03 13:24:26 | 000,000,000 | ---D | M] ("The weDownload Manager") -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\b1ac2ff7-8e51-4bb6-8bf8-87f1d567919a@4bb97481-aead-4c2e-a62b-e25e264651bb.com
[2012/07/22 15:35:52 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\
[email protected]
[2014/09/05 09:47:24 | 000,000,000 | ---D | M] (PlayOn) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\
[email protected]
[2011/03/26 15:31:49 | 000,000,000 | ---D | M] (Ancestry.com Advanced Image Viewer) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\
[email protected]
[2015/01/03 13:24:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\b1ac2ff7-8e51-4bb6-8bf8-87f1d567919a@4bb97481-aead-4c2e-a62b-e25e264651bb.com\extensionData
[2015/01/03 13:24:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\b1ac2ff7-8e51-4bb6-8bf8-87f1d567919a@4bb97481-aead-4c2e-a62b-e25e264651bb.com\extensionData\plugins
[2015/01/03 13:24:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\b1ac2ff7-8e51-4bb6-8bf8-87f1d567919a@4bb97481-aead-4c2e-a62b-e25e264651bb.com\extensionData\userCode
[2014/12/28 14:05:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\q28cj05m.default\extensions
[2014/09/05 09:47:24 | 000,000,000 | ---D | M] (PlayOn) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\q28cj05m.default\extensions\
[email protected]
[2014/12/28 17:26:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\q28cj05m.default\extensions\staged
[2014/12/12 10:18:35 | 002,551,632 | ---- | M] () (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\
[email protected]
[2015/01/02 14:22:31 | 000,544,302 | ---- | M] () (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2014/12/17 12:27:26 | 000,085,243 | ---- | M] () (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\{9D6218B8-03C7-4b91-AA43-680B305DD35C}.xpi
[2014/11/12 16:34:54 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/04/30 21:55:07 | 000,002,325 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\searchplugins\askcom.xml
[2010/12/20 08:51:09 | 000,001,832 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\searchplugins\bing.xml
[2014/02/19 16:25:50 | 000,000,880 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\searchplugins\conduit-search.xml
[2013/04/11 11:46:34 | 000,001,294 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\searchplugins\delta.xml
[2014/12/23 09:04:10 | 000,001,168 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\searchplugins\vafmusic2-customized-web-search.xml
[2014/12/28 17:30:49 | 000,002,827 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\searchplugins\Vosteran.xml
[2014/12/23 19:26:33 | 000,008,141 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\Mozilla\Firefox\Profiles\2x7ofyo3.default\searchplugins\yahoo_ff.xml
[2014/12/18 10:00:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2014/12/18 10:00:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\
[email protected]
[2014/12/18 10:00:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/12/18 10:00:18 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: RivalGaming Addon (Enabled) = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\adhmhclafdhfabmmglbcngpddpdeijgd\npRivalGamingGC.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha\0.5.4_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\jncebfkpboiagfoihpgjknfkkkpaphjk\1.5_1\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh\3.2_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce\0.3.9_0\
CHR - Extension: No name found = C:\Users\Norm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (The weDownload Manager) - {11111111-1111-1111-1111-110411901174} - C:\Program Files (x86)\The weDownload Manager\The weDownload Manager-bho64.dll (weDownload)
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2:64bit: - BHO: (PlayOn) - {9A87E478-A2BD-44C4-9F8C-D3989A5271B1} - C:\Program Files (x86)\MediaMall\toolbar\pobho64.dll (MediaMall Technologies, Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - No CLSID value found.
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (PlayOn) - {9A87E478-A2BD-44C4-9F8C-D3989A5271B1} - C:\Program Files (x86)\MediaMall\toolbar\pobho.dll (MediaMall Technologies, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (PlayOn) - {9A87E478-A2BD-44C4-9F8C-D3989A5271B1} - C:\Program Files (x86)\MediaMall\toolbar\pobho64.dll (MediaMall Technologies, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (PlayOn) - {9A87E478-A2BD-44C4-9F8C-D3989A5271B1} - C:\Program Files (x86)\MediaMall\toolbar\pobho.dll (MediaMall Technologies, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [CNAP2 Launcher] C:\Windows\SysNative\spool\drivers\x64\3\CNAP2LAK.EXE (CANON INC.)
O4 - HKLM..\Run: [ACSW14EN] C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe (ACD Systems)
O4 - HKLM..\Run: [ACSW17EN] C:\Program Files (x86)\ACD Systems\ACDSee\17.0\acdIDInTouch2.exe (ACD Systems)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2015\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [NETGEAR USB Control Center] C:\Program Files (x86)\NETGEAR\USB Control Center\Control Center.exe ()
O4 - HKLM..\Run: [nmctxth] C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [VIDC04EN] C:\Program Files (x86)\ACD Systems\ACDSee Video Converter 4.1\acdIDInTouch2.exe (ACD Systems)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Norm\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE File not found
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_13722F0580CA191EC89E26C74285026F] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [NETGEARGenie] C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe (NETGEAR Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O8:64bit: - Extra context menu item: MasterCook: Select Image - C:\Program Files (x86)\MasterCook 9\Web\MCIEContext.hta ()
O8 - Extra context menu item: MasterCook: Select Image - C:\Program Files (x86)\MasterCook 9\Web\MCIEContext.hta ()
O9:64bit: - Extra Button: PlayOn - {936CEA21-9A68-46D9-A31B-1173A976D896} - C:\Program Files (x86)\MediaMall\toolbar\pobho64.dll (MediaMall Technologies, Inc.)
O9:64bit: - Extra 'Tools' menuitem : PlayOn - {936CEA21-9A68-46D9-A31B-1173A976D896} - C:\Program Files (x86)\MediaMall\toolbar\pobho64.dll (MediaMall Technologies, Inc.)
O9 - Extra Button: PlayOn - {936CEA21-9A68-46D9-A31B-1173A976D896} - C:\Program Files (x86)\MediaMall\toolbar\pobho.dll (MediaMall Technologies, Inc.)
O9 - Extra 'Tools' menuitem : PlayOn - {936CEA21-9A68-46D9-A31B-1173A976D896} - C:\Program Files (x86)\MediaMall\toolbar\pobho.dll (MediaMall Technologies, Inc.)
O9 - Extra Button: MasterCook Web Import Bar - {E6EF5071-7647-4E85-9785-87B6CF5CB561} - Reg Error: Key error. File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9DE30F4-74F0-46BD-ACD7-46D35606D948}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\Norm\AppData\Roaming\skype.dat) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{3ab7d94d-9960-11e3-97ee-000272a92cfd}\Shell - "" = AutoRun
O33 - MountPoints2\{3ab7d94d-9960-11e3-97ee-000272a92cfd}\Shell\AutoRun\command - "" = E:\MotorolaDeviceManagerSetup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015/01/04 13:58:29 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Norm\Desktop\OTL.exe
[2015/01/03 18:51:58 | 000,000,000 | ---D | C] -- C:\FRST
[2015/01/03 18:51:36 | 002,123,776 | ---- | C] (Farbar) -- C:\Users\Norm\Desktop\FRST64.exe
[2015/01/03 11:02:11 | 000,040,248 | ---- | C] (AVG Technologies) -- C:\Windows\SysNative\TURegOpt.exe
[2015/01/03 11:02:11 | 000,029,496 | ---- | C] (AVG Technologies) -- C:\Windows\SysNative\authuitu.dll
[2015/01/03 11:02:11 | 000,025,400 | ---- | C] (AVG Technologies) -- C:\Windows\SysWow64\authuitu.dll
[2015/01/03 11:01:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015
[2015/01/03 10:58:24 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Local\Avg
[2014/12/31 12:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DLLSuite
[2014/12/30 22:09:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014/12/30 21:35:44 | 000,000,000 | ---D | C] -- C:\Users\Norm\Documents\Chrome
[2014/12/30 16:11:57 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Roaming\AVG2015
[2014/12/30 16:10:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2014/12/30 16:10:19 | 000,000,000 | -H-D | C] -- C:\$AVG
[2014/12/30 16:10:19 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2015
[2014/12/30 14:21:27 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Local\Avg2015
[2014/12/30 14:20:57 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Local\Avg2014
[2014/12/30 12:31:10 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Microsoft
[2014/12/30 11:14:13 | 000,189,920 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\mfevtps.exe.31b0.deleteme
[2014/12/30 11:05:27 | 000,189,920 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\mfevtps.exe.3078.deleteme
[2014/12/29 17:47:25 | 000,000,000 | ---D | C] -- C:\stinger
[2014/12/29 17:38:11 | 000,000,000 | ---D | C] -- C:\Quarantine
[2014/12/29 10:50:01 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2014/12/29 08:17:56 | 000,000,000 | ---D | C] -- C:\Users\Norm\Documents\del
[2014/12/28 17:28:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DriverRestore
[2014/12/28 14:07:58 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Local\Vosteran
[2014/12/28 14:07:37 | 000,020,872 | ---- | C] (Phoenix Technologies) -- C:\Windows\SysWow64\drivers\DrvAgent64.SYS
[2014/12/28 14:07:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
[2014/12/28 14:05:33 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Roaming\WSE_Vosteran
[2014/12/28 11:34:37 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Roaming\SparkTrust
[2014/12/28 11:33:25 | 000,000,000 | ---D | C] -- C:\ProgramData\SparkTrust
[2014/12/23 18:05:20 | 000,000,000 | ---D | C] -- C:\Elwood Software
[2014/12/23 16:48:58 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Roaming\StatTrak Address Manager
[2014/12/23 15:58:18 | 000,000,000 | ---D | C] -- C:\Users\Norm\Documents\StatTrak Address Manager
[2014/12/23 15:12:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\All-Pro Software
[2014/12/18 10:00:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014/12/17 15:50:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2014/12/16 09:29:50 | 000,000,000 | ---D | C] -- C:\Users\Norm\Documents\TempDoc
[2014/12/11 13:00:33 | 000,000,000 | ---D | C] -- C:\Users\Norm\AppData\Local\{040D2414-9CC3-4E56-9880-A87CB8C55660}
[2014/12/11 07:39:02 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appraiser
[2014/12/08 21:24:26 | 000,260,888 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[28 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015/01/04 13:59:10 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015/01/04 13:59:10 | 000,662,384 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015/01/04 13:59:10 | 000,122,252 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015/01/04 13:56:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Norm\Desktop\OTL.exe
[2015/01/04 13:52:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/01/04 13:22:47 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/01/04 08:27:19 | 000,022,256 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/01/04 08:27:19 | 000,022,256 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/01/04 08:21:07 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/01/04 08:17:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/01/04 08:17:38 | 1945,608,191 | -HS- | M] () -- C:\hiberfil.sys
[2015/01/03 18:40:16 | 002,123,776 | ---- | M] (Farbar) -- C:\Users\Norm\Desktop\FRST64.exe
[2015/01/03 11:28:09 | 000,020,830 | ---- | M] () -- C:\Users\Norm\Documents\MyInfo.kdbx
[2015/01/03 11:01:54 | 000,002,229 | ---- | M] () -- C:\Users\Public\Desktop\AVG 1-Click Maintenance.lnk
[2015/01/03 11:01:54 | 000,002,203 | ---- | M] () -- C:\Users\Public\Desktop\AVG PC TuneUp 2015.lnk
[2014/12/31 08:11:36 | 000,002,283 | ---- | M] () -- C:\Users\Norm\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/12/30 22:09:34 | 000,002,259 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/12/30 16:10:59 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2015.lnk
[2014/12/28 15:06:38 | 000,000,010 | ---- | M] () -- C:\Users\Norm\AppData\Local\DSI.DAT
[2014/12/28 15:06:24 | 000,000,226 | ---- | M] () -- C:\Users\Norm\AppData\Roaming\WB.CFG
[2014/12/26 22:15:08 | 000,000,978 | ---- | M] () -- C:\Users\Norm\Desktop\Backup1.cmd - Shortcut.lnk
[2014/12/24 09:22:47 | 000,014,878 | ---- | M] () -- C:\Users\Norm\Documents\Addresses-2.csv
[2014/12/23 16:13:42 | 000,001,113 | ---- | M] () -- C:\Users\Norm\Documents\Addresses_1.csv
[2014/12/23 15:10:16 | 000,114,688 | ---- | M] () -- C:\Users\Norm\Documents\ContactKeeper.mdb
[2014/12/23 12:59:06 | 000,010,272 | ---- | M] () -- C:\Users\Norm\Documents\Addresses Query.pdf
[2014/12/21 10:13:37 | 000,002,048 | ---- | M] () -- C:\Users\Norm\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2014/12/17 15:51:32 | 000,002,114 | ---- | M] () -- C:\Users\Norm\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2014/12/16 19:31:20 | 000,000,355 | ---- | M] () -- C:\Users\Norm\Desktop\Computer - Shortcut.lnk
[2014/12/08 21:24:26 | 000,260,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2014/12/06 07:12:12 | 000,438,088 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[28 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015/01/03 11:01:54 | 000,002,229 | ---- | C] () -- C:\Users\Public\Desktop\AVG 1-Click Maintenance.lnk
[2015/01/03 11:01:54 | 000,002,203 | ---- | C] () -- C:\Users\Public\Desktop\AVG PC TuneUp 2015.lnk
[2015/01/03 11:01:53 | 000,002,215 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk
[2014/12/30 22:09:34 | 000,002,283 | ---- | C] () -- C:\Users\Norm\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/12/30 22:09:34 | 000,002,259 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/12/30 16:10:59 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2015.lnk
[2014/12/28 15:06:38 | 000,000,010 | ---- | C] () -- C:\Users\Norm\AppData\Local\DSI.DAT
[2014/12/26 22:07:55 | 000,000,978 | ---- | C] () -- C:\Users\Norm\Desktop\Backup1.cmd - Shortcut.lnk
[2014/12/23 18:19:45 | 000,014,878 | ---- | C] () -- C:\Users\Norm\Documents\Addresses-2.csv
[2014/12/23 16:07:39 | 000,001,113 | ---- | C] () -- C:\Users\Norm\Documents\Addresses_1.csv
[2014/12/23 14:58:40 | 000,114,688 | ---- | C] () -- C:\Users\Norm\Documents\ContactKeeper.mdb
[2014/12/23 12:56:18 | 000,010,272 | ---- | C] () -- C:\Users\Norm\Documents\Addresses Query.pdf
[2014/12/16 19:31:20 | 000,000,355 | ---- | C] () -- C:\Users\Norm\Desktop\Computer - Shortcut.lnk
[2014/10/09 10:10:53 | 000,000,064 | ---- | C] () -- C:\Users\Norm\AppData\Local\eabb7061177c578f3330c42e293d6adb
[2013/09/22 16:07:01 | 000,000,226 | ---- | C] () -- C:\Users\Norm\AppData\Roaming\WB.CFG
[2013/03/19 09:56:47 | 000,000,004 | ---- | C] () -- C:\Users\Norm\AppData\Roaming\skype.ini
[2012/07/22 14:11:00 | 000,031,465 | ---- | C] () -- C:\Users\Norm\AppData\Local\funmoods.crx
[2012/02/10 20:53:11 | 000,001,240 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2011/04/13 16:55:58 | 052,989,952 | ---- | C] () -- C:\Users\Norm\JAMES3.QDF-backup
[2011/03/27 21:55:20 | 000,044,544 | ---- | C] () -- C:\Users\Norm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/25 14:47:11 | 000,007,600 | ---- | C] () -- C:\Users\Norm\AppData\Local\resmon.resmoncfg
[2009/10/30 11:13:49 | 000,061,224 | ---- | C] () -- C:\Users\Norm\GoToAssistDownloadHelper.exe
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 21:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 20:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/04/13 07:29:43 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\ACD Systems
[2013/07/12 11:52:33 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\AnvSoft
[2013/09/13 15:25:45 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Audacity
[2015/01/03 11:01:24 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\AVG
[2014/12/30 16:11:57 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\AVG2015
[2012/01/22 16:50:37 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Babylon
[2011/03/25 18:44:57 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Barnes & Noble
[2012/12/23 07:50:39 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\DriverCure
[2013/04/11 11:46:11 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\DSite
[2011/04/08 09:47:57 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\EPSON
[2013/11/10 14:42:16 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\FamilyTreeMaker
[2013/05/30 16:07:16 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Funmoods
[2013/06/18 14:06:23 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\GrabPro
[2014/10/15 08:39:38 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Green Parrots Software
[2014/10/01 07:19:14 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\ISpeedPC
[2015/01/03 19:07:38 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\KeePass
[2011/03/25 20:32:42 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Leadertech
[2012/01/16 14:02:30 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Nokia
[2011/03/28 20:32:41 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Nokia Ovi Suite
[2012/01/16 13:43:36 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Nokia Suite
[2013/07/12 11:51:27 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\OpenCandy
[2013/10/14 08:29:22 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\OpenOffice
[2011/03/25 18:59:17 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\OpenOffice.org
[2014/08/12 06:37:19 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Oracle
[2013/06/18 14:19:19 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Orbit
[2012/12/23 07:50:38 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\ParetoLogic
[2013/04/14 11:07:29 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\PC Suite
[2013/06/18 14:06:29 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\ProgSense
[2014/11/15 11:58:05 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\SketchUp
[2012/03/21 08:13:24 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Softland
[2014/12/28 11:34:37 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\SparkTrust
[2014/12/23 16:48:58 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\StatTrak Address Manager
[2013/05/22 13:12:41 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Strongvault
[2014/10/12 20:06:57 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\TextPad
[2011/04/29 15:47:29 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Thunderbird
[2011/03/25 19:22:32 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\TomTom
[2013/02/17 18:06:17 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\TuneUp Software
[2013/10/19 13:41:48 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Tyre
[2014/12/05 10:35:25 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\VideoPerformer
[2011/03/27 09:02:54 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\Windows Live Writer
[2014/12/28 14:06:22 | 000,000,000 | ---D | M] -- C:\Users\Norm\AppData\Roaming\WSE_Vosteran
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 76 bytes -> C:\Users\Norm\Documents\hedge.jpg:Roxio EMC Stream
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4
< End of report >