I'm posting the logs to make it easier to read for me.
I'll be back after I've had time to research these.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-03-2014
Ran by User (administrator) on HOME on 05-03-2014 14:34:49
Running from C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\JAKG28F6
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2012\avgwdsvc.exe
() C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe
() C:\Program Files\NetDrive\wdService.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\loggingserver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2012\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2012\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2012\avgcsrvx.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
() C:\Program Files\AVG Secure Search\vprot.exe
(Koyote-Lab, inc) C:\Program Files\Settings Alerter\Datamngr\datamngrUI.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2012\avgtray.exe
(Safer Networking Limited) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\JAKG28F6\FRST[1].exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [itype] - C:\Program Files\Microsoft IntelliType Pro\itype.exe [437008 2005-12-04] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [461584 2005-12-04] (Microsoft Corporation)
HKLM\...\Run: [pdfFactory Pro Dispatcher v2] - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe [499712 2006-04-06] (FinePrint Software, LLC)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Common Files\Real\Update_OB\realsched.exe [198160 2010-02-11] (RealNetworks, Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2552856 2014-03-02] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [38872 2012-07-31] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-11] (Adobe Systems Incorporated)
HKLM\...\Run: [DATAMNGR] - C:\Program Files\Settings Alerter\Datamngr\datamngrUI.exe [1684016 2013-02-05] (Koyote-Lab, inc)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SunJavaUpdateSched] - "C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM\...\Run: [AVG_TRAY] - C:\Program Files\AVG\AVG2012\avgtray.exe [2596984 2012-07-31] (AVG Technologies CZ, s.r.o.)
HKLM\...\runonceex: [] - [X]
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
HKU\.DEFAULT\...\Run: [DWQueuedReporting] - C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [39264 2007-03-13] (Microsoft Corporation)
HKU\S-1-5-21-1266927252-1395366336-781762406-1005\...\MountPoints2: G - G:\LaunchU3.exe
HKU\S-1-5-21-1266927252-1395366336-781762406-1005\...\MountPoints2: {63c54ca6-3192-11dd-91b8-000fb53d70e5} - G:\LaunchU3.exe -a
AppInit_DLLs: C:\DOCUME~1\ALLUSE~1\APPLIC~1\Wincert\WIN32C~1.DLL => C:\Documents and Settings\All Users\Application Data\Wincert\win32cert.dll [7168 2012-12-20] ()
AppInit_DLLs: C:\PROGRA~1\SETTIN~1\Datamngr\datamngr.dll => C:\PROGRA~1\SETTIN~1\Datamngr\datamngr.dll File Not Found
AppInit_DLLs: C:\PROGRA~1\SETTIN~1\Datamngr\IEBHO.dll => C:\PROGRA~1\SETTIN~1\Datamngr\IEBHO.dll File Not Found
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DesktopWeatherAlerts.lnk
ShortcutTarget: DesktopWeatherAlerts.lnk -> C:\Documents and Settings\User\Local Settings\Application Data\WeatherAlerts\DesktopWeatherAlertsApp.exe (No File)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Weather Alerts.lnk
ShortcutTarget: Weather Alerts.lnk -> C:\Documents and Settings\User\Local Settings\Application Data\WeatherAlerts\WeatherAlerts.exe (No File)
Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
ShortcutTarget: ERUNT AutoBackup.lnk -> C:\Program Files\ERUNT\AUTOBACK.EXE ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.yahoo.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.coupons.com/
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=107&systemid=465&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=107&systemid=465&q={searchTerms}
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=107&systemid=465&q={searchTerms}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={BB0DF854-3FD9-463C-87B5-E3E22F8E6471}&mid=5bb1442fcf05010cec7e7e879cb0efd6-06ce4fc639803a2e3563922518183d8e94088cb9&lang=en&ds=AVG&pr=fr&d=2012-05-10 19:23:05&v=14.2.0.1&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://search.coupons.com/search.asp?p=df&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=107&systemid=465&q={searchTerms}
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: PlurPush - {82249076-d5c8-431d-982b-023779779587} - C:\Program Files\PlurPush\PlurPushbho.dll (PlurPush)
BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\18.0.0.248\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll No File
BHO: TBSB07898 Class - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll No File
Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\18.0.0.248\AVG Secure Search_toolbar.dll (AVG Secure Search)
Toolbar: HKLM - Coupons.com CouponBar - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll No File
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3}
http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {1663ed61-23eb-11d2-b92f-008048fdd814}
https://www.corestaff.com/application/ScriptX.cab
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1}
http://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8}
http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3}
http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141696688906
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A4110378-789B-455F-AE86-3A1BFC402853}
http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {C2B78FF1-6E5A-4854-AC24-E09A0E2411BA}
http://static1.meetupstatic.com/applet/MeetUploader5.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937}
http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941}
http://driveragent.com/files/driveragent.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.0\ViProtocol.dll (AVG Secure Search)
Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\WINDOWS\Downloaded Program Files\mimectl.dll No File
ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\br7jorsi.default
FF user.js: detected! => C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\br7jorsi.default\user.js
FF DefaultSearchEngine: AVG Secure Search
FF SearchEngineOrder.1: Web Search
FF SelectedSearchEngine: AVG Secure Search
FF Homepage: hxxp://my.yahoo.com/
FF NetworkProxy: "no_proxies_on", "127.0.0.1,localhost,*.local"
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.0.0\\npsitesafety.dll (AVG Technologies)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.448 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npmnqmp07030901.dll (Move Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npmozax.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF SearchPlugin: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\br7jorsi.default\searchplugins\web-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\WebSearch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml
FF Extension: No Name - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\br7jorsi.default\Extensions\nostmp [2012-02-01]
FF Extension: Adobe DLM (powered by getPlus(R)) - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\br7jorsi.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2011-06-21]
FF Extension: PlurPush - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\br7jorsi.default\Extensions\{552199fb-9890-4055-9aaf-b2f6d51d46e9}.xpi [2014-02-26]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-02-09]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013-02-09]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Program Files\Real\RealPlayer\browserrecord\firefox\ext
FF Extension: RealPlayer Browser Record Plugin - C:\Program Files\Real\RealPlayer\browserrecord\firefox\ext [2010-02-11]
FF HKLM\...\Firefox\Extensions: [ShopperReports@ShopperReports.com] - C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions
FF Extension: ShopperReports - C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions [2011-06-09]
FF HKLM\...\Firefox\Extensions: [avg@toolbar] - C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\18.0.0.248
FF Extension: AVG Security Toolbar - C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\18.0.0.248 [2014-03-02]
FF HKLM\...\Firefox\Extensions: [{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}] - C:\Program Files\Coupons.com CouponBar\firefox\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\Coupons.com.xpi
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF HKLM\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files\AVG\AVG2012\Firefox4\
FF Extension: AVG Safe Search - C:\Program Files\AVG\AVG2012\Firefox4\ []
========================== Services (Whitelisted) =================
S3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [1025352 2011-09-01] ()
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [5174392 2012-11-02] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
R2 Level Quality Watcher; C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe [546112 2014-01-27] ()
S2 SLService; C:\WINDOWS\system32\slserv.exe [45056 2002-07-02] ( )
R2 vToolbarUpdater18.0.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [1759768 2014-03-02] (AVG Secure Search)
R2 WebDriveService; C:\Program Files\NetDrive\wdService.exe [94208 2003-03-26] ()
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [659356 2002-10-02] (Avance Logic, Inc.)
R3 AN983; C:\WINDOWS\System32\DRIVERS\AN983.sys [36224 2002-08-29] (ADMtek Incorporated.)
R3 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [139856 2011-12-23] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSFilter; C:\WINDOWS\System32\DRIVERS\avgidsfilterx.sys [24144 2011-12-23] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [24896 2012-04-19] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [17232 2011-12-23] (AVG Technologies CZ, s.r.o. )
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [237408 2012-07-26] (AVG Technologies CZ, s.r.o.)
R1 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [41040 2011-12-23] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [31952 2012-01-31] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [301920 2012-08-24] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [42784 2014-03-02] (AVG Technologies)
S3 CVirtA; C:\WINDOWS\System32\DRIVERS\CVirtA.sys [5315 2005-05-17] (Cisco Systems, Inc.)
S3 DNINDIS5; C:\WINDOWS\system32\DNINDIS5.SYS [17149 2003-07-24] (Printing Communications Assoc., Inc. (PCAUSA))
R1 FileDisk; C:\WINDOWS\system32\Drivers\FileDisk.sys [12928 2005-10-16] (Bo Brantén)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51056 2003-05-14] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2003-05-14] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21488 2003-05-14] (HP)
R2 MDC8021X; C:\WINDOWS\System32\DRIVERS\mdc8021x.sys [15890 2006-03-10] (Meetinghouse Data Communications)
S3 MLFILEM; C:\WINDOWS\system32\drivers\MLFILEM.SYS [28288 2004-06-04] (Sysinternals -
www.sysinternals.com)
R3 Mtlmnt5; C:\WINDOWS\System32\DRIVERS\Mtlmnt5.sys [197152 2002-09-24] ( )
S3 Mtlstrm; C:\WINDOWS\System32\DRIVERS\Mtlstrm.sys [1807568 2002-07-02] ( )
S3 NtMtlFax; C:\WINDOWS\System32\DRIVERS\NtMtlFax.sys [161976 2002-07-02] ( )
R3 NuidFltr; C:\WINDOWS\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
R3 Slntamr; C:\WINDOWS\System32\DRIVERS\slntamr.sys [418720 2002-07-02] ( )
S3 SlNtHal; C:\WINDOWS\System32\DRIVERS\Slnthal.sys [84720 2002-07-02] ( )
R3 SlWdmSup; C:\WINDOWS\System32\DRIVERS\SlWdmSup.sys [39348 2002-07-02] (Vireo Software)
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [716272 2008-11-01] ()
S3 TVICHW32; C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS [23600 2008-01-03] (EnTech Taiwan)
R2 WebDriveFSD; C:\Program Files\NetDrive\rffsd.sys [67032 2002-11-27] ()
R1 {6080A529-897E-4629-A488-ABA0C29B635E}; C:\WINDOWS\System32\drivers\ialmsbw.sys [91390 2002-07-31] (Intel Corporation)
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}; C:\WINDOWS\System32\drivers\ialmkchw.sys [71258 2002-07-31] (Intel Corporation)
S3 AR5523; system32\DRIVERS\wg11tnd5.sys [X]
S3 ATHFMWDL; System32\Drivers\ATHFMWDL.sys [X]
S3 mcdbus; system32\DRIVERS\mcdbus.sys [X]
S4 RFNP32; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-05 14:34 - 2014-03-05 14:34 - 00000000 ____D () C:\FRST
2014-03-05 14:18 - 2014-03-05 14:24 - 00213888 _____ () C:\Documents and Settings\User\Desktop\Rkill.txt
2014-03-05 13:47 - 2014-03-05 13:47 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Unused Desktop Shortcuts
2014-03-05 12:51 - 2014-03-05 12:36 - 00451108 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140305-125113.backup
2014-03-05 12:36 - 2014-03-02 18:39 - 00446704 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140305-123626.backup
2014-03-05 12:24 - 2014-03-05 12:24 - 00002067 _____ () C:\Documents and Settings\User\Desktop\aswMBR.txt
2014-03-05 12:24 - 2014-03-05 12:24 - 00000512 _____ () C:\Documents and Settings\User\Desktop\MBR.dat
2014-03-05 11:53 - 2014-03-05 11:53 - 00014985 ____C () C:\Documents and Settings\User\Desktop\attach.txt
2014-03-05 11:53 - 2014-03-05 11:52 - 00015852 _____ () C:\Documents and Settings\User\Desktop\dds.txt
2014-03-05 11:49 - 2014-03-05 12:47 - 00000000 ____D () C:\WINDOWS\ERDNT
2014-03-05 11:49 - 2014-03-05 11:49 - 00000000 ____D () C:\Program Files\ERUNT
2014-03-05 11:49 - 2014-03-05 11:49 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
2014-03-03 11:20 - 2014-03-03 11:20 - 00000000 ____D () C:\Documents and Settings\User\Application Data\ParetoLogic
2014-03-03 11:20 - 2014-03-03 11:20 - 00000000 ____D () C:\Documents and Settings\User\Application Data\DriverCure
2014-03-03 11:15 - 2014-03-03 12:59 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\ParetoLogic
2014-03-03 10:02 - 2014-03-03 10:02 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG
2014-03-02 19:58 - 2014-03-03 13:14 - 00072877 _____ () C:\WINDOWS\setupapi.log
2014-03-02 18:39 - 2013-04-06 18:27 - 00446704 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140302-183920.backup
2014-03-02 15:49 - 2014-03-05 12:42 - 00000000 ____D () C:\Program Files\SavingsBull
2014-03-01 21:54 - 2014-03-01 21:54 - 00862120 _____ (Download Manager ) C:\Documents and Settings\User\Desktop\java(1).exe
2014-03-01 21:53 - 2014-03-01 21:53 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Weather Alerts
2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Program Files\Level Quality Watcher
2014-03-01 21:50 - 2014-03-01 21:51 - 00000000 ____D () C:\Program Files\PlurPush
2014-03-01 21:49 - 2014-03-02 19:57 - 00000000 ____D () C:\Program Files\SearchProtect
2014-03-01 21:09 - 2014-03-01 21:12 - 00015385 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-03-01 20:43 - 2014-03-01 20:43 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-03-01 20:24 - 2014-03-01 20:25 - 00004867 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-03-01 18:52 - 2014-03-01 18:52 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-03-01 18:51 - 2014-03-01 18:52 - 00009419 _____ () C:\WINDOWS\KB2914368.log
2014-03-01 18:51 - 2014-03-01 18:51 - 00009399 _____ () C:\WINDOWS\KB2904266.log
2014-03-01 18:51 - 2014-03-01 18:51 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904266$
2014-03-01 18:50 - 2014-03-01 18:50 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
2014-03-01 18:48 - 2014-03-01 18:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893984$
2014-03-01 18:48 - 2014-03-01 18:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2892075$
2014-03-01 18:47 - 2014-03-01 18:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893294$
2014-03-01 18:46 - 2014-03-01 18:46 - 00007706 _____ () C:\WINDOWS\KB2900986.log
2014-03-01 18:46 - 2014-03-01 18:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
2014-03-01 18:45 - 2014-03-01 18:45 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876331$
2014-03-01 18:44 - 2014-03-01 18:44 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868626$
2014-03-01 18:43 - 2014-03-01 18:43 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$
2014-03-01 18:36 - 2014-03-01 18:36 - 17858952 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-03-01 18:08 - 2014-03-01 20:43 - 00011995 _____ () C:\WINDOWS\KB2916036.log
2014-03-01 18:08 - 2014-03-01 18:50 - 00016197 _____ () C:\WINDOWS\KB2898715.log
2014-03-01 18:08 - 2014-03-01 18:45 - 00013778 _____ () C:\WINDOWS\KB2868626.log
2014-03-01 18:07 - 2014-03-01 18:48 - 00015700 _____ () C:\WINDOWS\KB2893984.log
2014-03-01 18:07 - 2014-03-01 18:47 - 00014503 _____ () C:\WINDOWS\KB2893294.log
2014-03-01 18:07 - 2014-03-01 18:46 - 00014365 _____ () C:\WINDOWS\KB2876331.log
2014-03-01 18:07 - 2014-03-01 18:43 - 00012789 _____ () C:\WINDOWS\KB2862152.log
2014-03-01 18:04 - 2014-03-01 18:48 - 00014515 _____ () C:\WINDOWS\KB2892075.log
==================== One Month Modified Files and Folders =======
2014-03-05 14:36 - 2012-05-06 20:37 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-03-05 14:34 - 2014-03-05 14:34 - 00000000 ____D () C:\FRST
2014-03-05 14:24 - 2014-03-05 14:18 - 00213888 _____ () C:\Documents and Settings\User\Desktop\Rkill.txt
2014-03-05 13:56 - 2010-01-06 14:29 - 00000886 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-05 13:47 - 2014-03-05 13:47 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Unused Desktop Shortcuts
2014-03-05 13:11 - 2006-03-12 13:11 - 00000340 _____ () C:\WINDOWS\Tasks\HP Usg Daily.job
2014-03-05 12:47 - 2014-03-05 11:49 - 00000000 ____D () C:\WINDOWS\ERDNT
2014-03-05 12:46 - 2010-01-06 14:29 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-05 12:46 - 2002-12-24 06:29 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-05 12:43 - 2006-03-06 20:58 - 01437880 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-05 12:42 - 2014-03-02 15:49 - 00000000 ____D () C:\Program Files\SavingsBull
2014-03-05 12:42 - 2002-12-23 23:37 - 00000157 _____ () C:\WINDOWS\wiadebug.log
2014-03-05 12:41 - 2002-12-24 07:43 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-05 12:41 - 2002-12-23 23:37 - 00000048 _____ () C:\WINDOWS\wiaservc.log
2014-03-05 12:40 - 2012-12-30 15:25 - 00014010 _____ () C:\WINDOWS\SchedLgU.Txt
2014-03-05 12:39 - 2006-03-06 18:39 - 00000278 ___SH () C:\Documents and Settings\User\ntuser.ini
2014-03-05 12:36 - 2014-03-05 12:51 - 00451108 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140305-125113.backup
2014-03-05 12:24 - 2014-03-05 12:24 - 00002067 _____ () C:\Documents and Settings\User\Desktop\aswMBR.txt
2014-03-05 12:24 - 2014-03-05 12:24 - 00000512 _____ () C:\Documents and Settings\User\Desktop\MBR.dat
2014-03-05 11:53 - 2014-03-05 11:53 - 00014985 ____C () C:\Documents and Settings\User\Desktop\attach.txt
2014-03-05 11:52 - 2014-03-05 11:53 - 00015852 _____ () C:\Documents and Settings\User\Desktop\dds.txt
2014-03-05 11:49 - 2014-03-05 11:49 - 00000000 ____D () C:\Program Files\ERUNT
2014-03-05 11:49 - 2014-03-05 11:49 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
2014-03-05 11:21 - 2008-07-23 11:17 - 00000420 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{1B35155B-B273-4F78-A4C9-B3AD29E35858}.job
2014-03-05 10:45 - 2011-04-22 12:25 - 00000000 ____D () C:\WINDOWS\system32\Drivers\AVG
2014-03-03 13:14 - 2014-03-02 19:58 - 00072877 _____ () C:\WINDOWS\setupapi.log
2014-03-03 12:59 - 2014-03-03 11:15 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\ParetoLogic
2014-03-03 11:30 - 2006-03-06 18:39 - 00001599 _____ () C:\Documents and Settings\User\Start Menu\Programs\Remote Assistance.lnk
2014-03-03 11:23 - 2002-12-24 07:43 - 00001599 _____ () C:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk
2014-03-03 11:22 - 2007-07-09 11:03 - 00001599 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
2014-03-03 11:20 - 2014-03-03 11:20 - 00000000 ____D () C:\Documents and Settings\User\Application Data\ParetoLogic
2014-03-03 11:20 - 2014-03-03 11:20 - 00000000 ____D () C:\Documents and Settings\User\Application Data\DriverCure
2014-03-03 10:02 - 2014-03-03 10:02 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG
2014-03-03 09:53 - 2011-04-22 12:08 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2014-03-02 22:57 - 2013-02-23 14:11 - 00000000 ____D () C:\Program Files\Settings Alerter
2014-03-02 21:23 - 2011-09-27 11:30 - 00000000 ____D () C:\Program Files\Common Files\AVG Secure Search
2014-03-02 21:23 - 2011-09-27 11:30 - 00000000 ____D () C:\Program Files\AVG Secure Search
2014-03-02 21:22 - 2012-09-05 09:44 - 00042784 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx86.sys
2014-03-02 21:22 - 2011-12-08 17:31 - 00000000 ____D () C:\WINDOWS\system32\cache
2014-03-02 21:22 - 2011-12-08 17:31 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVG Secure Search
2014-03-02 19:57 - 2014-03-01 21:49 - 00000000 ____D () C:\Program Files\SearchProtect
2014-03-02 19:57 - 2006-03-10 13:07 - 00003503 _____ () C:\WINDOWS\wininit.ini
2014-03-02 18:39 - 2014-03-05 12:36 - 00446704 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140305-123626.backup
2014-03-02 18:33 - 2006-10-08 18:00 - 00000000 ____D () C:\Program Files\Java
2014-03-02 18:21 - 2006-03-22 16:42 - 00000000 ____D () C:\WINDOWS\Corel
2014-03-02 18:00 - 2011-03-24 22:37 - 00000000 ____D () C:\Program Files\OpenOffice.org 3
2014-03-02 18:00 - 2008-09-29 19:31 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-03-02 17:50 - 2006-03-15 10:59 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Kodak
2014-03-02 17:24 - 2007-11-10 18:37 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Google
2014-03-02 17:24 - 2006-05-06 16:51 - 00000000 ____D () C:\Program Files\Google
2014-03-02 17:24 - 2006-05-06 16:51 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Google
2014-03-01 21:59 - 2012-06-20 15:22 - 00859072 _____ (Oracle Corporation) C:\WINDOWS\system32\npdeployJava1.dll
2014-03-01 21:59 - 2010-12-08 23:57 - 00779704 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll
2014-03-01 21:54 - 2014-03-01 21:54 - 00862120 _____ (Download Manager ) C:\Documents and Settings\User\Desktop\java(1).exe
2014-03-01 21:53 - 2014-03-01 21:53 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Weather Alerts
2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Program Files\Level Quality Watcher
2014-03-01 21:51 - 2014-03-01 21:50 - 00000000 ____D () C:\Program Files\PlurPush
2014-03-01 21:30 - 2013-02-09 14:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-01 21:12 - 2014-03-01 21:09 - 00015385 _____ () C:\WINDOWS\KB2909921-IE8.log
2014-03-01 21:12 - 2009-06-24 22:57 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-03-01 21:12 - 2006-03-06 23:59 - 00482093 _____ () C:\WINDOWS\updspapi.log
2014-03-01 21:12 - 2002-12-23 23:35 - 03283003 _____ () C:\WINDOWS\FaxSetup.log
2014-03-01 21:12 - 2002-12-23 23:35 - 01270282 _____ () C:\WINDOWS\tsoc.log
2014-03-01 21:12 - 2002-12-23 23:35 - 00621392 _____ () C:\WINDOWS\ntdtcsetup.log
2014-03-01 21:12 - 2002-12-23 23:35 - 00518548 _____ () C:\WINDOWS\iis6.log
2014-03-01 21:12 - 2002-12-23 23:35 - 00166046 _____ () C:\WINDOWS\ocmsn.log
2014-03-01 21:12 - 2002-12-23 23:35 - 00165529 _____ () C:\WINDOWS\msgsocm.log
2014-03-01 21:09 - 2013-10-20 20:39 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-03-01 20:49 - 2002-12-23 23:34 - 00570014 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-03-01 20:43 - 2014-03-01 20:43 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-03-01 20:43 - 2014-03-01 18:08 - 00011995 _____ () C:\WINDOWS\KB2916036.log
2014-03-01 20:43 - 2002-12-23 23:35 - 00001355 _____ () C:\WINDOWS\imsins.BAK
2014-03-01 20:25 - 2014-03-01 20:24 - 00004867 _____ () C:\WINDOWS\KB2909210-IE8.log
2014-03-01 19:44 - 2012-05-06 20:18 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\AVG Secure Search
2014-03-01 19:28 - 2012-05-06 20:37 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-03-01 19:28 - 2011-08-20 11:39 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-03-01 19:19 - 2002-12-23 23:34 - 00220840 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-01 18:52 - 2014-03-01 18:52 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-03-01 18:52 - 2014-03-01 18:51 - 00009419 _____ () C:\WINDOWS\KB2914368.log
2014-03-01 18:51 - 2014-03-01 18:51 - 00009399 _____ () C:\WINDOWS\KB2904266.log
2014-03-01 18:51 - 2014-03-01 18:51 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904266$
2014-03-01 18:51 - 2007-02-16 00:30 - 00894282 _____ () C:\WINDOWS\system32\TZLog.log
2014-03-01 18:50 - 2014-03-01 18:50 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
2014-03-01 18:50 - 2014-03-01 18:08 - 00016197 _____ () C:\WINDOWS\KB2898715.log
2014-03-01 18:48 - 2014-03-01 18:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893984$
2014-03-01 18:48 - 2014-03-01 18:48 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2892075$
2014-03-01 18:48 - 2014-03-01 18:07 - 00015700 _____ () C:\WINDOWS\KB2893984.log
2014-03-01 18:48 - 2014-03-01 18:04 - 00014515 _____ () C:\WINDOWS\KB2892075.log
2014-03-01 18:47 - 2014-03-01 18:47 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893294$
2014-03-01 18:47 - 2014-03-01 18:07 - 00014503 _____ () C:\WINDOWS\KB2893294.log
2014-03-01 18:46 - 2014-03-01 18:46 - 00007706 _____ () C:\WINDOWS\KB2900986.log
2014-03-01 18:46 - 2014-03-01 18:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
2014-03-01 18:46 - 2014-03-01 18:07 - 00014365 _____ () C:\WINDOWS\KB2876331.log
2014-03-01 18:45 - 2014-03-01 18:45 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876331$
2014-03-01 18:45 - 2014-03-01 18:08 - 00013778 _____ () C:\WINDOWS\KB2868626.log
2014-03-01 18:44 - 2014-03-01 18:44 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868626$
2014-03-01 18:43 - 2014-03-01 18:43 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$
2014-03-01 18:43 - 2014-03-01 18:07 - 00012789 _____ () C:\WINDOWS\KB2862152.log
2014-03-01 18:36 - 2014-03-01 18:36 - 17858952 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-03-01 17:18 - 2006-03-10 11:10 - 00002489 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
2014-02-06 03:54 - 2006-11-07 03:26 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
2014-02-06 03:54 - 2002-12-24 06:28 - 00174592 ____N (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-05 18:26 - 2012-06-15 16:32 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
2014-02-05 18:26 - 2010-06-10 05:02 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
2014-02-05 18:26 - 2009-06-24 22:55 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
2014-02-05 18:26 - 2009-06-24 22:55 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
2014-02-05 18:26 - 2009-03-08 03:33 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll
2014-02-05 18:26 - 2007-05-08 19:14 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
2014-02-05 18:26 - 2007-05-08 19:14 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
2014-02-05 18:26 - 2007-05-08 19:14 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
2014-02-05 18:26 - 2007-05-08 19:14 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2014-02-05 18:26 - 2006-11-07 21:03 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-05 18:26 - 2006-11-07 21:03 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-05 18:26 - 2006-11-07 21:03 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-02-05 18:26 - 2006-11-07 03:27 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
2014-02-05 18:26 - 2006-10-17 12:05 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
2014-02-05 18:26 - 2006-10-17 12:05 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
2014-02-05 18:26 - 2006-10-17 12:05 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
2014-02-05 18:26 - 2006-10-17 12:04 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
2014-02-05 18:26 - 2006-10-17 11:57 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-05 18:26 - 2006-09-18 09:15 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
2014-02-05 18:26 - 2006-05-19 10:08 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-02-05 18:26 - 2006-05-10 00:23 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
2014-02-05 18:26 - 2006-05-10 00:23 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
2014-02-05 18:26 - 2006-05-10 00:23 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
2014-02-05 18:26 - 2006-05-10 00:23 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
2014-02-05 18:26 - 2006-05-10 00:22 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
2014-02-05 18:26 - 2006-05-10 00:22 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
2014-02-05 18:26 - 2005-11-22 16:49 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-05 18:26 - 2005-10-21 12:51 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-05 18:26 - 2005-10-21 12:51 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-05 18:26 - 2002-12-24 06:29 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-02-05 18:26 - 2002-12-24 06:29 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-02-05 18:26 - 2002-12-24 06:28 - 01469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-05 18:26 - 2002-12-24 06:28 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
2014-02-05 18:26 - 2002-12-24 06:28 - 00387584 ____N (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-02-05 18:26 - 2002-12-24 06:28 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-02-05 18:26 - 2002-12-24 06:28 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-02-05 18:26 - 2002-12-24 06:28 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-02-05 18:26 - 2002-12-24 06:28 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-05 18:26 - 2002-12-24 06:28 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll
2014-02-05 17:24 - 2006-03-07 00:38 - 00385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-02-04 19:09 - 2006-03-06 23:59 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================