start
CreateRestorePoint:
CloseProcesses:
Shortcut: C:\Users\WilliamF\Documents\Dirty Dangerous & Deadly Productions Limited\Website\Hijack Ad4.CDR.lnk -> F:\Dirty Dangerous & Deadly Productions Limited\Webpages\HomePages\August 1, 2004\Hijack Ad4.CDR (No File)
Shortcut: C:\Users\WilliamF\Documents\Dirty Dangerous & Deadly Productions Limited\Logos\Hijack Ad4.CDR.lnk -> F:\Dirty Dangerous & Deadly Productions Limited\Webpages\HomePages\August 1, 2004\Hijack Ad4.CDR (No File)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about
:blank
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
2015-10-18 08:25 - 2015-09-25 15:39 - 00450771 _____ C:\windows\system32\Drivers\etc\hosts.20151018-082502.backup
2013-08-22 09:25 - 2015-10-26 11:45 - 00449982 ____R C:\windows\system32\Drivers\etc\hosts
AlternateDataStreams: C:\ProgramData\Temp:0FF263E8
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
End