========== Chrome ==========
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcogajbgikalbpphmoedjlcfjkhgh\1.0.0_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcogajbgikalbpphmoedjlcfjkhgh\1.0.0_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013/10/11 15:32:09 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Search Enhancement Tool) - {8E0B5CFE-A7EB-4F19-848A-C862F2AD464D} - C:\Program Files (x86)\Search Enhancement Tool\ScriptHost.dll File not found
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Motorola Solutions, Inc.)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PocketCloud Location] C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe (Wyse Technology Inc.)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SA3\SACpl.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001..\Run: [MPOptimizer] "C:\Program Files\MaxPerforma Optimizer\MaxPerforma.exe" /scan File not found
O4 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001..\Run: [MyTomTomSA.exe] C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe (TomTom)
O4 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O8 - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect121.cab (GMNRev Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8CD337DF-52CD-43E5-9077-B97A39B0DDB8}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C198D7BB-C461-459E-AE12-7906DB84A4DC}: DhcpNameServer = 167.206.245.130 167.206.245.129
O18:64bit: - Protocol\Handler\dssrequest - No CLSID value found
O18:64bit: - Protocol\Handler\sacore - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\sacore - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/10/11 23:08:40 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/10/11 23:03:18 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/10/11 23:02:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Home PC\Desktop\OTL.exe
[2013/10/11 23:02:22 | 001,032,220 | ---- | C] (Thisisu) -- C:\Users\Home PC\Desktop\JRT.exe
[2013/10/11 19:25:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2013/10/11 19:25:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/10/11 19:25:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/10/11 16:06:14 | 000,378,944 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2013/10/11 16:06:14 | 000,033,400 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/10/11 16:06:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/10/11 16:06:13 | 000,072,016 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/10/11 16:06:13 | 000,064,288 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2013/10/11 16:06:07 | 001,030,952 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2013/10/11 16:06:07 | 000,080,816 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/10/11 16:05:53 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2013/10/11 15:54:16 | 000,000,000 | ---D | C] -- C:\ProgramData\ZalmanInstaller_52332
[2013/10/11 15:54:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BrowserSafeguard
[2013/10/11 15:33:44 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/10/11 15:33:38 | 000,000,000 | ---D | C] -- C:\Users\Home PC\AppData\Local\temp
[2013/10/11 15:11:54 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/10/11 15:11:54 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/10/11 15:11:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2013/10/11 15:11:54 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/10/11 15:11:50 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/10/11 15:11:38 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/10/11 14:53:17 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Microsoft
[2013/10/10 14:23:51 | 005,131,844 | R--- | C] (Swearware) -- C:\Users\Home PC\Desktop\ComboFix.exe
[2013/10/09 23:04:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/10/09 22:58:27 | 000,000,000 | ---D | C] -- C:\Users\Home PC\Desktop\mbar
[2013/10/09 22:57:55 | 012,907,592 | ---- | C] (Malwarebytes Corp.) -- C:\Users\Home PC\Desktop\mbar-1.07.0.1005.exe
[2013/10/09 22:28:40 | 000,000,000 | ---D | C] -- C:\Users\Home PC\Desktop\RK_Quarantine
[2013/10/09 20:12:08 | 003,191,888 | ---- | C] (McAfee, Inc.) -- C:\Users\Home PC\Desktop\MCPR.exe
[2013/10/07 21:22:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013/10/07 21:21:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/10/07 21:21:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2013/10/04 18:18:32 | 000,000,000 | ---D | C] -- C:\Users\Home PC\AppData\Roaming\Malwarebytes
[2013/10/04 18:16:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/10/04 18:16:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/10/04 18:16:33 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/10/04 18:16:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/10/04 18:08:00 | 000,287,840 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2013/10/04 18:06:22 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013/10/04 18:05:07 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2013/10/04 16:46:08 | 000,000,000 | ---D | C] -- C:\Users\Home PC\AppData\Local\MyTechGurus
[2013/10/04 16:46:08 | 000,000,000 | ---D | C] -- C:\ProgramData\MyTechGurus
[2013/09/23 19:43:51 | 000,000,000 | ---D | C] -- C:\sn0wbreeze
[2013/09/18 15:48:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/09/18 15:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/09/18 15:47:55 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/09/18 15:47:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013/09/18 15:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
========== Files - Modified Within 30 Days ==========
[2013/10/11 23:07:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/10/11 23:05:43 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013/10/11 23:05:40 | 2467,315,711 | -HS- | M] () -- C:\hiberfil.sys
[2013/10/11 23:02:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Home PC\Desktop\OTL.exe
[2013/10/11 23:02:22 | 001,032,220 | ---- | M] (Thisisu) -- C:\Users\Home PC\Desktop\JRT.exe
[2013/10/11 23:01:25 | 001,048,960 | ---- | M] () -- C:\Users\Home PC\Desktop\adwcleaner.exe
[2013/10/11 22:58:00 | 000,000,926 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3483428752-1065640187-117278773-1001UA.job
[2013/10/11 16:58:02 | 000,000,874 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3483428752-1065640187-117278773-1001Core.job
[2013/10/11 16:10:35 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2013/10/11 16:06:14 | 000,001,924 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/10/11 16:04:35 | 131,918,888 | ---- | M] () -- C:\Users\Home PC\Desktop\avast_free_antivirus_setup.exe
[2013/10/11 15:39:38 | 000,850,046 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/10/11 15:39:38 | 000,720,456 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/10/11 15:39:38 | 000,133,284 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/10/11 15:32:09 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/10/11 14:55:27 | 000,415,440 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/10/10 14:23:52 | 005,131,844 | R--- | M] (Swearware) -- C:\Users\Home PC\Desktop\ComboFix.exe
[2013/10/09 23:27:45 | 000,000,335 | ---- | M] () -- C:\local.conf
[2013/10/09 22:57:55 | 012,907,592 | ---- | M] (Malwarebytes Corp.) -- C:\Users\Home PC\Desktop\mbar-1.07.0.1005.exe
[2013/10/09 22:14:08 | 000,950,272 | ---- | M] () -- C:\Users\Home PC\Desktop\RogueKiller.exe
[2013/10/09 20:12:08 | 003,191,888 | ---- | M] (McAfee, Inc.) -- C:\Users\Home PC\Desktop\MCPR.exe
[2013/10/07 21:21:38 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/10/04 21:35:59 | 000,002,376 | ---- | M] () -- C:\Users\Home PC\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/10/04 21:35:59 | 000,002,374 | ---- | M] () -- C:\Users\Home PC\Desktop\Google Chrome.lnk
[2013/10/04 18:17:02 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/10/01 13:22:35 | 000,781,193 | ---- | M] () -- C:\Users\Home PC\Desktop\paspo.jpeg
[2013/09/26 18:31:21 | 000,000,157 | ---- | M] () -- C:\Windows\SysWow64\SystemPreferences.xml
[2013/09/18 15:48:56 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
========== Files Created - No Company Name ==========
[2013/10/11 23:01:25 | 001,048,960 | ---- | C] () -- C:\Users\Home PC\Desktop\adwcleaner.exe
[2013/10/11 16:06:14 | 000,001,924 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/10/11 16:06:07 | 000,204,880 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2013/10/11 16:06:07 | 000,065,336 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/10/11 16:04:35 | 131,918,888 | ---- | C] () -- C:\Users\Home PC\Desktop\avast_free_antivirus_setup.exe
[2013/10/11 15:11:54 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/10/11 15:11:54 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/10/11 15:11:54 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/10/11 15:11:54 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/10/11 15:11:54 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/10/11 14:55:16 | 000,415,440 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/10/09 23:17:33 | 000,000,335 | ---- | C] () -- C:\local.conf
[2013/10/09 22:14:08 | 000,950,272 | ---- | C] () -- C:\Users\Home PC\Desktop\RogueKiller.exe
[2013/10/07 21:21:38 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/10/04 18:17:02 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/10/04 18:08:01 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2013/10/04 17:13:09 | 000,002,159 | ---- | C] () -- C:\Users\Home PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Tech Gurus, Inc (3).lnk
[2013/10/04 17:01:54 | 000,002,195 | ---- | C] () -- C:\Users\Home PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Tech Gurus, Inc (2).lnk
[2013/10/04 16:28:42 | 000,002,219 | ---- | C] () -- C:\Users\Home PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Tech Gurus, Inc.lnk
[2013/10/01 13:20:19 | 000,781,193 | ---- | C] () -- C:\Users\Home PC\Desktop\paspo.jpeg
[2013/09/18 15:48:56 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/09/12 20:40:32 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2013/09/12 20:39:34 | 000,387,583 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
[2013/07/20 01:38:54 | 000,000,258 | RHS- | C] () -- C:\Users\Home PC\ntuser.pol
[2013/05/11 10:27:15 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2013/03/02 22:15:01 | 000,000,469 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/01/11 22:11:45 | 000,220,540 | ---- | C] () -- C:\Windows\hpwins22.dat
[2013/01/11 22:11:45 | 000,002,658 | ---- | C] () -- C:\Windows\hpwmdl22.dat
[2012/11/16 21:39:53 | 000,866,452 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/06 01:12:28 | 000,598,780 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng700.bin
[2012/10/06 01:12:22 | 000,755,048 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng700.bin
[2012/10/06 01:12:10 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/07/26 04:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 16:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2012/06/02 10:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2012/04/20 15:59:44 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[2012/12/08 17:48:27 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/03/06 02:31:28 | 019,758,592 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/03/06 01:03:37 | 017,561,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/25 23:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/25 23:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/25 23:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/06/04 18:24:04 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\.minecraft
[2013/07/03 18:53:07 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\.technic
[2013/07/20 01:38:50 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\AVSoftware
[2013/05/18 22:26:21 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\com.Shutterfly.ExpressUploader
[2013/05/07 18:16:04 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\iFunbox_UserCache
[2012/12/08 17:40:01 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\Leadertech
[2013/04/17 14:53:27 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\Open Download Manager
[2012/12/21 22:46:40 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\PCDr
[2013/08/07 21:54:05 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\PDF Software
[2013/05/29 16:38:57 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\player
[2013/05/11 16:14:11 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\redsn0w
[2013/05/16 20:08:44 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\skyz
[2013/02/03 14:25:00 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\TomTom
[2013/05/11 10:28:16 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\TuneUp Software
[2013/05/07 21:28:57 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\Unity
[2013/07/20 01:43:21 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\uTorrent
========== Purity Check ==========
< End of report >
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcogajbgikalbpphmoedjlcfjkhgh\1.0.0_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_0\
CHR - Extension: SafeSearch = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpooidjoepcceohjkoffjgioneogihij\1.11_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcogajbgikalbpphmoedjlcfjkhgh\1.0.0_0\
CHR - Extension: No name found = C:\Users\Home PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013/10/11 15:32:09 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Search Enhancement Tool) - {8E0B5CFE-A7EB-4F19-848A-C862F2AD464D} - C:\Program Files (x86)\Search Enhancement Tool\ScriptHost.dll File not found
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Motorola Solutions, Inc.)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PocketCloud Location] C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe (Wyse Technology Inc.)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SA3\SACpl.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001..\Run: [MPOptimizer] "C:\Program Files\MaxPerforma Optimizer\MaxPerforma.exe" /scan File not found
O4 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001..\Run: [MyTomTomSA.exe] C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe (TomTom)
O4 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3483428752-1065640187-117278773-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O8 - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect121.cab (GMNRev Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8CD337DF-52CD-43E5-9077-B97A39B0DDB8}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C198D7BB-C461-459E-AE12-7906DB84A4DC}: DhcpNameServer = 167.206.245.130 167.206.245.129
O18:64bit: - Protocol\Handler\dssrequest - No CLSID value found
O18:64bit: - Protocol\Handler\sacore - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\sacore - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/10/11 23:08:40 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/10/11 23:03:18 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/10/11 23:02:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Home PC\Desktop\OTL.exe
[2013/10/11 23:02:22 | 001,032,220 | ---- | C] (Thisisu) -- C:\Users\Home PC\Desktop\JRT.exe
[2013/10/11 19:25:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2013/10/11 19:25:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/10/11 19:25:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/10/11 16:06:14 | 000,378,944 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2013/10/11 16:06:14 | 000,033,400 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/10/11 16:06:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/10/11 16:06:13 | 000,072,016 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/10/11 16:06:13 | 000,064,288 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2013/10/11 16:06:07 | 001,030,952 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2013/10/11 16:06:07 | 000,080,816 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/10/11 16:05:53 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2013/10/11 15:54:16 | 000,000,000 | ---D | C] -- C:\ProgramData\ZalmanInstaller_52332
[2013/10/11 15:54:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BrowserSafeguard
[2013/10/11 15:33:44 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/10/11 15:33:38 | 000,000,000 | ---D | C] -- C:\Users\Home PC\AppData\Local\temp
[2013/10/11 15:11:54 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/10/11 15:11:54 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/10/11 15:11:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2013/10/11 15:11:54 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/10/11 15:11:50 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/10/11 15:11:38 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/10/11 14:53:17 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Microsoft
[2013/10/10 14:23:51 | 005,131,844 | R--- | C] (Swearware) -- C:\Users\Home PC\Desktop\ComboFix.exe
[2013/10/09 23:04:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/10/09 22:58:27 | 000,000,000 | ---D | C] -- C:\Users\Home PC\Desktop\mbar
[2013/10/09 22:57:55 | 012,907,592 | ---- | C] (Malwarebytes Corp.) -- C:\Users\Home PC\Desktop\mbar-1.07.0.1005.exe
[2013/10/09 22:28:40 | 000,000,000 | ---D | C] -- C:\Users\Home PC\Desktop\RK_Quarantine
[2013/10/09 20:12:08 | 003,191,888 | ---- | C] (McAfee, Inc.) -- C:\Users\Home PC\Desktop\MCPR.exe
[2013/10/07 21:22:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013/10/07 21:21:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/10/07 21:21:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2013/10/04 18:18:32 | 000,000,000 | ---D | C] -- C:\Users\Home PC\AppData\Roaming\Malwarebytes
[2013/10/04 18:16:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/10/04 18:16:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/10/04 18:16:33 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/10/04 18:16:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/10/04 18:08:00 | 000,287,840 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2013/10/04 18:06:22 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013/10/04 18:05:07 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2013/10/04 16:46:08 | 000,000,000 | ---D | C] -- C:\Users\Home PC\AppData\Local\MyTechGurus
[2013/10/04 16:46:08 | 000,000,000 | ---D | C] -- C:\ProgramData\MyTechGurus
[2013/09/23 19:43:51 | 000,000,000 | ---D | C] -- C:\sn0wbreeze
[2013/09/18 15:48:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/09/18 15:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/09/18 15:47:55 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/09/18 15:47:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013/09/18 15:47:55 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
========== Files - Modified Within 30 Days ==========
[2013/10/11 23:07:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/10/11 23:05:43 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013/10/11 23:05:40 | 2467,315,711 | -HS- | M] () -- C:\hiberfil.sys
[2013/10/11 23:02:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Home PC\Desktop\OTL.exe
[2013/10/11 23:02:22 | 001,032,220 | ---- | M] (Thisisu) -- C:\Users\Home PC\Desktop\JRT.exe
[2013/10/11 23:01:25 | 001,048,960 | ---- | M] () -- C:\Users\Home PC\Desktop\adwcleaner.exe
[2013/10/11 22:58:00 | 000,000,926 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3483428752-1065640187-117278773-1001UA.job
[2013/10/11 16:58:02 | 000,000,874 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3483428752-1065640187-117278773-1001Core.job
[2013/10/11 16:10:35 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2013/10/11 16:06:14 | 000,001,924 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/10/11 16:04:35 | 131,918,888 | ---- | M] () -- C:\Users\Home PC\Desktop\avast_free_antivirus_setup.exe
[2013/10/11 15:39:38 | 000,850,046 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/10/11 15:39:38 | 000,720,456 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/10/11 15:39:38 | 000,133,284 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/10/11 15:32:09 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/10/11 14:55:27 | 000,415,440 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/10/10 14:23:52 | 005,131,844 | R--- | M] (Swearware) -- C:\Users\Home PC\Desktop\ComboFix.exe
[2013/10/09 23:27:45 | 000,000,335 | ---- | M] () -- C:\local.conf
[2013/10/09 22:57:55 | 012,907,592 | ---- | M] (Malwarebytes Corp.) -- C:\Users\Home PC\Desktop\mbar-1.07.0.1005.exe
[2013/10/09 22:14:08 | 000,950,272 | ---- | M] () -- C:\Users\Home PC\Desktop\RogueKiller.exe
[2013/10/09 20:12:08 | 003,191,888 | ---- | M] (McAfee, Inc.) -- C:\Users\Home PC\Desktop\MCPR.exe
[2013/10/07 21:21:38 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/10/04 21:35:59 | 000,002,376 | ---- | M] () -- C:\Users\Home PC\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/10/04 21:35:59 | 000,002,374 | ---- | M] () -- C:\Users\Home PC\Desktop\Google Chrome.lnk
[2013/10/04 18:17:02 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/10/01 13:22:35 | 000,781,193 | ---- | M] () -- C:\Users\Home PC\Desktop\paspo.jpeg
[2013/09/26 18:31:21 | 000,000,157 | ---- | M] () -- C:\Windows\SysWow64\SystemPreferences.xml
[2013/09/18 15:48:56 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
========== Files Created - No Company Name ==========
[2013/10/11 23:01:25 | 001,048,960 | ---- | C] () -- C:\Users\Home PC\Desktop\adwcleaner.exe
[2013/10/11 16:06:14 | 000,001,924 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/10/11 16:06:07 | 000,204,880 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2013/10/11 16:06:07 | 000,065,336 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/10/11 16:04:35 | 131,918,888 | ---- | C] () -- C:\Users\Home PC\Desktop\avast_free_antivirus_setup.exe
[2013/10/11 15:11:54 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/10/11 15:11:54 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/10/11 15:11:54 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/10/11 15:11:54 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/10/11 15:11:54 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/10/11 14:55:16 | 000,415,440 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/10/09 23:17:33 | 000,000,335 | ---- | C] () -- C:\local.conf
[2013/10/09 22:14:08 | 000,950,272 | ---- | C] () -- C:\Users\Home PC\Desktop\RogueKiller.exe
[2013/10/07 21:21:38 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/10/04 18:17:02 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/10/04 18:08:01 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2013/10/04 17:13:09 | 000,002,159 | ---- | C] () -- C:\Users\Home PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Tech Gurus, Inc (3).lnk
[2013/10/04 17:01:54 | 000,002,195 | ---- | C] () -- C:\Users\Home PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Tech Gurus, Inc (2).lnk
[2013/10/04 16:28:42 | 000,002,219 | ---- | C] () -- C:\Users\Home PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Tech Gurus, Inc.lnk
[2013/10/01 13:20:19 | 000,781,193 | ---- | C] () -- C:\Users\Home PC\Desktop\paspo.jpeg
[2013/09/18 15:48:56 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/09/12 20:40:32 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2013/09/12 20:39:34 | 000,387,583 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
[2013/07/20 01:38:54 | 000,000,258 | RHS- | C] () -- C:\Users\Home PC\ntuser.pol
[2013/05/11 10:27:15 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2013/03/02 22:15:01 | 000,000,469 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/01/11 22:11:45 | 000,220,540 | ---- | C] () -- C:\Windows\hpwins22.dat
[2013/01/11 22:11:45 | 000,002,658 | ---- | C] () -- C:\Windows\hpwmdl22.dat
[2012/11/16 21:39:53 | 000,866,452 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/06 01:12:28 | 000,598,780 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng700.bin
[2012/10/06 01:12:22 | 000,755,048 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng700.bin
[2012/10/06 01:12:10 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/07/26 04:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 16:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2012/06/02 10:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2012/04/20 15:59:44 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[2012/12/08 17:48:27 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/03/06 02:31:28 | 019,758,592 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/03/06 01:03:37 | 017,561,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/25 23:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/25 23:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/25 23:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/06/04 18:24:04 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\.minecraft
[2013/07/03 18:53:07 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\.technic
[2013/07/20 01:38:50 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\AVSoftware
[2013/05/18 22:26:21 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\com.Shutterfly.ExpressUploader
[2013/05/07 18:16:04 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\iFunbox_UserCache
[2012/12/08 17:40:01 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\Leadertech
[2013/04/17 14:53:27 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\Open Download Manager
[2012/12/21 22:46:40 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\PCDr
[2013/08/07 21:54:05 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\PDF Software
[2013/05/29 16:38:57 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\player
[2013/05/11 16:14:11 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\redsn0w
[2013/05/16 20:08:44 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\skyz
[2013/02/03 14:25:00 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\TomTom
[2013/05/11 10:28:16 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\TuneUp Software
[2013/05/07 21:28:57 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\Unity
[2013/07/20 01:43:21 | 000,000,000 | ---D | M] -- C:\Users\Home PC\AppData\Roaming\uTorrent
========== Purity Check ==========
< End of report >