OTL.txt part 2:
O1 HOSTS File: ([2012/10/22 23:10:23 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Giant Savings) - {11111111-1111-1111-1111-110011441179} - C:\Program Files (x86)\Giant Savings\Giant Savings.dll (215 Apps)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4:
64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:
64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [LTCM Client] C:\Program Files (x86)\LTCM Client\ltcmClient.exe (Leader Technologies Inc.)
O4 - HKLM..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-770038861-190149619-3254999276-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-770038861-190149619-3254999276-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O8:
64bit: - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\MP4-Converter\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\MP4-Converter\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-770038861-190149619-3254999276-1001\..Trusted Domains: yahoo.com ([football.fantasysports] http in Trusted sites)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16:
64bit: - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3047B09C-D541-47A2-9857-9AECBB1B184A}: DhcpNameServer = 62.24.0.10 62.24.0.9
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41B6F70D-E0F3-4CAF-9C2C-477DDD151E6B}: DhcpNameServer = 192.168.2.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/10/23 00:14:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Jim\Desktop\OTL.exe
[2012/10/23 00:13:34 | 000,000,000 | R--D | C] -- C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2012/10/22 23:59:43 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Roaming\Malwarebytes
[2012/10/22 23:59:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/22 23:59:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/10/22 23:59:32 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/10/22 23:59:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/10/22 23:55:30 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Roaming\AVG2013
[2012/10/22 23:54:50 | 010,669,952 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Jim\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/22 23:54:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/10/22 23:53:19 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/10/22 23:50:11 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\Avg2013
[2012/10/22 23:32:44 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/10/22 23:12:07 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/10/22 23:03:04 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/10/22 23:03:04 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/10/22 23:03:04 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/10/22 22:59:52 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/22 22:59:30 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/10/22 22:42:51 | 004,987,434 | R--- | C] (Swearware) -- C:\Users\Jim\Desktop\ComboFix.exe
[2012/10/22 22:26:19 | 000,000,000 | ---D | C] -- C:\Users\Jim\Desktop\RK_Quarantine
[2012/10/22 22:02:07 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Jim\Desktop\aswMBR.exe
[2012/10/22 21:30:39 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/10/21 21:54:04 | 000,000,000 | ---D | C] -- C:\FRST
[2012/10/21 16:44:08 | 000,000,000 | ---D | C] -- C:\found.000
[2012/10/21 12:28:45 | 000,000,000 | ---D | C] -- C:\Update
[2012/10/21 09:51:07 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\Programs
[2012/10/21 09:50:34 | 000,000,000 | ---D | C] -- C:\Users\Jim\Documents\WebCam Media
[2012/10/21 09:16:53 | 000,000,000 | ---D | C] -- C:\ArcSoft
[2012/10/18 18:07:08 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{EE5A87E0-318C-485B-B50F-3B7CE4C15B70}
[2012/10/17 21:55:07 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{6DA602AC-B60A-4ECA-872A-D6CDC78E70AA}
[2012/10/17 06:23:16 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{88559C51-1587-4B0E-A97B-7E95FC32A01C}
[2012/10/16 17:24:36 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{F6F3F0CA-E4C4-4865-B0C9-90E0C4C7CFED}
[2012/10/15 21:05:52 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{FA4BEF3E-3FA2-45C4-A066-B45D890A255A}
[2012/10/12 16:06:33 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{72DE389D-4BB1-4302-9505-5C63E7CFC5D5}
[2012/10/11 19:07:00 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\ArcSoft
[2012/10/11 19:06:53 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Roaming\ArcSoft
[2012/10/11 18:41:52 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{B59ADBA3-7FF2-4B5C-BB8B-97F3A54F065E}
[2012/10/11 06:27:10 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{A6DF6C27-F40F-48C2-8ADE-E8A6FCCE433E}
[2012/10/10 18:26:48 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{ECCC1833-EBB3-4449-9C52-FD9E7187805F}
[2012/10/10 06:26:25 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{79BCC48C-12B4-4209-AC87-13EAEEA287CF}
[2012/10/09 18:12:18 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{ED75F15E-BB0D-4FC7-A441-E78E79C2D54D}
[2012/10/08 19:58:51 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{C46D6CC5-5812-4921-B311-24CA551CC355}
[2012/10/08 07:58:39 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{1D73A6D5-4347-4A08-BF30-0C3B3DBDD927}
[2012/10/07 19:52:45 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{50600E1B-A148-49B7-B220-7F5D44187E0C}
[2012/10/05 07:42:16 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{8CFDB3AE-2F1D-401E-A9B3-30831FFD78FE}
[2012/10/05 03:26:22 | 000,111,456 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2012/10/04 18:17:49 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{D38F0391-C255-46DB-B18D-07ACAA60AECE}
[2012/10/04 06:17:37 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{15E46865-E31E-47C3-8622-53FB15C4DB7F}
[2012/10/03 22:21:51 | 000,000,000 | ---D | C] -- C:\Converted
[2012/10/03 22:19:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP4-Converter
[2012/10/03 22:19:40 | 000,260,608 | ---- | C] (SMServer) -- C:\Windows\SysWow64\snmvtsvc.exe
[2012/10/03 22:19:39 | 000,034,088 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\MP4ConverterAudio.sys
[2012/10/03 22:19:39 | 000,034,088 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\MP4ConverterAudio.sys
[2012/10/03 22:19:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MP4-Converter
[2012/10/03 21:54:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DownloadManager
[2012/10/03 21:54:10 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\Giant Savings
[2012/10/03 21:54:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Giant Savings
[2012/10/03 21:54:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funmoods
[2012/10/03 21:29:07 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Roaming\Apple Computer
[2012/10/03 21:29:07 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\Apple Computer
[2012/10/03 21:29:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/10/03 21:28:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2012/10/03 21:27:02 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/10/03 21:27:01 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/10/03 21:27:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012/10/03 21:27:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2012/10/03 21:27:01 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/10/03 21:26:22 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\Apple
[2012/10/03 21:26:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2012/10/03 21:25:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2012/10/03 21:25:39 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/10/03 21:25:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2012/10/03 21:25:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2012/10/03 21:25:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2012/10/03 18:05:41 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{94DF0E26-CF66-4970-855D-8992E9758F98}
[2012/10/03 06:05:31 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{1ECC667C-CC7F-4EBF-8EDD-0D0CBCFC6905}
[2012/10/02 17:20:55 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{6E695C1D-EA87-43ED-8252-D19E30DABBB6}
[2012/10/02 03:30:38 | 000,185,696 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2012/10/01 17:20:23 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{15C3B862-493B-4EF6-9DE2-FD0B778FA626}
[2012/09/30 22:59:05 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{E461E881-3E77-4280-A204-F0089437A857}
[2012/09/30 08:31:57 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{5117E04E-E15B-422A-8C62-13E94EFCDBD7}
[2012/09/29 20:31:34 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{A2F9BBFD-553F-4C1E-9B53-FA008723BF00}
[2012/09/29 08:31:24 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{91383E65-2251-4C39-8822-96BF4690B9B6}
[2012/09/28 20:12:10 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{9BD8BBCB-9BEA-41A4-9221-447C805EFDFC}
[2012/09/27 21:28:20 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{788C0246-FCD2-4D9A-9CE3-DC4420E50541}
[2012/09/26 21:44:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2012/09/26 21:44:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2012/09/26 20:27:18 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{F8FF1EFC-8009-4A31-835D-2994FF9693B1}
[2012/09/25 06:26:51 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\{3962C4FA-D2F0-4910-AD14-949FD9F2059C}
[2012/09/24 15:32:52 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Local\Cyberlink
[2012/09/24 15:32:37 | 000,000,000 | ---D | C] -- C:\Users\Jim\Documents\CyberLink
[2012/09/24 15:32:37 | 000,000,000 | ---D | C] -- C:\Users\Jim\AppData\Roaming\CyberLink
[2012/09/24 15:32:37 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2012/09/23 09:46:52 | 000,000,000 | ---D | C] -- C:\Downloads
[2012/06/18 10:02:22 | 005,591,552 | ---- | C] (Jeffrey Harris) -- C:\Program Files\SharePod.exe
========== Files - Modified Within 30 Days ==========
[2012/10/23 00:12:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/23 00:12:36 | 458,510,335 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/23 00:00:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/22 23:59:34 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/22 23:54:07 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk
[2012/10/22 23:38:13 | 000,020,928 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/22 23:38:13 | 000,020,928 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/22 23:10:23 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/10/22 22:59:23 | 004,987,434 | R--- | M] (Swearware) -- C:\Users\Jim\Desktop\ComboFix.exe
[2012/10/22 22:38:01 | 000,000,512 | ---- | M] () -- C:\Users\Jim\Desktop\MBR.dat
[2012/10/22 12:48:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jim\Desktop\OTL.exe
[2012/10/22 12:26:56 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Jim\Desktop\aswMBR.exe
[2012/10/22 12:25:29 | 010,669,952 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Jim\Desktop\mbam-setup-1.65.1.1000.exe
[2012/10/22 12:21:10 | 001,425,920 | ---- | M] () -- C:\Users\Jim\Desktop\RogueKiller.exe
[2012/10/21 17:27:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-770038861-190149619-3254999276-1001UA.job
[2012/10/21 09:36:23 | 000,778,660 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/21 09:36:23 | 000,660,318 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/10/21 09:36:23 | 000,121,214 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/10/21 09:01:23 | 000,129,024 | ---- | M] () -- C:\Users\Jim\Documents\9606e3a.dll
[2012/10/21 08:35:24 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-770038861-190149619-3254999276-1001Core.job
[2012/10/14 08:46:14 | 000,097,652 | ---- | M] () -- C:\ProgramData\eolbudrbawuxzlv
[2012/10/11 06:09:04 | 000,002,473 | ---- | M] () -- C:\Users\Jim\Desktop\Google Chrome.lnk
[2012/10/05 03:26:22 | 000,111,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2012/10/03 22:19:50 | 000,001,977 | ---- | M] () -- C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\MP4-Converter.lnk
[2012/10/03 22:19:50 | 000,001,953 | ---- | M] () -- C:\Users\Public\Desktop\MP4-Converter.lnk
[2012/10/03 22:19:50 | 000,001,930 | ---- | M] () -- C:\Users\Public\Desktop\MP4-Converter CDRipper.lnk
[2012/10/03 22:19:50 | 000,001,030 | ---- | M] () -- C:\Users\Public\Desktop\Buy MP4-Converter Now.lnk
[2012/10/03 21:58:19 | 005,591,552 | ---- | M] (Jeffrey Harris) -- C:\Program Files\SharePod.exe
[2012/10/03 21:55:20 | 000,002,073 | ---- | M] () -- C:\Users\Jim\Desktop\JDownloader.lnk
[2012/10/03 21:55:20 | 000,002,037 | ---- | M] () -- C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\JDownloader.lnk
[2012/10/03 21:54:05 | 000,141,086 | ---- | M] () -- C:\Users\Jim\AppData\Local\funmoods-speeddial_sf.crx
[2012/10/03 21:31:20 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/10/03 21:29:01 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/10/03 20:54:54 | 000,001,241 | ---- | M] () -- C:\Users\Jim\Desktop\Videos - Shortcut.lnk
[2012/10/02 03:30:38 | 000,185,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2012/09/29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/26 21:44:32 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
========== Files Created - No Company Name ==========
[2012/10/22 23:59:34 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/22 23:54:07 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk
[2012/10/22 23:03:04 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/10/22 23:03:04 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/10/22 23:03:04 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/10/22 23:03:04 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/10/22 23:03:04 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/10/22 22:38:01 | 000,000,512 | ---- | C] () -- C:\Users\Jim\Desktop\MBR.dat
[2012/10/22 22:01:49 | 001,425,920 | ---- | C] () -- C:\Users\Jim\Desktop\RogueKiller.exe
[2012/10/21 09:43:43 | 000,008,031 | ---- | C] () -- C:\Users\Jim\Documents\080704_065046.jpg
[2012/10/21 09:01:23 | 000,129,024 | ---- | C] () -- C:\Users\Jim\Documents\9606e3a.dll
[2012/10/14 08:46:05 | 000,097,652 | ---- | C] () -- C:\ProgramData\eolbudrbawuxzlv
[2012/10/03 22:19:50 | 000,001,977 | ---- | C] () -- C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\MP4-Converter.lnk
[2012/10/03 22:19:50 | 000,001,953 | ---- | C] () -- C:\Users\Public\Desktop\MP4-Converter.lnk
[2012/10/03 22:19:50 | 000,001,930 | ---- | C] () -- C:\Users\Public\Desktop\MP4-Converter CDRipper.lnk
[2012/10/03 22:19:50 | 000,001,030 | ---- | C] () -- C:\Users\Public\Desktop\Buy MP4-Converter Now.lnk
[2012/10/03 22:19:40 | 000,252,928 | ---- | C] () -- C:\Windows\SysWow64\GSService.exe
[2012/10/03 22:19:39 | 000,022,019 | ---- | C] () -- C:\Windows\SysNative\MP4ConverterAudio.inf
[2012/10/03 22:19:39 | 000,008,023 | ---- | C] () -- C:\Windows\SysNative\MP4ConverterAudio.cat
[2012/10/03 21:55:20 | 000,002,073 | ---- | C] () -- C:\Users\Jim\Desktop\JDownloader.lnk
[2012/10/03 21:55:20 | 000,002,037 | ---- | C] () -- C:\Users\Jim\Application Data\Microsoft\Internet Explorer\Quick Launch\JDownloader.lnk
[2012/10/03 21:55:00 | 000,002,037 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012/10/03 21:55:00 | 000,001,981 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2012/10/03 21:55:00 | 000,001,960 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012/10/03 21:54:18 | 000,141,086 | ---- | C] () -- C:\Users\Jim\AppData\Local\funmoods-speeddial_sf.crx
[2012/10/03 21:31:20 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/10/03 21:29:01 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/10/03 21:26:19 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/10/03 20:54:54 | 000,001,241 | ---- | C] () -- C:\Users\Jim\Desktop\Videos - Shortcut.lnk
[2012/09/26 21:44:32 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/09/26 21:44:31 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/09/02 16:22:56 | 000,000,071 | ---- | C] () -- C:\Windows\ENX330.ini
[2012/03/14 16:54:37 | 000,963,912 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012/03/14 16:54:36 | 013,184,512 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2012/03/14 16:54:36 | 000,261,208 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012/03/14 16:54:36 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2012/03/14 16:54:36 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/02/03 01:08:26 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2011/02/10 19:03:27 | 000,772,682 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== ZeroAccess Check ==========
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 01:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 00:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/10/12 16:24:26 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2012/10/12 16:24:26 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012/10/22 23:55:30 | 000,000,000 | ---D | M] -- C:\Users\Jim\AppData\Roaming\AVG2013
[2012/10/10 03:18:18 | 000,000,000 | ---D | M] -- C:\Users\Jim\AppData\Roaming\BitComet
[2012/09/12 06:27:17 | 000,000,000 | ---D | M] -- C:\Users\Jim\AppData\Roaming\Epson
[2012/09/12 06:27:16 | 000,000,000 | ---D | M] -- C:\Users\Jim\AppData\Roaming\Leader Technologies
[2012/09/02 16:29:27 | 000,000,000 | ---D | M] -- C:\Users\Jim\AppData\Roaming\Leadertech
[2012/09/20 22:10:45 | 000,000,000 | ---D | M] -- C:\Users\Jim\AppData\Roaming\TuneUp Software
[2012/09/09 22:47:02 | 000,000,000 | ---D | M] -- C:\Users\Jim\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
< End of report >