========== Chrome ==========
CHR - homepage:
http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\pdf.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Disabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Disabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Disabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Disabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Winamp Application Detector (Disabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U35 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Disabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Disabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
O1 HOSTS File: ([2012/10/08 19:55:36 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:
64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:
64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:
64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:
64bit: - HKLM\..\Toolbar: (no name) - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AsioReg] C:\Windows\SysWow64\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KORG USB-MIDI Driver] C:\Program Files (x86)\KORG\KORG USB-MIDI Driver\EsHelper2.exe (KORG Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe (SONIX)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000..\Run: [Nexus] C:\Program Files (x86)\Winstep\Nexus.exe (Winstep Software Technologies)
O4 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000..\Run: [SmartRAM] "C:\Program Files (x86)\IObit\Advanced SystemCare 5\Suo10_SmartRAM.exe" /m File not found
O4 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000..\Run: [Wisdom-soft ScreenHunter 5.1 Free] 0 File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1770259247-518088782-3831662574-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm File not found
O8:
64bit: - Extra context menu item: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm File not found
O8 - Extra context menu item: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm File not found
O8 - Extra context menu item: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88}
http://www.convergysworkathome.com/AppHardT.CAB (WNICheck2 Class)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.217.0.5 24.217.201.67 24.247.15.53
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9486293-EF9D-4EDB-BB9E-72D5A7DA36FE}: DhcpNameServer = 24.217.0.5 24.217.201.67 24.247.15.53
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\WB: DllName - (C:\Program Files (x86)\Stardock\MyColors\fast64.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/10/08 20:41:03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\living room\Desktop\OTL.exe
[2012/10/08 20:36:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group
[2012/10/08 20:36:00 | 000,000,000 | ---D | C] -- C:\Users\living room\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2012/10/08 20:27:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Add Remove Cleaner
[2012/10/08 20:00:41 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/10/08 20:00:41 | 000,000,000 | ---D | C] -- C:\Users\living room\AppData\Local\temp
[2012/10/08 19:55:46 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/10/08 19:40:22 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/10/08 19:40:22 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/10/08 19:40:22 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/10/08 19:37:58 | 004,764,063 | R--- | C] (Swearware) -- C:\Users\living room\Desktop\ComboFix.exe
[2012/10/08 17:25:22 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/08 17:23:46 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/10/08 16:36:44 | 000,000,000 | ---D | C] -- C:\Users\living room\Desktop\RK_Quarantine
[2012/10/08 13:09:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2012/10/08 13:08:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
[2012/10/07 17:45:23 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/10/07 17:45:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2012/10/07 17:44:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/10/07 15:14:04 | 000,000,000 | ---D | C] -- C:\Users\living room\Desktop\Victor
[2012/10/03 20:38:04 | 000,000,000 | ---D | C] -- C:\Users\living room\AppData\Local\{95B4EA89-D1FE-4323-9116-52EEDDDFD60E}
[2012/09/28 19:40:23 | 000,000,000 | ---D | C] -- C:\Users\living room\Desktop\phone pics 2
[2012/09/28 19:38:47 | 000,000,000 | ---D | C] -- C:\Users\living room\Desktop\Robs House
[2012/09/20 13:37:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Analog Devices
[2012/09/19 22:49:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2012/09/19 22:49:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2012/09/19 22:49:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2012/09/19 22:17:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games
[2012/09/19 22:00:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\2K Games
[2012/09/17 21:11:41 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\AI_RecycleBin
[2012/09/16 13:33:22 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/09/15 14:31:07 | 000,000,000 | ---D | C] -- C:\Users\living room\AppData\Local\{B774529A-B455-47C1-9617-70D5C7453A74}
[2012/09/08 21:27:32 | 000,000,000 | -H-D | C] -- C:\ProgramData\{3689B77C-90FA-4663-91AB-5AB34383CD81}
[2012/09/08 21:24:12 | 000,000,000 | -H-D | C] -- C:\ProgramData\{24E3A4D8-9E57-4B19-9715-6E61513095D7}
[2012/09/08 21:23:53 | 000,000,000 | -H-D | C] -- C:\ProgramData\{442B6EC3-77A0-4817-825F-67F47D7A2E54}
[12 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/08 20:56:25 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/08 20:41:06 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\living room\Desktop\OTL.exe
[2012/10/08 20:36:00 | 000,001,224 | ---- | M] () -- C:\Users\living room\Desktop\Revo Uninstaller.lnk
[2012/10/08 20:20:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/08 20:08:08 | 000,016,560 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/08 20:08:08 | 000,016,560 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/08 20:03:08 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/08 20:02:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/08 20:02:42 | 1583,566,848 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/08 19:55:36 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/10/08 19:54:37 | 000,000,398 | ---- | M] () -- C:\Windows\tasks\ReclaimerResumeInstall_living room.job
[2012/10/08 19:38:13 | 004,764,063 | R--- | M] (Swearware) -- C:\Users\living room\Desktop\ComboFix.exe
[2012/10/08 18:17:43 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/10/08 18:17:37 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/10/08 17:12:37 | 000,005,909 | ---- | M] () -- C:\Users\living room\Desktop\Techspot help 2.rtf
[2012/10/08 16:52:19 | 000,000,512 | ---- | M] () -- C:\Users\living room\Desktop\MBR.dat
[2012/10/08 16:28:18 | 000,002,282 | ---- | M] () -- C:\Users\living room\Desktop\tech spot help.rtf
[2012/10/08 15:42:18 | 000,329,660 | ---- | M] () -- C:\Users\living room\Desktop\FireShot Screen Capture #034 - 'UPDATED 5-step Viruses_Spyware_Malware Preliminary Removal Instructions - TechSpot Forums' - www_techspot_com_community_topics_updated-5-step-viruses-spyware-malware-preliminary-r.pdf
[2012/10/08 13:08:55 | 000,001,121 | ---- | M] () -- C:\Users\living room\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2012/09/26 19:20:58 | 001,312,538 | ---- | M] () -- C:\Users\living room\9-26-2012 Project save.RPP
[2012/09/25 18:10:57 | 000,778,834 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/25 18:10:57 | 000,660,068 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/25 18:10:57 | 000,120,996 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/19 22:17:13 | 000,002,306 | ---- | M] () -- C:\Users\Public\Desktop\Borderlands 2.lnk
[2012/09/19 13:45:23 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/19 12:42:42 | 000,355,765 | ---- | M] () -- C:\Users\living room\Desktop\RMA_Form for powerpayless.com
[2012/09/15 09:24:08 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\ClipGrab.lnk
[2012/09/13 20:40:01 | 000,001,013 | ---- | M] () -- C:\Users\living room\Desktop\Eusing Free Registry Cleaner.lnk
[2012/09/12 20:21:33 | 000,001,127 | ---- | M] () -- C:\Users\living room\Desktop\Advanced SystemCare 5.lnk
[2012/09/12 20:21:22 | 000,001,182 | ---- | M] () -- C:\Users\living room\Desktop\Turbo Boost.lnk
[2012/09/08 21:30:44 | 000,001,655 | ---- | M] () -- C:\Users\living room\Desktop\Traktor Pro - Shortcut.lnk
[12 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/08 20:36:00 | 000,001,224 | ---- | C] () -- C:\Users\living room\Desktop\Revo Uninstaller.lnk
[2012/10/08 19:40:22 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/10/08 19:40:22 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/10/08 19:40:22 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/10/08 19:40:22 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/10/08 19:40:22 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/10/08 18:38:02 | 000,000,398 | ---- | C] () -- C:\Windows\tasks\ReclaimerResumeInstall_living room.job
[2012/10/08 18:17:43 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/10/08 17:12:37 | 000,005,909 | ---- | C] () -- C:\Users\living room\Desktop\Techspot help 2.rtf
[2012/10/08 16:52:19 | 000,000,512 | ---- | C] () -- C:\Users\living room\Desktop\MBR.dat
[2012/10/08 16:28:18 | 000,002,282 | ---- | C] () -- C:\Users\living room\Desktop\tech spot help.rtf
[2012/10/08 15:42:18 | 000,329,660 | ---- | C] () -- C:\Users\living room\Desktop\FireShot Screen Capture #034 - 'UPDATED 5-step Viruses_Spyware_Malware Preliminary Removal Instructions - TechSpot Forums' - www_techspot_com_community_topics_updated-5-step-viruses-spyware-malware-preliminary-r.pdf
[2012/10/08 13:08:55 | 000,001,121 | ---- | C] () -- C:\Users\living room\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2012/09/26 19:20:58 | 001,312,538 | ---- | C] () -- C:\Users\living room\9-26-2012 Project save.RPP
[2012/09/19 22:17:13 | 000,002,306 | ---- | C] () -- C:\Users\Public\Desktop\Borderlands 2.lnk
[2012/09/19 13:45:23 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/19 12:45:48 | 000,355,765 | ---- | C] () -- C:\Users\living room\Desktop\RMA_Form for powerpayless.com
[2012/09/15 09:24:08 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\ClipGrab.lnk
[2012/09/13 20:38:44 | 000,001,013 | ---- | C] () -- C:\Users\living room\Desktop\Eusing Free Registry Cleaner.lnk
[2012/09/12 20:21:33 | 000,001,127 | ---- | C] () -- C:\Users\living room\Desktop\Advanced SystemCare 5.lnk
[2012/09/12 20:21:22 | 000,001,182 | ---- | C] () -- C:\Users\living room\Desktop\Turbo Boost.lnk
[2012/09/08 21:30:44 | 000,001,655 | ---- | C] () -- C:\Users\living room\Desktop\Traktor Pro - Shortcut.lnk
[2012/04/18 19:39:10 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012/03/13 13:06:30 | 004,417,024 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
[2012/03/10 08:55:16 | 000,172,032 | ---- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2012/03/10 08:55:10 | 006,454,984 | ---- | C] () -- C:\Windows\SysWow64\avcodec-lav-54.dll
[2012/03/10 08:55:10 | 001,146,161 | ---- | C] () -- C:\Windows\SysWow64\avformat-lav-54.dll
[2012/03/10 08:55:10 | 000,371,592 | ---- | C] () -- C:\Windows\SysWow64\swscale-lav-2.dll
[2012/03/10 08:55:10 | 000,206,473 | ---- | C] () -- C:\Windows\SysWow64\avutil-lav-51.dll
[2012/03/10 08:55:10 | 000,142,473 | ---- | C] () -- C:\Windows\SysWow64\avfilter-lav-2.dll
[2012/02/26 11:47:02 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/02/26 11:46:18 | 000,260,608 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
[2012/02/26 11:46:00 | 000,158,720 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
[2012/02/26 11:46:00 | 000,099,840 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
[2012/02/26 11:45:58 | 001,525,248 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
[2012/02/26 11:45:58 | 000,146,944 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
[2012/02/26 11:45:56 | 000,212,480 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
[2012/02/26 11:45:56 | 000,115,200 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
[2012/02/26 11:45:54 | 000,328,704 | ---- | C] () -- C:\Windows\SysWow64\ff_libfaad2.dll
[2012/02/26 11:45:54 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
[2012/02/14 21:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/02/14 21:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/01/11 13:52:19 | 000,772,558 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/01/11 11:14:42 | 000,000,179 | ---- | C] () -- C:\Windows\EQ3D.ini
[2011/12/17 09:52:10 | 000,000,412 | ---- | C] () -- C:\Users\living room\AppData\Roaming\All CPU Meter_Settings.ini
[2011/12/11 10:34:04 | 000,000,339 | ---- | C] () -- C:\Users\living room\AppData\Roaming\Drives Meter_Settings.ini
[2011/12/10 22:59:18 | 000,167,936 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall.exe
[2011/12/10 22:59:18 | 000,017,877 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpowerAMP Music Converter.dat
[2011/12/07 14:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\Lagarith.dll
[2011/12/06 17:06:16 | 000,101,072 | ---- | C] () -- C:\Windows\UTP.exe
[2011/12/06 11:57:34 | 000,007,602 | ---- | C] () -- C:\Users\living room\AppData\Local\Resmon.ResmonCfg
[2011/12/04 00:09:24 | 000,005,120 | ---- | C] () -- C:\Users\living room\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/02 02:06:59 | 000,000,231 | ---- | C] () -- C:\Windows\AC3API.INI
[2011/12/02 02:06:58 | 001,048,576 | ---- | C] () -- C:\Windows\SysWow64\SFMAN.DAT
[2011/12/02 02:06:37 | 000,037,727 | ---- | C] () -- C:\Windows\SysWow64\Emu10kx.ini
[2011/12/02 02:06:37 | 000,000,029 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2011/12/02 02:06:33 | 000,179,669 | ---- | C] () -- C:\Windows\SysWow64\CTSTATIC.DAT
[2011/12/02 02:06:33 | 000,164,044 | ---- | C] () -- C:\Windows\SysWow64\CTDLANG.DAT
[2011/12/02 02:06:33 | 000,113,373 | ---- | C] () -- C:\Windows\SysWow64\CTBASICW.DAT
[2011/12/02 02:06:33 | 000,113,273 | ---- | C] () -- C:\Windows\SysWow64\CTBAS2W.DAT
[2011/12/02 02:06:33 | 000,044,055 | ---- | C] () -- C:\Windows\SysWow64\CTDAUGHT.DAT
[2011/12/02 02:06:31 | 000,184,320 | ---- | C] () -- C:\Windows\PSCONV.EXE
[2011/12/02 02:06:31 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\KILLAPPS.EXE
[2011/12/02 02:06:31 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\REGPLIB.EXE
[2011/12/02 02:06:31 | 000,000,180 | ---- | C] () -- C:\Windows\SysWow64\KILL.INI
[2011/12/02 02:06:30 | 000,065,536 | ---- | C] ( ) -- C:\Windows\SysWow64\A3D.DLL
[2011/11/30 10:48:47 | 000,000,058 | ---- | C] () -- C:\Windows\SysWow64\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011/11/30 10:48:47 | 000,000,058 | ---- | C] () -- C:\Users\living room\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2011/11/30 10:22:44 | 000,843,776 | ---- | C] () -- C:\Windows\vsnpstd3.exe
[2011/11/30 10:22:44 | 000,015,498 | ---- | C] () -- C:\Windows\snpstd3.ini
[2011/11/30 10:22:43 | 000,172,032 | ---- | C] ( ) -- C:\Windows\SysWow64\rsnpstd3.dll
[2011/11/30 10:22:43 | 000,061,440 | ---- | C] ( ) -- C:\Windows\SysWow64\vsnpstd3.dll
[2011/11/30 10:22:43 | 000,053,248 | ---- | C] ( ) -- C:\Windows\csnpstd3.dll
[2011/11/30 07:53:58 | 000,064,764 | ---- | C] () -- C:\Users\living room\AppData\Roaming\UserTile.png
[2011/11/30 07:50:47 | 000,109,016 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/11/30 06:38:27 | 000,030,155 | ---- | C] () -- C:\Windows\Q-Dir.ini
[2011/11/30 05:51:00 | 000,000,128 | ---- | C] () -- C:\Windows\SBWIN.INI
[2011/11/30 03:52:09 | 000,030,756 | ---- | C] () -- C:\Windows\SysWow64\e10kxwdm.ini
[2011/11/24 21:16:05 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/10/25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011/09/12 17:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/09/08 09:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\SysWow64\mkx.dll
[2011/09/08 09:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\SysWow64\mp4.dll
[2011/09/08 09:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\ogm.dll
[2011/09/08 09:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\SysWow64\dxr.dll
[2011/09/08 09:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\dsmux.exe
[2011/09/08 09:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\SysWow64\ts.dll
[2011/09/08 09:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\SysWow64\mkv2vfr.exe
[2011/09/08 09:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\SysWow64\gdsmux.exe
[2011/09/08 08:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\SysWow64\mkzlib.dll
[2011/09/08 08:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\mkunicode.dll
[2011/05/30 08:42:50 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/05/23 02:46:30 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/03/03 06:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\SysWow64\avi.dll
[2011/03/03 06:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\SysWow64\avs.dll
[2011/03/03 06:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\SysWow64\avss.dll
[2011/02/11 03:47:34 | 000,057,904 | ---- | C] () -- C:\Windows\SysWow64\wbload.dll
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/01/04 05:44:25 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/01/04 03:59:38 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/01/05 17:47:50 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Ableton
[2011/12/25 19:45:05 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\All Free Disc Burner
[2012/03/23 15:15:34 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\AnvSoft
[2012/10/08 14:05:19 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Azureus
[2012/03/23 11:56:00 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Bidgood Svcs
[2012/01/18 23:51:13 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Canneverbe Limited
[2011/11/30 07:50:42 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\com.facebookdesktop.app
[2011/12/13 15:02:50 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Copernic
[2011/12/06 08:11:16 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Creevity Mp3 Cover Downloader
[2011/11/30 10:48:47 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\DonationCoder
[2012/03/05 23:56:09 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\DraftSight
[2012/06/03 15:48:08 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\DVDVideoSoft
[2011/12/28 14:20:16 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\FireShot
[2012/01/05 10:53:18 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Foxit Software
[2011/12/13 10:18:21 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\GetRightToGo
[2011/12/02 16:07:27 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\GlarySoft
[2011/12/13 09:56:18 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Highresolution Enterprises
[2011/12/29 20:27:02 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\ImgBurn
[2011/12/12 13:31:31 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\InfraRecorder
[2012/08/08 21:51:29 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\IObit
[2011/12/11 14:24:58 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\IrfanView
[2012/01/02 14:48:11 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\iZotope
[2011/11/30 16:51:58 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Korg
[2012/05/21 14:27:16 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\OpenOffice.org
[2011/12/12 12:41:15 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Opera
[2011/12/31 13:18:53 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Proteus VX
[2011/11/30 06:38:43 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Q-Dir
[2012/01/13 17:43:00 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\REAPER
[2012/01/21 00:03:09 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\SMRecorder
[2011/12/06 07:59:31 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Songbird2
[2011/12/06 16:44:58 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Stardock
[2012/01/02 14:49:07 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Teragon Audio
[2011/12/06 18:40:49 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\ThemeManager
[2011/12/02 21:35:30 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\WinBatch
[2011/12/06 17:59:22 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Windows 7 Taskbar Color Changer
[2012/08/15 22:14:00 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\Windows Live Writer
[2012/05/27 09:25:12 | 000,000,000 | ---D | M] -- C:\Users\living room\AppData\Roaming\WinPatrol
========== Purity Check ==========
< End of report >