OTL.txt 2/2
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google

riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google

mniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google

ageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - Extension: Google Docs = C:\Users\Leong\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: avast! Online Security = C:\Users\Leong\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2011.70_0\
CHR - Extension: RealDownloader = C:\Users\Leong\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_0\
CHR - Extension: Google Wallet = C:\Users\Leong\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
CHR - Extension: Gmail = C:\Users\Leong\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/11 00:00:26 | 000,000,824 | ---- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O2:
64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
O3:
64bit: - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [BLEServicesCtrl] C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKU\S-1-5-21-994249627-1979807694-3722736761-1001..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-994249627-1979807694-3722736761-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-994249627-1979807694-3722736761-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.20.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0078F24E-9339-444C-9997-6AAABD586D9A}: DhcpNameServer = 172.20.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8DCD3E1F-BCA1-4352-936B-0E238B228057}: DhcpNameServer = 172.20.0.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/01/06 00:02:13 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/01/05 23:50:47 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/01/05 19:37:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/01/05 19:37:03 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2014/01/05 19:27:35 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/01/05 19:27:35 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/01/05 19:27:35 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/01/05 19:27:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/01/05 19:27:12 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/01/05 00:09:52 | 000,089,304 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/01/05 00:08:11 | 000,000,000 | ---D | C] -- C:\Users\Leong\Desktop\mbar
[2014/01/05 00:00:20 | 000,425,272 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\SynTP.sys.bak
[2014/01/05 00:00:19 | 000,067,184 | ---- | C] (STMicroelectronics) -- C:\Windows\SysNative\drivers\ST_ACCEL.sys.bak
[2014/01/05 00:00:17 | 000,022,128 | ---- | C] (ST Microelectronics) -- C:\Windows\SysNative\drivers\stdcfltn.sys.bak
[2014/01/05 00:00:14 | 000,024,888 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys.bak
[2014/01/05 00:00:13 | 000,024,888 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys.bak
[2014/01/05 00:00:04 | 000,646,248 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys.bak
[2014/01/04 23:59:11 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys.bak
[2014/01/04 23:59:10 | 000,065,600 | ---- | C] (LSI Corporation) -- C:\Windows\SysNative\drivers\lsi_sas2.sys.bak
[2014/01/04 23:58:46 | 000,109,056 | ---- | C] (Ozmo Inc) -- C:\Windows\SysNative\drivers\hswpan.sys.bak
[2014/01/04 23:58:40 | 000,031,232 | ---- | C] (Hauppauge Computer Works, Inc.) -- C:\Windows\SysNative\drivers\hcw85cir.sys.bak
[2014/01/04 23:57:56 | 000,195,584 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\AmpPal.sys.bak
[2014/01/04 23:57:55 | 000,194,128 | ---- | C] (AMD Technologies Inc.) -- C:\Windows\SysNative\drivers\amdsbs.sys.bak
[2014/01/04 23:56:23 | 000,000,000 | ---D | C] -- C:\Users\Leong\Desktop\RK_Quarantine
[2014/01/03 22:01:39 | 000,000,000 | ---D | C] -- C:\Emergency
[2014/01/03 21:17:53 | 000,000,000 | ---D | C] -- C:\Windows\SMINST
[2014/01/03 19:11:16 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2014/01/03 17:27:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
[2014/01/03 17:27:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HD Tune
[2014/01/03 17:21:49 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2014/01/03 17:05:30 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2014/01/03 15:19:14 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\ElevatedDiagnostics
[2014/01/03 12:20:36 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2014/01/03 12:12:38 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Adobe
[2014/01/03 12:08:36 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2014/01/03 12:00:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\dumps
[2014/01/03 11:59:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2014/01/03 11:59:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2014/01/03 11:52:08 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\AVAST Software
[2014/01/03 11:52:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
[2014/01/03 11:51:14 | 000,079,672 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswstm.sys
[2014/01/03 11:51:09 | 001,034,464 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2014/01/03 11:51:06 | 000,422,216 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014/01/03 11:51:01 | 000,078,648 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014/01/03 11:50:59 | 000,092,544 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014/01/03 11:50:57 | 000,334,136 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014/01/03 11:50:45 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014/01/03 11:50:03 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014/01/03 11:49:23 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Opera Software
[2014/01/03 11:49:22 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Opera Software
[2014/01/03 11:49:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2014/01/03 11:49:00 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\RealNetworks
[2014/01/03 11:48:59 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014/01/03 11:48:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PANDORATV
[2014/01/03 11:48:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RealNetworks
[2014/01/03 11:47:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PANDORA.TV
[2014/01/03 11:47:47 | 000,000,000 | ---D | C] -- C:\ProgramData\RealNetworks
[2014/01/03 11:47:25 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
[2014/01/03 11:47:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2014/01/03 11:46:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The KMPlayer
[2014/01/03 11:46:27 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2014/01/03 11:46:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2014/01/03 11:45:40 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Real
[2014/01/03 11:42:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2014/01/03 11:35:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014/01/03 11:33:38 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Malwarebytes
[2014/01/03 11:33:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2014/01/03 11:33:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/01/03 11:33:17 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/01/03 11:33:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2014/01/03 11:32:58 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Programs
[2014/01/03 11:32:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2014/01/03 11:32:30 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Google
[2014/01/03 11:31:53 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Apps
[2014/01/03 11:31:51 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Deployment
[2014/01/03 11:30:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell Digital Delivery
[2014/01/03 11:29:10 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Macromedia
[2014/01/03 11:29:03 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Adobe
[2014/01/03 11:27:27 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Creative
[2014/01/03 11:27:25 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Intel Corporation
[2014/01/03 11:27:23 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Leadertech
[2014/01/03 11:26:53 | 000,000,000 | R--D | C] -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014/01/03 11:26:53 | 000,000,000 | R--D | C] -- C:\Users\Leong\Searches
[2014/01/03 11:26:53 | 000,000,000 | R--D | C] -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014/01/03 11:26:52 | 000,000,000 | -H-D | C] -- C:\Users\Leong\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2014/01/03 11:26:35 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Identities
[2014/01/03 11:26:29 | 000,000,000 | R--D | C] -- C:\Users\Leong\Contacts
[2014/01/03 11:26:24 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\VirtualStore
[2014/01/03 11:23:01 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Absolute_Software
[2014/01/03 11:17:53 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Intel
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\AppData\Local\Temporary Internet Files
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Templates
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Start Menu
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\SendTo
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Recent
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\PrintHood
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\NetHood
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Documents\My Videos
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Documents\My Pictures
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Documents\My Music
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\My Documents
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Local Settings
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\AppData\Local\History
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Cookies
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\Application Data
[2014/01/03 11:17:07 | 000,000,000 | -HSD | C] -- C:\Users\Leong\AppData\Local\Application Data
[2014/01/03 11:16:58 | 000,000,000 | --SD | C] -- C:\Users\Leong\AppData\Roaming\Microsoft
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Videos
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Saved Games
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Pictures
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Music
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Links
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Favorites
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Downloads
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Documents
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\Desktop
[2014/01/03 11:16:58 | 000,000,000 | R--D | C] -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014/01/03 11:16:58 | 000,000,000 | -H-D | C] -- C:\Users\Leong\AppData
[2014/01/03 11:16:58 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Temp
[2014/01/03 11:16:58 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\SoftThinks
[2014/01/03 11:16:58 | 000,000,000 | ---D | C] -- C:\Users\Leong\Roaming
[2014/01/03 11:16:58 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Local\Microsoft
[2014/01/03 11:16:58 | 000,000,000 | ---D | C] -- C:\Users\Leong\AppData\Roaming\Media Center Programs
[2013/12/13 14:03:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2013/12/13 14:03:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real
========== Files - Modified Within 30 Days ==========
[2014/01/06 00:04:37 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/01/06 00:04:37 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/01/05 23:57:17 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/01/05 23:56:58 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/01/05 23:55:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/01/05 23:54:54 | 2054,926,335 | -HS- | M] () -- C:\hiberfil.sys
[2014/01/05 22:56:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/01/05 02:06:54 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Leong\Desktop\TDSSKiller.exe
[2014/01/05 00:09:52 | 000,089,304 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/01/05 00:00:20 | 000,425,272 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\SynTP.sys.bak
[2014/01/05 00:00:19 | 000,067,184 | ---- | M] (STMicroelectronics) -- C:\Windows\SysNative\drivers\ST_ACCEL.sys.bak
[2014/01/05 00:00:17 | 000,022,128 | ---- | M] (ST Microelectronics) -- C:\Windows\SysNative\drivers\stdcfltn.sys.bak
[2014/01/05 00:00:14 | 000,024,888 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys.bak
[2014/01/05 00:00:14 | 000,024,888 | ---- | M] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys.bak
[2014/01/05 00:00:04 | 000,646,248 | ---- | M] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys.bak
[2014/01/04 23:59:12 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys.bak
[2014/01/04 23:59:10 | 000,065,600 | ---- | M] (LSI Corporation) -- C:\Windows\SysNative\drivers\lsi_sas2.sys.bak
[2014/01/04 23:58:52 | 014,760,096 | ---- | M] () -- C:\Windows\SysNative\drivers\igdkmd64.sys.bak
[2014/01/04 23:58:47 | 000,109,056 | ---- | M] (Ozmo Inc) -- C:\Windows\SysNative\drivers\hswpan.sys.bak
[2014/01/04 23:58:40 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) -- C:\Windows\SysNative\drivers\hcw85cir.sys.bak
[2014/01/04 23:57:57 | 000,195,584 | ---- | M] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\AmpPal.sys.bak
[2014/01/04 23:57:55 | 000,194,128 | ---- | M] (AMD Technologies Inc.) -- C:\Windows\SysNative\drivers\amdsbs.sys.bak
[2014/01/04 19:34:18 | 000,007,460 | ---- | M] () -- C:\Users\Leong\AppData\Roaming\AbsoluteReminder.xml
[2014/01/03 19:11:20 | 000,003,344 | ---- | M] () -- C:\bootsqm.dat
[2014/01/03 18:15:10 | 000,108,227 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2014/01/03 18:15:10 | 000,108,227 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2014/01/03 16:55:27 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014/01/03 12:41:59 | 000,778,278 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/01/03 12:41:59 | 000,647,420 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/01/03 12:41:59 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/01/03 11:51:57 | 000,079,672 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswstm.sys
[2014/01/03 11:50:47 | 001,034,464 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2014/01/03 11:50:47 | 000,422,216 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014/01/03 11:50:47 | 000,334,136 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014/01/03 11:50:47 | 000,207,904 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014/01/03 11:50:47 | 000,078,648 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014/01/03 11:50:47 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014/01/03 11:50:46 | 000,092,544 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014/01/03 11:50:45 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014/01/03 11:46:27 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2014/01/03 11:36:04 | 000,002,281 | ---- | M] () -- C:\Users\Leong\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/01/03 11:27:56 | 000,001,439 | ---- | M] () -- C:\Users\Leong\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
========== Files Created - No Company Name ==========
[2014/01/05 19:27:35 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/01/05 19:27:35 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014/01/05 19:27:35 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/01/05 19:27:35 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/01/05 19:27:35 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/01/04 23:58:51 | 014,760,096 | ---- | C] () -- C:\Windows\SysNative\drivers\igdkmd64.sys.bak
[2014/01/03 19:11:20 | 000,003,344 | ---- | C] () -- C:\bootsqm.dat
[2014/01/03 18:11:45 | 2054,926,335 | -HS- | C] () -- C:\hiberfil.sys
[2014/01/03 16:55:27 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014/01/03 11:51:11 | 000,207,904 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014/01/03 11:51:10 | 000,065,776 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014/01/03 11:49:15 | 000,001,131 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2014/01/03 11:35:41 | 000,002,281 | ---- | C] () -- C:\Users\Leong\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/01/03 11:33:12 | 000,000,896 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/01/03 11:33:06 | 000,000,892 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/01/03 11:27:55 | 000,001,439 | ---- | C] () -- C:\Users\Leong\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/01/03 11:27:02 | 000,001,411 | ---- | C] () -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2014/01/03 11:26:55 | 000,001,445 | ---- | C] () -- C:\Users\Leong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/01/03 11:23:00 | 000,007,460 | ---- | C] () -- C:\Users\Leong\AppData\Roaming\AbsoluteReminder.xml
[2014/01/03 11:19:32 | 000,001,975 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Help Documentation.lnk
[2014/01/03 11:16:58 | 000,000,290 | ---- | C] () -- C:\Users\Leong\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2014/01/03 11:16:58 | 000,000,272 | ---- | C] () -- C:\Users\Leong\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/09/14 14:38:51 | 000,755,572 | ---- | C] () -- C:\Windows\SysWow64\igkrng700.bin
[2012/09/14 14:38:49 | 000,559,972 | ---- | C] () -- C:\Windows\SysWow64\igfcg700m.bin
[2012/09/14 14:38:45 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/09/14 14:38:43 | 013,026,816 | ---- | C] () -- C:\Windows\SysWow64\ig7icd32.dll
[2012/02/25 17:45:12 | 000,417,600 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/01/11 04:39:16 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[2009/07/14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\shell32.dll -- [2012/09/14 14:54:03 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/09/14 14:54:03 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\fastprox.dll -- [2009/07/14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 06:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\wbemess.dll -- [2009/07/14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/01/03 11:52:08 | 000,000,000 | ---D | M] -- C:\Users\Leong\AppData\Roaming\AVAST Software
[2014/01/03 11:27:25 | 000,000,000 | ---D | M] -- C:\Users\Leong\AppData\Roaming\Leadertech
[2014/01/03 11:49:22 | 000,000,000 | ---D | M] -- C:\Users\Leong\AppData\Roaming\Opera Software
========== Purity Check ==========
< End of report >