OTL.txt Part 5
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/17 16:56:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\temp
[2011/12/17 16:42:26 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/12/17 16:42:26 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/12/17 16:42:26 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/12/17 16:41:52 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2011/12/09 19:34:49 | 000,000,000 | --SD | C] -- C:\zaSetupWeb_101_065_000
[2011/12/06 16:58:29 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/12/06 16:58:22 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/05 19:12:36 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Malwarebytes
[2011/12/05 19:12:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/05 19:12:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/12/05 19:12:21 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/12/05 19:12:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/29 16:07:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/11/29 16:07:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/11/27 09:45:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZoneAlarm
[2011/11/27 09:44:29 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ZoneLabs
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/23 08:30:55 | 000,010,048 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/23 08:30:54 | 000,010,048 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/23 08:27:28 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/23 08:27:00 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011/12/23 08:23:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/23 08:22:17 | 2409,078,784 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/23 07:47:03 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/15 18:48:21 | 000,002,340 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/12/14 15:43:53 | 000,618,864 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/06 17:16:14 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/12/06 16:51:09 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/12/06 16:50:34 | 000,629,152 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/12/06 16:50:34 | 000,112,592 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/12/06 16:46:40 | 000,001,354 | ---- | M] () -- C:\Users\Admin\Desktop\Resume ZoneAlarm Security Install.lnk
[2011/12/06 16:35:46 | 000,000,408 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/12/05 20:59:26 | 000,000,512 | ---- | M] () -- C:\Users\Admin\Documents\MBR.dat
[2011/12/05 20:56:40 | 000,000,512 | ---- | M] () -- C:\Users\Admin\Desktop\MBR.dat
[2011/12/05 19:12:28 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/05 17:44:58 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/12/05 17:44:58 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/12/05 07:15:33 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011/11/29 05:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/11/29 05:01:23 | 000,199,816 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011/11/29 05:01:14 | 000,256,960 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011/11/29 04:54:06 | 000,591,192 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011/11/29 04:53:58 | 000,304,472 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011/11/29 04:52:22 | 000,042,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011/11/29 04:52:20 | 000,058,712 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011/11/29 04:52:11 | 000,066,904 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/11/29 04:51:53 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/11/27 16:28:57 | 000,749,548 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/27 09:45:21 | 000,420,800 | ---- | M] () -- C:\Windows\SysNative\drivers\vsconfig.xml
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/17 16:42:26 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/12/17 16:42:26 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/12/17 16:42:26 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/12/17 16:42:26 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/12/17 16:42:26 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/12/05 20:57:39 | 000,000,512 | ---- | C] () -- C:\Users\Admin\Documents\MBR.dat
[2011/12/05 20:51:19 | 000,000,512 | ---- | C] () -- C:\Users\Admin\Desktop\MBR.dat
[2011/12/05 19:12:28 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/02 19:48:17 | 000,000,408 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/04/20 11:34:55 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/04/20 11:34:55 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2010/02/20 22:00:05 | 000,755,074 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/09/27 13:45:37 | 000,000,832 | ---- | C] () -- C:\Windows\SysWow64\E_ADDNET.DAT
[2009/09/27 12:52:39 | 000,111,932 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2009/09/27 12:52:39 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2009/09/27 12:52:39 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2009/09/27 12:52:39 | 000,026,154 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2009/09/27 12:52:39 | 000,024,903 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2009/09/27 12:52:39 | 000,021,390 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2009/09/27 12:52:39 | 000,020,148 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2009/09/27 12:52:39 | 000,011,811 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2009/09/27 12:52:39 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2009/09/27 12:52:39 | 000,001,146 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2009/09/27 12:52:39 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2009/09/27 12:52:39 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2009/09/27 12:52:39 | 000,001,136 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2009/09/27 12:52:39 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2009/09/27 12:52:39 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2009/09/27 12:52:39 | 000,001,120 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2009/09/27 12:52:39 | 000,001,107 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2009/09/27 12:52:39 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2009/09/27 12:52:39 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2009/09/11 17:03:12 | 002,050,952 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin
[2009/08/08 08:56:20 | 000,372,384 | ---- | C] () -- C:\Windows\SysWow64\atwtusb.exe
[2009/08/08 08:56:20 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\InstallService.exe
[2009/08/08 08:56:19 | 001,969,824 | ---- | C] () -- C:\Windows\SysWow64\WTMKM.exe
[2009/08/08 08:56:18 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\ATWTINK.DLL
[2009/08/08 08:56:18 | 000,102,048 | ---- | C] () -- C:\Windows\RmTablet.exe
[2009/08/08 08:56:17 | 000,010,251 | ---- | C] () -- C:\Windows\SysWow64\Vista.ini
[2009/08/08 08:56:17 | 000,009,868 | ---- | C] () -- C:\Windows\SysWow64\XP_2000.ini
[2009/08/08 08:56:17 | 000,007,261 | ---- | C] () -- C:\Windows\aiptbl.ini
[2009/08/08 08:56:17 | 000,000,593 | ---- | C] () -- C:\Windows\SysWow64\MKProfile.ini
[2009/08/07 20:15:38 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\MFC_InstDrvDLL.dll
[2009/08/07 20:04:32 | 000,000,216 | ---- | C] () -- C:\Windows\Ulead32.ini
[2009/07/14 16:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 13:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 13:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 11:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 10:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 08:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 08:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/06/02 22:20:32 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/02/24 21:31:59 | 000,002,004 | ---- | C] () -- C:\Windows\wininit.ini
[2008/12/22 11:11:30 | 000,000,076 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\7ac6d22d.dat
[2008/12/07 13:08:06 | 000,795,648 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2008/12/07 13:08:04 | 000,130,048 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2008/11/24 15:32:44 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2008/06/06 22:47:12 | 000,000,082 | ---- | C] () -- C:\Windows\SysWow64\Sun Clock 6.ini
[2008/02/09 10:04:39 | 000,000,100 | ---- | C] () -- C:\Windows\Sharktales.INI
[2007/12/25 19:17:36 | 000,000,081 | ---- | C] () -- C:\Windows\HUMANJAP.INI
[2007/11/17 14:45:29 | 000,000,099 | ---- | C] () -- C:\Windows\MFRWORDS.INI
[2007/11/17 14:41:09 | 000,000,108 | ---- | C] () -- C:\Windows\ABC.ini
[2007/11/17 14:32:09 | 000,000,103 | ---- | C] () -- C:\Windows\Pfb.ini
[2007/09/17 22:05:33 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2007/09/04 11:56:10 | 000,164,352 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2007/07/07 12:22:56 | 000,204,800 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeW7.dll
[2007/07/07 12:22:56 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeA6.dll
[2007/07/07 12:22:56 | 000,192,512 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeP6.dll
[2007/07/07 12:22:56 | 000,192,512 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeM6.dll
[2007/07/07 12:22:56 | 000,188,416 | ---- | C] () -- C:\Windows\SysWow64\IVIresizePX.dll
[2007/07/07 12:22:56 | 000,020,480 | ---- | C] () -- C:\Windows\SysWow64\IVIresize.dll
[2007/05/10 00:36:12 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2007/02/05 20:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2007/01/20 01:30:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\px.ini
[2006/09/19 17:02:40 | 000,520,192 | ---- | C] () -- C:\Windows\SysWow64\CddbPlaylist2Roxio.dll
[2006/09/19 17:02:40 | 000,204,800 | ---- | C] () -- C:\Windows\SysWow64\CddbFileTaggerRoxio.dll
[1998/05/07 13:10:00 | 000,069,632 | R--- | C] () -- C:\Windows\SysWow64\ODMA32.dll
========== LOP Check ==========
[2010/02/20 22:31:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\CometNetwork
[2010/02/20 22:31:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Epson
[2010/02/20 22:31:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\InterVideo
[2010/09/04 19:56:47 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\LimeWire
[2010/02/20 22:31:54 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Map Maker
[2010/02/20 22:31:59 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\SecondLife
[2010/02/20 22:32:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\System
[2010/02/20 22:32:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Thunderbird
[2010/05/30 11:06:23 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\XTrackCad
[2010/02/20 22:26:01 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\AVEO
[2011/05/28 14:41:53 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\CheckPoint
[2010/02/20 22:26:01 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\Epson
[2010/02/20 22:26:02 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\InterVideo
[2010/09/04 13:48:33 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\LimeWire
[2010/02/20 22:26:05 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\Map Maker
[2010/02/20 22:26:08 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\OpenOffice.org
[2009/08/01 16:29:30 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\SampleView
[2010/02/20 22:26:13 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\SecondLife
[2011/05/28 21:45:12 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\Thunderbird
[2010/10/02 10:29:13 | 000,000,000 | ---D | M] -- C:\Users\Glyn\AppData\Roaming\TomTom
[2010/02/20 22:30:54 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\Babylon
[2010/02/20 22:30:54 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\Epson
[2010/02/20 22:30:54 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\InterVideo
[2010/02/20 22:31:04 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\Map Maker
[2010/03/30 18:50:14 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\OpenOffice.org
[2010/02/20 22:31:10 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\Stellarium
[2009/04/01 12:01:49 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\System
[2010/10/04 08:54:51 | 000,000,000 | ---D | M] -- C:\Users\Matthew\AppData\Roaming\Thunderbird
[2010/02/20 22:29:46 | 000,000,000 | ---D | M] -- C:\Users\Mum\AppData\Roaming\Babylon
[2010/02/20 22:29:46 | 000,000,000 | ---D | M] -- C:\Users\Mum\AppData\Roaming\CometNetwork
[2010/02/20 22:29:46 | 000,000,000 | ---D | M] -- C:\Users\Mum\AppData\Roaming\Epson
[2010/02/20 22:29:47 | 000,000,000 | ---D | M] -- C:\Users\Mum\AppData\Roaming\InterVideo
[2010/02/20 22:30:00 | 000,000,000 | ---D | M] -- C:\Users\Mum\AppData\Roaming\OpenOffice.org
[2010/10/03 18:21:17 | 000,000,000 | ---D | M] -- C:\Users\Mum\AppData\Roaming\Thunderbird
[2011/12/06 16:35:46 | 000,000,408 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/12/16 16:24:36 | 000,032,568 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/12/06 16:33:46 | 000,699,100 | ---- | M] () -- C:\aaw7boot.log
[2010/11/20 23:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2010/02/21 16:52:39 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/02/20 19:41:51 | 000,000,584 | ---- | M] () -- C:\Ciam_LogFile.log
[2007/05/10 01:43:14 | 000,000,000 | ---- | M] () -- C:\C_USERPART
[2011/12/23 08:22:17 | 2409,078,784 | -HS- | M] () -- C:\hiberfil.sys
[2008/03/04 21:02:04 | 000,262,144 | ---- | M] () -- C:\ntuser.dat
[2011/11/27 14:25:45 | 000,005,120 | -H-- | M] () -- C:\ntuser.dat.LOG1
[2008/03/02 16:11:46 | 000,000,000 | -H-- | M] () -- C:\ntuser.dat.LOG2
[2008/03/02 16:11:47 | 000,065,536 | -HS- | M] () -- C:\ntuser.dat{b644e7a3-e80c-11dc-942f-0017a4e21afb}.TM.blf
[2008/03/02 16:11:47 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{b644e7a3-e80c-11dc-942f-0017a4e21afb}.TMContainer00000000000000000001.regtrans-ms
[2008/03/02 16:11:47 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{b644e7a3-e80c-11dc-942f-0017a4e21afb}.TMContainer00000000000000000002.regtrans-ms
[2008/03/02 18:14:36 | 000,065,536 | -HS- | M] () -- C:\ntuser.dat{b644e7cf-e80c-11dc-942f-0017a4e21afb}.TM.blf
[2008/03/02 18:14:36 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{b644e7cf-e80c-11dc-942f-0017a4e21afb}.TMContainer00000000000000000001.regtrans-ms
[2008/03/02 18:14:36 | 000,524,288 | -HS- | M] () -- C:\ntuser.dat{b644e7cf-e80c-11dc-942f-0017a4e21afb}.TMContainer00000000000000000002.regtrans-ms
[2011/12/23 08:22:24 | 3212,107,776 | -HS- | M] () -- C:\pagefile.sys
[2011/12/18 12:39:30 | 000,077,924 | ---- | M] () -- C:\TDSSKiller.2.6.23.0_18.12.2011_12.36.15_log.txt
[2008/03/02 16:10:17 | 000,441,446 | ---- | M] () -- C:\vcredist_x86.log
< %systemroot%\Fonts\*.com >
[2009/07/14 16:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 16:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 16:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 16:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 07:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/29 05:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 15:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/02 21:38:44 | 000,000,286 | -HS- | M] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2010/02/20 23:39:12 | 000,000,221 | -HS- | M] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2008/10/01 15:08:14 | 014,968,808 | ---- | M] (Safer Networking Limited ) -- C:\Users\Admin\Desktop\spybotsd160.exe
[2009/02/24 19:03:31 | 013,352,960 | ---- | M] (Safer Networking Limited ) -- C:\Users\Admin\Desktop\spybotsd162.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/11 08:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/09/03 15:10:19 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/09/03 15:10:19 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2010/05/15 11:38:44 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2010/05/15 11:38:44 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/08/10 20:04:01 | 000,000,402 | -HS- | M] () -- C:\Users\Admin\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
