Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/05/25 18:06:31 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
[2012/05/24 20:58:35 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/05/24 10:09:23 | 000,000,000 | ---D | C] -- C:\ProgramData\GFI Software
[2012/05/24 09:59:58 | 004,526,123 | R--- | C] (Swearware) -- C:\Users\owner\Desktop\your_name.exe
[2012/05/24 09:56:29 | 009,989,040 | ---- | C] (OPSWAT, Inc.) -- C:\Users\owner\Desktop\AppRemover.exe
[2012/05/23 21:27:56 | 004,502,264 | R--- | C] (Swearware) -- C:\Users\owner\Desktop\ComboFix.exe
[2012/05/22 20:39:51 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\owner\Desktop\aswMBR.exe
[2012/05/22 20:26:56 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\owner\Desktop\boot_cleaner.exe
[2012/05/22 12:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/05/22 12:51:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/05/22 12:22:04 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\owner\Desktop\dds.scr
[2012/05/22 12:14:13 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Malwarebytes
[2012/05/22 11:57:10 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\owner\Desktop\HijackThis.exe
[2012/05/22 11:44:15 | 002,126,936 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\owner\Desktop\TDSSKiller.exe
[2012/05/22 11:27:55 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Local\adaware
[2012/05/22 11:27:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Browsing Protection
[2012/05/22 11:18:40 | 055,656,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MRT.exe
[2012/05/21 20:51:01 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Populus
[2012/05/21 20:51:01 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CF Toolbox
[2012/05/21 19:19:43 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/05/21 19:09:58 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\GlarySoft
[2012/05/20 18:16:01 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/05/19 19:50:43 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\Diablo III
[2012/05/19 19:50:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2012/05/19 19:47:16 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/05/19 19:47:13 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/19 19:47:13 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/05/19 19:47:12 | 001,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2012/05/19 19:47:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net
[2012/05/19 19:34:03 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Google
[2012/05/10 13:11:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012/05/10 13:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/05/09 19:54:12 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Local\Chromium
[2012/05/09 18:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2012/05/09 18:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios
[2012/05/09 18:40:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hi-Rez Studios
[2012/05/04 09:38:09 | 000,419,488 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2011/08/31 21:39:17 | 001,169,224 | ---- | C] (Microsoft Corporation) -- C:\Users\owner\AppData\Roaming\38H3R06LO0.exe
[2010/11/19 00:27:00 | 000,587,776 | ---- | C] (Igor Pavlov) -- C:\Users\owner\AppData\Roaming\7za.exe
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/25 18:06:32 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
[2012/05/25 18:05:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/05/24 21:59:52 | 000,783,334 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/24 21:59:52 | 000,663,434 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/05/24 21:59:52 | 000,122,270 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/05/24 21:10:40 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/24 21:10:40 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/24 21:02:40 | 477,532,159 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/24 20:18:00 | 000,000,280 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{BE27CBCD-8037-4D3D-93A3-C853578A158A}.job
[2012/05/24 16:08:35 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2012/05/24 10:00:35 | 001,012,656 | ---- | M] () -- C:\Users\owner\Desktop\rkill.com
[2012/05/24 09:59:58 | 004,526,123 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\your_name.exe
[2012/05/24 09:56:43 | 009,989,040 | ---- | M] (OPSWAT, Inc.) -- C:\Users\owner\Desktop\AppRemover.exe
[2012/05/24 09:52:04 | 004,502,264 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\ComboFix.exe
[2012/05/23 10:19:46 | 000,000,512 | ---- | M] () -- C:\Users\owner\Desktop\MBR.dat
[2012/05/23 08:16:44 | 002,126,936 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\owner\Desktop\TDSSKiller.exe
[2012/05/22 20:52:21 | 000,002,260 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[2012/05/22 20:52:14 | 000,001,520 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2012/05/22 20:51:24 | 999,983,021 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/05/22 20:40:06 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\owner\Desktop\aswMBR.exe
[2012/05/22 20:26:11 | 000,044,607 | ---- | M] () -- C:\Users\owner\Desktop\bootkit_remover.zip
[2012/05/22 12:22:06 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\dds.scr
[2012/05/22 12:14:55 | 000,302,592 | ---- | M] () -- C:\Users\owner\Desktop\idri9fe4.exe
[2012/05/22 11:57:12 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\owner\Desktop\HijackThis.exe
[2012/05/20 18:04:46 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/20 18:04:46 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/05/19 20:12:33 | 000,427,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/04 12:14:59 | 000,000,969 | ---- | M] () -- C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/04/26 20:08:16 | 055,656,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MRT.exe
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/24 20:18:00 | 000,000,280 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{BE27CBCD-8037-4D3D-93A3-C853578A158A}.job
[2012/05/24 10:00:34 | 001,012,656 | ---- | C] () -- C:\Users\owner\Desktop\rkill.com
[2012/05/22 20:51:24 | 999,983,021 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/05/22 20:49:46 | 000,000,512 | ---- | C] () -- C:\Users\owner\Desktop\MBR.dat
[2012/05/22 20:26:10 | 000,044,607 | ---- | C] () -- C:\Users\owner\Desktop\bootkit_remover.zip
[2012/05/22 12:14:53 | 000,302,592 | ---- | C] () -- C:\Users\owner\Desktop\idri9fe4.exe
[2012/04/02 22:37:59 | 000,033,792 | ---- | C] () -- C:\Windows\SysWow64\drivers\libusb0.sys
[2012/04/02 16:17:38 | 000,040,985 | ---- | C] () -- C:\Users\owner\AppData\Roaming\a.7z
[2011/10/26 23:15:39 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/26 23:15:38 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/26 22:55:00 | 002,580,552 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011/09/26 22:27:56 | 000,001,241 | ---- | C] () -- C:\Windows\hpomdl49.dat.temp
[2011/09/14 11:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/08/29 17:06:29 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/28 18:07:20 | 000,206,514 | ---- | C] () -- C:\Windows\hpoins49.dat
[2011/08/21 13:44:16 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
[2011/08/21 11:54:57 | 000,026,960 | ---- | C] () -- C:\Users\owner\AppData\Roaming\fed
[2011/07/05 19:28:01 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2010/11/17 16:02:57 | 000,777,550 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010/09/23 18:55:05 | 000,007,602 | ---- | C] () -- C:\Users\owner\AppData\Local\Resmon.ResmonCfg
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/05/23 13:27:54 | 000,000,135 | ---- | M] () -- C:\11.txt
[2009/06/15 07:11:59 | 000,000,054 | ---- | M] () -- C:\AdobeReader.log
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2009/07/29 02:03:37 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/02/10 20:00:47 | 000,000,086 | ---- | M] () -- C:\creative.log
[2010/02/10 20:14:47 | 000,017,488 | ---- | M] () -- C:\devlist.txt
[2010/09/23 17:21:29 | 000,000,127 | ---- | M] () -- C:\dfinstall.log
[2011/08/25 21:31:02 | 000,000,024 | ---- | M] () -- C:\dx3_eyefinity.log
[2011/09/30 23:59:38 | 000,000,043 | ---- | M] () -- C:\END
[2010/02/10 20:14:46 | 000,000,009 | ---- | M] () -- C:\Finish.log
[2010/01/05 04:11:29 | 002,097,152 | -H-- | M] () -- C:\G73Jh.BIN
[2010/01/05 10:03:50 | 000,000,018 | ---- | M] () -- C:\G73JH_WIN7.10
[2012/05/24 21:02:40 | 477,532,159 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/10 20:02:12 | 000,458,892 | ---- | M] () -- C:\if.log
[2010/02/10 20:28:26 | 001,609,104 | ---- | M] () -- C:\inject.log.txt
[2011/09/06 20:30:20 | 000,000,070 | ---- | M] () -- C:\installer_log.txt
[2012/05/24 21:02:43 | 2068,369,407 | -HS- | M] () -- C:\pagefile.sys
[2010/02/10 04:49:40 | 000,000,105 | ---- | M] () -- C:\Pass.txt
[2010/01/07 23:49:43 | 000,000,339 | ---- | M] () -- C:\Patch_Win7.log
[2010/01/05 10:03:50 | 000,000,007 | ---- | M] () -- C:\RECOVERY.DAT
[2010/02/10 19:58:03 | 000,003,340 | ---- | M] () -- C:\RHDSetup.log
[2012/05/24 17:13:01 | 000,000,425 | ---- | M] () -- C:\rkill.log
[2011/08/21 12:18:16 | 000,000,083 | ---- | M] () -- C:\setup.log
[2011/10/28 17:42:59 | 000,177,122 | ---- | M] () -- C:\shared.log
[2010/02/10 20:09:04 | 000,000,170 | ---- | M] () -- C:\SumHidd.txt
[2010/02/10 20:08:26 | 000,000,098 | ---- | M] () -- C:\SumOS.txt
[2012/05/22 11:57:34 | 000,277,592 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_22.05.2012_11.44.26_log.txt
[2012/05/25 15:55:53 | 000,000,348 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_25.05.2012_15.55.50_log.txt
[2012/05/25 15:57:18 | 000,132,230 | ---- | M] () -- C:\TDSSKiller.2.7.37.0_25.05.2012_15.56.17_log.txt
[2009/09/16 14:04:46 | 000,000,024 | ---- | M] () -- C:\v82.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/12/05 02:55:20 | 000,307,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/09 20:15:28 | 000,000,221 | -HS- | M] () -- C:\Users\owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/05/24 09:56:43 | 009,989,040 | ---- | M] (OPSWAT, Inc.) -- C:\Users\owner\Desktop\AppRemover.exe
[2012/05/22 20:40:06 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\owner\Desktop\aswMBR.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\owner\Desktop\boot_cleaner.exe
[2012/05/24 09:52:04 | 004,502,264 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\ComboFix.exe
[2012/05/22 11:57:12 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\owner\Desktop\HijackThis.exe
[2012/05/22 12:14:55 | 000,302,592 | ---- | M] () -- C:\Users\owner\Desktop\idri9fe4.exe
[2012/05/25 18:06:32 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
[2012/05/23 08:16:44 | 002,126,936 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\owner\Desktop\TDSSKiller.exe
[2012/05/24 09:59:58 | 004,526,123 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\your_name.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/05/24 21:53:45 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/05/24 21:52:44 | 000,032,682 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
[2012/05/24 20:18:00 | 000,000,280 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{BE27CBCD-8037-4D3D-93A3-C853578A158A}.job
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/09/10 19:46:13 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/09/10 19:46:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/09/10 19:46:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/09/10 19:46:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/09/10 19:46:13 | 000,786,432 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
[2011/09/10 19:46:13 | 001,056,768 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/04/19 06:26:36 | 000,000,402 | -HS- | M] () -- C:\Users\owner\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/11/13 00:23:22 | 000,005,116 | ---- | M] () -- C:\ProgramData\hpzinstall.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 971 bytes -> C:\ProgramData:$SS_DESCRIPTOR_SBXNV9VVGV1BF1V4WG4H6PT4KGM8HTV4K6N636VFSVF7JB4VPJGF
< End of report >
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/05/25 18:06:31 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
[2012/05/24 20:58:35 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/05/24 10:09:23 | 000,000,000 | ---D | C] -- C:\ProgramData\GFI Software
[2012/05/24 09:59:58 | 004,526,123 | R--- | C] (Swearware) -- C:\Users\owner\Desktop\your_name.exe
[2012/05/24 09:56:29 | 009,989,040 | ---- | C] (OPSWAT, Inc.) -- C:\Users\owner\Desktop\AppRemover.exe
[2012/05/23 21:27:56 | 004,502,264 | R--- | C] (Swearware) -- C:\Users\owner\Desktop\ComboFix.exe
[2012/05/22 20:39:51 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\owner\Desktop\aswMBR.exe
[2012/05/22 20:26:56 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\owner\Desktop\boot_cleaner.exe
[2012/05/22 12:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/05/22 12:51:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/05/22 12:22:04 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\owner\Desktop\dds.scr
[2012/05/22 12:14:13 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Malwarebytes
[2012/05/22 11:57:10 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\owner\Desktop\HijackThis.exe
[2012/05/22 11:44:15 | 002,126,936 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\owner\Desktop\TDSSKiller.exe
[2012/05/22 11:27:55 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Local\adaware
[2012/05/22 11:27:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Browsing Protection
[2012/05/22 11:18:40 | 055,656,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MRT.exe
[2012/05/21 20:51:01 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Populus
[2012/05/21 20:51:01 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CF Toolbox
[2012/05/21 19:19:43 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/05/21 19:09:58 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\GlarySoft
[2012/05/20 18:16:01 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/05/19 19:50:43 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\Diablo III
[2012/05/19 19:50:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2012/05/19 19:47:16 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/05/19 19:47:13 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/19 19:47:13 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/05/19 19:47:12 | 001,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2012/05/19 19:47:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net
[2012/05/19 19:34:03 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Google
[2012/05/10 13:11:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012/05/10 13:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/05/09 19:54:12 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Local\Chromium
[2012/05/09 18:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2012/05/09 18:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios
[2012/05/09 18:40:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hi-Rez Studios
[2012/05/04 09:38:09 | 000,419,488 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2011/08/31 21:39:17 | 001,169,224 | ---- | C] (Microsoft Corporation) -- C:\Users\owner\AppData\Roaming\38H3R06LO0.exe
[2010/11/19 00:27:00 | 000,587,776 | ---- | C] (Igor Pavlov) -- C:\Users\owner\AppData\Roaming\7za.exe
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/25 18:06:32 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
[2012/05/25 18:05:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/05/24 21:59:52 | 000,783,334 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/24 21:59:52 | 000,663,434 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/05/24 21:59:52 | 000,122,270 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/05/24 21:10:40 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/24 21:10:40 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/24 21:02:40 | 477,532,159 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/24 20:18:00 | 000,000,280 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{BE27CBCD-8037-4D3D-93A3-C853578A158A}.job
[2012/05/24 16:08:35 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2012/05/24 10:00:35 | 001,012,656 | ---- | M] () -- C:\Users\owner\Desktop\rkill.com
[2012/05/24 09:59:58 | 004,526,123 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\your_name.exe
[2012/05/24 09:56:43 | 009,989,040 | ---- | M] (OPSWAT, Inc.) -- C:\Users\owner\Desktop\AppRemover.exe
[2012/05/24 09:52:04 | 004,502,264 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\ComboFix.exe
[2012/05/23 10:19:46 | 000,000,512 | ---- | M] () -- C:\Users\owner\Desktop\MBR.dat
[2012/05/23 08:16:44 | 002,126,936 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\owner\Desktop\TDSSKiller.exe
[2012/05/22 20:52:21 | 000,002,260 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[2012/05/22 20:52:14 | 000,001,520 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2012/05/22 20:51:24 | 999,983,021 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/05/22 20:40:06 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\owner\Desktop\aswMBR.exe
[2012/05/22 20:26:11 | 000,044,607 | ---- | M] () -- C:\Users\owner\Desktop\bootkit_remover.zip
[2012/05/22 12:22:06 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\dds.scr
[2012/05/22 12:14:55 | 000,302,592 | ---- | M] () -- C:\Users\owner\Desktop\idri9fe4.exe
[2012/05/22 11:57:12 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\owner\Desktop\HijackThis.exe
[2012/05/20 18:04:46 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/20 18:04:46 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/05/19 20:12:33 | 000,427,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/04 12:14:59 | 000,000,969 | ---- | M] () -- C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/04/26 20:08:16 | 055,656,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MRT.exe
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/24 20:18:00 | 000,000,280 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{BE27CBCD-8037-4D3D-93A3-C853578A158A}.job
[2012/05/24 10:00:34 | 001,012,656 | ---- | C] () -- C:\Users\owner\Desktop\rkill.com
[2012/05/22 20:51:24 | 999,983,021 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/05/22 20:49:46 | 000,000,512 | ---- | C] () -- C:\Users\owner\Desktop\MBR.dat
[2012/05/22 20:26:10 | 000,044,607 | ---- | C] () -- C:\Users\owner\Desktop\bootkit_remover.zip
[2012/05/22 12:14:53 | 000,302,592 | ---- | C] () -- C:\Users\owner\Desktop\idri9fe4.exe
[2012/04/02 22:37:59 | 000,033,792 | ---- | C] () -- C:\Windows\SysWow64\drivers\libusb0.sys
[2012/04/02 16:17:38 | 000,040,985 | ---- | C] () -- C:\Users\owner\AppData\Roaming\a.7z
[2011/10/26 23:15:39 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/26 23:15:38 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/26 22:55:00 | 002,580,552 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011/09/26 22:27:56 | 000,001,241 | ---- | C] () -- C:\Windows\hpomdl49.dat.temp
[2011/09/14 11:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/08/29 17:06:29 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/28 18:07:20 | 000,206,514 | ---- | C] () -- C:\Windows\hpoins49.dat
[2011/08/21 13:44:16 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
[2011/08/21 11:54:57 | 000,026,960 | ---- | C] () -- C:\Users\owner\AppData\Roaming\fed
[2011/07/05 19:28:01 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2010/11/17 16:02:57 | 000,777,550 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010/09/23 18:55:05 | 000,007,602 | ---- | C] () -- C:\Users\owner\AppData\Local\Resmon.ResmonCfg
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/05/23 13:27:54 | 000,000,135 | ---- | M] () -- C:\11.txt
[2009/06/15 07:11:59 | 000,000,054 | ---- | M] () -- C:\AdobeReader.log
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2009/07/29 02:03:37 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/02/10 20:00:47 | 000,000,086 | ---- | M] () -- C:\creative.log
[2010/02/10 20:14:47 | 000,017,488 | ---- | M] () -- C:\devlist.txt
[2010/09/23 17:21:29 | 000,000,127 | ---- | M] () -- C:\dfinstall.log
[2011/08/25 21:31:02 | 000,000,024 | ---- | M] () -- C:\dx3_eyefinity.log
[2011/09/30 23:59:38 | 000,000,043 | ---- | M] () -- C:\END
[2010/02/10 20:14:46 | 000,000,009 | ---- | M] () -- C:\Finish.log
[2010/01/05 04:11:29 | 002,097,152 | -H-- | M] () -- C:\G73Jh.BIN
[2010/01/05 10:03:50 | 000,000,018 | ---- | M] () -- C:\G73JH_WIN7.10
[2012/05/24 21:02:40 | 477,532,159 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/10 20:02:12 | 000,458,892 | ---- | M] () -- C:\if.log
[2010/02/10 20:28:26 | 001,609,104 | ---- | M] () -- C:\inject.log.txt
[2011/09/06 20:30:20 | 000,000,070 | ---- | M] () -- C:\installer_log.txt
[2012/05/24 21:02:43 | 2068,369,407 | -HS- | M] () -- C:\pagefile.sys
[2010/02/10 04:49:40 | 000,000,105 | ---- | M] () -- C:\Pass.txt
[2010/01/07 23:49:43 | 000,000,339 | ---- | M] () -- C:\Patch_Win7.log
[2010/01/05 10:03:50 | 000,000,007 | ---- | M] () -- C:\RECOVERY.DAT
[2010/02/10 19:58:03 | 000,003,340 | ---- | M] () -- C:\RHDSetup.log
[2012/05/24 17:13:01 | 000,000,425 | ---- | M] () -- C:\rkill.log
[2011/08/21 12:18:16 | 000,000,083 | ---- | M] () -- C:\setup.log
[2011/10/28 17:42:59 | 000,177,122 | ---- | M] () -- C:\shared.log
[2010/02/10 20:09:04 | 000,000,170 | ---- | M] () -- C:\SumHidd.txt
[2010/02/10 20:08:26 | 000,000,098 | ---- | M] () -- C:\SumOS.txt
[2012/05/22 11:57:34 | 000,277,592 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_22.05.2012_11.44.26_log.txt
[2012/05/25 15:55:53 | 000,000,348 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_25.05.2012_15.55.50_log.txt
[2012/05/25 15:57:18 | 000,132,230 | ---- | M] () -- C:\TDSSKiller.2.7.37.0_25.05.2012_15.56.17_log.txt
[2009/09/16 14:04:46 | 000,000,024 | ---- | M] () -- C:\v82.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/12/05 02:55:20 | 000,307,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/09 20:15:28 | 000,000,221 | -HS- | M] () -- C:\Users\owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/05/24 09:56:43 | 009,989,040 | ---- | M] (OPSWAT, Inc.) -- C:\Users\owner\Desktop\AppRemover.exe
[2012/05/22 20:40:06 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\owner\Desktop\aswMBR.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\owner\Desktop\boot_cleaner.exe
[2012/05/24 09:52:04 | 004,502,264 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\ComboFix.exe
[2012/05/22 11:57:12 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\owner\Desktop\HijackThis.exe
[2012/05/22 12:14:55 | 000,302,592 | ---- | M] () -- C:\Users\owner\Desktop\idri9fe4.exe
[2012/05/25 18:06:32 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
[2012/05/23 08:16:44 | 002,126,936 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\owner\Desktop\TDSSKiller.exe
[2012/05/24 09:59:58 | 004,526,123 | R--- | M] (Swearware) -- C:\Users\owner\Desktop\your_name.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/05/24 21:53:45 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/05/24 21:52:44 | 000,032,682 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
[2012/05/24 20:18:00 | 000,000,280 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{BE27CBCD-8037-4D3D-93A3-C853578A158A}.job
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/09/10 19:46:13 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/09/10 19:46:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/09/10 19:46:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/09/10 19:46:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/09/10 19:46:13 | 000,786,432 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
[2011/09/10 19:46:13 | 001,056,768 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/04/19 06:26:36 | 000,000,402 | -HS- | M] () -- C:\Users\owner\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/11/13 00:23:22 | 000,005,116 | ---- | M] () -- C:\ProgramData\hpzinstall.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 971 bytes -> C:\ProgramData:$SS_DESCRIPTOR_SBXNV9VVGV1BF1V4WG4H6PT4KGM8HTV4K6N636VFSVF7JB4VPJGF
< End of report >