OTL.txt Part 2:
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/11 13:02:43 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/11 12:49:13 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/11 12:49:13 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\temp
[2012/06/11 12:20:45 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/11 12:20:45 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/11 12:20:45 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/11 12:11:50 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/06/11 07:40:02 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{E9C9F6DD-B2FB-46CC-8B8E-12758F87DCDA}
[2012/06/11 07:39:33 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{6602F7BA-3A23-43B8-9828-7759D4EA44E0}
[2012/06/10 09:08:09 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{873177E0-EE72-4794-94EF-F86D586FE446}
[2012/06/10 09:07:40 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{C9F2B28F-0E3C-4EF9-80EF-D18D79A5F3BC}
[2012/06/09 19:47:41 | 000,000,000 | ---D | C] -- C:\Users\scawi03\Desktop\Payback
[2012/06/09 18:52:15 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{5A121C77-FF9D-4DF6-B350-F8F6933C175E}
[2012/06/09 17:06:32 | 000,000,000 | ---D | C] -- C:\Users\scawi03\Desktop\bootkit_remover
[2012/06/09 16:53:21 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{DC1B05F2-D0F9-41B6-9CF8-8BB1456CE939}
[2012/06/09 08:05:35 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{359FA905-4B1C-44D5-A779-B99F99639808}
[2012/06/09 08:05:06 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{A37026EC-B337-48F5-BC42-58F30777E0E2}
[2012/06/08 11:12:22 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{9565FD2F-1E3C-42FA-914F-F84DF3E98CDD}
[2012/06/08 11:11:52 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{54DC08A7-6776-4DBC-B64E-B6CC12669513}
[2012/06/08 11:00:33 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/06/08 10:42:52 | 000,000,000 | ---D | C] -- C:\Users\scawi03\Desktop\Malware
[2012/06/08 07:04:07 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{C3D4F00F-FEE9-4112-99E2-8D889150663D}
[2012/06/08 07:03:38 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{831C086F-5F5C-436B-A9CA-258B5CAAF9BC}
[2012/06/07 21:39:48 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{45F8E6C0-2236-4DCA-8275-8C7602659223}
[2012/06/07 12:13:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/07 12:13:50 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/06/07 12:13:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/06/07 08:52:58 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{39F5377A-69C4-4253-A37E-2CCFF6AF6499}
[2012/06/07 08:52:29 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{5A24C51C-8F99-4B38-8A18-E891F7B9B436}
[2012/06/06 09:32:20 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{061809A9-8139-43A6-8BCD-8AEF1BA7A361}
[2012/06/06 09:31:52 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{EBE7C887-C725-44C4-A623-78AD333A903C}
[2012/06/06 08:53:26 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{959AA318-1153-45D6-BE3B-11B9D1992E12}
[2012/06/05 07:26:25 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{520AB355-4D8D-4F94-AAA8-F976AE447236}
[2012/06/05 07:25:56 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{F4363911-8163-4754-8C57-30B7FD93D500}
[2012/06/04 20:38:36 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{01095BE3-26B2-4FD4-A486-F432174715C6}
[2012/06/04 20:25:49 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/04 16:42:16 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Roaming\Malwarebytes
[2012/06/04 16:42:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/04 08:31:23 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{09BAFCCD-321F-406B-BC73-D8CAFEE1A6AB}
[2012/06/04 08:30:55 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{68A96DF0-B160-4E61-B78F-DDD68ED8C517}
[2012/06/04 07:29:53 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{6847EC8A-41AB-41F5-BB53-9D734EC551F1}
[2012/06/03 09:54:28 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{C1B359E9-5682-444F-8C00-918982283719}
[2012/06/03 09:54:00 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{A6ADBE24-01D4-45C3-B26C-DCEB4F5DFA5D}
[2012/06/03 08:12:55 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{1F8458C0-F445-4F8C-B0CC-5CF25EE3B3A9}
[2012/06/02 19:22:55 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{78B53D62-EDF3-4246-9BB3-E48F1005EBB7}
[2012/06/02 19:22:26 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{F964B9BC-BD2C-47DA-8FAC-D9F2FEC8F2CB}
[2012/06/02 11:15:11 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{AC5BF3C4-BD10-4E69-B185-F28D7F3549A1}
[2012/06/02 06:44:57 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{8BED3E31-26E7-4E71-A20E-676133C9863C}
[2012/06/02 06:44:12 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{CDA3E864-B6E3-4E50-BC57-48914DF44707}
[2012/06/01 10:19:14 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/06/01 10:08:09 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{909ED6E9-ABFB-11E1-8270-B8AC6F996F26}
[2012/06/01 10:08:09 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{909E9D64-ABFB-11E1-8270-B8AC6F996F26}
[2012/06/01 07:15:06 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{93C29078-FD81-422A-8B55-D21B43287FC8}
[2012/06/01 07:14:38 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{FBADD4E7-7A04-4E3F-927A-BEE635BADE1C}
[2012/05/31 07:20:46 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{2A96B3D0-7637-472D-9B6F-03ECF7E678B6}
[2012/05/31 07:20:17 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{058ACFA7-4BCA-4EE6-B117-114EC4288F96}
[2012/05/30 10:34:27 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{306D520F-DC93-43E3-9A26-B38FBD093461}
[2012/05/30 10:33:58 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{021A96FE-9B53-414B-9B05-3A1AB4C092C0}
[2012/05/30 08:09:34 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{28D65F1F-7710-4A2C-A5A6-0EA69B52FD10}
[2012/05/30 08:09:04 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{1EB4B2B9-971E-4632-A21E-321462A6142E}
[2012/05/29 09:08:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glomark-Governan
[2012/05/29 09:08:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DAODLL
[2012/05/29 07:43:26 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{86156F4C-5CD9-4435-B75A-C939A356229A}
[2012/05/29 07:42:57 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{97363206-4DDD-4A00-B643-81CD71ED52FD}
[2012/05/28 09:08:22 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{4F3C4473-B9E5-40A7-B9B3-9C3465235003}
[2012/05/28 09:07:53 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{EF75F89B-6039-46A6-9D3B-D5B3775DF851}
[2012/05/27 08:22:08 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{74583D06-878B-48D6-9173-471DB117C36B}
[2012/05/27 08:21:39 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{078502E1-45EA-4683-976A-10562DBB2BE5}
[2012/05/26 20:53:56 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{044A8920-78A6-48F2-880B-1254892CF201}
[2012/05/26 08:00:51 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{DD4F496E-A26D-44EC-A7AC-698A9DE0F36B}
[2012/05/26 08:00:22 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{0FD3D43A-67F7-4BDF-9455-96AAC199167F}
[2012/05/25 14:22:29 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{960A2629-2EA5-45A5-AC2B-0C8D855F7FB1}
[2012/05/25 14:22:00 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{0CD2E786-E3BC-4E1D-8B11-E9E86EC65380}
[2012/05/25 06:41:58 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{B08DF0C7-2E93-4F72-958C-807FED9025ED}
[2012/05/25 06:41:29 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{08475346-084D-42E3-A029-F71E4C72C782}
[2012/05/24 14:57:37 | 000,000,000 | ---D | C] -- C:\Windows\Offline Address Books
[2012/05/24 10:07:03 | 000,000,000 | ---D | C] -- C:\Users\scawi03\Desktop\Surveys
[2012/05/24 08:30:53 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{8BAA13E8-A8A8-450A-882B-F2568F797E39}
[2012/05/24 08:30:25 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{BBC5CAB9-1930-4D55-BEDA-1939856CCB5C}
[2012/05/24 07:18:39 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{AD97FD21-B846-4C0B-94A7-EB851933CAB5}
[2012/05/24 07:18:10 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{E0795A8B-0237-434F-8D0D-C1427436690A}
[2012/05/23 12:22:46 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{023AA2C2-0F42-487F-8D4B-0F3EF6710813}
[2012/05/23 12:22:17 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{51E58A89-18DE-4221-ADB1-4196BF51C10E}
[2012/05/23 09:03:43 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{0E205A41-A2E5-435D-8B7A-E42B184802A6}
[2012/05/23 07:31:02 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{B828F135-B4E7-462D-8954-DEC8AB9BDC63}
[2012/05/23 07:30:33 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{9A64D25A-5674-4B14-9ED5-935D03A2FD5B}
[2012/05/22 20:24:40 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{F3C06F46-7E24-474C-BCFE-BF783465A29C}
[2012/05/22 15:30:15 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{21DF5155-474D-4034-8AC7-0412D68325E9}
[2012/05/22 14:56:01 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{053D4326-B505-4CBE-A874-F74653757995}
[2012/05/22 14:12:45 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{C328A7E1-2307-4E71-A3DA-246B65F74556}
[2012/05/22 14:12:16 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{D58AACA1-DABD-4559-B5C2-3AD17C8F7864}
[2012/05/22 08:07:48 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{0E83A7AA-E28B-4E3F-9037-4C3F69BE604A}
[2012/05/21 20:59:49 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{A41C29D1-E042-4910-9CB9-6D6ECF53F47A}
[2012/05/21 07:35:24 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{907FF929-3AEA-4DDF-81E0-53CA76769FE2}
[2012/05/21 07:34:55 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{7714D82A-88E8-4672-BF19-0656710B430D}
[2012/05/20 17:41:43 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{79149EC1-6AA4-4E83-9BB4-BECF9E26AB11}
[2012/05/20 17:41:13 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{D35C490A-9E26-42A7-9A0F-7307BB7EEC79}
[2012/05/19 11:56:58 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{BE908F2C-6EED-4143-BABA-22DE4B05F90C}
[2012/05/19 11:56:29 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{34B3C130-00B1-4F76-89DB-6606F2C3D69B}
[2012/05/18 13:04:00 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{6C88AB9D-370C-43A3-8CD6-ACC55955C929}
[2012/05/18 13:03:32 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{E522E8C5-01E1-4AD8-96C4-E43974ECEDD1}
[2012/05/18 11:10:00 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\HPVirtualRooms
[2012/05/18 11:08:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hewlett-Packard
[2012/05/17 13:53:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/05/17 13:53:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/05/17 11:54:35 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{3E4F1BC1-3BEA-4CCC-ADD8-A6CBCFE70FFA}
[2012/05/17 11:54:07 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{6C23757C-0921-444F-BD2B-0E96EAE38396}
[2012/05/16 20:40:19 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{CAF79B69-E3B6-45E9-A2BC-128019096386}
[2012/05/16 20:39:50 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{6DF43704-4686-4B95-BF48-07D408E3C964}
[2012/05/16 08:32:55 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{916A6FC6-4FAB-4EB8-843D-B518BBDCAA76}
[2012/05/16 08:32:27 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{AF5AFE12-C04E-4DE2-BA9D-9BB7DD12B6B3}
[2012/05/16 07:36:54 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{6C2C1C1B-563A-4F08-A403-9A5C08566504}
[2012/05/16 07:36:25 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{2A368020-1112-4A6A-810A-0B64BF7442D6}
[2012/05/15 08:38:32 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{0691FB5F-6583-47DE-A7AE-2BF50DB456CB}
[2012/05/15 08:38:04 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{618DDD61-BDEB-42A4-9B85-198FFD0AFA99}
[2012/05/15 07:35:28 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{EC825408-C0BD-4BAC-836A-788DACC016C1}
[2012/05/14 10:41:40 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{30DE9678-2326-4FA6-AC0A-0A819A8E9A0C}
[2012/05/14 10:41:12 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{FC739C77-442D-4011-B66F-45E51DBEFE47}
[2012/05/14 09:50:20 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{DA69C7D1-CF6D-48FF-871D-6CABA3F21E1A}
[2012/05/13 21:15:47 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{423C8E5B-BDEF-4111-9E28-8B9E8912EE09}
[2012/05/13 21:15:18 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{D6405202-6C82-431C-ABE9-0BC465A0355E}
[2012/05/13 07:41:42 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{AA8C58B0-116D-4DF7-88B7-5247D09D5DE4}
[2012/05/13 07:41:13 | 000,000,000 | ---D | C] -- C:\Users\scawi03\AppData\Local\{7EF8B65D-78AC-40FC-B0E7-C8665C52BF6E}
========== Files - Modified Within 30 Days ==========
[2012/06/11 12:57:58 | 000,012,272 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/11 12:57:58 | 000,012,272 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/11 12:52:00 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2129867641-919698055-327642922-376640UA.job
[2012/06/11 12:44:01 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/11 12:43:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/11 12:43:25 | 3060,535,296 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/11 12:35:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/11 11:52:00 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2129867641-919698055-327642922-376640Core.job
[2012/06/11 11:11:02 | 000,060,808 | ---- | M] () -- C:\Users\scawi03\Desktop\Pizza Hut.jpg
[2012/06/10 17:01:32 | 000,000,454 | ---- | M] () -- C:\Windows\tasks\SyncBack Projects.job
[2012/06/10 17:00:58 | 000,000,454 | ---- | M] () -- C:\Windows\tasks\SyncBack Personal.job
[2012/06/07 12:35:38 | 000,000,691 | ---- | M] () -- C:\Users\scawi03\AppData\Roaming\GetValue.vbs
[2012/06/07 12:35:38 | 000,000,035 | ---- | M] () -- C:\Users\scawi03\AppData\Roaming\SetValue.bat
[2012/06/07 07:44:52 | 000,420,184 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/06 12:59:20 | 003,110,730 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/06 12:59:20 | 000,706,178 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2012/06/06 12:59:20 | 000,627,756 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/06 12:59:20 | 000,411,484 | ---- | M] () -- C:\Windows\SysNative\perfh012.dat
[2012/06/06 12:59:20 | 000,400,266 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
[2012/06/06 12:59:20 | 000,373,516 | ---- | M] () -- C:\Windows\SysNative\prfh0804.dat
[2012/06/06 12:59:20 | 000,131,792 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2012/06/06 12:59:20 | 000,108,040 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
[2012/06/06 12:59:20 | 000,108,040 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/06 12:59:20 | 000,106,328 | ---- | M] () -- C:\Windows\SysNative\perfc012.dat
[2012/06/06 12:59:20 | 000,105,900 | ---- | M] () -- C:\Windows\SysNative\prfc0804.dat
[2012/06/06 12:24:21 | 503,569,867 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/06/04 20:04:35 | 001,012,656 | ---- | M] () -- C:\rkill.com
[2012/05/29 09:08:08 | 000,002,097 | ---- | M] () -- C:\Users\Public\Desktop\GeniusPro8.0.6.lnk
[2012/05/19 18:18:30 | 000,007,619 | ---- | M] () -- C:\Users\scawi03\AppData\Local\Resmon.ResmonCfg
========== Files Created - No Company Name ==========
[2012/06/11 12:20:45 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/11 12:20:45 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/11 12:20:45 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/11 12:20:45 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/11 12:20:45 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/11 11:11:21 | 000,060,808 | ---- | C] () -- C:\Users\scawi03\Desktop\Pizza Hut.jpg
[2012/06/07 12:35:38 | 000,000,691 | ---- | C] () -- C:\Users\scawi03\AppData\Roaming\GetValue.vbs
[2012/06/07 12:35:38 | 000,000,035 | ---- | C] () -- C:\Users\scawi03\AppData\Roaming\SetValue.bat
[2012/06/04 20:04:31 | 001,012,656 | ---- | C] () -- C:\rkill.com
[2012/05/29 09:08:08 | 000,002,097 | ---- | C] () -- C:\Users\Public\Desktop\GeniusPro8.0.6.lnk
[2012/02/27 21:43:25 | 000,007,619 | ---- | C] () -- C:\Users\scawi03\AppData\Local\Resmon.ResmonCfg
[2012/02/27 20:40:39 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2012/02/27 20:40:32 | 000,316,928 | ---- | C] () -- C:\Windows\SysWow64\hpcc3118.dll
[2012/02/23 16:39:01 | 000,002,048 | -HS- | C] () -- C:\Users\scawi03\AppData\Local\{f8086325-62b9-a61f-c556-08526f707c54}\@
[2012/02/23 16:21:37 | 003,103,496 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/23 16:17:34 | 000,190,976 | ---- | C] () -- C:\Windows\SysWow64\Tngremov.exe
[2012/02/23 16:15:05 | 000,047,104 | ---- | C] () -- C:\Windows\KX16.DLL
[2011/05/03 14:45:52 | 000,035,412 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/05/03 14:10:41 | 000,000,783 | ---- | C] () -- C:\Windows\{1B80FEE7-70AB-466B-8124-12570278E98D}_WiseFW.ini
[2011/05/03 13:44:42 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini
[2010/11/29 05:21:32 | 000,128,204 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010/11/29 05:21:30 | 000,867,020 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010/11/29 05:21:30 | 000,105,408 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
========== LOP Check ==========
[2011/05/03 14:17:04 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Jolly Giant Software
[2011/05/03 14:17:04 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Jolly Giant Software
[2011/05/03 14:17:04 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Jolly Giant Software
[2012/02/23 16:27:16 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\CA
[2012/02/23 16:15:04 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Citrix
[2012/03/09 10:49:24 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Garmin
[2011/05/03 14:17:04 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Jolly Giant Software
[2012/03/01 17:28:01 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Juniper Networks
[2012/06/08 14:28:05 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Webex
[2012/02/28 16:08:59 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Windows Live Writer
[2012/03/17 08:48:20 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Wondershare Video Converter Platinum
[2012/03/13 15:14:09 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\Xcelsius
[2012/03/13 15:10:42 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\XcelsiuscustomThemes
[2012/03/13 15:10:42 | 000,000,000 | ---D | M] -- C:\Users\scawi03\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2009/07/14 00:08:49 | 000,032,298 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/06/10 17:00:58 | 000,000,454 | ---- | M] () -- C:\Windows\Tasks\SyncBack Personal.job
[2012/06/10 17:01:32 | 000,000,454 | ---- | M] () -- C:\Windows\Tasks\SyncBack Projects.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/07/14 10:47:13 | 000,006,148 | -H-- | M] () -- C:\.DS_Store
[2012/06/11 08:02:58 | 000,000,668 | ---- | M] () -- C:\blitzblank.log
[2009/10/27 11:50:14 | 000,000,092 | ---- | M] () -- C:\ca.ckey
[2011/08/08 19:06:08 | 000,006,835 | ---- | M] () -- C:\ChangeLog.txt
[2012/02/23 16:28:22 | 001,502,770 | ---- | M] () -- C:\cms_am.txt
[2012/02/23 16:26:28 | 001,217,684 | ---- | M] () -- C:\cms_bhw.txt
[2012/02/23 16:34:54 | 001,985,690 | ---- | M] () -- C:\cms_rc.txt
[2012/02/23 16:30:23 | 002,158,054 | ---- | M] () -- C:\cms_sd.txt
[2012/02/23 16:24:40 | 000,227,864 | ---- | M] () -- C:\cms_SSA.txt
[2012/06/11 12:48:49 | 000,024,709 | ---- | M] () -- C:\ComboFix.txt
[2012/06/11 12:43:25 | 3060,535,296 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/23 16:23:11 | 000,002,782 | ---- | M] () -- C:\itcmservers.yaml
[2012/02/23 16:34:56 | 000,003,829 | ---- | M] () -- C:\logon1.log
[2006/12/01 22:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2012/06/11 12:43:31 | 4080,713,728 | -HS- | M] () -- C:\pagefile.sys
[2012/06/07 12:37:29 | 000,002,711 | ---- | M] () -- C:\rapport.txt
[2012/06/04 20:04:35 | 001,012,656 | ---- | M] () -- C:\rkill.com
[2012/06/04 20:27:54 | 000,000,359 | ---- | M] () -- C:\rkill.log
[2012/03/26 10:06:42 | 000,000,002 | ---- | M] () -- C:\S.LOG
[2012/06/08 08:28:33 | 000,138,108 | ---- | M] () -- C:\TDSSKiller.2.7.36.0_08.06.2012_08.27.55_log.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
[2012/02/23 16:27:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CA\DSM\Agent\units\00000001\BAK
[2012/05/29 17:26:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CA\DSM\Agent\units\00000001\uam\BAK
[2012/05/10 08:38:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CA\DSM\Agent\units\00000003\uam\BAK
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/07 13:41:08 | 000,000,221 | -HS- | M] () -- C:\Users\scawi03\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/06/11 12:35:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/11 11:52:00 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2129867641-919698055-327642922-376640Core.job
[2012/06/11 12:52:00 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2129867641-919698055-327642922-376640UA.job
[2012/06/11 12:43:38 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/07/14 00:08:49 | 000,032,298 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
[2012/06/10 17:00:58 | 000,000,454 | ---- | M] () -- C:\Windows\tasks\SyncBack Personal.job
[2012/06/10 17:01:32 | 000,000,454 | ---- | M] () -- C:\Windows\tasks\SyncBack Projects.job
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2012/05/29 17:17:59 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2012/05/29 17:17:59 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/05/10 15:16:48 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/05/10 15:16:48 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/04/20 15:01:04 | 000,000,402 | -HS- | M] () -- C:\Users\scawi03\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/02/23 15:41:32 | 000,035,412 | RHS- | M] () -- C:\ProgramData\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 512 bytes -> C:\Windows\SysWow64\Tngremov.exe:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\SysWow64\Tngremo_.exe:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KX95.DLL:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KX32.DLL:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KX16.DLL:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KixFlag.gis:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KIX32.EXE:CA_INOCULATEIT
< End of report >