========== Files/Folders - Created Within 30 Days ==========
[2012/06/27 00:46:36 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\Public\Desktop\OTL.exe
[2012/06/27 00:44:55 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/27 00:35:20 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/06/27 00:34:46 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Public\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/27 00:09:32 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/27 00:09:32 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\temp
[2012/06/26 23:57:52 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/26 23:57:52 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/26 23:57:52 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/26 23:48:19 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/26 23:48:04 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/06/26 23:45:20 | 004,569,121 | R--- | C] (Swearware) -- C:\Users\Public\Desktop\ComboFix.exe
[2012/06/26 23:14:15 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{A9D2D1DC-AA7D-4D1C-A28A-75792CE4E267}
[2012/06/26 23:14:03 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BE19CFCA-4465-444F-A35A-8D64C90CB3FC}
[2012/06/26 17:04:11 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Public\Desktop\dds.scr
[2012/06/26 16:33:09 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Roaming\Malwarebytes
[2012/06/26 16:33:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/26 11:59:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012/06/26 10:43:46 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{C4D6F55E-F4F7-40E3-BC7B-92B6D5FCB52F}
[2012/06/26 10:43:35 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{28D69BF8-0A52-4325-AD90-C236A965E0A2}
[2012/06/26 03:05:34 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/25 23:07:45 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{2BEA565A-45AD-4AAD-AC8E-F17D3C8C286B}
[2012/06/25 11:07:18 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{1E15E48E-6792-40E6-8213-D497D20B8166}
[2012/06/25 11:07:07 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7514C88C-9B34-48B8-A1F2-E517B7CC3AE6}
[2012/06/24 23:06:41 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5757C6B8-3532-4AB4-97DD-E0828B0910EF}
[2012/06/24 11:06:15 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B4162938-D7DF-4596-BDF9-8BF13B3C9A9F}
[2012/06/24 11:06:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{FAF37296-9157-4E2A-812A-5F203B6E84E8}
[2012/06/23 23:05:34 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{A1B6E7D3-6235-4846-A12B-1F43D498803C}
[2012/06/23 11:04:59 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{01207C5C-7344-49BB-8641-79C30D24BC99}
[2012/06/23 11:04:47 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3B223EED-CE3B-4852-AF82-08FA27CFF327}
[2012/06/22 22:57:50 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B2E3F918-315E-4879-BC5B-739FA63D36B8}
[2012/06/22 10:57:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{68499900-6038-4AC3-9E85-0446FDB7EE38}
[2012/06/22 10:57:14 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{EA367037-E514-4447-ADBF-A0E07D4DB999}
[2012/06/21 23:11:16 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012/06/21 10:56:55 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{29774224-5E2B-4D4D-9A41-EDEF23CCF170}
[2012/06/21 10:56:44 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3FA1AE99-A833-464F-87B8-FFC15D7568CF}
[2012/06/20 21:51:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{23A57A80-5F8E-4833-A5F5-2157E17D2C83}
[2012/06/20 09:50:36 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5EB02097-10B2-4812-8BD9-691FAFEE19F2}
[2012/06/20 09:50:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7D90CC2A-A404-485C-8156-6C397A11AE15}
[2012/06/19 12:27:33 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{AE615E9E-0114-40C5-9929-FD164B860985}
[2012/06/19 12:27:11 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{A27E2966-D641-4DC7-ACCD-6A38FC9723CC}
[2012/06/19 00:26:39 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{232E81B1-21A9-43CC-8529-C63571FEDC60}
[2012/06/18 12:26:11 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{55AFAAFC-2AA1-4152-AB9F-EC521B2D56D0}
[2012/06/17 12:25:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{CF3AED8B-6387-42A0-8BE1-815D71287A12}
[2012/06/16 12:24:56 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{42A1F61A-8CB8-4B95-9C42-C383C7B37476}
[2012/06/15 12:24:21 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{52D08118-63E4-4814-A462-A12FBCC9131F}
[2012/06/14 12:23:42 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5516CD33-F259-4B22-A169-C3E633FF857E}
[2012/06/14 12:23:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{438C34EC-B366-4A16-84B8-9737D8A05C62}
[2012/06/14 02:51:42 | 000,000,000 | ---D | C] -- E:\My Documents\セイバーフィッシュ
[2012/06/14 02:12:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\褐色少女 乳辱・恥辱に裂ける心
[2012/06/14 00:23:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{23B2A6F8-4D93-4588-A0D3-65A3C1F8B7E3}
[2012/06/13 12:22:38 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{844628A1-641C-412C-A5DF-7AF525FC34F2}
[2012/06/13 12:22:27 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{2B7167AF-3557-4B87-A619-F102272BB782}
[2012/06/13 00:22:02 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3DEF93F7-704B-4416-9AAB-74B01D5CC678}
[2012/06/12 12:21:35 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{30FBF2DC-B1B7-4450-B674-D5AD624A06B8}
[2012/06/12 12:21:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{E2082479-13DD-4E6C-BE1C-421AEDADFA6B}
[2012/06/12 12:21:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\AVG Secure Search
[2012/06/11 16:07:48 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{CECF9AAC-D106-4B9B-9929-6CB80360516D}
[2012/06/11 16:07:37 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5374AD78-5984-4CED-805E-7B13E61FEDDA}
[2012/06/11 00:50:53 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5D03C2F8-7DB7-461B-9834-481E8C9D8488}
[2012/06/10 12:50:28 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B87DB652-909A-4DE9-9108-78DB5B838644}
[2012/06/10 12:50:17 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{168BEEC7-A21F-4A3D-AFB0-0784926B88D9}
[2012/06/10 00:49:49 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{DB3D3B24-BC14-468B-AC7F-941D485B530B}
[2012/06/09 19:43:06 | 000,000,000 | ---D | C] -- E:\My Documents\My Games
[2012/06/09 19:42:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\イベントへいこう7
[2012/06/09 12:49:23 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7B71C9C6-58A2-4E57-B4AA-AF6CDC80E63D}
[2012/06/09 12:49:13 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7368AAF3-1551-4BF2-92AA-531EB6CC31E8}
[2012/06/09 00:48:46 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{E7AADB7E-ABDA-4573-94C5-57CE76FCFC03}
[2012/06/08 12:48:20 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{6AA53459-1755-4A73-B115-CD9261F2DF12}
[2012/06/08 12:48:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{55BDB168-3743-4C5A-95EB-5E8665C2A9F3}
[2012/06/08 00:47:45 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{680FA72D-05AE-4EF9-B917-CF5D157BAC55}
[2012/06/07 19:18:16 | 000,000,000 | ---D | C] -- C:\Users\Public\Desktop\Solution Manual - College Physics 7th Edition - Serway
[2012/06/07 12:46:55 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{E8BEEA8D-5E9E-4E66-A84B-86CF998118C6}
[2012/06/07 12:46:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7B6E633A-EF44-48F0-9A50-675370EA5415}
[2012/06/06 23:05:12 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{34D6D826-E094-4972-92B4-66BED691C696}
[2012/06/06 11:04:47 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{82772CE8-4360-44B6-9964-A3A8B3991178}
[2012/06/06 11:04:36 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B5B3E639-7B68-4844-9515-BCDD7115780E}
[2012/06/05 21:53:02 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{87954C51-914B-4547-AC01-E65D85789EB8}
[2012/06/05 21:52:51 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{0453B17B-ACAB-4D6A-BC42-CABFEF543FC2}
[2012/06/05 09:52:34 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{934D49A9-2E46-424C-9680-024E89F4825B}
[2012/06/05 09:52:22 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{D7567517-BDA0-42A8-9CCD-9C7ABDADDD8E}
[2012/06/04 18:51:33 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Roaming\YCanPDF
[2012/06/04 14:42:21 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{9D603707-857C-4308-93AA-03E8E88F59AA}
[2012/06/04 14:42:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5043AE95-9B93-46F6-BE5D-C76EAD9CC988}
[2012/06/03 18:07:03 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{1462E041-DB56-4111-B19C-C998DE97FCB3}
[2012/06/03 18:06:52 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{449E7849-5DD4-4181-98EF-3AEAB890A09C}
[2012/06/01 22:17:08 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B1A1FE1A-8EAF-4C51-9310-39741B2396EF}
[2012/06/01 10:16:42 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7453935B-040A-465A-8E9D-E64A6E2C4520}
[2012/06/01 10:16:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3E741CC7-1F2C-4809-93A0-ECF76870C0BE}
[2012/05/31 22:16:05 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{F5092756-8D9A-4AAC-8C86-693DA5ECF799}
[2012/05/31 10:15:40 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{CF2B90F6-A7DC-4517-BDBC-5E269DB07B2C}
[2012/05/31 10:15:29 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BE66D834-ECC6-4D2A-AA38-ACAFD4C935C1}
[2012/05/30 22:15:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{F53DF2F8-0CB1-46E3-9051-261F5073351F}
[2012/05/30 10:14:37 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{83149F39-4E01-4C1E-93F7-A39A5A31264C}
[2012/05/30 10:14:26 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{6429AB73-FC24-4A93-AA1A-833920CCE398}
[2012/05/29 21:46:52 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{F69A0680-6348-4F57-9DEE-DEE39AF272AB}
[2012/05/29 09:46:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5341A8D8-CBAA-4292-A7D6-727443EB7CAD}
[2012/05/29 09:46:14 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{8A871B0A-C699-4B05-9657-903CC7D72190}
[2012/05/28 21:32:58 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{70A55B94-ECA4-4810-A3AC-D55623494C9A}
[2012/05/28 09:32:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BC5E6D51-4C7D-40D5-8712-1A086685E277}
[2012/05/28 09:32:20 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BA00A6D4-7308-4421-9C04-FC84D758A237}
========== Files - Modified Within 30 Days ==========
[2012/06/27 00:51:38 | 000,026,576 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/27 00:51:38 | 000,026,576 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/27 00:46:36 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Public\Desktop\OTL.exe
[2012/06/27 00:45:04 | 000,000,476 | ---- | M] () -- C:\Windows\tasks\SDMsgUpdate (TE).job
[2012/06/27 00:44:49 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\FixCleaner Startup.job
[2012/06/27 00:44:46 | 000,000,540 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/27 00:43:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/27 00:34:58 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Public\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/27 00:17:00 | 000,000,544 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/27 00:14:00 | 000,000,560 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000UA.job
[2012/06/27 00:11:46 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/27 00:11:35 | 000,618,936 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/27 00:11:35 | 000,388,248 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
[2012/06/27 00:11:35 | 000,107,256 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
[2012/06/27 00:11:35 | 000,107,256 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/27 00:05:00 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/26 23:45:27 | 004,569,121 | R--- | M] (Swearware) -- C:\Users\Public\Desktop\ComboFix.exe
[2012/06/26 23:17:12 | 001,231,616 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/26 19:18:18 | 000,000,056 | ---- | M] () -- C:\Windows\kgt2k.INI
[2012/06/26 17:04:01 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Public\Desktop\dds.scr
[2012/06/26 11:30:05 | 001,242,390 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/25 15:14:00 | 000,000,508 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000Core.job
[2012/06/17 19:25:29 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2012/06/14 09:52:43 | 004,973,008 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/09 19:42:59 | 000,000,065 | ---- | M] () -- C:\Windows\.ini
========== Files Created - No Company Name ==========
[2012/06/26 23:57:52 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/26 23:57:52 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/26 23:57:52 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/26 23:57:52 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/26 23:57:52 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/26 16:37:22 | 000,302,592 | ---- | C] () -- C:\Users\Public\Desktop\gmer.exe
[2012/06/17 19:25:29 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2012/06/09 19:42:59 | 000,000,065 | ---- | C] () -- C:\Windows\.ini
[2012/05/21 22:27:37 | 000,000,125 | ---- | C] () -- C:\Windows\FlashDecompiler.INI
[2012/05/04 17:54:41 | 000,003,584 | ---- | C] () -- C:\Users\Jeffery\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/18 20:21:52 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cid_store.dat
[2011/10/07 20:43:20 | 000,000,056 | ---- | C] () -- C:\Windows\kgt2k.INI
[2011/08/13 02:53:10 | 000,000,000 | ---- | C] () -- C:\Users\Jeffery\AppData\Local\{E901E54F-7911-4C1E-A94F-38020C689740}
[2011/08/10 23:26:07 | 000,129,518 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat
[2011/07/24 01:47:42 | 000,019,652 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat
[2011/07/24 01:47:10 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2011/07/23 23:50:33 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/07/22 03:08:01 | 000,100,352 | ---- | C] () -- C:\Windows\SysWow64\zlib1.dll
[2011/07/22 03:07:58 | 000,394,752 | ---- | C] () -- C:\Windows\SysWow64\cygwinb19.dll
[2011/07/22 03:07:58 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\libpng13.dll
[2011/07/22 03:07:55 | 001,202,763 | ---- | C] () -- C:\Windows\unins002.exe
[2011/07/22 03:07:55 | 000,012,634 | ---- | C] () -- C:\Windows\unins002.dat
[2011/07/22 03:06:50 | 000,709,719 | ---- | C] () -- C:\Windows\unins001.exe
[2011/07/22 03:06:50 | 000,007,954 | ---- | C] () -- C:\Windows\unins001.dat
[2011/07/22 03:06:13 | 001,199,175 | ---- | C] () -- C:\Windows\unins000.exe
[2011/07/22 03:06:13 | 000,020,831 | ---- | C] () -- C:\Windows\unins000.dat
[2011/07/21 19:38:19 | 001,242,390 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/21 18:52:33 | 001,425,816 | ---- | C] () -- C:\Windows\SysWow64\OfficeTabFunction.dll
[2011/07/21 18:52:33 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ArmAccess.dll
[2011/07/03 22:48:42 | 000,147,456 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2011/06/20 07:10:44 | 003,164,160 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2011/06/17 09:26:10 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/06/17 09:17:28 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/05/05 01:59:10 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2011/05/05 01:43:40 | 000,081,920 | -H-- | C] () -- C:\Windows\SysWow64\v3shrtkgn.dll
[2011/04/11 19:09:18 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/01/04 17:28:18 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
========== LOP Check ==========
[2011/07/24 00:58:24 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Avant Downloader
[2012/02/03 18:03:00 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\BitComet
[2011/12/27 15:12:40 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\BITS
[2012/05/21 22:40:17 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\com.adobe.dmp.contentviewer
[2012/05/13 23:38:48 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\DAEMON Tools Lite
[2012/04/06 23:29:10 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Dropbox
[2011/07/21 22:19:51 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\ESET
[2012/05/19 11:00:38 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\FixCleaner
[2011/07/24 01:46:02 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\FlashGet
[2011/07/24 01:45:57 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\FlashGetBHO
[2012/05/27 14:54:15 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\IObit
[2011/07/21 19:52:36 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Maxthon3
[2012/05/03 01:51:46 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\MotioninJoy
[2011/05/05 14:39:41 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\R-TT
[2011/07/24 01:30:04 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Shark007
[2012/02/20 02:29:19 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\SlimBrowser
[2012/03/06 01:05:55 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\SmartDraw
[2012/06/23 00:13:14 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\TeraCopy
[2012/05/21 22:32:17 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\TuneUpMedia
[2011/05/05 01:43:28 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\URSoft
[2011/07/24 01:28:41 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Win7codecs
[2012/05/10 20:51:53 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Windows Live Writer
[2011/12/03 05:26:02 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\XnView
[2012/06/04 18:51:33 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\YCanPDF
[2012/05/25 10:59:16 | 000,000,304 | -H-- | M] () -- C:\Windows\Tasks\DefragExpress.job
[2012/06/27 00:44:49 | 000,000,406 | ---- | M] () -- C:\Windows\Tasks\FixCleaner Startup.job
[2012/05/13 10:52:30 | 000,032,688 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/06/27 00:45:04 | 000,000,476 | ---- | M] () -- C:\Windows\Tasks\SDMsgUpdate (TE).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/06/27 00:09:31 | 000,025,701 | ---- | M] () -- C:\ComboFix.txt
[2012/06/27 00:43:37 | 4284,719,103 | -HS- | M] () -- C:\pagefile.sys
[2012/05/04 15:15:18 | 000,000,050 | ---- | M] () -- C:\rsqVistadir.ini
[2012/05/11 12:24:55 | 000,000,050 | ---- | M] () -- C:\user.js
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
[2011/07/30 17:35:47 | 000,000,568 | ---- | M] () -- C:\Program Files (x86)\RejoinCommandLine.txt
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/05 03:46:39 | 000,000,221 | -HS- | M] () -- C:\Users\Jeffery\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/05/25 10:59:16 | 000,000,304 | -H-- | M] () -- C:\Windows\tasks\DefragExpress.job
[2012/06/27 00:44:49 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\FixCleaner Startup.job
[2012/06/27 00:44:46 | 000,000,540 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/27 00:17:00 | 000,000,544 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/25 15:14:00 | 000,000,508 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000Core.job
[2012/06/27 00:14:00 | 000,000,560 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000UA.job
[2012/06/27 00:43:48 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/05/13 10:52:30 | 000,032,688 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
[2012/06/27 00:45:04 | 000,000,476 | ---- | M] () -- C:\Windows\tasks\SDMsgUpdate (TE).job
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/07/21 14:59:33 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/07/21 14:59:33 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/07/21 14:59:33 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/05/05 00:32:58 | 000,000,402 | -HS- | M] () -- C:\Users\Jeffery\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"RebootRelaunchTimeoutEnabled" = 1
"RebootRelaunchTimeout" = 10
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >
[2012/06/27 00:46:36 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\Public\Desktop\OTL.exe
[2012/06/27 00:44:55 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/27 00:35:20 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/06/27 00:34:46 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Public\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/27 00:09:32 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/27 00:09:32 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\temp
[2012/06/26 23:57:52 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/26 23:57:52 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/26 23:57:52 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/26 23:48:19 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/26 23:48:04 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/06/26 23:45:20 | 004,569,121 | R--- | C] (Swearware) -- C:\Users\Public\Desktop\ComboFix.exe
[2012/06/26 23:14:15 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{A9D2D1DC-AA7D-4D1C-A28A-75792CE4E267}
[2012/06/26 23:14:03 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BE19CFCA-4465-444F-A35A-8D64C90CB3FC}
[2012/06/26 17:04:11 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Public\Desktop\dds.scr
[2012/06/26 16:33:09 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Roaming\Malwarebytes
[2012/06/26 16:33:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/26 11:59:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012/06/26 10:43:46 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{C4D6F55E-F4F7-40E3-BC7B-92B6D5FCB52F}
[2012/06/26 10:43:35 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{28D69BF8-0A52-4325-AD90-C236A965E0A2}
[2012/06/26 03:05:34 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/25 23:07:45 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{2BEA565A-45AD-4AAD-AC8E-F17D3C8C286B}
[2012/06/25 11:07:18 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{1E15E48E-6792-40E6-8213-D497D20B8166}
[2012/06/25 11:07:07 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7514C88C-9B34-48B8-A1F2-E517B7CC3AE6}
[2012/06/24 23:06:41 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5757C6B8-3532-4AB4-97DD-E0828B0910EF}
[2012/06/24 11:06:15 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B4162938-D7DF-4596-BDF9-8BF13B3C9A9F}
[2012/06/24 11:06:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{FAF37296-9157-4E2A-812A-5F203B6E84E8}
[2012/06/23 23:05:34 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{A1B6E7D3-6235-4846-A12B-1F43D498803C}
[2012/06/23 11:04:59 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{01207C5C-7344-49BB-8641-79C30D24BC99}
[2012/06/23 11:04:47 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3B223EED-CE3B-4852-AF82-08FA27CFF327}
[2012/06/22 22:57:50 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B2E3F918-315E-4879-BC5B-739FA63D36B8}
[2012/06/22 10:57:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{68499900-6038-4AC3-9E85-0446FDB7EE38}
[2012/06/22 10:57:14 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{EA367037-E514-4447-ADBF-A0E07D4DB999}
[2012/06/21 23:11:16 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012/06/21 10:56:55 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{29774224-5E2B-4D4D-9A41-EDEF23CCF170}
[2012/06/21 10:56:44 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3FA1AE99-A833-464F-87B8-FFC15D7568CF}
[2012/06/20 21:51:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{23A57A80-5F8E-4833-A5F5-2157E17D2C83}
[2012/06/20 09:50:36 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5EB02097-10B2-4812-8BD9-691FAFEE19F2}
[2012/06/20 09:50:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7D90CC2A-A404-485C-8156-6C397A11AE15}
[2012/06/19 12:27:33 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{AE615E9E-0114-40C5-9929-FD164B860985}
[2012/06/19 12:27:11 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{A27E2966-D641-4DC7-ACCD-6A38FC9723CC}
[2012/06/19 00:26:39 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{232E81B1-21A9-43CC-8529-C63571FEDC60}
[2012/06/18 12:26:11 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{55AFAAFC-2AA1-4152-AB9F-EC521B2D56D0}
[2012/06/17 12:25:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{CF3AED8B-6387-42A0-8BE1-815D71287A12}
[2012/06/16 12:24:56 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{42A1F61A-8CB8-4B95-9C42-C383C7B37476}
[2012/06/15 12:24:21 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{52D08118-63E4-4814-A462-A12FBCC9131F}
[2012/06/14 12:23:42 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5516CD33-F259-4B22-A169-C3E633FF857E}
[2012/06/14 12:23:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{438C34EC-B366-4A16-84B8-9737D8A05C62}
[2012/06/14 02:51:42 | 000,000,000 | ---D | C] -- E:\My Documents\セイバーフィッシュ
[2012/06/14 02:12:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\褐色少女 乳辱・恥辱に裂ける心
[2012/06/14 00:23:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{23B2A6F8-4D93-4588-A0D3-65A3C1F8B7E3}
[2012/06/13 12:22:38 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{844628A1-641C-412C-A5DF-7AF525FC34F2}
[2012/06/13 12:22:27 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{2B7167AF-3557-4B87-A619-F102272BB782}
[2012/06/13 00:22:02 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3DEF93F7-704B-4416-9AAB-74B01D5CC678}
[2012/06/12 12:21:35 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{30FBF2DC-B1B7-4450-B674-D5AD624A06B8}
[2012/06/12 12:21:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{E2082479-13DD-4E6C-BE1C-421AEDADFA6B}
[2012/06/12 12:21:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\AVG Secure Search
[2012/06/11 16:07:48 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{CECF9AAC-D106-4B9B-9929-6CB80360516D}
[2012/06/11 16:07:37 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5374AD78-5984-4CED-805E-7B13E61FEDDA}
[2012/06/11 00:50:53 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5D03C2F8-7DB7-461B-9834-481E8C9D8488}
[2012/06/10 12:50:28 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B87DB652-909A-4DE9-9108-78DB5B838644}
[2012/06/10 12:50:17 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{168BEEC7-A21F-4A3D-AFB0-0784926B88D9}
[2012/06/10 00:49:49 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{DB3D3B24-BC14-468B-AC7F-941D485B530B}
[2012/06/09 19:43:06 | 000,000,000 | ---D | C] -- E:\My Documents\My Games
[2012/06/09 19:42:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\イベントへいこう7
[2012/06/09 12:49:23 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7B71C9C6-58A2-4E57-B4AA-AF6CDC80E63D}
[2012/06/09 12:49:13 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7368AAF3-1551-4BF2-92AA-531EB6CC31E8}
[2012/06/09 00:48:46 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{E7AADB7E-ABDA-4573-94C5-57CE76FCFC03}
[2012/06/08 12:48:20 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{6AA53459-1755-4A73-B115-CD9261F2DF12}
[2012/06/08 12:48:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{55BDB168-3743-4C5A-95EB-5E8665C2A9F3}
[2012/06/08 00:47:45 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{680FA72D-05AE-4EF9-B917-CF5D157BAC55}
[2012/06/07 19:18:16 | 000,000,000 | ---D | C] -- C:\Users\Public\Desktop\Solution Manual - College Physics 7th Edition - Serway
[2012/06/07 12:46:55 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{E8BEEA8D-5E9E-4E66-A84B-86CF998118C6}
[2012/06/07 12:46:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7B6E633A-EF44-48F0-9A50-675370EA5415}
[2012/06/06 23:05:12 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{34D6D826-E094-4972-92B4-66BED691C696}
[2012/06/06 11:04:47 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{82772CE8-4360-44B6-9964-A3A8B3991178}
[2012/06/06 11:04:36 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B5B3E639-7B68-4844-9515-BCDD7115780E}
[2012/06/05 21:53:02 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{87954C51-914B-4547-AC01-E65D85789EB8}
[2012/06/05 21:52:51 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{0453B17B-ACAB-4D6A-BC42-CABFEF543FC2}
[2012/06/05 09:52:34 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{934D49A9-2E46-424C-9680-024E89F4825B}
[2012/06/05 09:52:22 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{D7567517-BDA0-42A8-9CCD-9C7ABDADDD8E}
[2012/06/04 18:51:33 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Roaming\YCanPDF
[2012/06/04 14:42:21 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{9D603707-857C-4308-93AA-03E8E88F59AA}
[2012/06/04 14:42:10 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5043AE95-9B93-46F6-BE5D-C76EAD9CC988}
[2012/06/03 18:07:03 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{1462E041-DB56-4111-B19C-C998DE97FCB3}
[2012/06/03 18:06:52 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{449E7849-5DD4-4181-98EF-3AEAB890A09C}
[2012/06/01 22:17:08 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{B1A1FE1A-8EAF-4C51-9310-39741B2396EF}
[2012/06/01 10:16:42 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{7453935B-040A-465A-8E9D-E64A6E2C4520}
[2012/06/01 10:16:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{3E741CC7-1F2C-4809-93A0-ECF76870C0BE}
[2012/05/31 22:16:05 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{F5092756-8D9A-4AAC-8C86-693DA5ECF799}
[2012/05/31 10:15:40 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{CF2B90F6-A7DC-4517-BDBC-5E269DB07B2C}
[2012/05/31 10:15:29 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BE66D834-ECC6-4D2A-AA38-ACAFD4C935C1}
[2012/05/30 22:15:04 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{F53DF2F8-0CB1-46E3-9051-261F5073351F}
[2012/05/30 10:14:37 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{83149F39-4E01-4C1E-93F7-A39A5A31264C}
[2012/05/30 10:14:26 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{6429AB73-FC24-4A93-AA1A-833920CCE398}
[2012/05/29 21:46:52 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{F69A0680-6348-4F57-9DEE-DEE39AF272AB}
[2012/05/29 09:46:25 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{5341A8D8-CBAA-4292-A7D6-727443EB7CAD}
[2012/05/29 09:46:14 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{8A871B0A-C699-4B05-9657-903CC7D72190}
[2012/05/28 21:32:58 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{70A55B94-ECA4-4810-A3AC-D55623494C9A}
[2012/05/28 09:32:31 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BC5E6D51-4C7D-40D5-8712-1A086685E277}
[2012/05/28 09:32:20 | 000,000,000 | ---D | C] -- C:\Users\Jeffery\AppData\Local\{BA00A6D4-7308-4421-9C04-FC84D758A237}
========== Files - Modified Within 30 Days ==========
[2012/06/27 00:51:38 | 000,026,576 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/27 00:51:38 | 000,026,576 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/27 00:46:36 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Public\Desktop\OTL.exe
[2012/06/27 00:45:04 | 000,000,476 | ---- | M] () -- C:\Windows\tasks\SDMsgUpdate (TE).job
[2012/06/27 00:44:49 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\FixCleaner Startup.job
[2012/06/27 00:44:46 | 000,000,540 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/27 00:43:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/27 00:34:58 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Public\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/27 00:17:00 | 000,000,544 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/27 00:14:00 | 000,000,560 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000UA.job
[2012/06/27 00:11:46 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/27 00:11:35 | 000,618,936 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/27 00:11:35 | 000,388,248 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
[2012/06/27 00:11:35 | 000,107,256 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
[2012/06/27 00:11:35 | 000,107,256 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/27 00:05:00 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/26 23:45:27 | 004,569,121 | R--- | M] (Swearware) -- C:\Users\Public\Desktop\ComboFix.exe
[2012/06/26 23:17:12 | 001,231,616 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/26 19:18:18 | 000,000,056 | ---- | M] () -- C:\Windows\kgt2k.INI
[2012/06/26 17:04:01 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Public\Desktop\dds.scr
[2012/06/26 11:30:05 | 001,242,390 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/25 15:14:00 | 000,000,508 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000Core.job
[2012/06/17 19:25:29 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2012/06/14 09:52:43 | 004,973,008 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/09 19:42:59 | 000,000,065 | ---- | M] () -- C:\Windows\.ini
========== Files Created - No Company Name ==========
[2012/06/26 23:57:52 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/26 23:57:52 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/26 23:57:52 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/26 23:57:52 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/26 23:57:52 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/26 16:37:22 | 000,302,592 | ---- | C] () -- C:\Users\Public\Desktop\gmer.exe
[2012/06/17 19:25:29 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2012/06/09 19:42:59 | 000,000,065 | ---- | C] () -- C:\Windows\.ini
[2012/05/21 22:27:37 | 000,000,125 | ---- | C] () -- C:\Windows\FlashDecompiler.INI
[2012/05/04 17:54:41 | 000,003,584 | ---- | C] () -- C:\Users\Jeffery\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/18 20:21:52 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cid_store.dat
[2011/10/07 20:43:20 | 000,000,056 | ---- | C] () -- C:\Windows\kgt2k.INI
[2011/08/13 02:53:10 | 000,000,000 | ---- | C] () -- C:\Users\Jeffery\AppData\Local\{E901E54F-7911-4C1E-A94F-38020C689740}
[2011/08/10 23:26:07 | 000,129,518 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat
[2011/07/24 01:47:42 | 000,019,652 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat
[2011/07/24 01:47:10 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2011/07/23 23:50:33 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/07/22 03:08:01 | 000,100,352 | ---- | C] () -- C:\Windows\SysWow64\zlib1.dll
[2011/07/22 03:07:58 | 000,394,752 | ---- | C] () -- C:\Windows\SysWow64\cygwinb19.dll
[2011/07/22 03:07:58 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\libpng13.dll
[2011/07/22 03:07:55 | 001,202,763 | ---- | C] () -- C:\Windows\unins002.exe
[2011/07/22 03:07:55 | 000,012,634 | ---- | C] () -- C:\Windows\unins002.dat
[2011/07/22 03:06:50 | 000,709,719 | ---- | C] () -- C:\Windows\unins001.exe
[2011/07/22 03:06:50 | 000,007,954 | ---- | C] () -- C:\Windows\unins001.dat
[2011/07/22 03:06:13 | 001,199,175 | ---- | C] () -- C:\Windows\unins000.exe
[2011/07/22 03:06:13 | 000,020,831 | ---- | C] () -- C:\Windows\unins000.dat
[2011/07/21 19:38:19 | 001,242,390 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/21 18:52:33 | 001,425,816 | ---- | C] () -- C:\Windows\SysWow64\OfficeTabFunction.dll
[2011/07/21 18:52:33 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ArmAccess.dll
[2011/07/03 22:48:42 | 000,147,456 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2011/06/20 07:10:44 | 003,164,160 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2011/06/17 09:26:10 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/06/17 09:17:28 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/05/05 01:59:10 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2011/05/05 01:43:40 | 000,081,920 | -H-- | C] () -- C:\Windows\SysWow64\v3shrtkgn.dll
[2011/04/11 19:09:18 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/01/04 17:28:18 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
========== LOP Check ==========
[2011/07/24 00:58:24 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Avant Downloader
[2012/02/03 18:03:00 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\BitComet
[2011/12/27 15:12:40 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\BITS
[2012/05/21 22:40:17 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\com.adobe.dmp.contentviewer
[2012/05/13 23:38:48 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\DAEMON Tools Lite
[2012/04/06 23:29:10 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Dropbox
[2011/07/21 22:19:51 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\ESET
[2012/05/19 11:00:38 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\FixCleaner
[2011/07/24 01:46:02 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\FlashGet
[2011/07/24 01:45:57 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\FlashGetBHO
[2012/05/27 14:54:15 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\IObit
[2011/07/21 19:52:36 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Maxthon3
[2012/05/03 01:51:46 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\MotioninJoy
[2011/05/05 14:39:41 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\R-TT
[2011/07/24 01:30:04 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Shark007
[2012/02/20 02:29:19 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\SlimBrowser
[2012/03/06 01:05:55 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\SmartDraw
[2012/06/23 00:13:14 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\TeraCopy
[2012/05/21 22:32:17 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\TuneUpMedia
[2011/05/05 01:43:28 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\URSoft
[2011/07/24 01:28:41 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Win7codecs
[2012/05/10 20:51:53 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\Windows Live Writer
[2011/12/03 05:26:02 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\XnView
[2012/06/04 18:51:33 | 000,000,000 | ---D | M] -- C:\Users\Jeffery\AppData\Roaming\YCanPDF
[2012/05/25 10:59:16 | 000,000,304 | -H-- | M] () -- C:\Windows\Tasks\DefragExpress.job
[2012/06/27 00:44:49 | 000,000,406 | ---- | M] () -- C:\Windows\Tasks\FixCleaner Startup.job
[2012/05/13 10:52:30 | 000,032,688 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/06/27 00:45:04 | 000,000,476 | ---- | M] () -- C:\Windows\Tasks\SDMsgUpdate (TE).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/06/27 00:09:31 | 000,025,701 | ---- | M] () -- C:\ComboFix.txt
[2012/06/27 00:43:37 | 4284,719,103 | -HS- | M] () -- C:\pagefile.sys
[2012/05/04 15:15:18 | 000,000,050 | ---- | M] () -- C:\rsqVistadir.ini
[2012/05/11 12:24:55 | 000,000,050 | ---- | M] () -- C:\user.js
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
[2011/07/30 17:35:47 | 000,000,568 | ---- | M] () -- C:\Program Files (x86)\RejoinCommandLine.txt
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/05 03:46:39 | 000,000,221 | -HS- | M] () -- C:\Users\Jeffery\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/05/25 10:59:16 | 000,000,304 | -H-- | M] () -- C:\Windows\tasks\DefragExpress.job
[2012/06/27 00:44:49 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\FixCleaner Startup.job
[2012/06/27 00:44:46 | 000,000,540 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/27 00:17:00 | 000,000,544 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/25 15:14:00 | 000,000,508 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000Core.job
[2012/06/27 00:14:00 | 000,000,560 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-351645184-3812066956-3475953073-1000UA.job
[2012/06/27 00:43:48 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/05/13 10:52:30 | 000,032,688 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
[2012/06/27 00:45:04 | 000,000,476 | ---- | M] () -- C:\Windows\tasks\SDMsgUpdate (TE).job
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/07/21 14:59:33 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/07/21 14:59:33 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/07/21 14:59:33 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/05/05 00:32:58 | 000,000,402 | -HS- | M] () -- C:\Users\Jeffery\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"RebootRelaunchTimeoutEnabled" = 1
"RebootRelaunchTimeout" = 10
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >