========== Files/Folders - Created Within 30 Days ==========
[2012-05-24 01:15:28 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\{0FD03D79-2EDF-4448-922D-8BF3555759B4}
[2012-05-24 01:15:15 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\{F7A3BA70-9467-44D2-8FBE-A14E69FC9950}
[2012-05-24 00:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
[2012-05-24 00:29:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimCleaner
[2012-05-24 00:29:49 | 000,000,000 | ---D | C] -- C:\Program Files\SlimCleaner
[2012-05-24 00:29:46 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\AVG Secure Search
[2012-05-24 00:29:33 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2012-05-24 00:29:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2012-05-24 00:28:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimComputer
[2012-05-24 00:28:12 | 000,000,000 | ---D | C] -- C:\Program Files\SlimComputer
[2012-05-23 23:40:59 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2012-05-23 23:22:16 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Roaming\Intel
[2012-05-23 23:21:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2012-05-23 23:01:57 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012-05-23 23:01:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012-05-23 22:53:31 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2012-05-23 22:52:59 | 001,783,056 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll
[2012-05-23 22:52:59 | 001,725,784 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesGUILib.dll
[2012-05-23 22:52:58 | 000,345,328 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2012-05-23 22:52:58 | 000,185,584 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll
[2012-05-23 22:52:58 | 000,140,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2012-05-23 22:52:57 | 000,173,296 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2012-05-23 22:52:56 | 000,214,368 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFNHK.dll
[2012-05-23 22:52:55 | 000,074,080 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFCOM.dll
[2012-05-23 22:52:55 | 000,068,960 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFAPO.dll
[2012-05-23 22:52:52 | 000,359,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2012-05-23 22:52:52 | 000,170,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2012-05-23 22:52:52 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2012-05-23 22:52:52 | 000,064,856 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2012-05-23 22:52:51 | 007,161,696 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEP32A.dll
[2012-05-23 22:52:51 | 000,351,072 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EED32A.dll
[2012-05-23 22:52:51 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2012-05-23 22:52:51 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2012-05-23 22:52:51 | 000,103,776 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEL32A.dll
[2012-05-23 22:52:51 | 000,088,928 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEA32A.dll
[2012-05-23 22:52:51 | 000,062,304 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEG32A.dll
[2012-05-23 22:52:49 | 000,350,552 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVolumeSDAPO.dll
[2012-05-23 22:52:48 | 007,783,768 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek.dll
[2012-05-23 22:52:48 | 001,099,096 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek2.dll
[2012-05-23 22:52:43 | 001,836,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll
[2012-05-23 22:52:42 | 000,693,592 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPOShell.dll
[2012-05-23 22:52:40 | 000,259,928 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO30.dll
[2012-05-23 22:52:39 | 000,232,792 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll
[2012-05-23 22:52:38 | 000,357,712 | ---- | C] (Knowles Acoustics ) -- C:\Windows\System32\KAAPORT.dll
[2012-05-23 22:52:38 | 000,132,368 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll
[2012-05-23 22:52:31 | 002,190,400 | ---- | C] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2012-05-23 22:52:31 | 001,509,480 | ---- | C] (DTS) -- C:\Windows\System32\DTSS2SpeakerDLL.dll
[2012-05-23 22:52:31 | 001,292,904 | ---- | C] (DTS) -- C:\Windows\System32\DTSS2HeadphoneDLL.dll
[2012-05-23 22:52:31 | 000,631,400 | ---- | C] (DTS) -- C:\Windows\System32\DTSSymmetryDLL.dll
[2012-05-23 22:52:31 | 000,601,704 | ---- | C] (DTS) -- C:\Windows\System32\DTSVoiceClarityDLL.dll
[2012-05-23 22:52:31 | 000,421,744 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PLFX32.dll
[2012-05-23 22:52:31 | 000,398,192 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PGFX32.dll
[2012-05-23 22:52:31 | 000,335,216 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PREC32.dll
[2012-05-23 22:52:30 | 001,220,200 | ---- | C] (DTS) -- C:\Windows\System32\DTSBoostDLL.dll
[2012-05-23 22:52:30 | 000,654,952 | ---- | C] (DTS) -- C:\Windows\System32\DTSBassEnhancementDLL.dll
[2012-05-23 22:52:30 | 000,458,344 | ---- | C] (DTS) -- C:\Windows\System32\DTSNeoPCDLL.dll
[2012-05-23 22:52:30 | 000,389,736 | ---- | C] (DTS) -- C:\Windows\System32\DTSGainCompensatorDLL.dll
[2012-05-23 22:52:30 | 000,375,400 | ---- | C] (DTS) -- C:\Windows\System32\DTSLimiterDLL.dll
[2012-05-23 22:52:30 | 000,218,728 | ---- | C] (DTS) -- C:\Windows\System32\DTSGFXAPONS.dll
[2012-05-23 22:52:30 | 000,218,728 | ---- | C] (DTS) -- C:\Windows\System32\DTSGFXAPO.dll
[2012-05-23 22:52:30 | 000,218,216 | ---- | C] (DTS) -- C:\Windows\System32\DTSLFXAPO.dll
[2012-05-23 22:43:34 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\SlimWare Utilities Inc
[2012-05-23 22:43:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2012-05-23 22:43:19 | 000,000,000 | ---D | C] -- C:\Program Files\SlimDrivers
[2012-05-23 22:43:17 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Downloaded Installers
[2012-05-23 19:58:11 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012-05-23 19:58:09 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012-05-23 19:58:09 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\temp
[2012-05-23 19:48:38 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012-05-23 19:48:38 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012-05-23 19:48:38 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012-05-23 19:48:32 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012-05-23 19:48:31 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012-05-23 19:43:47 | 004,502,778 | R--- | C] (Swearware) -- C:\Users\NOOR\Desktop\ComboFix.exe
[2012-05-23 01:15:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012-05-16 01:13:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
[2012-05-16 01:13:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2012-05-14 01:02:26 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Roaming\GarenaPlus
[2012-05-14 01:02:06 | 000,000,000 | ---D | C] -- C:\ProgramData\GarenaMessenger
[2012-05-13 00:52:40 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Roaming\Malwarebytes
[2012-05-13 00:33:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012-05-13 00:33:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012-05-13 00:33:53 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012-05-13 00:33:53 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012-05-12 05:28:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2012-05-12 05:28:28 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012-05-12 05:28:20 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2012-05-10 04:53:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2012-05-10 04:53:19 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Blizzard Entertainment
[2012-05-08 03:36:32 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\{CB7F20FD-E6EE-43E1-8F7E-3405C77F1D9D}
[2012-05-08 03:36:19 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\{B015C0AB-DE1F-4165-B104-667562C4CABF}
[2012-05-07 21:09:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2012-05-07 21:08:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2012-05-04 01:45:26 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Roaming\Spearit
[2012-05-04 01:45:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Spearit
[2012-05-04 01:45:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Laplink
[2012-05-01 14:47:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Futuremark
[2012-05-01 14:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\Futuremark
[2012-05-01 14:28:20 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\WinZip
[2012-05-01 14:28:06 | 000,000,000 | ---D | C] -- C:\Users\NOOR\AppData\Local\CRE
[2012-05-01 14:27:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2012-05-01 14:27:05 | 000,000,000 | ---D | C] -- C:\ProgramData\WinZip
[2012-05-01 14:27:03 | 000,000,000 | ---D | C] -- C:\Program Files\WinZip
[2012-04-29 23:39:21 | 000,000,000 | ---D | C] -- C:\Program Files\Moozy
[2012-04-26 10:23:20 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-05-24 04:47:09 | 000,045,270 | ---- | M] () -- C:\Users\NOOR\AppData\Roaming\room_v3.dat
[2012-05-24 04:17:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-05-24 04:16:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-05-24 00:29:50 | 000,002,455 | ---- | M] () -- C:\Users\Public\Desktop\SlimCleaner.lnk
[2012-05-24 00:28:35 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-05-24 00:28:35 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-05-24 00:28:12 | 000,002,457 | ---- | M] () -- C:\Users\Public\Desktop\SlimComputer.lnk
[2012-05-24 00:25:55 | 000,626,040 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012-05-24 00:25:55 | 000,107,316 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012-05-24 00:21:55 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2012-05-24 00:21:38 | 000,011,232 | ---- | M] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2012-05-24 00:21:35 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-05-24 00:21:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-05-24 00:21:11 | 1607,143,424 | -HS- | M] () -- C:\hiberfil.sys
[2012-05-23 23:21:45 | 000,410,488 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012-05-23 23:20:06 | 000,002,097 | ---- | M] () -- C:\Users\Public\Desktop\Intel(R) Desktop Utilities.lnk
[2012-05-23 23:03:34 | 000,002,562 | ---- | M] () -- C:\Users\NOOR\Desktop\Google Chrome.lnk
[2012-05-23 22:43:20 | 000,002,455 | ---- | M] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2012-05-23 19:56:44 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012-05-23 19:45:33 | 004,502,778 | R--- | M] (Swearware) -- C:\Users\NOOR\Desktop\ComboFix.exe
[2012-05-23 08:41:15 | 000,000,512 | ---- | M] () -- C:\Users\NOOR\Desktop\MBR.dat
[2012-05-22 07:12:40 | 000,139,128 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012-05-22 07:12:26 | 000,215,128 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2012-05-16 01:13:46 | 000,001,135 | ---- | M] () -- C:\Users\NOOR\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2012-05-16 01:13:46 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2012-05-14 22:22:32 | 000,001,043 | ---- | M] () -- C:\Users\NOOR\Desktop\Garena Plus.lnk
[2012-05-13 00:50:29 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012-05-13 00:33:56 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-05-13 00:29:47 | 000,002,198 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012-05-12 21:29:11 | 000,002,560 | ---- | M] () -- C:\Windows\_MSRSTRT.EXE
[2012-05-12 05:29:09 | 000,001,900 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012-05-12 05:28:28 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012-05-07 21:09:13 | 000,001,238 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012-05-07 21:08:33 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012-05-01 14:27:15 | 000,002,205 | ---- | M] () -- C:\Users\Public\Desktop\WinZip.lnk
[2012-04-28 14:24:35 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-05-24 00:29:50 | 000,002,455 | ---- | C] () -- C:\Users\Public\Desktop\SlimCleaner.lnk
[2012-05-24 00:28:12 | 000,002,457 | ---- | C] () -- C:\Users\Public\Desktop\SlimComputer.lnk
[2012-05-23 23:20:06 | 000,002,097 | ---- | C] () -- C:\Users\Public\Desktop\Intel(R) Desktop Utilities.lnk
[2012-05-23 22:52:52 | 000,272,629 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2012-05-23 22:43:39 | 000,000,384 | ---- | C] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2012-05-23 22:43:35 | 000,011,232 | ---- | C] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2012-05-23 22:43:20 | 000,002,455 | ---- | C] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2012-05-23 19:48:38 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012-05-23 19:48:38 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012-05-23 19:48:38 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012-05-23 19:48:38 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012-05-23 19:48:38 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012-05-23 08:41:15 | 000,000,512 | ---- | C] () -- C:\Users\NOOR\Desktop\MBR.dat
[2012-05-16 01:13:46 | 000,001,135 | ---- | C] () -- C:\Users\NOOR\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2012-05-16 01:13:46 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2012-05-14 22:22:32 | 000,001,043 | ---- | C] () -- C:\Users\NOOR\Desktop\Garena Plus.lnk
[2012-05-13 00:50:29 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012-05-13 00:33:56 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-05-12 21:29:10 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2012-05-12 05:29:09 | 000,001,900 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012-05-07 21:09:13 | 000,001,238 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012-05-01 14:27:15 | 000,002,205 | ---- | C] () -- C:\Users\Public\Desktop\WinZip.lnk
[2012-04-29 17:01:36 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-04-22 00:00:53 | 000,109,216 | ---- | C] () -- C:\Windows\System32\EasyHook64.dll
[2012-04-22 00:00:53 | 000,084,480 | ---- | C] () -- C:\Windows\System32\EasyHook32.dll
[2012-04-17 10:00:45 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012-03-14 19:34:11 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2012-03-12 06:46:21 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012-02-29 13:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2012-02-15 13:15:15 | 000,000,127 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2012-02-12 16:11:43 | 000,139,128 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012-02-12 16:11:35 | 000,215,128 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2012-02-12 16:11:23 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011-10-20 09:32:32 | 000,000,982 | ---- | C] () -- C:\Windows\eReg.dat
[2011-09-27 01:57:23 | 000,000,108 | ---- | C] () -- C:\Windows\VSWizard.ini
[2011-08-16 16:44:36 | 000,045,270 | ---- | C] () -- C:\Users\NOOR\AppData\Roaming\room_v3.dat
[2011-08-16 04:49:59 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011-08-16 04:48:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011-04-09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
========== LOP Check ==========
[2011-10-13 00:35:44 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Command and Conquer 4
[2012-05-13 00:20:34 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
[2012-04-21 13:54:40 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\GarenaPlus
[2012-05-04 01:45:26 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Spearit
[2012-05-13 00:48:16 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\uTorrent
[2011-11-18 14:47:29 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Auto-Joiner
[2012-01-25 04:30:20 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Babylon
[2012-04-03 22:41:32 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011-10-26 20:21:20 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Command and Conquer 4
[2012-03-09 15:05:49 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\DAEMON Tools Lite
[2011-10-10 21:50:34 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Day 1 Studios
[2012-03-12 08:56:52 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\driveridentifier
[2012-05-24 00:57:34 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\GarenaPlus
[2011-09-28 01:44:46 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Leadertech
[2012-05-13 21:33:06 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Nitro PDF
[2012-05-02 03:58:57 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\OpenCandy
[2011-10-18 01:45:42 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Red Alert 3
[2012-03-10 10:20:31 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Registry Mechanic
[2012-05-04 01:45:26 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Spearit
[2011-12-09 21:04:35 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\Tific
[2012-01-03 02:41:57 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\TuneUp Software
[2012-05-24 04:51:41 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\uTorrent
[2011-09-17 18:26:55 | 000,000,000 | ---D | M] -- C:\Users\NOOR\AppData\Roaming\WinZip
[2012-05-12 05:19:44 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012-05-24 00:21:55 | 000,000,384 | ---- | M] () -- C:\Windows\Tasks\SlimDrivers Startup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011-09-09 21:31:19 | 000,388,818 | ---- | M] () -- C:\AnalysisLog.sr0
[2009-06-11 02:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2010-11-20 17:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2011-08-16 04:13:10 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012-05-23 19:58:08 | 000,020,681 | ---- | M] () -- C:\ComboFix.txt
[2009-06-11 02:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2011-10-13 00:22:39 | 000,003,648 | ---- | M] () -- C:\config.xml
[2007-11-07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007-11-07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007-11-07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007-11-07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007-11-07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007-11-07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007-11-07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007-11-07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007-11-07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007-11-07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2011-08-15 16:09:21 | 000,203,836 | RHS- | M] () -- C:\grldr
[2012-05-24 00:21:11 | 1607,143,424 | -HS- | M] () -- C:\hiberfil.sys
[2007-11-07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2007-11-07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007-11-07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007-11-07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007-11-07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007-11-07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007-11-07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007-11-07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007-11-07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007-11-07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007-11-07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2012-04-21 14:42:17 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012-04-21 12:59:53 | 000,000,217 | ---- | M] () -- C:\lan.log
[2012-05-01 23:09:22 | 000,003,138 | ---- | M] () -- C:\MAKEMSI_VBSCA-Kaspersky Security Scan(1.0.0.500)-Tuesday.log
[2012-04-21 14:42:17 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2012-05-24 00:21:28 | 2142,859,264 | -HS- | M] () -- C:\pagefile.sys
[2012-04-21 12:54:16 | 000,000,206 | ---- | M] () -- C:\realtek.log
[2012-04-21 12:54:16 | 000,002,107 | ---- | M] () -- C:\RHDSetup.log
[2012-03-14 19:35:53 | 000,000,184 | ---- | M] () -- C:\setup.log
[2007-03-07 13:31:26 | 000,303,616 | ---- | M] () -- C:\tp_icon.dll
[2012-02-12 01:14:15 | 000,002,981 | ---- | M] () -- C:\user.js
[2007-11-07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007-11-07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007-11-07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
[2011-08-15 16:09:21 | 000,000,000 | RHS- | M] () -- C:\winx.ld
< %systemroot%\Fonts\*.com >
[2009-07-14 09:52:25 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 09:52:25 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 09:52:25 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 09:52:25 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009-06-11 02:31:19 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009-07-14 06:15:35 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010-11-20 17:21:36 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012-03-08 18:37:20 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2012-03-12 12:21:43 | 000,001,702 | -HS- | M] () -- C:\Users\NOOR\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009-07-14 09:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011-10-18 23:33:02 | 000,000,317 | -HS- | M] () -- C:\Users\NOOR\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012-05-23 19:45:33 | 004,502,778 | R--- | M] (Swearware) -- C:\Users\NOOR\Desktop\ComboFix.exe
[2006-11-01 09:07:32 | 008,904,704 | ---- | M] () -- C:\Users\NOOR\Desktop\nfsc.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012-05-24 04:17:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-05-24 00:21:35 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-05-24 04:16:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-05-24 00:21:30 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012-05-12 05:19:44 | 000,032,628 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
[2012-05-24 00:21:55 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009-06-11 02:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012-02-15 22:18:54 | 000,000,402 | -HS- | M] () -- C:\Users\NOOR\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-05-13 19:35:25
========== Alternate Data Streams ==========
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7631EA83
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:553CA6CA
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP

1B5B4F1
< End of report >