========== Files Created - No Company Name ==========
[2012/04/15 22:43:59 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/04/15 22:43:59 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/04/15 22:43:59 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/04/15 22:43:59 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/04/15 22:43:59 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/04/15 18:34:43 | 000,111,597 | ---- | C] () -- C:\Users\Dave\Desktop\27329398.jpg
[2012/04/15 18:33:23 | 000,108,015 | ---- | C] () -- C:\Users\Dave\Desktop\air8245715.jpg
[2012/04/13 16:38:38 | 000,765,837 | ---- | C] () -- C:\Users\Dave\Desktop\hours report March 2012.jpg
[2012/04/13 16:32:04 | 000,000,512 | ---- | C] () -- C:\Users\Dave\Desktop\MBR.dat
[2012/04/07 22:22:07 | 000,635,607 | ---- | C] () -- C:\Users\Dave\Desktop\STEP Guide (PDF).pdf
[2012/04/07 11:30:42 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/04/01 16:31:57 | 000,001,112 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Player.lnk
[2012/03/03 23:02:04 | 000,123,368 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/02/29 13:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/12/22 12:03:22 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/12/01 16:34:04 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2011/11/10 13:24:30 | 000,027,187 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011/11/10 13:24:30 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\asrussian.dll
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\askorean.dll
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\asjapan.dll
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\asgerman.dll
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\asfrench.dll
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\aseng.dll
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\ASCHT.dll
[2011/11/10 13:13:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\aschs.dll
[2011/10/19 22:14:52 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/10/19 15:13:59 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/08/24 20:19:10 | 000,056,320 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/03/17 17:51:46 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/01/21 16:28:57 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2010/11/04 21:20:19 | 000,273,167 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\Fallen Earth_2.49.5.5_2010-11-05-04-20.dmp
[2010/10/25 20:25:43 | 000,271,818 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\Fallen Earth_2.49.5.3_2010-10-26-03-25.dmp
[2010/10/15 12:11:07 | 002,601,752 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_moh.exe
[2010/09/05 17:40:26 | 000,073,690 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\icarus-dxdiag.xml
[2010/06/14 16:01:35 | 000,000,176 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\default.rss
========== LOP Check ==========
[2011/03/03 01:05:17 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\.minecraft
[2010/03/09 14:16:34 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Bioshock
[2010/04/07 19:19:08 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Bioshock2
[2012/04/07 22:10:28 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\BitTorrent
[2010/01/15 21:02:02 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\DAEMON Tools Pro
[2010/02/27 18:44:02 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Facebook
[2011/06/05 23:04:34 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\GetRightToGo
[2011/06/26 13:34:42 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Hi-Rez Studios
[2011/10/17 10:08:42 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\IrfanView
[2011/02/10 19:38:36 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Kalypso Media
[2011/06/05 22:50:19 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Laconic Software
[2010/03/27 20:08:55 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Leadertech
[2012/01/19 19:01:45 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Motorola
[2010/08/13 16:52:06 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\My Games
[2011/02/14 11:08:45 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\OpenOffice.org
[2012/03/06 22:02:13 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Origin
[2012/01/03 12:16:05 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\RIFT
[2012/01/04 23:58:23 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Samsung
[2010/02/04 17:24:09 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Shark007
[2010/05/17 19:41:42 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SPORE
[2011/04/12 16:32:26 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\The Creative Assembly
[2010/02/04 17:22:38 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Win7codecs
[2011/05/05 20:24:56 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Windows Live Writer
[2012/02/02 10:35:49 | 000,032,550 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/11/20 05:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2009/10/24 15:01:03 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012/04/15 22:54:12 | 000,025,657 | ---- | M] () -- C:\ComboFix.txt
[2009/09/17 10:51:13 | 000,000,197 | ---- | M] () -- C:\csb.log
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2012/04/15 23:12:00 | 2127,908,863 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/05 17:10:00 | 000,000,079 | ---- | M] () -- C:\ifsverifylog.txt
[2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2009/09/17 10:49:55 | 000,000,200 | ---- | M] () -- C:\Install.log
[2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2006/12/01 23:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2012/04/15 23:12:03 | 4268,867,583 | -HS- | M] () -- C:\pagefile.sys
[2009/09/17 10:45:53 | 000,001,705 | ---- | M] () -- C:\RHDSetup.log
[2012/04/10 16:54:29 | 000,000,361 | ---- | M] () -- C:\rkill.log
[2012/04/15 23:13:07 | 000,000,198 | ---- | M] () -- C:\service.log
[2012/04/10 16:56:29 | 000,143,948 | ---- | M] () -- C:\TDSSKiller.2.7.28.0_10.04.2012_16.55.41_log.txt
[2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/03/06 16:15:19 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/12/11 06:53:48 | 002,766,336 | ---- | M] (Laconic Software) -- C:\Windows\freefire.scr
[2010/11/10 02:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2009/12/27 23:38:09 | 000,001,686 | -HS- | M] () -- C:\Users\Dave\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/07 23:22:58 | 000,000,286 | -HS- | M] () -- C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/05/11 21:07:23 | 000,000,221 | -HS- | M] () -- C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/04/12 22:10:47 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Dave\Desktop\aswMBR.exe
[2012/04/15 14:33:52 | 004,463,836 | R--- | M] (Swearware) -- C:\Users\Dave\Desktop\ComboFix.exe
[2012/04/16 16:46:56 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Desktop\OTL.exe
[2009/12/20 00:30:58 | 000,610,304 | ---- | M] (Speed Guide Inc.) -- C:\Users\Dave\Desktop\TCPOptimizer.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/04/16 16:42:08 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/04/15 23:18:57 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/16 16:42:09 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/15 23:12:16 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/02/02 10:35:49 | 000,032,550 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2011/01/30 18:26:19 | 000,000,600 | ---- | M] () -- C:\Windows\AppPatch\Custom\{2f4afba0-a593-4e8c-82e9-32d2a7b8c0dc}.sdb
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 14:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2012/03/14 18:26:20 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2012/03/14 18:26:20 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/03/15 11:15:00 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/03/15 11:15:00 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2012/03/14 18:26:20 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/02/15 15:38:33 | 000,000,402 | -HS- | M] () -- C:\Users\Dave\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/02/14 10:24:42 | 000,000,239 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2011/12/22 16:40:32 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP

FC5A2B2
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:C946DB94
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:798A3728
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:525DFE14
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >