rocksalt27
Posts: 23 +0
[2012/01/12 08:09:36 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\BitTorrent
[2011/07/15 07:27:10 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/15 07:49:27 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
[2012/01/12 07:42:50 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\SoftGrid Client
[2012/01/11 03:19:29 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\tixati
[2010/11/24 09:31:15 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\TP
[2011/02/04 23:15:33 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\WildTangent
[2010/11/25 00:15:47 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\Windows Live Writer
[2012/01/15 22:41:02 | 000,000,926 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424543794-2751099967-4147281046-1001Core.job
[2012/01/16 08:27:10 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424543794-2751099967-4147281046-1001UA.job
[2011/12/28 16:17:50 | 000,029,690 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/01/15 22:41:16 | 000,022,440 | ---- | M] () -- C:\ComboFix.txt
[2010/10/16 17:14:50 | 000,003,766 | ---- | M] () -- C:\dell.sdr
[2012/01/15 22:22:34 | 3061,202,944 | -HS- | M] () -- C:\hiberfil.sys
[2006/12/01 20:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2012/01/15 22:22:37 | 4081,606,656 | -HS- | M] () -- C:\pagefile.sys
[2011/09/11 20:46:34 | 000,036,180 | ---- | M] () -- C:\RPSetup.exe.log
< %systemroot%\Fonts\*.com >
[2009/07/13 21:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 12:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 10:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2009/07/10 09:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 20:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/23 20:58:28 | 000,000,221 | -HS- | M] () -- C:\Users\Rocksalt27\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/01/15 09:29:31 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\Rocksalt27\Desktop\aswMBR.exe
[2012/01/15 17:32:37 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\Rocksalt27\Desktop\boot_cleaner.exe
[2012/01/13 09:35:00 | 060,416,552 | ---- | M] (COMODO) -- C:\Users\Rocksalt27\Desktop\cispremium_installer_x86.exe
[2012/01/15 22:05:15 | 004,384,281 | R--- | M] (Swearware) -- C:\Users\Rocksalt27\Desktop\ComboFix.exe
[2012/01/13 12:21:42 | 000,302,592 | ---- | M] () -- C:\Users\Rocksalt27\Desktop\l8q0myh6.exe
[2012/01/13 12:05:50 | 010,847,608 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Rocksalt27\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/16 08:37:11 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Rocksalt27\Desktop\OTL.exe
[1 C:\Users\Rocksalt27\Desktop\*.tmp files -> C:\Users\Rocksalt27\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 13:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/01/12 20:33:20 | 000,000,402 | -HS- | M] () -- C:\Users\Rocksalt27\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/01/13 20:19:33 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP
FC5A2B2
< End of report >
[2011/07/15 07:27:10 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/15 07:49:27 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
[2012/01/12 07:42:50 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\SoftGrid Client
[2012/01/11 03:19:29 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\tixati
[2010/11/24 09:31:15 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\TP
[2011/02/04 23:15:33 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\WildTangent
[2010/11/25 00:15:47 | 000,000,000 | ---D | M] -- C:\Users\Rocksalt27\AppData\Roaming\Windows Live Writer
[2012/01/15 22:41:02 | 000,000,926 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424543794-2751099967-4147281046-1001Core.job
[2012/01/16 08:27:10 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424543794-2751099967-4147281046-1001UA.job
[2011/12/28 16:17:50 | 000,029,690 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/01/15 22:41:16 | 000,022,440 | ---- | M] () -- C:\ComboFix.txt
[2010/10/16 17:14:50 | 000,003,766 | ---- | M] () -- C:\dell.sdr
[2012/01/15 22:22:34 | 3061,202,944 | -HS- | M] () -- C:\hiberfil.sys
[2006/12/01 20:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2012/01/15 22:22:37 | 4081,606,656 | -HS- | M] () -- C:\pagefile.sys
[2011/09/11 20:46:34 | 000,036,180 | ---- | M] () -- C:\RPSetup.exe.log
< %systemroot%\Fonts\*.com >
[2009/07/13 21:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 12:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 10:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2009/07/10 09:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 20:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/23 20:58:28 | 000,000,221 | -HS- | M] () -- C:\Users\Rocksalt27\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/01/15 09:29:31 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\Rocksalt27\Desktop\aswMBR.exe
[2012/01/15 17:32:37 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\Rocksalt27\Desktop\boot_cleaner.exe
[2012/01/13 09:35:00 | 060,416,552 | ---- | M] (COMODO) -- C:\Users\Rocksalt27\Desktop\cispremium_installer_x86.exe
[2012/01/15 22:05:15 | 004,384,281 | R--- | M] (Swearware) -- C:\Users\Rocksalt27\Desktop\ComboFix.exe
[2012/01/13 12:21:42 | 000,302,592 | ---- | M] () -- C:\Users\Rocksalt27\Desktop\l8q0myh6.exe
[2012/01/13 12:05:50 | 010,847,608 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Rocksalt27\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/16 08:37:11 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Rocksalt27\Desktop\OTL.exe
[1 C:\Users\Rocksalt27\Desktop\*.tmp files -> C:\Users\Rocksalt27\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 13:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/01/12 20:33:20 | 000,000,402 | -HS- | M] () -- C:\Users\Rocksalt27\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/01/13 20:19:33 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP
< End of report >