2nd half of OTL.TXT
O1 HOSTS File: ([2012/04/08 15:41:46 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll File not found
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:
64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll File not found
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:
64bit: - HKLM..\Run: [WrtMon.exe] C:\Windows\SysNative\spool\drivers\x64\3\WrtMon.exe ()
O4 - HKLM..\Run: [FPCCSMiddleware] C:\Program Files (x86)\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O15 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-278354598-3277908703-583346675-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}
http://d1ylr6sba64qi3.cloudfront.net/global/bin/srldetect_intel_4.1.66.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8528F691-CBFB-42FD-B63E-A7D1F7551261}: DhcpNameServer = 10.0.0.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/09 17:30:11 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{B27D0D64-2336-45D1-A52D-3081ECC07593}
[2012/04/08 15:41:53 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/04/08 15:32:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/04/08 15:32:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/04/08 15:32:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/04/08 15:32:34 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/04/08 15:32:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/04/06 04:40:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{408A86A3-D5A5-43EA-88AC-DE51B75A67A9}
[2012/04/05 21:18:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/04/05 21:09:20 | 009,502,424 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.60.1.1000.exe
[2012/04/05 12:42:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{2359EC90-DE16-4B32-AFD3-6E4DA84F02E3}
[2012/04/05 00:13:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Recovery
[2012/04/04 17:40:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{089AB1D1-C206-4F0C-BCAA-80DE526FD5CC}
[2012/04/03 19:10:44 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{EB5A1DCE-B9A9-4E6F-9E74-E1B952B62123}
[2012/03/31 21:48:59 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{F128828E-4AF3-41D1-B2D5-EAF8BEDF4450}
[2012/03/31 08:09:33 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{37BD4E2E-72D0-4028-8671-5AED4DE333A0}
[2012/03/31 02:45:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/03/31 02:45:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/03/29 12:17:35 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Webroot
[2012/03/25 20:42:41 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{3D321CEC-F128-493D-8F51-2C04E3499297}
[2012/03/25 20:42:18 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{0AD8E8CD-63FA-4CB3-BB0B-8F8FD1403352}
[2012/03/18 09:59:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/03/18 09:59:25 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/03/16 19:44:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sprint_Activation
[2012/03/16 19:44:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Motive
[2012/03/16 19:43:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Motive
[2012/03/16 19:42:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Motive
[2012/03/14 18:54:00 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{9109FDB6-6333-4550-B9E5-86B5042659EE}
[2012/03/14 18:53:49 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{C06AC02E-3E33-43BB-BB35-B6DAB034F0F4}
[2012/03/14 03:25:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PERRLA
[2012/03/13 02:35:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2012/03/13 02:35:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
[2012/03/13 02:35:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Coupons
[2012/03/13 02:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Photo Creations
[2012/03/13 02:35:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP Photo Creations
[2012/03/13 02:34:17 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/09 17:41:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/09 17:40:12 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/09 17:36:22 | 000,001,410 | ---- | M] () -- C:\Users\Owner\Desktop\OTL - Shortcut.lnk
[2012/04/09 17:35:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-278354598-3277908703-583346675-1000UA.job
[2012/04/09 17:32:38 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForOwner.job
[2012/04/09 17:30:19 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/04/09 17:30:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/04/09 15:00:19 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-278354598-3277908703-583346675-1000Core.job
[2012/04/08 16:22:51 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/08 16:22:51 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/08 16:15:49 | 000,000,632 | RHS- | M] () -- C:\Users\Owner\ntuser.pol
[2012/04/08 16:15:30 | 3063,046,144 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/08 15:41:46 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/04/08 15:29:48 | 000,001,461 | ---- | M] () -- C:\Users\Owner\Desktop\ComboFix - Shortcut.lnk
[2012/04/08 08:45:13 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\Owner\Desktop\boot_cleaner.exe
[2012/04/08 08:27:51 | 000,000,512 | ---- | M] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/04/06 11:52:11 | 000,729,880 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/06 11:52:11 | 000,626,868 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/04/06 11:52:11 | 000,108,298 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/04/06 03:48:08 | 000,002,359 | ---- | M] () -- C:\Users\Owner\Desktop\Google Chrome.lnk
[2012/04/05 21:18:03 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/05 21:12:18 | 000,001,587 | ---- | M] () -- C:\Users\Owner\Desktop\mbam-setup-1.60.1.1000 - Shortcut.lnk
[2012/04/05 21:09:35 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.60.1.1000.exe
[2012/04/03 19:24:19 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/04/03 05:07:32 | 519,392,533 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/03/31 02:45:27 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/03/31 02:45:07 | 000,744,030 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/03/29 11:51:15 | 000,623,424 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/03/27 13:58:27 | 000,320,940 | ---- | M] () -- C:\Users\Owner\Documents\cc_20120327_135806.reg
[2012/03/26 20:58:27 | 000,007,606 | ---- | M] () -- C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2012/03/25 21:02:37 | 000,208,477 | ---- | M] () -- C:\Windows\hpoins40.dat
[2012/03/24 23:24:05 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2012/03/24 23:24:05 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2012/03/19 19:12:42 | 000,037,559 | ---- | M] () -- C:\Users\Owner\Documents\Assignment 1 Adams and Jefferson.rtf
[2012/03/14 03:25:25 | 000,001,566 | ---- | M] () -- C:\Users\Public\Desktop\Launch PERRLA.lnk
[2012/03/13 02:35:37 | 000,001,057 | ---- | M] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk
[2012/03/13 02:35:12 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Shop for HP Supplies.lnk
[2012/03/13 02:34:09 | 000,001,275 | ---- | M] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2012/03/13 02:32:54 | 000,002,059 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/03/13 00:35:53 | 000,201,770 | ---- | M] () -- C:\Windows\hpoins40.dat.temp
[2 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/09 17:36:22 | 000,001,410 | ---- | C] () -- C:\Users\Owner\Desktop\OTL - Shortcut.lnk
[2012/04/08 15:32:39 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/04/08 15:32:39 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/04/08 15:32:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/04/08 15:32:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/04/08 15:32:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/04/08 15:29:48 | 000,001,461 | ---- | C] () -- C:\Users\Owner\Desktop\ComboFix - Shortcut.lnk
[2012/04/08 08:27:51 | 000,000,512 | ---- | C] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/04/05 21:18:03 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/05 21:12:18 | 000,001,587 | ---- | C] () -- C:\Users\Owner\Desktop\mbam-setup-1.60.1.1000 - Shortcut.lnk
[2012/04/04 21:24:09 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/04/03 05:07:32 | 519,392,533 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/03/31 08:11:46 | 000,000,632 | RHS- | C] () -- C:\Users\Owner\ntuser.pol
[2012/03/31 02:45:27 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012/03/31 02:45:07 | 000,744,030 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/03/31 02:45:02 | 000,001,897 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/03/27 13:58:13 | 000,320,940 | ---- | C] () -- C:\Users\Owner\Documents\cc_20120327_135806.reg
[2012/03/26 20:58:27 | 000,007,606 | ---- | C] () -- C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2012/03/26 12:33:22 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForOwner.job
[2012/03/19 19:12:42 | 000,037,559 | ---- | C] () -- C:\Users\Owner\Documents\Assignment 1 Adams and Jefferson.rtf
[2012/03/13 02:35:37 | 000,001,057 | ---- | C] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk
[2012/03/13 02:20:51 | 000,201,770 | ---- | C] () -- C:\Windows\hpoins40.dat.temp
[2011/12/10 19:42:11 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/12/10 19:42:11 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/10/22 23:22:39 | 000,059,447 | ---- | C] () -- C:\ProgramData\starcoloring_vehicles_coloring_book_cfg
[2011/02/21 22:26:20 | 000,001,854 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\GhostObjGAFix.xml
[2011/02/17 03:05:06 | 000,011,776 | ---- | C] () -- C:\Windows\SysWow64\pmsbfn32.dll
[2011/02/17 03:03:23 | 000,000,424 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2010/10/16 20:14:31 | 000,030,424 | ---- | C] () -- C:\Windows\SysWow64\wrLZMA.dll
[2010/10/12 02:45:49 | 000,000,000 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/06/16 00:23:31 | 000,000,918 | ---- | C] () -- C:\Windows\hpomdl40.dat.temp
[2010/06/10 19:42:26 | 000,208,477 | ---- | C] () -- C:\Windows\hpoins40.dat
========== LOP Check ==========
[2010/10/11 19:38:18 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Avery
[2011/09/12 15:10:24 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Canon
[2011/12/07 19:46:12 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CheckPoint
[2011/08/22 17:48:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/15 17:18:49 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\LEGO Company
[2011/06/09 17:18:28 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\NewSoft
[2011/02/17 03:03:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ScanSoft
[2010/10/12 02:45:52 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Template
[2011/09/30 20:29:40 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Windows Live Writer
[2012/03/14 09:46:10 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/03/26 01:59:00 | 000,009,785 | ---- | M] () -- C:\aaw7boot.log
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2012/04/08 15:45:39 | 000,026,733 | ---- | M] () -- C:\ComboFix.txt
[2012/04/08 16:15:30 | 3063,046,144 | -HS- | M] () -- C:\hiberfil.sys
[2010/06/20 17:44:14 | 000,000,186 | ---- | M] () -- C:\hpqlb.log
[2012/01/20 18:23:50 | 000,001,570 | ---- | M] () -- C:\MAKEMSI_VBSCA-Kaspersky Security Scan(1.0.0.500)-Friday.log
[2012/04/08 16:15:33 | 4084,064,256 | -HS- | M] () -- C:\pagefile.sys
[2011/07/28 23:02:10 | 000,000,312 | ---- | M] () -- C:\rkill.log
[2010/06/20 17:40:11 | 000,000,084 | ---- | M] () -- C:\SYNTPAD.LOG
[2 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | -H-- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 13:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/08 14:42:47 | 000,000,221 | -HS- | M] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/04/08 08:45:13 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\Owner\Desktop\boot_cleaner.exe
[2011/02/04 04:56:14 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.50.1.1100.exe
[2012/04/05 21:09:35 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.60.1.1000.exe
[2011/12/08 03:58:21 | 000,462,496 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Owner\Desktop\uninstall_flash_player_64bit.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/04/09 17:30:19 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/04/09 17:40:12 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/09 17:41:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/09 15:00:19 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-278354598-3277908703-583346675-1000Core.job
[2012/04/09 17:35:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-278354598-3277908703-583346675-1000UA.job
[2012/04/09 17:32:38 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForOwner.job
[2012/04/08 16:15:40 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/03/14 09:46:10 | 000,032,636 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 16:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/08/27 02:51:32 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/08/27 02:51:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/08/23 22:35:52 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/08/23 22:35:52 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/08/27 02:51:32 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/02/15 04:27:37 | 000,000,402 | -HS- | M] () -- C:\Users\Owner\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/03/25 10:28:23 | 000,000,188 | ---- | M] () -- C:\ProgramData\HPWALog.txt
[2012/03/25 21:02:38 | 000,013,045 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2012/01/01 14:57:29 | 000,059,447 | ---- | M] () -- C:\ProgramData\starcoloring_vehicles_coloring_book_cfg
[2010/02/16 04:39:49 | 000,000,032 | ---- | M] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/01/09 20:05:56 | 000,000,109 | ---- | M] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/02/16 04:39:24 | 000,000,032 | ---- | M] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/01/09 20:02:19 | 000,000,105 | ---- | M] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/02/16 04:38:51 | 000,000,032 | ---- | M] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/02/16 04:39:39 | 000,000,032 | ---- | M] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/01/09 20:01:27 | 000,000,107 | ---- | M] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2010/01/09 20:05:13 | 000,000,110 | ---- | M] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/02/16 04:39:56 | 000,000,105 | ---- | M] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp

FC5A2B2
< End of repor