O4 - Startup: C:\Users\Default\Pictures [2009/07/13 21:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Default\PrintHood [2009/07/14 00:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Recent [2009/07/14 00:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Roaming [2013/05/02 23:12:25 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Default\Saved Games [2009/07/13 21:34:59 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Default\SendTo [2009/07/14 00:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Start Menu [2009/07/14 00:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Templates [2009/07/14 00:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\Default\Videos [2009/07/13 21:34:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\AppData [2014/01/30 19:07:56 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\Desktop [2013/05/05 18:28:40 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Documents [2009/07/14 00:08:56 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Downloads [2009/07/13 23:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Favorites [2009/07/13 21:34:59 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Libraries [2009/07/13 23:54:24 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Music [2009/07/13 23:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Pictures [2009/07/13 23:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Recorded TV [2013/06/17 13:57:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Roaming [2013/05/02 22:54:25 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\Videos [2009/07/13 23:54:24 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\.shsh [2013/05/02 23:06:44 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\User\AppData [2013/05/02 23:06:47 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\User\Application Data [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Contacts [2013/06/05 17:29:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\Cookies [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Desktop [2014/01/31 21:11:16 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\My Documents [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Downloads [2013/08/19 14:13:34 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\Favorites [2013/11/30 23:09:02 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\Links [2014/01/25 21:21:22 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\Local Settings [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Music [2013/06/05 17:29:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\My Documents [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\My PaperPort.com [2013/02/24 15:51:27 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\User\NetHood [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\ntuser.dat ()
O4 - Startup: C:\Users\User\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\User\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\User\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\User\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\User\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{5c36b422-85e6-11e3-87f1-001e653cc1ac}.TM.blf ()
O4 - Startup: C:\Users\User\ntuser.dat{5c36b422-85e6-11e3-87f1-001e653cc1ac}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{5c36b422-85e6-11e3-87f1-001e653cc1ac}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{6ba3743a-d75e-11e2-87d9-001e33d40161}.TM.blf ()
O4 - Startup: C:\Users\User\ntuser.dat{6ba3743a-d75e-11e2-87d9-001e33d40161}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{6ba3743a-d75e-11e2-87d9-001e33d40161}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{c9df8421-fefa-11e2-a862-001e33d40161}.TM.blf ()
O4 - Startup: C:\Users\User\ntuser.dat{c9df8421-fefa-11e2-a862-001e33d40161}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{c9df8421-fefa-11e2-a862-001e33d40161}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{d0e6e2a6-846e-11e3-873a-001e33d40161}.TM.blf ()
O4 - Startup: C:\Users\User\ntuser.dat{d0e6e2a6-846e-11e3-873a-001e33d40161}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{d0e6e2a6-846e-11e3-873a-001e33d40161}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{e4940cdc-86d3-11e3-aa0f-001e33d40161}.TxR.0.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{e4940cdc-86d3-11e3-aa0f-001e33d40161}.TxR.1.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{e4940cdc-86d3-11e3-aa0f-001e33d40161}.TxR.2.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{e4940cdc-86d3-11e3-aa0f-001e33d40161}.TxR.blf ()
O4 - Startup: C:\Users\User\ntuser.dat{e4940cdd-86d3-11e3-aa0f-001e33d40161}.TM.blf ()
O4 - Startup: C:\Users\User\ntuser.dat{e4940cdd-86d3-11e3-aa0f-001e33d40161}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.dat{e4940cdd-86d3-11e3-aa0f-001e33d40161}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\User\ntuser.ini ()
O4 - Startup: C:\Users\User\Pictures [2013/12/05 09:37:25 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\PrintHood [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Recent [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Roaming [2013/05/02 23:09:10 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\User\Saved Games [2013/06/05 17:29:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\Searches [2013/06/05 17:29:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\User\SendTo [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Start Menu [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\Sti_Trace.log ()
O4 - Startup: C:\Users\User\Templates [2013/05/02 22:43:41 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\User\umbrella0.log ()
O4 - Startup: C:\Users\User\Videos [2013/06/05 17:29:59 | 000,000,000 | R--D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3484798978-2103683542-120407626-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3484798978-2103683542-120407626-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-3484798978-2103683542-120407626-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 10.21.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3197978C-19DE-43B7-9DF0-AC3E1D7C068B}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:
64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\TOSHIBA-1.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\TOSHIBA-1.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/17 13:02:36 | 000,000,215 | -H-- | M] () - E:\autorun.inf -- [ FAT ]
O32 - AutoRun File - [2010/03/17 13:02:36 | 000,000,215 | R--- | M] () - E:\AUTORUN_.INF -- [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/01/31 20:54:17 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/01/30 19:07:58 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/01/30 19:07:56 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2014/01/30 18:14:17 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/01/30 18:14:17 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/01/30 18:14:17 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/01/30 18:12:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/01/29 11:40:09 | 000,119,000 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/01/29 11:40:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/01/29 11:39:17 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/01/27 18:36:49 | 000,000,000 | ---D | C] -- C:\FRST
[2014/01/26 18:20:34 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\%LocalAppData%
[2014/01/25 12:44:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2014/01/25 10:29:58 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2014/01/25 10:02:08 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
========== Files - Modified Within 30 Days ==========
[2014/01/31 21:19:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/01/31 21:07:14 | 000,011,440 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/01/31 21:07:14 | 000,011,440 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/01/31 21:03:50 | 000,778,834 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/01/31 21:03:50 | 000,660,318 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/01/31 21:03:50 | 000,121,214 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/01/31 20:57:19 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/01/31 20:56:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/01/31 20:56:21 | 3219,644,416 | -HS- | M] () -- C:\hiberfil.sys
[2014/01/30 19:05:25 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/01/30 18:55:38 | 000,002,243 | ---- | M] () -- C:\Windows\epplauncher.mif
[2014/01/29 11:40:09 | 000,119,000 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/01/29 11:39:51 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
========== Files Created - No Company Name ==========
[2014/01/31 20:53:24 | 000,602,112 | ---- | C] () -- \OTL.exe
[2014/01/31 20:53:13 | 001,037,068 | ---- | C] () -- \JRT.exe
[2014/01/31 20:52:59 | 001,166,132 | ---- | C] () -- \adwcleaner.exe
[2014/01/30 18:14:17 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/01/30 18:14:17 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014/01/30 18:14:17 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/01/30 18:14:17 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/01/30 18:14:17 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/01/30 18:09:10 | 001,933,048 | ---- | C] () -- \rkill.exe
[2014/01/30 18:06:26 | 005,177,551 | R--- | C] () -- \ComboFix.exe
[2014/01/29 11:31:05 | 004,380,160 | ---- | C] () -- \RogueKillerX64.exe
[2014/01/29 11:15:13 | 012,589,848 | ---- | C] () -- \mbar-1.07.0.1009.exe
[2014/01/27 18:59:31 | 000,688,992 | R--- | C] () -- \dds.com
[2014/01/27 18:26:32 | 002,079,232 | ---- | C] () -- \FRST64.exe
[2013/05/03 04:43:34 | 000,773,050 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/05/02 22:42:39 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013/03/07 14:05:43 | 002,870,860 | ---- | C] () -- \Tightrope edit.mp3
[2012/10/29 07:45:53 | 012,189,838 | ---- | C] () -- \twow1.pdf
[2012/10/29 07:45:51 | 011,197,299 | ---- | C] () -- \twow2.pdf
[2012/09/14 15:19:53 | 000,000,416 | ---- | C] () -- \SGPortable.lnk
[2012/09/14 15:19:53 | 000,000,215 | R--- | C] () -- \AUTORUN_.INF
[2012/09/14 15:19:53 | 000,000,215 | -H-- | C] () -- \autorun.inf
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/02/27 00:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/26 23:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/05/02 22:52:58 | 000,000,000 | ---D | M] -- C:\Users\All Users\2EDBAA6B18AAF2BD00002EDB7B93F717
[2013/05/02 22:52:59 | 000,000,000 | ---D | M] -- C:\Users\All Users\34BE82C4-E596-4e99-A191-52C6199EBF69
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Application Data
[2013/05/02 22:53:03 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ
[2013/12/04 19:38:25 | 000,000,000 | ---D | M] -- C:\Users\All Users\CanonIJ
[2013/12/04 19:28:56 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonIJEGV
[2013/05/02 22:53:04 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonIJMyPrinter
[2014/01/10 16:02:36 | 000,000,000 | ---D | M] -- C:\Users\All Users\CanonIJPLM
[2013/05/02 22:53:04 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonIJScan
[2013/05/02 22:53:04 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonIJSolutionMenu
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Desktop
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Documents
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Favorites
[2013/05/02 22:53:05 | 000,000,000 | ---D | M] -- C:\Users\All Users\Geek Squad
[2013/05/02 22:53:05 | 000,000,000 | ---D | M] -- C:\Users\All Users\InterVideo
[2013/05/02 22:53:23 | 000,000,000 | ---D | M] -- C:\Users\All Users\NovaStor
[2013/05/02 22:53:31 | 000,000,000 | ---D | M] -- C:\Users\All Users\Nuance
[2014/01/25 12:44:11 | 000,000,000 | ---D | M] -- C:\Users\All Users\Oracle
[2013/05/02 22:53:31 | 000,000,000 | ---D | M] -- C:\Users\All Users\ScanSoft
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Start Menu
[2013/12/04 19:29:38 | 000,000,000 | ---D | M] -- C:\Users\All Users\Temp
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Templates
[2013/05/02 22:53:40 | 000,000,000 | ---D | M] -- C:\Users\All Users\Toshiba
[2013/05/02 22:53:40 | 000,000,000 | ---D | M] -- C:\Users\All Users\Ulead Systems
[2013/05/02 22:53:41 | 000,000,000 | ---D | M] -- C:\Users\All Users\WildTangent
[2013/05/02 22:54:23 | 000,000,000 | ---D | M] -- C:\Users\All Users\Zeon
[2013/05/02 22:54:23 | 000,000,000 | ---D | M] -- C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2009/07/13 22:20:08 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\Application Data
[2009/07/13 21:34:59 | 000,000,000 | R--D | M] -- C:\Users\Default\Desktop
[2009/07/14 00:08:56 | 000,000,000 | R--D | M] -- C:\Users\Default\Documents
[2009/07/13 21:34:59 | 000,000,000 | R--D | M] -- C:\Users\Default\Downloads
[2013/05/02 23:12:25 | 000,000,000 | R--D | M] -- C:\Users\Default\Favorites
[2009/07/13 21:34:59 | 000,000,000 | R--D | M] -- C:\Users\Default\Links
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\Local Settings
[2009/07/13 21:34:59 | 000,000,000 | R--D | M] -- C:\Users\Default\Music
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\My Documents
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\NetHood
[2009/07/13 21:34:59 | 000,000,000 | R--D | M] -- C:\Users\Default\Pictures
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\PrintHood
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\Recent
[2013/05/02 23:12:25 | 000,000,000 | ---D | M] -- C:\Users\Default\Roaming
[2009/07/13 21:34:59 | 000,000,000 | ---D | M] -- C:\Users\Default\Saved Games
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\SendTo
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\Start Menu
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- C:\Users\Default\Templates
[2009/07/13 21:34:59 | 000,000,000 | R--D | M] -- C:\Users\Default\Videos
[2014/01/30 19:07:56 | 000,000,000 | ---D | M] -- C:\Users\Public\AppData
[2013/05/05 18:28:40 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop
[2009/07/14 00:08:56 | 000,000,000 | R--D | M] -- C:\Users\Public\Documents
[2009/07/13 23:54:24 | 000,000,000 | R--D | M] -- C:\Users\Public\Downloads
[2009/07/13 21:34:59 | 000,000,000 | RH-D | M] -- C:\Users\Public\Favorites
[2009/07/13 23:54:24 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries
[2009/07/13 23:54:24 | 000,000,000 | R--D | M] -- C:\Users\Public\Music
[2009/07/13 23:54:24 | 000,000,000 | R--D | M] -- C:\Users\Public\Pictures
[2013/06/17 13:57:59 | 000,000,000 | R--D | M] -- C:\Users\Public\Recorded TV
[2013/05/02 22:54:25 | 000,000,000 | ---D | M] -- C:\Users\Public\Roaming
[2009/07/13 23:54:24 | 000,000,000 | R--D | M] -- C:\Users\Public\Videos
[2013/05/02 23:06:44 | 000,000,000 | ---D | M] -- C:\Users\User\.shsh
[2013/05/02 23:06:47 | 000,000,000 | -H-D | M] -- C:\Users\User\AppData
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\Application Data
[2013/06/05 17:29:59 | 000,000,000 | R--D | M] -- C:\Users\User\Contacts
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\Cookies
[2014/01/31 21:11:16 | 000,000,000 | R--D | M] -- C:\Users\User\Desktop
[2013/11/11 11:22:53 | 000,000,000 | R--D | M] -- C:\Users\User\Documents
[2013/08/19 14:13:34 | 000,000,000 | R--D | M] -- C:\Users\User\Downloads
[2013/11/30 23:09:02 | 000,000,000 | R--D | M] -- C:\Users\User\Favorites
[2014/01/25 21:21:22 | 000,000,000 | R--D | M] -- C:\Users\User\Links
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\Local Settings
[2013/06/05 17:29:59 | 000,000,000 | R--D | M] -- C:\Users\User\Music
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\My Documents
[2013/02/24 15:51:27 | 000,000,000 | ---D | M] -- C:\Users\User\My PaperPort.com
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\NetHood
[2013/12/05 09:37:25 | 000,000,000 | R--D | M] -- C:\Users\User\Pictures
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\PrintHood
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\Recent
[2013/05/02 23:09:10 | 000,000,000 | ---D | M] -- C:\Users\User\Roaming
[2013/06/05 17:29:59 | 000,000,000 | R--D | M] -- C:\Users\User\Saved Games
[2013/06/05 17:29:59 | 000,000,000 | R--D | M] -- C:\Users\User\Searches
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\SendTo
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\Start Menu
[2013/05/02 22:43:41 | 000,000,000 | -HSD | M] -- C:\Users\User\Templates
[2013/06/05 17:29:59 | 000,000,000 | R--D | M] -- C:\Users\User\Videos
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 145 bytes -> C:\Users\All Users\Temp:FD9CE1F3
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:FD9CE1F3
< End of report >