Part 2 of OTL.txt:
========== Files/Folders - Created Within 30 Days ==========
[2012/06/17 00:39:51 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\R830-10C\Desktop\OTL.exe
[2012/06/17 00:37:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/16 18:52:40 | 000,000,000 | ---D | C] -- C:\windows\temp
[2012/06/16 18:35:17 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\VirtualStore
[2012/06/14 10:07:27 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\R830-10C\Desktop\dds.scr
[2012/06/13 13:07:24 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2012/06/13 13:07:24 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2012/06/13 13:07:24 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2012/06/13 13:07:18 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2012/06/13 13:05:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/13 13:02:27 | 004,559,503 | R--- | C] (Swearware) -- C:\Users\R830-10C\Desktop\ComboFix.exe
[2012/06/13 10:35:47 | 000,000,000 | R--D | C] -- C:\Users\R830-10C\Documents\Scanned Documents
[2012/06/13 10:35:46 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\Fax
[2012/06/12 22:34:41 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/12 17:07:04 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Malwarebytes
[2012/06/12 17:05:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/12 17:05:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/12 17:05:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/06/12 12:22:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/06/12 00:18:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/06/12 00:18:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/06/07 20:04:56 | 000,000,000 | -HSD | C] -- C:\windows\SysNative\%APPDATA%
[2012/06/03 12:09:53 | 000,000,000 | R--D | C] -- C:\Users\R830-10C\Dropbox
[2012/06/03 12:07:58 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/06/03 12:06:36 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Dropbox
[2012/05/30 13:06:49 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Apple Computer
[2012/05/30 09:44:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WMP Tag Plus
[2012/05/30 05:29:23 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Apple Computer
[2012/05/29 23:00:18 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\order_receipt_cd_final.php_files
[2012/05/29 16:50:48 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\Downloaded Radio
[2012/05/29 16:49:22 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\www.nerdoftheherd.com
[2012/05/29 16:49:19 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\www.nerdoftheherd.com
[2012/05/29 16:23:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FLV_Extract_v1.6.2
[2012/05/29 15:21:59 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\FLV Extract
[2012/05/29 14:59:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/05/29 14:59:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/05/29 14:59:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2012/05/29 14:58:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2012/05/29 14:58:34 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Apple
[2012/05/29 14:58:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2012/05/29 14:58:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2012/05/29 14:36:57 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\Topsevenreviews
[2012/05/29 14:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topsevenreviews
[2012/05/29 14:36:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Topsevenreviews
[2012/05/29 14:00:33 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Applian
[2012/05/29 13:36:17 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\My Streaming Media
[2012/05/29 13:36:14 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Jaksta_Technologies_Pty_L
[2012/05/29 13:35:08 | 000,033,888 | ---- | C] (Applian Technologies Inc.) -- C:\windows\SysNative\drivers\appliand.sys
[2012/05/29 13:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies
[2012/05/29 13:34:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Applian Technologies
[2012/05/29 13:34:44 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Replay Media Catcher 4
[2012/05/29 13:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Applian
[2012/05/24 15:21:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2012/05/24 15:19:49 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\uTorrent
[2012/05/21 06:11:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/21 06:10:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/05/21 06:10:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/17 00:45:19 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/17 00:45:19 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/17 00:39:55 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\R830-10C\Desktop\OTL.exe
[2012/06/17 00:37:45 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/06/17 00:37:40 | 2071,531,519 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/17 00:35:00 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/06/17 00:17:48 | 000,730,554 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/06/17 00:17:48 | 000,631,004 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/06/17 00:17:48 | 000,111,798 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/06/16 18:47:52 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2012/06/16 18:37:38 | 004,559,503 | R--- | M] (Swearware) -- C:\Users\R830-10C\Desktop\ComboFix.exe
[2012/06/13 06:43:40 | 000,002,050 | ---- | M] () -- C:\Users\R830-10C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
[2012/06/12 17:01:44 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\R830-10C\Desktop\dds.scr
[2012/06/12 00:19:06 | 000,001,945 | ---- | M] () -- C:\windows\epplauncher.mif
[2012/06/12 00:18:45 | 000,736,096 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/06/12 00:14:38 | 000,067,584 | --S- | M] () -- C:\windows\bootstat(23).dat
[2012/06/11 16:38:05 | 000,000,134 | ---- | M] () -- C:\Users\R830-10C\Desktop\Microsoft Fix it.url
[2012/06/07 20:14:02 | 000,001,316 | ---- | M] () -- C:\Users\Public\Desktop\Replay Media Catcher 4.lnk
[2012/06/03 12:09:53 | 000,001,059 | ---- | M] () -- C:\Users\R830-10C\Desktop\Dropbox.lnk
[2012/05/29 23:00:19 | 000,007,145 | ---- | M] () -- C:\Users\R830-10C\Documents\order_receipt_cd_final.php.htm
[2012/05/29 16:24:01 | 000,001,487 | ---- | M] () -- C:\Users\R830-10C\Desktop\FLVExtract.lnk
[2012/05/29 14:59:27 | 000,001,856 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/05/29 14:36:55 | 000,001,430 | ---- | M] () -- C:\Users\R830-10C\Desktop\Free FLV to Audio Converter.lnk
[2012/05/24 15:21:07 | 000,000,982 | ---- | M] () -- C:\Users\R830-10C\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/05/24 15:21:07 | 000,000,958 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/13 13:07:24 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2012/06/13 13:07:24 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2012/06/13 13:07:24 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2012/06/13 13:07:24 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2012/06/13 13:07:24 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2012/06/12 00:18:47 | 000,001,926 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/11 16:38:05 | 000,000,134 | ---- | C] () -- C:\Users\R830-10C\Desktop\Microsoft Fix it.url
[2012/06/03 12:09:53 | 000,001,059 | ---- | C] () -- C:\Users\R830-10C\Desktop\Dropbox.lnk
[2012/05/29 23:00:18 | 000,007,145 | ---- | C] () -- C:\Users\R830-10C\Documents\order_receipt_cd_final.php.htm
[2012/05/29 16:24:01 | 000,001,487 | ---- | C] () -- C:\Users\R830-10C\Desktop\FLVExtract.lnk
[2012/05/29 14:59:27 | 000,001,856 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/05/29 14:58:33 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/05/29 14:36:55 | 000,001,430 | ---- | C] () -- C:\Users\R830-10C\Desktop\Free FLV to Audio Converter.lnk
[2012/05/29 13:35:06 | 000,001,316 | ---- | C] () -- C:\Users\Public\Desktop\Replay Media Catcher 4.lnk
[2012/05/24 15:21:07 | 000,000,982 | ---- | C] () -- C:\Users\R830-10C\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/05/24 15:21:07 | 000,000,958 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/03/12 13:19:05 | 000,010,240 | ---- | C] () -- C:\windows\SysWow64\drivers\mdvrmng.sys
[2012/03/10 01:40:54 | 000,819,200 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2012/03/10 01:40:54 | 000,180,224 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2012/03/10 01:09:42 | 000,003,417 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp Shorten Codec.dat
[2012/03/10 01:09:08 | 000,003,297 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp m4a Codec.dat
[2012/03/10 01:08:30 | 000,003,018 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp WavPack Codec.dat
[2012/03/10 01:07:55 | 000,003,149 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
[2012/03/10 01:07:22 | 000,017,755 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2012/03/10 01:07:21 | 000,653,176 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall.exe
[2012/03/10 00:35:59 | 000,736,096 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011/07/15 21:01:00 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI
[2011/04/05 04:07:00 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/04/05 04:06:58 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/04/05 04:06:58 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/02/04 03:56:58 | 000,066,856 | ---- | C] () -- C:\windows\SysWow64\SynTPEnhPS.dll
========== LOP Check ==========
[2012/03/12 13:19:38 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Birdstep Technology
[2012/03/13 14:23:27 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\dBpoweramp
[2012/06/14 06:26:37 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Dropbox
[2012/05/29 15:22:05 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\FLV Extract
[2012/06/13 13:12:10 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Free Download Manager
[2012/05/16 16:36:52 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Leadertech
[2012/06/09 14:53:14 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Mp3tag
[2012/05/29 13:36:17 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Replay Media Catcher 4
[2012/06/16 08:34:47 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\SoftGrid Client
[2012/04/05 12:28:31 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Toshiba
[2012/03/11 20:07:27 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\TOSHIBA Online Product Information
[2012/03/10 11:41:12 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\TP
[2012/06/11 15:28:59 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\uTorrent
[2011/10/06 17:07:10 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\WinBatch
[2012/05/29 16:49:19 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\www.nerdoftheherd.com
[2012/05/30 09:59:41 | 000,024,018 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/11/21 04:23:51 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2011/05/09 09:19:03 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012/06/16 18:52:39 | 000,030,169 | ---- | M] () -- C:\ComboFix.txt
[2012/03/12 13:19:23 | 000,005,054 | ---- | M] () -- C:\debug.txt
[2012/06/17 00:37:40 | 2071,531,519 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/17 00:37:44 | 4193,701,887 | -HS- | M] () -- C:\pagefile.sys
[2008/07/08 23:52:19 | 000,022,528 | ---- | M] () -- C:\Wedding Order Of Service.doc
< %systemroot%\Fonts\*.com >
[2009/07/14 06:32:31 | 000,026,040 | ---- | M] () -- C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 06:32:31 | 000,026,489 | ---- | M] () -- C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 06:32:31 | 000,029,779 | ---- | M] () -- C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 06:32:31 | 000,043,318 | ---- | M] () -- C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 21:49:50 | 000,000,065 | ---- | M] () -- C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 05:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/09 17:57:57 | 000,000,221 | -HS- | M] () -- C:\Users\R830-10C\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/06/16 18:37:38 | 004,559,503 | R--- | M] (Swearware) -- C:\Users\R830-10C\Desktop\ComboFix.exe
[2012/06/17 00:39:55 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\R830-10C\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/06/17 00:35:00 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/06/17 00:37:51 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2012/05/30 09:59:41 | 000,024,018 | ---- | M] () -- C:\windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2011/12/11 20:16:30 | 000,000,922 | ---- | M] () -- C:\windows\AppPatch\Custom\{00a8ce68-cb2e-4652-aecd-c05c0d9d53a7}.sdb
[2008/12/12 10:40:24 | 000,001,036 | R--- | M] () -- C:\windows\AppPatch\Custom\{22950922-8438-4c84-80d5-a17e6c2a5717}.sdb
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 22:20:04 | 000,000,802 | ---- | M] () -- C:\windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/07/15 20:38:59 | 000,008,192 | ---- | M] () -- C:\windows\SECURITY\Database\edb.chk
[2011/07/15 20:38:59 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edb.log
[2011/07/15 20:24:28 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00001.jrs
[2011/07/15 20:24:28 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00002.jrs
[2011/07/15 20:38:59 | 001,056,768 | ---- | M] () -- C:\windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/03/10 04:59:41 | 000,000,402 | -HS- | M] () -- C:\Users\R830-10C\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:3B71D0B4
< End of report >
========== Files/Folders - Created Within 30 Days ==========
[2012/06/17 00:39:51 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\R830-10C\Desktop\OTL.exe
[2012/06/17 00:37:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/16 18:52:40 | 000,000,000 | ---D | C] -- C:\windows\temp
[2012/06/16 18:35:17 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\VirtualStore
[2012/06/14 10:07:27 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\R830-10C\Desktop\dds.scr
[2012/06/13 13:07:24 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2012/06/13 13:07:24 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2012/06/13 13:07:24 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2012/06/13 13:07:18 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2012/06/13 13:05:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/13 13:02:27 | 004,559,503 | R--- | C] (Swearware) -- C:\Users\R830-10C\Desktop\ComboFix.exe
[2012/06/13 10:35:47 | 000,000,000 | R--D | C] -- C:\Users\R830-10C\Documents\Scanned Documents
[2012/06/13 10:35:46 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\Fax
[2012/06/12 22:34:41 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/12 17:07:04 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Malwarebytes
[2012/06/12 17:05:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/12 17:05:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/12 17:05:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/06/12 12:22:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/06/12 00:18:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/06/12 00:18:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/06/07 20:04:56 | 000,000,000 | -HSD | C] -- C:\windows\SysNative\%APPDATA%
[2012/06/03 12:09:53 | 000,000,000 | R--D | C] -- C:\Users\R830-10C\Dropbox
[2012/06/03 12:07:58 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/06/03 12:06:36 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Dropbox
[2012/05/30 13:06:49 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Apple Computer
[2012/05/30 09:44:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WMP Tag Plus
[2012/05/30 05:29:23 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Apple Computer
[2012/05/29 23:00:18 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\order_receipt_cd_final.php_files
[2012/05/29 16:50:48 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\Downloaded Radio
[2012/05/29 16:49:22 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\www.nerdoftheherd.com
[2012/05/29 16:49:19 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\www.nerdoftheherd.com
[2012/05/29 16:23:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FLV_Extract_v1.6.2
[2012/05/29 15:21:59 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\FLV Extract
[2012/05/29 14:59:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/05/29 14:59:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/05/29 14:59:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2012/05/29 14:58:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2012/05/29 14:58:34 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Apple
[2012/05/29 14:58:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2012/05/29 14:58:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2012/05/29 14:36:57 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\Topsevenreviews
[2012/05/29 14:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topsevenreviews
[2012/05/29 14:36:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Topsevenreviews
[2012/05/29 14:00:33 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Applian
[2012/05/29 13:36:17 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\Documents\My Streaming Media
[2012/05/29 13:36:14 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Local\Jaksta_Technologies_Pty_L
[2012/05/29 13:35:08 | 000,033,888 | ---- | C] (Applian Technologies Inc.) -- C:\windows\SysNative\drivers\appliand.sys
[2012/05/29 13:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies
[2012/05/29 13:34:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Applian Technologies
[2012/05/29 13:34:44 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\Replay Media Catcher 4
[2012/05/29 13:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Applian
[2012/05/24 15:21:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2012/05/24 15:19:49 | 000,000,000 | ---D | C] -- C:\Users\R830-10C\AppData\Roaming\uTorrent
[2012/05/21 06:11:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/21 06:10:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/05/21 06:10:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/17 00:45:19 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/17 00:45:19 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/17 00:39:55 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\R830-10C\Desktop\OTL.exe
[2012/06/17 00:37:45 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/06/17 00:37:40 | 2071,531,519 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/17 00:35:00 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/06/17 00:17:48 | 000,730,554 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/06/17 00:17:48 | 000,631,004 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/06/17 00:17:48 | 000,111,798 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/06/16 18:47:52 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2012/06/16 18:37:38 | 004,559,503 | R--- | M] (Swearware) -- C:\Users\R830-10C\Desktop\ComboFix.exe
[2012/06/13 06:43:40 | 000,002,050 | ---- | M] () -- C:\Users\R830-10C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
[2012/06/12 17:01:44 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\R830-10C\Desktop\dds.scr
[2012/06/12 00:19:06 | 000,001,945 | ---- | M] () -- C:\windows\epplauncher.mif
[2012/06/12 00:18:45 | 000,736,096 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/06/12 00:14:38 | 000,067,584 | --S- | M] () -- C:\windows\bootstat(23).dat
[2012/06/11 16:38:05 | 000,000,134 | ---- | M] () -- C:\Users\R830-10C\Desktop\Microsoft Fix it.url
[2012/06/07 20:14:02 | 000,001,316 | ---- | M] () -- C:\Users\Public\Desktop\Replay Media Catcher 4.lnk
[2012/06/03 12:09:53 | 000,001,059 | ---- | M] () -- C:\Users\R830-10C\Desktop\Dropbox.lnk
[2012/05/29 23:00:19 | 000,007,145 | ---- | M] () -- C:\Users\R830-10C\Documents\order_receipt_cd_final.php.htm
[2012/05/29 16:24:01 | 000,001,487 | ---- | M] () -- C:\Users\R830-10C\Desktop\FLVExtract.lnk
[2012/05/29 14:59:27 | 000,001,856 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/05/29 14:36:55 | 000,001,430 | ---- | M] () -- C:\Users\R830-10C\Desktop\Free FLV to Audio Converter.lnk
[2012/05/24 15:21:07 | 000,000,982 | ---- | M] () -- C:\Users\R830-10C\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/05/24 15:21:07 | 000,000,958 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/13 13:07:24 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2012/06/13 13:07:24 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2012/06/13 13:07:24 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2012/06/13 13:07:24 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2012/06/13 13:07:24 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2012/06/12 00:18:47 | 000,001,926 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/11 16:38:05 | 000,000,134 | ---- | C] () -- C:\Users\R830-10C\Desktop\Microsoft Fix it.url
[2012/06/03 12:09:53 | 000,001,059 | ---- | C] () -- C:\Users\R830-10C\Desktop\Dropbox.lnk
[2012/05/29 23:00:18 | 000,007,145 | ---- | C] () -- C:\Users\R830-10C\Documents\order_receipt_cd_final.php.htm
[2012/05/29 16:24:01 | 000,001,487 | ---- | C] () -- C:\Users\R830-10C\Desktop\FLVExtract.lnk
[2012/05/29 14:59:27 | 000,001,856 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/05/29 14:58:33 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/05/29 14:36:55 | 000,001,430 | ---- | C] () -- C:\Users\R830-10C\Desktop\Free FLV to Audio Converter.lnk
[2012/05/29 13:35:06 | 000,001,316 | ---- | C] () -- C:\Users\Public\Desktop\Replay Media Catcher 4.lnk
[2012/05/24 15:21:07 | 000,000,982 | ---- | C] () -- C:\Users\R830-10C\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/05/24 15:21:07 | 000,000,958 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/03/12 13:19:05 | 000,010,240 | ---- | C] () -- C:\windows\SysWow64\drivers\mdvrmng.sys
[2012/03/10 01:40:54 | 000,819,200 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2012/03/10 01:40:54 | 000,180,224 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2012/03/10 01:09:42 | 000,003,417 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp Shorten Codec.dat
[2012/03/10 01:09:08 | 000,003,297 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp m4a Codec.dat
[2012/03/10 01:08:30 | 000,003,018 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp WavPack Codec.dat
[2012/03/10 01:07:55 | 000,003,149 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
[2012/03/10 01:07:22 | 000,017,755 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2012/03/10 01:07:21 | 000,653,176 | ---- | C] () -- C:\windows\SysWow64\SpoonUninstall.exe
[2012/03/10 00:35:59 | 000,736,096 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011/07/15 21:01:00 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI
[2011/04/05 04:07:00 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/04/05 04:06:58 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/04/05 04:06:58 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/02/04 03:56:58 | 000,066,856 | ---- | C] () -- C:\windows\SysWow64\SynTPEnhPS.dll
========== LOP Check ==========
[2012/03/12 13:19:38 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Birdstep Technology
[2012/03/13 14:23:27 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\dBpoweramp
[2012/06/14 06:26:37 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Dropbox
[2012/05/29 15:22:05 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\FLV Extract
[2012/06/13 13:12:10 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Free Download Manager
[2012/05/16 16:36:52 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Leadertech
[2012/06/09 14:53:14 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Mp3tag
[2012/05/29 13:36:17 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Replay Media Catcher 4
[2012/06/16 08:34:47 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\SoftGrid Client
[2012/04/05 12:28:31 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\Toshiba
[2012/03/11 20:07:27 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\TOSHIBA Online Product Information
[2012/03/10 11:41:12 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\TP
[2012/06/11 15:28:59 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\uTorrent
[2011/10/06 17:07:10 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\WinBatch
[2012/05/29 16:49:19 | 000,000,000 | ---D | M] -- C:\Users\R830-10C\AppData\Roaming\www.nerdoftheherd.com
[2012/05/30 09:59:41 | 000,024,018 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/11/21 04:23:51 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2011/05/09 09:19:03 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012/06/16 18:52:39 | 000,030,169 | ---- | M] () -- C:\ComboFix.txt
[2012/03/12 13:19:23 | 000,005,054 | ---- | M] () -- C:\debug.txt
[2012/06/17 00:37:40 | 2071,531,519 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/17 00:37:44 | 4193,701,887 | -HS- | M] () -- C:\pagefile.sys
[2008/07/08 23:52:19 | 000,022,528 | ---- | M] () -- C:\Wedding Order Of Service.doc
< %systemroot%\Fonts\*.com >
[2009/07/14 06:32:31 | 000,026,040 | ---- | M] () -- C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 06:32:31 | 000,026,489 | ---- | M] () -- C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 06:32:31 | 000,029,779 | ---- | M] () -- C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 06:32:31 | 000,043,318 | ---- | M] () -- C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 21:49:50 | 000,000,065 | ---- | M] () -- C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 05:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/09 17:57:57 | 000,000,221 | -HS- | M] () -- C:\Users\R830-10C\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/06/16 18:37:38 | 004,559,503 | R--- | M] (Swearware) -- C:\Users\R830-10C\Desktop\ComboFix.exe
[2012/06/17 00:39:55 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\R830-10C\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/06/17 00:35:00 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/06/17 00:37:51 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2012/05/30 09:59:41 | 000,024,018 | ---- | M] () -- C:\windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2011/12/11 20:16:30 | 000,000,922 | ---- | M] () -- C:\windows\AppPatch\Custom\{00a8ce68-cb2e-4652-aecd-c05c0d9d53a7}.sdb
[2008/12/12 10:40:24 | 000,001,036 | R--- | M] () -- C:\windows\AppPatch\Custom\{22950922-8438-4c84-80d5-a17e6c2a5717}.sdb
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 22:20:04 | 000,000,802 | ---- | M] () -- C:\windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/07/15 20:38:59 | 000,008,192 | ---- | M] () -- C:\windows\SECURITY\Database\edb.chk
[2011/07/15 20:38:59 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edb.log
[2011/07/15 20:24:28 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00001.jrs
[2011/07/15 20:24:28 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00002.jrs
[2011/07/15 20:38:59 | 001,056,768 | ---- | M] () -- C:\windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/03/10 04:59:41 | 000,000,402 | -HS- | M] () -- C:\Users\R830-10C\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:3B71D0B4
< End of report >