Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/18 19:26:44 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Roro\Desktop\OTL.exe
[2012/06/18 18:59:56 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/18 18:59:54 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\temp
[2012/06/18 18:49:51 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/06/18 18:33:15 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/18 18:33:15 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/18 18:33:14 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/18 18:32:58 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/18 18:32:29 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/06/18 18:32:15 | 004,560,591 | R--- | C] (Swearware) -- C:\Users\Roro\Desktop\ComboFix.exe
[2012/06/18 08:15:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/18 04:16:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/06/17 23:12:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/06/17 23:12:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/06/17 18:57:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/06/17 18:57:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/06/17 18:47:07 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{45B85C41-F061-4ABB-99CC-0F4BA49CBFAE}
[2012/06/17 15:36:27 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/16 21:59:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/06/16 21:59:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/06/16 21:20:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/06/16 21:20:17 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/06/16 21:07:35 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{D11F1A42-0F75-4FC6-9C5F-783B8E24518E}
[2012/06/16 19:14:47 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{CEA6F0BE-13EE-4FEA-89DC-F2CF15CC5D31}
[2012/06/16 17:08:40 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Roaming\Malwarebytes
[2012/06/16 17:08:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/16 15:39:24 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{30F3A819-689E-4B9A-88FF-46742C398D05}
[2012/06/15 18:31:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client(14)
[2012/06/15 18:25:42 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{30BDB61B-6C5A-4778-9D53-13513BDC9F95}
[2012/06/15 16:50:21 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{3E302D9C-4120-453A-858A-CA45961E5784}
[2012/06/14 17:33:46 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{89289C1D-E075-4134-A416-03E4E20D1500}
[2012/06/14 10:47:10 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F8C7771A-9574-4810-B8B4-06194CB59F07}
[2012/06/14 10:46:57 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{A861B378-DB20-4E28-A841-7ABFAE244D90}
[2012/06/13 19:43:03 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{BE8CB79F-715F-4778-8E8F-CA9F2570F236}
[2012/06/13 16:49:52 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{B1BC5B80-8209-4300-8164-0F549B99CFA9}
[2012/06/13 16:49:33 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{ABCF5D9D-0A75-4EDD-9319-4E367BEF54CD}
[2012/06/13 09:37:31 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{8EB03730-13DF-4619-8953-F1D6B7C0A67A}
[2012/06/12 16:01:18 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{51908B7C-533F-4CAE-BF0B-00A42DEECEA9}
[2012/06/11 19:37:39 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F7F570EF-817E-4929-BAAC-9B1CFF032A52}
[2012/06/11 19:37:25 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{6C7A7D6F-8923-4DD3-9E85-F0C5AE065D45}
[2012/06/11 16:35:14 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{80A49C0A-74EB-4313-927D-CCF24AA8AD45}
[2012/06/11 16:34:48 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{EF670CAA-8CA3-4E6D-ACAF-6BDF28A21F7B}
[2012/06/11 11:48:14 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{77AA4C5C-E6D6-4520-A7A0-2C8FA69999EA}
[2012/06/11 11:47:55 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{95E359F8-25E3-4C65-95E5-D0CC607A99E8}
[2012/06/10 20:00:31 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F991EAF3-0495-4BE3-A43D-E9A3A3CC36F9}
[2012/06/10 16:14:35 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{727DA021-3B55-4F06-A94C-B26FFB223444}
[2012/06/10 16:14:18 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{FDC0816C-78F7-4128-9FCB-B23576F39D27}
[2012/06/10 11:27:15 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{7190957A-EC97-492A-AADF-902D6DB6425E}
[2012/06/10 11:26:57 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{1A8DCCB9-3674-471B-807E-EAB5ACF956FB}
[2012/06/09 09:37:04 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{637696D9-349F-4AC9-9F14-A398CC9709C8}
[2012/06/09 09:36:44 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{59DE2CBD-EBAB-471C-8A87-C1DA2CB90A5D}
[2012/06/08 20:08:31 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{28345844-4C0A-4BD7-B361-5CD77071F282}
[2012/06/08 20:08:18 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{70AFA0F3-3F13-4596-BCAA-9B78D5C66ED7}
[2012/06/08 17:03:33 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F88578FC-690D-446D-B06F-D298D2EC585B}
[2012/06/08 17:03:14 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{31D342E6-DEB0-45BC-84C8-E328F278E1BA}
[2012/06/07 18:43:31 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012/06/07 12:07:47 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/06/07 11:15:35 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{2B1541D8-6A6B-49D2-B2FA-F721570C4961}
[2012/06/06 23:14:09 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{B135E15B-4397-47CD-A672-D5F6FC975F55}
[2012/06/06 23:13:56 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{CD292F6F-4411-498F-B542-F809D6881A02}
[2012/06/06 21:49:08 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{9F1D4578-AFD3-4759-B600-7FD8B1F6CF6A}
[2012/06/06 21:48:32 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{854315AD-8C4E-408E-A66C-D5F5FCF4ECFC}
[2012/06/06 17:17:21 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{B8A6037B-DC18-4A2F-8673-0ECFC558638C}
[2012/06/06 17:17:07 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{AFFA9265-33A9-41D2-B487-F776CCBACF6B}
[2012/06/05 15:44:58 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{B8FCA6A8-1318-4CBA-9311-3E6B575F246D}
[2012/06/05 15:44:38 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{571416F7-983F-41D2-BE16-71ABF1B3439A}
[2012/06/04 20:02:32 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{3FC7BE79-E63C-4790-88AC-8212ED07FA53}
[2012/06/04 20:02:07 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{93D4133B-2227-495C-94D3-78EB54409D02}
[2012/06/04 17:22:47 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{685DBB42-08D1-40DD-A5E0-C17AF998D3E9}
[2012/06/04 17:22:27 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{8CAFD218-DC35-45A0-A581-125EABDA4143}
[2012/06/03 20:00:47 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{7731C29B-198E-49A7-B166-62087500708F}
[2012/06/03 20:00:32 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F9840410-2AE6-4A13-96F2-EEF56DD6AB1A}
[2012/06/03 19:54:31 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{113B3250-4819-47D8-B977-3754BDFE6FD1}
[2012/06/03 19:54:11 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{636775A9-2A84-4EBA-ACA0-8873F317131C}
[2012/06/03 19:24:02 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{174D23F7-CBD4-4743-83DA-D9042D0FDB71}
[2012/06/03 17:56:41 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{2D7749E0-2417-4555-9127-2D2CA050AEFD}
[2012/06/03 17:56:25 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{06559D90-A225-4F13-8622-B0BF818F81E3}
[2012/06/03 10:38:35 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{69B1A7E5-E1F5-4939-B31C-8BF79DB30F87}
[2012/06/03 10:38:24 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{846C74C7-1B36-4490-A49C-CD742B16989D}
[2012/06/02 20:25:04 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{03713A32-D6AC-497A-94F2-293A70FA0D00}
[2012/06/02 20:24:52 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{56EEEF16-7EDF-426B-AD7B-7E5106B9FDB5}
[2012/06/02 18:02:13 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{9C7D5DF1-3E8E-4A2B-B469-FCF089D989E2}
[2012/06/02 18:01:57 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{4D6162DB-7CC6-4F76-96A2-6984BD635FF9}
[2012/06/02 14:48:53 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{646BDDBC-96B4-4FE2-AE07-E742AD8ECC6A}
[2012/06/02 14:48:42 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{700ABBF7-5892-4CB2-8C13-404E2D762F7E}
[2012/06/02 12:18:31 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{42AC4235-38E2-4908-957B-2E783C41A6FA}
[2012/06/02 12:18:13 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{5350CB6A-A99C-4BA8-8848-F5D86CAB685F}
[2012/06/01 19:54:39 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{84500295-5605-4483-AFDD-89E2D1ABF9B0}
[2012/06/01 19:54:25 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{99FCF2A8-ED2A-49AB-A36D-532D8B0A3789}
[2012/06/01 17:37:48 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{FEECB48D-6F14-45B2-AA1B-076A8CA7CED7}
[2012/06/01 17:37:32 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{17BACA8A-26CA-49D6-BD82-827D93A3E756}
[2012/05/31 20:00:21 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{588519F3-0981-4294-9C5F-0220AB2F098F}
[2012/05/31 20:00:06 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{7697C496-6FEB-4FCF-B345-97AFA01B2DB8}
[2012/05/31 16:42:38 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{1FA694EC-4AEC-44B6-B45F-F5318CE557C4}
[2012/05/31 16:42:13 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{638D4115-2680-4EEA-BD6C-4DFC9DE8595E}
[2012/05/30 21:04:03 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{046E3267-6250-493B-82E4-BF49986679F2}
[2012/05/30 21:03:53 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{A4CA15A9-9CD8-4691-BF9D-D79D40B79A38}
[2012/05/30 20:11:07 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{C9335B84-0FD6-403D-98A0-F28CE67FEAE1}
[2012/05/30 20:10:42 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F400EF32-B650-4C29-B88A-AA0FF8CA56FC}
[2012/05/30 12:11:05 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{A845C48C-5545-4989-8756-68EEFCC9B982}
[2012/05/30 12:10:49 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{BE3EA9AC-49C1-4383-B38B-A903E01F48B0}
[2012/05/29 20:02:33 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{69B29B92-9C71-4E5B-94D8-7EC40BF1C310}
[2012/05/29 20:02:20 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{DD049F7C-4BC9-497A-86C1-12979BD89294}
[2012/05/29 15:12:23 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{00E85362-8517-485C-BB65-06AECBDCD7F5}
[2012/05/29 15:12:12 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{862D4347-9AF5-4820-ACA9-F13F72677949}
[2012/05/28 16:55:29 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{391E7C5E-1170-4140-99EC-1A780E23782B}
[2012/05/28 16:54:54 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{C58FF71E-F463-42BE-980F-B4D9971F654D}
[2012/05/27 11:40:58 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{28772F21-660E-456E-A715-83DAEF3286F0}
[2012/05/27 11:40:41 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{B6295E86-1513-4589-A77C-7BCD8FF63FF6}
[2012/05/26 19:50:01 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{ED059805-F70A-4EA0-AB95-D643814FF04A}
[2012/05/26 19:49:40 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{82F4EACB-06D0-4110-888F-F5643B3F7CB0}
[2012/05/26 11:08:31 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{496DD109-C654-4D33-86EA-B01464FE45A9}
[2012/05/26 11:08:12 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{C8122670-2520-4BBD-84DD-4455C7547218}
[2012/05/26 10:54:43 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{AD782732-01DB-43B1-9B2C-3CC9727366CC}
[2012/05/25 19:46:20 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{92FA4555-D9BA-4184-B1C5-24C4116E89BE}
[2012/05/25 15:41:16 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{61A435BE-75F0-4D7C-B68E-13037759B81B}
[2012/05/25 15:40:58 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F24B54E3-B447-4172-9373-1C8198A6C4DD}
[2012/05/24 10:33:24 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{D90FDD4C-9DDF-4012-918D-F7F546EDCD63}
[2012/05/24 10:33:13 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{106953E0-BE1A-4B2E-A4B8-3EBAA1619276}
[2012/05/23 20:20:24 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{D0FFEF85-2BC2-4430-BBF9-ECDABD90291D}
[2012/05/23 20:20:04 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{A07E62A2-0F88-47D3-A729-66C9BFFB6BC3}
[2012/05/23 19:34:50 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{861CCAEE-E170-497F-A744-29E1D05DA566}
[2012/05/23 17:32:07 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{4419CECB-FB57-4569-908D-3FDB513B027B}
[2012/05/23 17:31:47 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{EFC8725F-4B13-47EC-B685-692001BFA6BD}
[2012/05/23 10:54:03 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{48108118-0A1D-4ADF-B56B-DD00638C70B5}
[2012/05/23 10:53:49 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{12F3B0E5-3328-44E8-923E-C0442AF85E79}
[2012/05/22 19:42:13 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F8B3DAD3-7E49-42EA-A554-3CFEE0CA81AF}
[2012/05/22 19:42:02 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{9DEF3C5E-5D98-4655-B1D9-E27A0EBDE5A1}
[2012/05/22 16:05:17 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{05C69F08-7C83-4D15-BD90-BC80DE90DBE9}
[2012/05/22 16:04:57 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{83491537-7EB2-40C5-83A6-4B79A9B3C61E}
[2012/05/22 08:33:25 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{F0003ED5-A82C-4657-ADF7-6C47B3E01C4A}
[2012/05/22 08:33:14 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{6874F5E3-5AEA-4735-81AD-EA09EFFA3564}
[2012/05/21 21:00:16 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{7BE247FC-A7A7-443E-858E-433E72CE21A7}
[2012/05/21 21:00:03 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{C2F5C679-57DA-4CF1-A591-57C59F6758AF}
[2012/05/21 09:56:08 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{4CF6E258-CD61-4DA4-A513-E84A7C1A1846}
[2012/05/21 09:55:51 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{05F11AB5-CB6A-429E-B425-3A98C7E119DD}
[2012/05/20 18:59:38 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{31BD0373-DE32-4F72-A020-76B81250D9BD}
[2012/05/20 18:59:17 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{9132196D-3945-4075-B5AE-61EA67075A1E}
[2012/05/20 18:04:59 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{8D34227C-3B7E-4249-9511-C54F8F70D685}
[2012/05/20 18:04:48 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{203BB117-F8D1-42D3-8F92-97E6C17ACB6C}
[2012/05/20 11:28:52 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{C6C4C08A-0C13-4ACC-B147-ECA73F47725E}
[2012/05/19 20:33:02 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{CF3A16B4-FF61-492C-8F4A-A0BD77194696}
[2012/05/19 20:32:43 | 000,000,000 | ---D | C] -- C:\Users\Roro\AppData\Local\{77068694-24A6-4C20-AE83-01EBBE75E45B}
========== Files - Modified Within 30 Days ==========
[2012/06/18 19:51:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/18 19:45:15 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/18 19:44:48 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/18 19:44:48 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/18 19:44:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/18 19:27:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/18 18:49:47 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/18 18:28:15 | 000,706,952 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/18 18:28:15 | 000,598,374 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/18 18:28:15 | 000,105,348 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/18 18:18:42 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-619972548-2511501635-1043203753-1000Core.job
[2012/06/18 18:16:34 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-619972548-2511501635-1043203753-1000UA.job
[2012/06/18 18:16:16 | 000,000,832 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012/06/18 08:15:48 | 000,001,654 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/18 04:16:37 | 000,001,716 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/06/17 23:50:43 | 000,334,048 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/17 23:08:12 | 000,001,877 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/06/17 14:32:50 | 000,001,460 | ---- | M] () -- C:\Users\Roro\AppData\Local\d3d9caps64.dat
[2012/06/16 21:59:57 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/16 21:59:29 | 000,713,686 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/16 21:38:16 | 000,506,616 | ---- | M] () -- C:\Users\Roro\Documents\cc_20120616_213745.reg
[2012/06/16 21:20:21 | 000,000,770 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/16 17:41:20 | 004,560,591 | R--- | M] (Swearware) -- C:\Users\Roro\Desktop\ComboFix.exe
[2012/06/15 13:23:30 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Roro\Desktop\OTL.exe
[2012/06/12 21:52:07 | 000,000,496 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Roro.job
[2012/06/10 21:15:36 | 000,011,110 | ---- | M] () -- C:\Users\Roro\AppData\Roaming\wklnhst.dat
[2012/06/03 19:48:11 | 001,732,608 | ---- | M] () -- C:\Users\Roro\Desktop\Pictures 4 Projects.wps
[2012/05/21 22:51:52 | 000,012,800 | ---- | M] () -- C:\Users\Roro\Music Paragraph.wps
========== Files Created - No Company Name ==========
[2012/06/18 18:33:15 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/18 18:33:15 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/18 18:33:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/18 18:33:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/18 18:33:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/18 08:15:48 | 000,001,654 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/18 04:16:37 | 000,001,716 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/06/17 23:03:15 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/06/17 23:03:15 | 000,001,877 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/06/16 21:59:32 | 000,001,826 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/16 21:37:53 | 000,506,616 | ---- | C] () -- C:\Users\Roro\Documents\cc_20120616_213745.reg
[2012/06/16 21:20:20 | 000,000,770 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/03 19:48:11 | 001,732,608 | ---- | C] () -- C:\Users\Roro\Desktop\Pictures 4 Projects.wps
[2012/05/21 22:38:04 | 000,012,800 | ---- | C] () -- C:\Users\Roro\Music Paragraph.wps
[2011/09/14 14:10:24 | 000,000,138 | ---- | C] () -- C:\Windows\vsfilter.INI
[2011/09/14 12:21:15 | 000,000,598 | ---- | C] () -- C:\Windows\SysWow64\bdsecushr.dat
[2011/07/10 14:10:16 | 000,000,008 | ---- | C] () -- C:\Users\Roro\AppData\Roaming\RSBuddy Login.ini
[2011/07/04 10:55:36 | 000,000,178 | ---- | C] () -- C:\Users\Roro\AppData\Roaming\RSBuddy_addy4141.ini
[2011/07/02 16:58:46 | 000,000,000 | ---- | C] () -- C:\Users\Roro\AppData\Local\{59DD9AE8-DD16-42C1-A154-AE4968814F44}
[2011/03/07 19:21:04 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll
[2011/03/07 19:21:03 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll
[2010/12/13 21:53:02 | 000,713,686 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== LOP Check ==========
[2011/05/19 21:30:09 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\360safe
[2010/01/10 17:32:27 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\5600-6600 Series
[2012/06/18 18:47:13 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\Baidu
[2009/05/27 12:45:38 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/02/04 01:23:32 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\CometPlayer
[2011/10/27 10:36:50 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\Garmin
[2009/04/04 08:08:44 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\InterVideo
[2010/01/10 17:31:12 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\Lexmark Productivity Studio
[2009/04/22 06:22:58 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\LG Electronics
[2011/09/07 15:12:41 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\PPStream
[2011/02/10 21:07:52 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\Registry Mechanic
[2011/12/09 18:32:00 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\SoftGrid Client
[2011/11/20 10:29:34 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\TeamViewer
[2009/04/04 08:11:51 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\Template
[2011/02/04 01:23:39 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\tigerplayer
[2011/07/11 17:37:25 | 000,000,000 | ---D | M] -- C:\Users\Roro\AppData\Roaming\TP
[2012/06/18 18:18:42 | 000,000,902 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-619972548-2511501635-1043203753-1000Core.job
[2012/06/18 18:16:34 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-619972548-2511501635-1043203753-1000UA.job
[2012/06/18 18:48:12 | 000,032,592 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2008/08/12 13:26:01 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2012/06/18 18:59:52 | 000,016,637 | ---- | M] () -- C:\ComboFix.txt
[2011/01/21 13:52:20 | 000,000,090 | -HS- | M] () -- C:\desktop.ini
[2012/06/17 18:40:21 | 000,077,653 | ---- | M] () -- C:\FRST.txt
[2008/09/25 00:02:00 | 000,000,187 | ---- | M] () -- C:\Installer_Setup.log
[2006/12/01 20:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2012/06/18 19:44:19 | 144,834,559 | -HS- | M] () -- C:\pagefile.sys
[2008/09/24 23:57:04 | 000,393,222 | ---- | M] () -- C:\vcredist_x86.log
< %systemroot%\Fonts\*.com >
[2006/11/02 08:06:41 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:06:41 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:06:41 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/13 23:35:47 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:35:48 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/02/10 18:31:43 | 000,001,666 | -H-- | M] () -- C:\Users\Roro\AppData\Roaming\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2008/01/20 20:21:59 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/01 10:09:33 | 000,000,286 | -HS- | M] () -- C:\Users\Roro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/06/16 17:41:20 | 004,560,591 | R--- | M] (Swearware) -- C:\Users\Roro\Desktop\ComboFix.exe
[2012/06/15 13:23:30 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Roro\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/06/18 19:27:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/18 18:18:42 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-619972548-2511501635-1043203753-1000Core.job
[2012/06/18 18:16:34 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-619972548-2511501635-1043203753-1000UA.job
[2012/06/18 18:16:16 | 000,000,832 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012/06/18 19:45:15 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/18 19:51:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/12 21:52:07 | 000,000,496 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Roro.job
[2012/06/18 19:44:56 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/06/18 18:48:12 | 000,032,592 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/04/03 21:43:34 | 000,000,402 | -HS- | M] () -- C:\Users\Roro\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/01/06 22:39:20 | 000,000,178 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2012/06/18 01:15:46 | 000,000,178 | ---- | M] () -- C:\ProgramData\lxdu.log
[2011/03/04 14:33:43 | 000,001,042 | ---- | M] () -- C:\ProgramData\lxduDiagnostics.log
[2012/05/10 10:57:16 | 000,029,088 | ---- | M] () -- C:\ProgramData\lxduJSW.log
[2010/01/10 17:04:06 | 000,000,000 | ---- | M] () -- C:\ProgramData\UpdaterLog.txt
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
< dir /b "%systemroot%\*.exe" | find /I " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP

1B5B4F1
< End of report >