second rounf of otl part 3 of 3
========== Files - Modified Within 30 Days ==========
[2011/06/03 05:39:29 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/03 05:38:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/03 05:38:52 | 2145,538,048 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/03 02:18:44 | 000,000,116 | -H-- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/06/02 23:10:56 | 000,932,400 | ---- | M] () -- C:\Documents and Settings\William\Desktop\Norton_Removal_Tool.exe
[2011/06/02 22:39:53 | 000,160,350 | ---- | M] () -- C:\Documents and Settings\William\Desktop\JavaRa.zip
[2011/06/02 21:26:41 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\William\Desktop\OTL.exe
[2011/06/02 21:05:13 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/06/02 20:59:25 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/06/02 19:48:19 | 006,389,088 | ---- | M] (OPSWAT, Inc.) -- C:\Documents and Settings\William\Desktop\AppRemover.exe
[2011/06/02 19:46:40 | 004,111,594 | R--- | M] (Swearware) -- C:\Documents and Settings\William\Desktop\ComboFix.exe
[2011/06/02 05:54:04 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\William\Desktop\RKUnhookerLE.EXE
[2011/06/02 05:49:38 | 000,000,099 | ---- | M] () -- C:\Documents and Settings\William\default.pls
[2011/06/02 05:48:48 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\William\Desktop\MBR.dat
[2011/06/02 05:44:11 | 000,589,632 | ---- | M] (AVAST Software) -- C:\Documents and Settings\William\Desktop\aswMBR.exe
[2011/06/01 19:57:19 | 000,607,294 | R--- | M] (Swearware) -- C:\Documents and Settings\William\Desktop\dds.scr
[2011/06/01 16:00:26 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\William\Desktop\fbuqgtev.exe
[2011/06/01 10:45:23 | 000,000,644 | RHS- | M] () -- C:\Documents and Settings\William\ntuser.pol
[2011/05/31 21:46:38 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\William\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/31 16:35:07 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\William\Desktop\mbam-setup-1.50.1.1100.exe
[2011/05/31 15:29:52 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\William\Desktop\Shortcut to firefox.exe.lnk
[2011/05/31 13:42:18 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/05/31 11:13:04 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/05/30 12:48:02 | 000,000,284 | -H-- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/28 00:01:50 | 000,000,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\22339364
[2011/05/26 11:39:16 | 000,052,560 | ---- | M] () -- C:\Documents and Settings\William\Desktop\2011052609584429.pdf
[2011/05/12 12:25:08 | 000,800,007 | ---- | M] () -- C:\Documents and Settings\William\Desktop\Raid Preparation.pdf
[2011/05/10 08:10:59 | 000,040,112 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/05/10 08:10:55 | 000,199,304 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/05/10 08:03:54 | 000,441,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/05/10 08:03:44 | 000,307,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/05/10 08:02:37 | 000,049,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/05/10 08:02:25 | 000,102,616 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/05/10 08:02:22 | 000,096,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/05/10 07:59:56 | 000,025,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/05/10 07:59:37 | 000,030,808 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/05/10 07:59:35 | 000,019,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/05/06 16:49:18 | 009,164,138 | ---- | M] () -- C:\Documents and Settings\William\Desktop\02 Rock That Body.m4a
[2011/05/06 14:39:16 | 000,060,452 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/05/05 08:00:39 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\William\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/02 23:10:55 | 000,932,400 | ---- | C] () -- C:\Documents and Settings\William\Desktop\Norton_Removal_Tool.exe
[2011/06/02 22:39:52 | 000,160,350 | ---- | C] () -- C:\Documents and Settings\William\Desktop\JavaRa.zip
[2011/06/02 20:59:25 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/06/02 20:59:22 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/06/02 20:50:08 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/06/02 20:50:08 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/06/02 20:50:08 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/06/02 20:50:08 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/06/02 20:50:08 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/06/02 05:54:03 | 000,139,264 | ---- | C] () -- C:\Documents and Settings\William\Desktop\RKUnhookerLE.EXE
[2011/06/02 05:48:48 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\William\Desktop\MBR.dat
[2011/06/01 16:00:26 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\William\Desktop\fbuqgtev.exe
[2011/06/01 14:29:44 | 2145,538,048 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/01 10:44:15 | 000,000,644 | RHS- | C] () -- C:\Documents and Settings\William\ntuser.pol
[2011/05/31 21:05:04 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2011/05/31 21:05:00 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2011/05/31 20:53:08 | 000,033,280 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisrndr.ax
[2011/05/31 20:53:03 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisdecd.dll
[2011/05/31 20:48:25 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2011/05/31 20:46:34 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2011/05/31 20:45:14 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2011/05/31 20:43:19 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll
[2011/05/31 20:43:14 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll
[2011/05/31 20:43:09 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll
[2011/05/31 20:43:05 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll
[2011/05/31 20:42:58 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll
[2011/05/31 20:23:06 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2011/05/31 20:20:15 | 000,029,768 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divasu.dll
[2011/05/31 20:20:14 | 000,037,962 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaprop.dll
[2011/05/31 20:20:12 | 000,006,216 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaci.dll
[2011/05/31 20:17:01 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys
[2011/05/31 20:17:00 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys
[2011/05/31 20:16:59 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys
[2011/05/31 20:16:59 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2011/05/31 20:16:58 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2011/05/31 20:16:57 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2011/05/31 20:16:57 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys
[2011/05/31 20:16:56 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys
[2011/05/31 20:16:54 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2011/05/31 20:16:48 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys
[2011/05/31 15:29:52 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\William\Desktop\Shortcut to firefox.exe.lnk
[2011/05/28 00:01:50 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\22339364
[2011/05/26 11:39:16 | 000,052,560 | ---- | C] () -- C:\Documents and Settings\William\Desktop\2011052609584429.pdf
[2011/05/12 12:25:07 | 000,800,007 | ---- | C] () -- C:\Documents and Settings\William\Desktop\Raid Preparation.pdf
[2011/05/06 20:06:04 | 009,164,138 | ---- | C] () -- C:\Documents and Settings\William\Desktop\02 Rock That Body.m4a
[2011/04/27 10:05:21 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\William\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/09 22:45:32 | 000,102,744 | -H-- | C] () -- C:\WINDOWS\System32\LogiDPPApp.exe
[2010/11/09 22:45:30 | 010,871,128 | -H-- | C] () -- C:\WINDOWS\System32\LogiDPP.dll
[2010/11/09 22:45:20 | 000,316,248 | -H-- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll
[2010/11/09 22:31:42 | 000,026,286 | -H-- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/10/16 17:31:27 | 000,000,032 | -H-- | C] () -- C:\WINDOWS\CD_Start.INI
[2010/10/01 15:18:08 | 000,207,226 | -H-- | C] () -- C:\WINDOWS\hpwins28.dat
[2010/10/01 15:18:08 | 000,000,418 | -H-- | C] () -- C:\WINDOWS\hpwmdl28.dat
[2010/06/07 17:44:06 | 000,000,256 | -H-- | C] () -- C:\WINDOWS\System32\pool.bin
[2010/05/07 19:46:36 | 000,014,168 | -H-- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2010/05/07 19:43:30 | 000,025,824 | -H-- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2010/01/19 12:26:21 | 000,016,968 | -H-- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2009/10/12 20:56:40 | 000,060,452 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/09/19 22:40:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/08/03 15:07:42 | 000,403,816 | -H-- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H-- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2008/05/16 20:18:43 | 000,000,118 | -H-- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/01/29 21:09:54 | 000,013,824 | ---- | C] () -- C:\Documents and Settings\William\Application Data\dvd.bmk
[2008/01/22 10:32:35 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\ativpsrm.bin
[2008/01/22 10:29:53 | 000,593,920 | -H-- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2007/12/20 22:35:44 | 003,107,788 | -H-- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2007/12/20 22:35:44 | 003,107,788 | -H-- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2007/12/20 22:35:44 | 000,887,724 | -H-- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2007/11/17 14:49:26 | 000,001,156 | -H-- | C] () -- C:\WINDOWS\mozver.dat
[2007/09/17 08:33:58 | 000,043,520 | -H-- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2007/08/21 17:59:24 | 000,001,087 | -H-- | C] () -- C:\WINDOWS\checkip.dat
[2007/08/21 17:49:09 | 000,001,213 | -H-- | C] () -- C:\WINDOWS\ipconfig.dat
[2007/03/18 11:01:59 | 000,000,120 | ---- | C] () -- C:\Documents and Settings\William\Application Data\FixVTS.ini
[2006/12/23 22:36:32 | 000,000,214 | -H-- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/11/24 20:36:08 | 000,000,040 | -HS- | C] () -- C:\Documents and Settings\William\Application Data\.zreglib
[2006/11/22 09:55:50 | 000,000,116 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/10/19 12:26:34 | 000,038,867 | -H-- | C] () -- C:\WINDOWS\hpomdl03.dat
[2006/10/19 12:26:34 | 000,029,133 | -H-- | C] () -- C:\WINDOWS\hpoins03.dat
[2006/10/06 15:28:25 | 000,000,002 | -H-- | C] () -- C:\WINDOWS\msoffice.ini
[2006/10/03 11:52:39 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/10/03 11:47:41 | 000,000,376 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2006/10/03 11:42:19 | 000,000,126 | -H-- | C] () -- C:\WINDOWS\wininit.ini
[2006/10/03 11:37:00 | 000,000,335 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2006/10/03 11:11:14 | 000,049,152 | -H-- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/10/03 11:11:12 | 000,095,617 | -H-- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/10/03 11:10:48 | 000,000,392 | -H-- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 08:56:34 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/11 17:24:19 | 000,000,791 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 17:19:30 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/11 17:12:14 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 17:11:31 | 000,001,793 | -H-- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 17:07:24 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/11 17:06:43 | 000,288,496 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 17:00:30 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/11 17:00:28 | 000,445,836 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/11 17:00:28 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/11 17:00:28 | 000,073,042 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/11 17:00:28 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/11 17:00:27 | 000,004,627 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/11 17:00:26 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/11 17:00:24 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/11 17:00:19 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/11 17:00:19 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/11 17:00:12 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/11 17:00:04 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/01/05 03:30:18 | 000,565,248 | -H-- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2003/01/07 15:05:08 | 000,002,695 | -H-- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2011/06/02 23:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2010/10/26 10:29:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/26 10:41:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2007/12/11 09:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output
[2007/12/11 09:34:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup
[2010/01/19 12:54:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2011/05/31 12:58:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iFaAaFc08200
[2010/06/07 17:40:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2007/02/24 16:50:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2011/05/31 13:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2006/10/03 11:38:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/23 13:03:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/06 10:01:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/09 15:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/07 12:57:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/10/26 14:17:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\AVG10
[2010/06/09 13:27:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Research In Motion
[2007/01/31 22:53:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Viewpoint
[2006/12/23 21:11:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Susan\Application Data\Walgreens
[2010/10/27 22:04:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tracy\Application Data\AVG10
[2010/06/08 07:37:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Blackberry Desktop
[2010/12/20 12:19:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Dyuv
[2007/12/11 09:37:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\eFax Messenger
[2009/03/29 10:32:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\HouseCall 6.6
[2006/10/27 13:19:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Leadertech
[2008/02/27 21:22:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\LimeWire
[2007/10/15 12:25:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Lost Marble
[2010/12/20 12:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Ohbato
[2010/06/07 17:43:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Research In Motion
[2006/11/24 20:37:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\SlySoft
[2008/05/08 07:55:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Thunderbird
[2011/01/02 09:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\William\Application Data\Walgreens
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/11 17:15:00 | 000,000,000 | -H-- | M] () -- C:\AUTOEXEC.BAT
[2011/05/31 13:42:18 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/06/02 20:59:25 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2011/06/02 21:07:55 | 000,029,532 | ---- | M] () -- C:\ComboFix.txt
[2004/08/11 17:15:00 | 000,000,000 | -H-- | M] () -- C:\CONFIG.SYS
[2006/10/03 11:14:46 | 000,006,754 | RH-- | M] () -- C:\dell.sdr
[2001/09/05 22:00:58 | 001,700,352 | -H-- | M] (Microsoft Corporation) -- C:\gdiplus.dll
[2011/06/03 05:38:52 | 2145,538,048 | -HS- | M] () -- C:\hiberfil.sys
[2006/10/19 12:31:24 | 000,004,128 | -H-- | M] () -- C:\INFCACHE.1
[2004/08/11 17:15:00 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2006/10/03 11:38:07 | 000,000,838 | -H-- | M] () -- C:\IPH.PH
[2011/06/02 22:41:00 | 000,026,779 | ---- | M] () -- C:\JavaRa.log
[2004/08/11 17:15:00 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/11/14 09:10:21 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/06/03 05:38:50 | 3218,079,744 | -HS- | M] () -- C:\pagefile.sys
[2006/10/06 16:28:02 | 000,017,404 | -H-- | M] () -- C:\PkgClnup.log
[2006/10/03 11:38:15 | 000,000,087 | -H-- | M] () -- C:\SystemInfo.ini
[2009/01/27 05:48:38 | 000,000,419 | -H-- | M] () -- C:\updatedatfix.log
[2007/02/01 23:20:28 | 000,938,582 | -H-- | M] () -- C:\winzip70.zip
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | -H-- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | -H-- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | -H-- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | -H-- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/11 17:14:22 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/06/09 01:43:12 | 000,316,928 | -H-- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp092.dll
[2007/04/09 14:23:54 | 000,028,552 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/10 08:10:59 | 000,040,112 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/11 17:06:14 | 000,094,208 | -H-- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/08/11 17:06:14 | 000,659,456 | -H-- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/08/11 17:06:14 | 000,876,544 | -H-- | M] () -- C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/10/06 15:39:55 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\William\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/02 19:48:19 | 006,389,088 | ---- | M] (OPSWAT, Inc.) -- C:\Documents and Settings\William\Desktop\AppRemover.exe
[2011/06/02 05:44:11 | 000,589,632 | ---- | M] (AVAST Software) -- C:\Documents and Settings\William\Desktop\aswMBR.exe
[2010/10/14 08:55:13 | 060,866,552 | ---- | M] (Online Media Technologies Ltd. ) -- C:\Documents and Settings\William\Desktop\AVSVideoConverter.exe
[2011/06/02 19:46:40 | 004,111,594 | R--- | M] (Swearware) -- C:\Documents and Settings\William\Desktop\ComboFix.exe
[2011/06/01 16:00:26 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\William\Desktop\fbuqgtev.exe
[2010/11/09 10:45:31 | 010,980,832 | ---- | M] () -- C:\Documents and Settings\William\Desktop\FCTBSetup.exe
[2010/01/16 10:16:59 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\William\Desktop\HijackThis.exe
[2010/10/26 13:45:13 | 006,238,016 | ---- | M] (SurfRight B.V.) -- C:\Documents and Settings\William\Desktop\HitmanPro35.exe
[2011/06/02 22:29:27 | 000,886,560 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\William\Desktop\jxpiinstall.exe
[2011/05/31 16:35:07 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\William\Desktop\mbam-setup-1.50.1.1100.exe
[2011/06/02 23:10:56 | 000,932,400 | ---- | M] () -- C:\Documents and Settings\William\Desktop\Norton_Removal_Tool.exe
[2011/06/02 21:26:41 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\William\Desktop\OTL.exe
[2011/06/02 05:54:04 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\William\Desktop\RKUnhookerLE.EXE
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/04 05:00:00 | 000,000,791 | -H-- | M] () -- C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/10/06 15:39:54 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\William\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2007/11/10 09:56:01 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\William\Cookies\desktop.ini
[2011/06/03 05:39:45 | 000,032,768 | -HS- | M] () -- C:\Documents and Settings\William\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2005/01/28 13:44:28 | 000,192,512 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2008/04/13 20:11:51 | 000,033,792 | -H-- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2004/08/04 01:06:34 | 000,004,821 | -H-- | M] () -- C:\Program Files\Messenger\logowin.gif
[2004/08/04 01:06:34 | 000,007,047 | -H-- | M] () -- C:\Program Files\Messenger\lvback.gif
[2008/05/02 10:01:49 | 000,083,968 | -H-- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
[2008/04/13 13:30:28 | 000,180,224 | -H-- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2008/04/13 20:12:28 | 001,695,232 | -H-- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2004/08/04 01:06:36 | 000,002,882 | -H-- | M] () -- C:\Program Files\Messenger\newalert.wav
[2004/08/04 01:06:36 | 000,006,156 | -H-- | M] () -- C:\Program Files\Messenger\newemail.wav
[2004/08/04 01:06:36 | 000,006,160 | -H-- | M] () -- C:\Program Files\Messenger\online.wav
[2004/08/04 01:06:36 | 000,004,454 | -H-- | M] () -- C:\Program Files\Messenger\type.wav
[2004/08/04 01:06:36 | 000,115,981 | -H-- | M] () -- C:\Program Files\Messenger\xpmsgr.chm
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP

FC5A2B2
< End of report >