Part 2
========== Files/Folders - Created Within 30 Days ==========
[2012/06/16 00:16:09 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Ryan\Desktop\aswMBR.exe
[2012/06/15 23:44:37 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/15 23:42:26 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/15 22:54:46 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2012/06/15 22:16:17 | 004,559,503 | R--- | C] (Swearware) -- C:\Users\Ryan\Desktop\ComboFix.exe
[2012/06/15 18:24:18 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/15 13:22:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/15 13:22:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/15 13:22:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/15 13:19:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/15 13:03:10 | 001,932,256 | ---- | C] (Symantec Corporation) -- C:\Users\Ryan\Desktop\FixTDSS.exe
[2012/06/15 12:00:40 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\Ryan\Desktop\boot_cleaner.exe
[2012/06/14 18:55:13 | 002,127,960 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Ryan\Desktop\TDSSKiller.exe
[2012/06/05 22:11:40 | 000,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Local\backburner
[2012/06/04 19:32:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/06/04 19:31:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/06/04 19:31:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/06/02 21:04:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/06/01 16:12:39 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/06/01 16:00:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/06/01 16:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/05/31 23:52:51 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/05/31 11:25:47 | 000,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Roaming\Malwarebytes
[2012/05/31 11:25:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/31 11:25:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/05/31 11:25:39 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/16 11:59:45 | 000,000,512 | ---- | M] () -- C:\Users\Ryan\Desktop\MBR.dat
[2012/06/16 11:53:57 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/16 11:53:57 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/16 11:53:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/16 11:46:51 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/16 11:46:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/16 03:44:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/16 03:33:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2388485762-2462165164-2089254216-1001UA.job
[2012/06/15 23:45:45 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2012/06/15 23:42:25 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/15 22:54:37 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2012/06/15 22:15:59 | 004,559,503 | R--- | M] (Swearware) -- C:\Users\Ryan\Desktop\ComboFix.exe
[2012/06/15 15:15:16 | 002,127,960 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Ryan\Desktop\TDSSKiller.exe
[2012/06/15 13:33:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2388485762-2462165164-2089254216-1001Core.job
[2012/06/15 13:03:03 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\Ryan\Desktop\FixTDSS.exe
[2012/06/15 12:02:31 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Ryan\Desktop\aswMBR.exe
[2012/06/14 19:44:39 | 000,007,632 | ---- | M] () -- C:\Users\Ryan\AppData\Local\Resmon.ResmonCfg
[2012/06/13 23:01:02 | 004,968,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/13 22:57:17 | 000,797,284 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/13 22:57:17 | 000,662,658 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/13 22:57:17 | 000,122,454 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/01 22:57:58 | 000,000,219 | ---- | M] () -- C:\0
[2012/06/01 16:00:17 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/01 16:00:11 | 000,797,064 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/31 23:59:36 | 000,001,002 | ---- | M] () -- C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mbam.exe - Shortcut.lnk
[2012/05/31 22:35:51 | 000,000,412 | ---- | M] () -- C:\Users\Ryan\AppData\Roaming\All CPU Meter_Settings.ini
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/15 13:22:00 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/15 13:22:00 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/15 13:22:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/15 13:22:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/15 13:22:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/15 12:30:10 | 000,000,512 | ---- | C] () -- C:\Users\Ryan\Desktop\MBR.dat
[2012/06/08 09:30:32 | 000,001,002 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mbam.exe - Shortcut.lnk
[2012/06/01 16:00:13 | 000,001,917 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/05/15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/04/29 18:11:51 | 000,004,608 | ---- | C] () -- C:\Windows\SysWow64\adesk_patcher64.exe
[2012/01/22 19:01:59 | 000,282,864 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/01/22 19:01:58 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/11/08 16:32:14 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/07/29 18:21:52 | 000,010,752 | ---- | C] () -- C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/22 15:01:43 | 000,000,412 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\All CPU Meter_Settings.ini
[2011/05/14 21:29:00 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
[2011/05/10 21:34:36 | 000,797,064 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/10 18:43:47 | 000,007,632 | ---- | C] () -- C:\Users\Ryan\AppData\Local\Resmon.ResmonCfg
[2011/04/16 22:27:35 | 000,001,200 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini
[2011/04/16 22:27:35 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini
[2011/04/16 22:27:35 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini
[2011/04/16 22:27:34 | 000,181,760 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011/04/16 22:27:34 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011/04/16 22:14:37 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
========== LOP Check ==========
[2012/05/31 00:00:24 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\.minecraft
[2012/04/15 18:07:19 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\.Nitrous
[2011/11/23 12:10:28 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Acapela Group
[2012/04/04 13:12:04 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Acronis
[2011/12/03 00:28:17 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Asus WebStorage
[2012/05/01 21:32:34 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Autodesk
[2012/06/09 16:55:25 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\BitTorrent
[2011/05/15 17:06:23 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/09/25 19:40:40 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\GameRanger
[2011/08/05 12:45:56 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\gtk-2.0
[2012/02/04 16:36:39 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\ImgBurn
[2011/06/02 22:03:44 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\iPodder
[2011/05/13 23:36:34 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\ManyCam
[2012/01/02 23:33:20 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\minecraft
[2012/01/19 23:07:40 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\MoreTerra
[2011/07/26 21:32:28 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\MotioninJoy
[2011/11/02 22:33:05 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Mount&Blade
[2011/11/03 12:24:16 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Mount&Blade Warband
[2012/04/15 19:25:46 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Notepad++
[2011/05/10 20:08:17 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Nuance
[2012/01/22 16:36:38 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Origin
[2011/06/02 22:27:16 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Participatory Culture Foundation
[2011/08/05 12:52:56 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\PCF-VLC
[2012/05/22 22:57:29 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Primal Pictures
[2011/12/17 23:37:31 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\RIFT
[2012/05/30 21:14:08 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\SHAPE Services
[2011/05/11 00:31:39 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/09/11 18:27:19 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\System
[2011/06/30 22:08:29 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\ToLTech
[2012/05/31 00:01:22 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\TS3Client
[2012/01/22 18:14:13 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Uniblue
[2011/09/11 18:41:02 | 000,000,000 | -HSD | M] -- C:\Users\Ryan\AppData\Roaming\wyUpdate AU
[2012/03/22 22:22:53 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Xilisoft
[2011/05/10 20:08:14 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Zeon
[2012/06/15 23:42:20 | 000,032,626 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:A1EDB939
< End of report >
========== Files/Folders - Created Within 30 Days ==========
[2012/06/16 00:16:09 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Ryan\Desktop\aswMBR.exe
[2012/06/15 23:44:37 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/06/15 23:42:26 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/15 22:54:46 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2012/06/15 22:16:17 | 004,559,503 | R--- | C] (Swearware) -- C:\Users\Ryan\Desktop\ComboFix.exe
[2012/06/15 18:24:18 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/15 13:22:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/15 13:22:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/15 13:22:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/15 13:19:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/15 13:03:10 | 001,932,256 | ---- | C] (Symantec Corporation) -- C:\Users\Ryan\Desktop\FixTDSS.exe
[2012/06/15 12:00:40 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\Ryan\Desktop\boot_cleaner.exe
[2012/06/14 18:55:13 | 002,127,960 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Ryan\Desktop\TDSSKiller.exe
[2012/06/05 22:11:40 | 000,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Local\backburner
[2012/06/04 19:32:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/06/04 19:31:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/06/04 19:31:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/06/02 21:04:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/06/01 16:12:39 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/06/01 16:00:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/06/01 16:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/05/31 23:52:51 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/05/31 11:25:47 | 000,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Roaming\Malwarebytes
[2012/05/31 11:25:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/31 11:25:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/05/31 11:25:39 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/06/16 11:59:45 | 000,000,512 | ---- | M] () -- C:\Users\Ryan\Desktop\MBR.dat
[2012/06/16 11:53:57 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/16 11:53:57 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/16 11:53:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/16 11:46:51 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/16 11:46:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/16 03:44:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/16 03:33:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2388485762-2462165164-2089254216-1001UA.job
[2012/06/15 23:45:45 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2012/06/15 23:42:25 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/15 22:54:37 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2012/06/15 22:15:59 | 004,559,503 | R--- | M] (Swearware) -- C:\Users\Ryan\Desktop\ComboFix.exe
[2012/06/15 15:15:16 | 002,127,960 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Ryan\Desktop\TDSSKiller.exe
[2012/06/15 13:33:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2388485762-2462165164-2089254216-1001Core.job
[2012/06/15 13:03:03 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\Ryan\Desktop\FixTDSS.exe
[2012/06/15 12:02:31 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Ryan\Desktop\aswMBR.exe
[2012/06/14 19:44:39 | 000,007,632 | ---- | M] () -- C:\Users\Ryan\AppData\Local\Resmon.ResmonCfg
[2012/06/13 23:01:02 | 004,968,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/13 22:57:17 | 000,797,284 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/13 22:57:17 | 000,662,658 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/13 22:57:17 | 000,122,454 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/01 22:57:58 | 000,000,219 | ---- | M] () -- C:\0
[2012/06/01 16:00:17 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/01 16:00:11 | 000,797,064 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/31 23:59:36 | 000,001,002 | ---- | M] () -- C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mbam.exe - Shortcut.lnk
[2012/05/31 22:35:51 | 000,000,412 | ---- | M] () -- C:\Users\Ryan\AppData\Roaming\All CPU Meter_Settings.ini
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/15 13:22:00 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/15 13:22:00 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/15 13:22:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/15 13:22:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/15 13:22:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/15 12:30:10 | 000,000,512 | ---- | C] () -- C:\Users\Ryan\Desktop\MBR.dat
[2012/06/08 09:30:32 | 000,001,002 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mbam.exe - Shortcut.lnk
[2012/06/01 16:00:13 | 000,001,917 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/05/15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/04/29 18:11:51 | 000,004,608 | ---- | C] () -- C:\Windows\SysWow64\adesk_patcher64.exe
[2012/01/22 19:01:59 | 000,282,864 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/01/22 19:01:58 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/11/08 16:32:14 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/07/29 18:21:52 | 000,010,752 | ---- | C] () -- C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/22 15:01:43 | 000,000,412 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\All CPU Meter_Settings.ini
[2011/05/14 21:29:00 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
[2011/05/10 21:34:36 | 000,797,064 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/10 18:43:47 | 000,007,632 | ---- | C] () -- C:\Users\Ryan\AppData\Local\Resmon.ResmonCfg
[2011/04/16 22:27:35 | 000,001,200 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini
[2011/04/16 22:27:35 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini
[2011/04/16 22:27:35 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini
[2011/04/16 22:27:34 | 000,181,760 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011/04/16 22:27:34 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011/04/16 22:14:37 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
========== LOP Check ==========
[2012/05/31 00:00:24 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\.minecraft
[2012/04/15 18:07:19 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\.Nitrous
[2011/11/23 12:10:28 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Acapela Group
[2012/04/04 13:12:04 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Acronis
[2011/12/03 00:28:17 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Asus WebStorage
[2012/05/01 21:32:34 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Autodesk
[2012/06/09 16:55:25 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\BitTorrent
[2011/05/15 17:06:23 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/09/25 19:40:40 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\GameRanger
[2011/08/05 12:45:56 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\gtk-2.0
[2012/02/04 16:36:39 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\ImgBurn
[2011/06/02 22:03:44 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\iPodder
[2011/05/13 23:36:34 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\ManyCam
[2012/01/02 23:33:20 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\minecraft
[2012/01/19 23:07:40 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\MoreTerra
[2011/07/26 21:32:28 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\MotioninJoy
[2011/11/02 22:33:05 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Mount&Blade
[2011/11/03 12:24:16 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Mount&Blade Warband
[2012/04/15 19:25:46 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Notepad++
[2011/05/10 20:08:17 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Nuance
[2012/01/22 16:36:38 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Origin
[2011/06/02 22:27:16 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Participatory Culture Foundation
[2011/08/05 12:52:56 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\PCF-VLC
[2012/05/22 22:57:29 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Primal Pictures
[2011/12/17 23:37:31 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\RIFT
[2012/05/30 21:14:08 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\SHAPE Services
[2011/05/11 00:31:39 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/09/11 18:27:19 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\System
[2011/06/30 22:08:29 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\ToLTech
[2012/05/31 00:01:22 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\TS3Client
[2012/01/22 18:14:13 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Uniblue
[2011/09/11 18:41:02 | 000,000,000 | -HSD | M] -- C:\Users\Ryan\AppData\Roaming\wyUpdate AU
[2012/03/22 22:22:53 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Xilisoft
[2011/05/10 20:08:14 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Zeon
[2012/06/15 23:42:20 | 000,032,626 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:A1EDB939
< End of report >