[2012/01/03 23:58:07 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/01/03 22:49:28 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/01/03 22:49:28 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/01/03 22:49:28 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/01/03 22:48:43 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/01/03 22:48:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/03 20:50:25 | 004,368,790 | R--- | C] (Swearware) -- C:\Users\Don\Desktop\ComboFix.exe
[2012/01/03 18:59:47 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Roaming\Malwarebytes
[2012/01/03 18:59:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/03 18:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/01/03 18:59:19 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/01/03 18:59:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/01/02 21:36:09 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/01/02 20:28:38 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/01/02 20:25:03 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2011/12/21 21:21:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2011/12/18 14:21:08 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
[2011/12/18 14:21:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2011/12/18 14:21:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2011/12/18 14:20:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NCH Software
[2011/12/18 14:20:56 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Roaming\NCH Software
[2011/12/18 14:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\YouTube Downloader
[2011/12/18 14:07:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader
[2011/12/18 14:07:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YouTube Downloader
[2011/12/05 23:48:52 | 000,000,000 | ---D | C] -- C:\Users\Don\Documents\My Received Files
[2011/12/05 23:47:19 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Local\PackageAware
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Don\Desktop\*.tmp files -> C:\Users\Don\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/04 00:04:15 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/03 23:55:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/01/03 23:53:40 | 000,786,854 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/03 23:53:40 | 000,665,600 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/01/03 23:53:40 | 000,123,336 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/01/03 23:51:33 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1919323110-2318573449-1776510850-1000UA.job
[2012/01/03 23:15:20 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/03 22:49:01 | 004,368,790 | R--- | M] (Swearware) -- C:\Users\Don\Desktop\ComboFix.exe
[2012/01/03 22:44:36 | 000,000,512 | ---- | M] () -- C:\Users\Don\Desktop\MBR.dat
[2012/01/03 21:51:23 | 000,023,248 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/03 21:51:23 | 000,023,248 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/03 21:43:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/03 21:43:06 | 964,967,220 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/01/03 21:43:02 | 3062,255,616 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/03 18:59:35 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/03 18:52:05 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1919323110-2318573449-1776510850-1000Core.job
[2012/01/02 20:25:04 | 000,000,677 | ---- | M] () -- C:\Users\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/02 20:05:01 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForDon.job
[2012/01/01 09:37:26 | 000,002,048 | ---- | M] () -- C:\Users\Don\Documents\Default.rdp
[2011/12/26 21:50:25 | 000,002,056 | ---- | M] () -- C:\Users\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/20 17:26:54 | 000,325,940 | ---- | M] () -- C:\Users\Don\Documents\elkiosko.pdf
[2011/12/18 14:29:11 | 000,006,656 | ---- | M] () -- C:\Users\Don\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/18 14:12:43 | 035,249,311 | ---- | M] () -- C:\Users\Don\Desktop\Christmas five minute countdown.flv
[2011/12/18 14:10:02 | 009,666,885 | ---- | M] () -- C:\Users\Don\Desktop\Jesus and Santa.mp4
[2011/12/16 18:35:14 | 000,438,568 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/12/10 10:38:44 | 000,089,600 | ---- | M] () -- C:\Users\Don\Documents\Menu December 2011.pub
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Don\Desktop\*.tmp files -> C:\Users\Don\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/03 22:49:28 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/01/03 22:49:28 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/01/03 22:49:28 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/01/03 22:49:28 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/01/03 22:49:28 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/01/03 22:44:36 | 000,000,512 | ---- | C] () -- C:\Users\Don\Desktop\MBR.dat
[2012/01/03 18:59:35 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/02 20:25:04 | 000,000,677 | ---- | C] () -- C:\Users\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2011/12/20 17:26:53 | 000,325,940 | ---- | C] () -- C:\Users\Don\Documents\elkiosko.pdf
[2011/12/18 14:09:53 | 009,666,885 | ---- | C] () -- C:\Users\Don\Desktop\Jesus and Santa.mp4
[2011/12/18 14:09:10 | 035,249,311 | ---- | C] () -- C:\Users\Don\Desktop\Christmas five minute countdown.flv
[2011/12/09 22:11:13 | 000,089,600 | ---- | C] () -- C:\Users\Don\Documents\Menu December 2011.pub
[2011/11/28 17:45:10 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/10/22 00:01:42 | 000,000,702 | ---- | C] () -- C:\Windows\NewsRover.INI
[2011/10/20 20:36:29 | 000,109,216 | ---- | C] () -- C:\Windows\SysWow64\EasyHook64.dll
[2011/10/20 20:36:29 | 000,090,784 | ---- | C] () -- C:\Windows\SysWow64\EasyHook32.dll
[2011/08/31 18:51:16 | 000,867,020 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/08/31 18:51:16 | 000,128,204 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2011/08/31 18:51:16 | 000,105,608 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/08/31 18:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/01/30 21:19:03 | 000,800,288 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/20 12:19:51 | 000,005,117 | ---- | C] () -- C:\ProgramData\ngqoeocq.huh
[2010/09/05 10:03:59 | 000,006,656 | ---- | C] () -- C:\Users\Don\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/29 19:22:23 | 000,000,096 | ---- | C] () -- C:\Users\Don\AppData\Roaming\wklnhst.dat
[2010/07/09 20:27:04 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/07/09 17:04:56 | 000,023,112 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/02/11 04:13:16 | 000,000,268 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini
[2010/02/11 04:13:16 | 000,000,209 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini
[2009/09/29 18:25:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/02/26 01:50:32 | 000,000,176 | ---- | C] () -- C:\Windows\explorer.exe.config
[2005/12/30 19:03:00 | 001,732,608 | R--- | C] () -- C:\Windows\SysWow64\ltmm_n.dll
[2005/12/08 20:07:00 | 000,045,056 | R--- | C] () -- C:\Windows\SysWow64\lfpcd14N.dll
[2005/02/11 21:08:00 | 000,843,776 | R--- | C] () -- C:\Windows\SysWow64\lteay14n.dll
[2005/02/11 21:08:00 | 000,688,128 | R--- | C] () -- C:\Windows\SysWow64\ltcry14n.dll
[2005/02/11 21:08:00 | 000,144,384 | R--- | C] () -- C:\Windows\SysWow64\lttls14n.dll
========== LOP Check ==========
[2011/10/23 15:05:21 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\2XClient
[2011/01/12 15:37:32 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Amazon
[2011/04/26 14:37:37 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\ASUS
[2011/12/24 23:51:46 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\ASUS WebStorage
[2011/04/26 21:56:33 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\ASUS.AF361EFD06694D11175EA8BF6E21597A36AD9F1D.1
[2011/03/13 11:45:07 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Audacity
[2011/11/27 15:59:55 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\BitLord
[2011/10/22 16:58:02 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Blender Foundation
[2010/07/09 19:58:40 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\BOXEE
[2011/01/05 16:03:35 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\DAEMON Tools Lite
[2011/04/26 14:43:16 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\eCareme
[2011/06/01 13:57:12 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\FileZilla
[2010/10/14 17:33:30 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Foxit
[2010/10/20 13:09:57 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Foxit Software
[2012/01/02 21:49:21 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Gmote
[2011/09/20 17:23:13 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\go
[2011/11/20 20:54:45 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\GrabIt
[2011/02/25 22:26:39 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\KVIrc4
[2010/09/15 00:02:59 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\muvee Technologies
[2011/08/21 00:52:03 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Notepad++
[2010/07/10 20:06:36 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\OpenSong
[2011/04/26 21:56:38 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Outlook
[2011/02/17 18:41:20 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Publish Providers
[2010/07/09 18:15:55 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Python-Eggs
[2011/10/19 22:46:24 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Sony
[2011/12/21 21:22:20 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Splashtop Remote Client
[2010/10/20 20:50:16 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Teleca
[2010/08/29 19:22:23 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Template
[2010/07/09 18:50:29 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Trillian
[2010/07/09 17:49:36 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/04/20 21:58:01 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Unity
[2011/12/27 22:26:48 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\XBMC
[2012/01/02 21:17:57 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\ASUS
[2011/01/30 22:06:44 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Audacity
[2011/01/30 11:10:38 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Gmote
[2010/11/10 23:51:00 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Teleca
[2010/08/03 19:23:19 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\WildTangent
[2012/01/03 20:46:00 | 000,032,588 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2012/01/03 23:58:06 | 000,020,377 | ---- | M] () -- C:\ComboFix.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2012/01/03 21:43:02 | 3062,255,616 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/03 21:12:00 | 000,000,186 | ---- | M] () -- C:\hpqlb.log
[2003/01/23 14:04:24 | 000,111,608 | ---- | M] (Infragistics, Inc.) -- C:\IGPrint.dll
[2003/01/23 14:04:18 | 001,143,832 | ---- | M] (Infragistics, Inc.) -- C:\IGUltraGrid20.ocx
[2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2012/01/03 21:43:06 | 4083,007,488 | -HS- | M] () -- C:\pagefile.sys
[2011/08/24 19:49:52 | 000,002,530 | ---- | M] () -- C:\RHDSetup.log
[2010/11/03 21:13:11 | 000,000,184 | ---- | M] () -- C:\setup.log
[2003/01/23 14:04:28 | 000,046,064 | ---- | M] (Infragistics, Inc.) -- C:\ssmask.dll
[2003/01/23 14:04:28 | 000,061,440 | ---- | M] (Infragistics, Inc.) -- C:\SSPng2.dll
[2012/01/02 20:43:23 | 000,082,718 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_02.01.2012_20.41.41_log.txt
[2012/01/02 21:02:54 | 000,162,172 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_02.01.2012_20.56.03_log.txt
[2012/01/02 21:41:46 | 000,244,840 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_02.01.2012_21.33.59_log.txt
[2011/11/27 22:12:26 | 000,000,019 | ---- | M] () -- C:\TOONSTRK.LCK
[2007/11/07 07:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
[2009/02/26 01:50:32 | 000,000,176 | ---- | M] () -- C:\Windows\explorer.exe.config
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/13 17:58:31 | 000,000,221 | -HS- | M] () -- C:\Users\Don\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/14 17:33:30 | 000,000,198 | ---- | M] () -- C:\Users\Don\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.url
< %USERPROFILE%\Desktop\*.exe >
[2012/01/03 22:49:01 | 004,368,790 | R--- | M] (Swearware) -- C:\Users\Don\Desktop\ComboFix.exe
[1 C:\Users\Don\Desktop\*.tmp files -> C:\Users\Don\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 16:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/10/02 21:48:19 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/10/02 21:48:19 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2010/09/13 11:35:09 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2010/09/13 11:35:09 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/10/02 21:48:19 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/01/03 23:58:44 | 000,000,649 | ---- | M] () -- C:\ProgramData\HPWALog.txt
[2010/07/09 17:08:55 | 000,000,759 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2010/10/20 12:19:51 | 000,005,117 | ---- | M] () -- C:\ProgramData\ngqoeocq.huh
[2010/02/11 04:26:52 | 000,000,032 | ---- | M] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/01/15 22:53:12 | 000,000,109 | ---- | M] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/02/11 04:26:24 | 000,000,032 | ---- | M] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:553CA6CA
< End of report >
[2012/01/03 22:49:28 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/01/03 22:49:28 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/01/03 22:49:28 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/01/03 22:48:43 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/01/03 22:48:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/03 20:50:25 | 004,368,790 | R--- | C] (Swearware) -- C:\Users\Don\Desktop\ComboFix.exe
[2012/01/03 18:59:47 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Roaming\Malwarebytes
[2012/01/03 18:59:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/03 18:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/01/03 18:59:19 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/01/03 18:59:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/01/02 21:36:09 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/01/02 20:28:38 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/01/02 20:25:03 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2011/12/21 21:21:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2011/12/18 14:21:08 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
[2011/12/18 14:21:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2011/12/18 14:21:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2011/12/18 14:20:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NCH Software
[2011/12/18 14:20:56 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Roaming\NCH Software
[2011/12/18 14:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\YouTube Downloader
[2011/12/18 14:07:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader
[2011/12/18 14:07:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YouTube Downloader
[2011/12/05 23:48:52 | 000,000,000 | ---D | C] -- C:\Users\Don\Documents\My Received Files
[2011/12/05 23:47:19 | 000,000,000 | ---D | C] -- C:\Users\Don\AppData\Local\PackageAware
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Don\Desktop\*.tmp files -> C:\Users\Don\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/04 00:04:15 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/03 23:55:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/01/03 23:53:40 | 000,786,854 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/03 23:53:40 | 000,665,600 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/01/03 23:53:40 | 000,123,336 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/01/03 23:51:33 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1919323110-2318573449-1776510850-1000UA.job
[2012/01/03 23:15:20 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/03 22:49:01 | 004,368,790 | R--- | M] (Swearware) -- C:\Users\Don\Desktop\ComboFix.exe
[2012/01/03 22:44:36 | 000,000,512 | ---- | M] () -- C:\Users\Don\Desktop\MBR.dat
[2012/01/03 21:51:23 | 000,023,248 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/03 21:51:23 | 000,023,248 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/03 21:43:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/03 21:43:06 | 964,967,220 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/01/03 21:43:02 | 3062,255,616 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/03 18:59:35 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/03 18:52:05 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1919323110-2318573449-1776510850-1000Core.job
[2012/01/02 20:25:04 | 000,000,677 | ---- | M] () -- C:\Users\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/02 20:05:01 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForDon.job
[2012/01/01 09:37:26 | 000,002,048 | ---- | M] () -- C:\Users\Don\Documents\Default.rdp
[2011/12/26 21:50:25 | 000,002,056 | ---- | M] () -- C:\Users\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/20 17:26:54 | 000,325,940 | ---- | M] () -- C:\Users\Don\Documents\elkiosko.pdf
[2011/12/18 14:29:11 | 000,006,656 | ---- | M] () -- C:\Users\Don\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/18 14:12:43 | 035,249,311 | ---- | M] () -- C:\Users\Don\Desktop\Christmas five minute countdown.flv
[2011/12/18 14:10:02 | 009,666,885 | ---- | M] () -- C:\Users\Don\Desktop\Jesus and Santa.mp4
[2011/12/16 18:35:14 | 000,438,568 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/12/10 10:38:44 | 000,089,600 | ---- | M] () -- C:\Users\Don\Documents\Menu December 2011.pub
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Don\Desktop\*.tmp files -> C:\Users\Don\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/03 22:49:28 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/01/03 22:49:28 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/01/03 22:49:28 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/01/03 22:49:28 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/01/03 22:49:28 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/01/03 22:44:36 | 000,000,512 | ---- | C] () -- C:\Users\Don\Desktop\MBR.dat
[2012/01/03 18:59:35 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/02 20:25:04 | 000,000,677 | ---- | C] () -- C:\Users\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2011/12/20 17:26:53 | 000,325,940 | ---- | C] () -- C:\Users\Don\Documents\elkiosko.pdf
[2011/12/18 14:09:53 | 009,666,885 | ---- | C] () -- C:\Users\Don\Desktop\Jesus and Santa.mp4
[2011/12/18 14:09:10 | 035,249,311 | ---- | C] () -- C:\Users\Don\Desktop\Christmas five minute countdown.flv
[2011/12/09 22:11:13 | 000,089,600 | ---- | C] () -- C:\Users\Don\Documents\Menu December 2011.pub
[2011/11/28 17:45:10 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/10/22 00:01:42 | 000,000,702 | ---- | C] () -- C:\Windows\NewsRover.INI
[2011/10/20 20:36:29 | 000,109,216 | ---- | C] () -- C:\Windows\SysWow64\EasyHook64.dll
[2011/10/20 20:36:29 | 000,090,784 | ---- | C] () -- C:\Windows\SysWow64\EasyHook32.dll
[2011/08/31 18:51:16 | 000,867,020 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/08/31 18:51:16 | 000,128,204 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2011/08/31 18:51:16 | 000,105,608 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/08/31 18:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/01/30 21:19:03 | 000,800,288 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/20 12:19:51 | 000,005,117 | ---- | C] () -- C:\ProgramData\ngqoeocq.huh
[2010/09/05 10:03:59 | 000,006,656 | ---- | C] () -- C:\Users\Don\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/29 19:22:23 | 000,000,096 | ---- | C] () -- C:\Users\Don\AppData\Roaming\wklnhst.dat
[2010/07/09 20:27:04 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/07/09 17:04:56 | 000,023,112 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/02/11 04:13:16 | 000,000,268 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini
[2010/02/11 04:13:16 | 000,000,209 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini
[2009/09/29 18:25:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/02/26 01:50:32 | 000,000,176 | ---- | C] () -- C:\Windows\explorer.exe.config
[2005/12/30 19:03:00 | 001,732,608 | R--- | C] () -- C:\Windows\SysWow64\ltmm_n.dll
[2005/12/08 20:07:00 | 000,045,056 | R--- | C] () -- C:\Windows\SysWow64\lfpcd14N.dll
[2005/02/11 21:08:00 | 000,843,776 | R--- | C] () -- C:\Windows\SysWow64\lteay14n.dll
[2005/02/11 21:08:00 | 000,688,128 | R--- | C] () -- C:\Windows\SysWow64\ltcry14n.dll
[2005/02/11 21:08:00 | 000,144,384 | R--- | C] () -- C:\Windows\SysWow64\lttls14n.dll
========== LOP Check ==========
[2011/10/23 15:05:21 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\2XClient
[2011/01/12 15:37:32 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Amazon
[2011/04/26 14:37:37 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\ASUS
[2011/12/24 23:51:46 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\ASUS WebStorage
[2011/04/26 21:56:33 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\ASUS.AF361EFD06694D11175EA8BF6E21597A36AD9F1D.1
[2011/03/13 11:45:07 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Audacity
[2011/11/27 15:59:55 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\BitLord
[2011/10/22 16:58:02 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Blender Foundation
[2010/07/09 19:58:40 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\BOXEE
[2011/01/05 16:03:35 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\DAEMON Tools Lite
[2011/04/26 14:43:16 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\eCareme
[2011/06/01 13:57:12 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\FileZilla
[2010/10/14 17:33:30 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Foxit
[2010/10/20 13:09:57 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Foxit Software
[2012/01/02 21:49:21 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Gmote
[2011/09/20 17:23:13 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\go
[2011/11/20 20:54:45 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\GrabIt
[2011/02/25 22:26:39 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\KVIrc4
[2010/09/15 00:02:59 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\muvee Technologies
[2011/08/21 00:52:03 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Notepad++
[2010/07/10 20:06:36 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\OpenSong
[2011/04/26 21:56:38 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Outlook
[2011/02/17 18:41:20 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Publish Providers
[2010/07/09 18:15:55 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Python-Eggs
[2011/10/19 22:46:24 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Sony
[2011/12/21 21:22:20 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Splashtop Remote Client
[2010/10/20 20:50:16 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Teleca
[2010/08/29 19:22:23 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Template
[2010/07/09 18:50:29 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Trillian
[2010/07/09 17:49:36 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/04/20 21:58:01 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\Unity
[2011/12/27 22:26:48 | 000,000,000 | ---D | M] -- C:\Users\Don\AppData\Roaming\XBMC
[2012/01/02 21:17:57 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\ASUS
[2011/01/30 22:06:44 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Audacity
[2011/01/30 11:10:38 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Gmote
[2010/11/10 23:51:00 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\Teleca
[2010/08/03 19:23:19 | 000,000,000 | ---D | M] -- C:\Users\Melissa\AppData\Roaming\WildTangent
[2012/01/03 20:46:00 | 000,032,588 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2012/01/03 23:58:06 | 000,020,377 | ---- | M] () -- C:\ComboFix.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2012/01/03 21:43:02 | 3062,255,616 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/03 21:12:00 | 000,000,186 | ---- | M] () -- C:\hpqlb.log
[2003/01/23 14:04:24 | 000,111,608 | ---- | M] (Infragistics, Inc.) -- C:\IGPrint.dll
[2003/01/23 14:04:18 | 001,143,832 | ---- | M] (Infragistics, Inc.) -- C:\IGUltraGrid20.ocx
[2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2012/01/03 21:43:06 | 4083,007,488 | -HS- | M] () -- C:\pagefile.sys
[2011/08/24 19:49:52 | 000,002,530 | ---- | M] () -- C:\RHDSetup.log
[2010/11/03 21:13:11 | 000,000,184 | ---- | M] () -- C:\setup.log
[2003/01/23 14:04:28 | 000,046,064 | ---- | M] (Infragistics, Inc.) -- C:\ssmask.dll
[2003/01/23 14:04:28 | 000,061,440 | ---- | M] (Infragistics, Inc.) -- C:\SSPng2.dll
[2012/01/02 20:43:23 | 000,082,718 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_02.01.2012_20.41.41_log.txt
[2012/01/02 21:02:54 | 000,162,172 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_02.01.2012_20.56.03_log.txt
[2012/01/02 21:41:46 | 000,244,840 | ---- | M] () -- C:\TDSSKiller.2.6.25.0_02.01.2012_21.33.59_log.txt
[2011/11/27 22:12:26 | 000,000,019 | ---- | M] () -- C:\TOONSTRK.LCK
[2007/11/07 07:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
[2009/02/26 01:50:32 | 000,000,176 | ---- | M] () -- C:\Windows\explorer.exe.config
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/13 17:58:31 | 000,000,221 | -HS- | M] () -- C:\Users\Don\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/14 17:33:30 | 000,000,198 | ---- | M] () -- C:\Users\Don\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.url
< %USERPROFILE%\Desktop\*.exe >
[2012/01/03 22:49:01 | 004,368,790 | R--- | M] (Swearware) -- C:\Users\Don\Desktop\ComboFix.exe
[1 C:\Users\Don\Desktop\*.tmp files -> C:\Users\Don\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 16:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/10/02 21:48:19 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/10/02 21:48:19 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2010/09/13 11:35:09 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2010/09/13 11:35:09 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/10/02 21:48:19 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/01/03 23:58:44 | 000,000,649 | ---- | M] () -- C:\ProgramData\HPWALog.txt
[2010/07/09 17:08:55 | 000,000,759 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2010/10/20 12:19:51 | 000,005,117 | ---- | M] () -- C:\ProgramData\ngqoeocq.huh
[2010/02/11 04:26:52 | 000,000,032 | ---- | M] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/01/15 22:53:12 | 000,000,109 | ---- | M] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/02/11 04:26:24 | 000,000,032 | ---- | M] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:553CA6CA
< End of report >