part 3
========== LOP Check ==========
[2011/03/01 21:20:27 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\WD
[2011/03/13 19:25:01 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\albumworks
[2011/12/12 19:44:26 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Audacity
[2012/01/14 12:25:06 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Azureus
[2012/01/14 11:43:40 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\BACS.exe
[2011/03/07 11:39:04 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Canon
[2012/01/15 15:14:03 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Dropbox
[2011/10/08 12:39:58 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\EndNote
[2011/12/04 20:12:26 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\HandBrake
[2011/11/13 18:22:43 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Leadertech
[2011/12/04 19:50:35 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\MPEG Streamclip
[2012/01/14 13:14:49 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Okm
[2011/02/12 14:08:55 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\PCDr
[2011/04/05 14:45:19 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Photobook Designer
[2011/03/30 18:09:46 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Thinstall
[2011/02/11 18:49:51 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\WD
[2011/10/27 15:03:03 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Windows Live Writer
[2012/01/14 13:16:00 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Ybews
[2012/01/14 16:43:01 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000Core.job
[2012/01/15 13:46:03 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000UA.job
[2011/12/24 11:36:52 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/12/12 12:25:32 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/01/15 14:56:13 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
[2012/01/15 16:00:00 | 000,000,416 | ---- | M] () -- C:\Windows\Tasks\vtscheduletask.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/01/15 15:39:36 | 000,045,840 | ---- | M] () -- C:\ComboFix.txt
[2011/02/01 14:14:42 | 000,005,155 | RH-- | M] () -- C:\dell.sdr
[2011/06/12 20:11:54 | 000,000,000 | ---- | M] () -- C:\foo.txt
[2012/01/15 15:16:48 | 2133,676,031 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/10 22:02:53 | 000,000,500 | ---- | M] () -- C:\My Book (J) - Shortcut.lnk
[2012/01/15 15:16:48 | 4276,559,871 | -HS- | M] () -- C:\pagefile.sys
[2012/01/13 19:40:17 | 000,000,457 | ---- | M] () -- C:\rkill.log
[2011/09/10 12:02:52 | 000,000,757 | ---- | M] () -- C:\Sys_LogWin.log
[2012/01/13 19:43:16 | 000,079,218 | ---- | M] () -- C:\TDSSKiller.2.7.0.0_13.01.2012_19.42.50_log.txt
[2012/01/15 11:21:03 | 000,003,300 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_11.21.00_log.txt
[2012/01/15 11:45:26 | 000,080,244 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_11.21.05_log.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 16:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 16:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 16:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 16:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 07:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 16:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 15:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/08 00:13:09 | 000,000,221 | -HS- | M] () -- C:\Users\Elliot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/01/07 04:37:34 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\Elliot\Desktop\aswMBR.exe
[2010/10/14 01:11:10 | 001,153,912 | ---- | M] (Emsi Software GmbH) -- C:\Users\Elliot\Desktop\BlitzBlank.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\Elliot\Desktop\boot_cleaner.exe
[2012/01/14 09:02:10 | 004,383,253 | R--- | M] (Swearware) -- C:\Users\Elliot\Desktop\ComboFix.exe
[2011/06/08 15:46:12 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\Elliot\Desktop\FixTDSS.exe
[2012/01/10 04:42:36 | 000,334,125 | ---- | M] () -- C:\Users\Elliot\Desktop\FSS.exe
[2012/01/14 16:37:56 | 000,302,592 | ---- | M] () -- C:\Users\Elliot\Desktop\hwwu458l.exe
[2012/01/13 09:22:46 | 000,799,545 | ---- | M] () -- C:\Users\Elliot\Desktop\ListParts64.exe
[2011/12/13 04:06:28 | 007,956,512 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Elliot\Desktop\mbam-rules.exe
[2012/01/14 12:54:02 | 009,851,496 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Elliot\Desktop\mbam-setup.exe
[2011/12/27 21:45:48 | 000,396,071 | ---- | M] () -- C:\Users\Elliot\Desktop\MiniToolBox.exe
[2012/01/14 12:35:42 | 079,769,280 | ---- | M] (Microsoft Corporation) -- C:\Users\Elliot\Desktop\msert.exe
[2011/10/17 00:22:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Elliot\Desktop\OTL.exe
[2012/01/14 12:18:40 | 050,331,648 | ---- | M] () -- C:\Users\Elliot\Desktop\R282233.exe
[2012/01/13 23:02:08 | 001,972,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Elliot\Desktop\tdsskiller.exe
[2009/11/16 10:31:46 | 094,540,416 | ---- | M] (Western Digital) -- C:\Users\Elliot\Desktop\wdab_4.50.6554.exe
[2 C:\Users\Elliot\Desktop\*.tmp files -> C:\Users\Elliot\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/11 08:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/06/11 04:25:06 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/06/11 04:25:06 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/06/11 04:25:06 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/06/11 04:25:06 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/06/11 04:25:06 | 000,786,432 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
[2011/06/11 04:25:06 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/06/11 04:26:27 | 000,000,402 | -HS- | M] () -- C:\Users\Elliot\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/01/13 19:36:12 | 000,014,440 | -HS- | M] () -- C:\ProgramData\db2am60oby25758xy4e00f7d271u4p355010g2o2s7gsn
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011/02/13 15:18:27 | 000,095,329 | ---- | M] ()(C:\Users\Elliot\Desktop\??+???+??...pdf) -- C:\Users\Elliot\Desktop\בן+יפה+נו...pdf
[2011/02/13 15:18:26 | 000,095,329 | ---- | C] ()(C:\Users\Elliot\Desktop\??+???+??...pdf) -- C:\Users\Elliot\Desktop\בן+יפה+נו...pdf
========== Alternate Data Streams ==========
@Alternate Data Stream - 65 bytes -> C:\Users\Elliot\Desktop\Invoice – 241111-1.docx:com.dropbox.attributes
< End of report >
========== LOP Check ==========
[2011/03/01 21:20:27 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\WD
[2011/03/13 19:25:01 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\albumworks
[2011/12/12 19:44:26 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Audacity
[2012/01/14 12:25:06 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Azureus
[2012/01/14 11:43:40 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\BACS.exe
[2011/03/07 11:39:04 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Canon
[2012/01/15 15:14:03 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Dropbox
[2011/10/08 12:39:58 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\EndNote
[2011/12/04 20:12:26 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\HandBrake
[2011/11/13 18:22:43 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Leadertech
[2011/12/04 19:50:35 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\MPEG Streamclip
[2012/01/14 13:14:49 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Okm
[2011/02/12 14:08:55 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\PCDr
[2011/04/05 14:45:19 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Photobook Designer
[2011/03/30 18:09:46 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Thinstall
[2011/02/11 18:49:51 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\WD
[2011/10/27 15:03:03 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Windows Live Writer
[2012/01/14 13:16:00 | 000,000,000 | ---D | M] -- C:\Users\Elliot\AppData\Roaming\Ybews
[2012/01/14 16:43:01 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000Core.job
[2012/01/15 13:46:03 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000UA.job
[2011/12/24 11:36:52 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/12/12 12:25:32 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/01/15 14:56:13 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
[2012/01/15 16:00:00 | 000,000,416 | ---- | M] () -- C:\Windows\Tasks\vtscheduletask.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/01/15 15:39:36 | 000,045,840 | ---- | M] () -- C:\ComboFix.txt
[2011/02/01 14:14:42 | 000,005,155 | RH-- | M] () -- C:\dell.sdr
[2011/06/12 20:11:54 | 000,000,000 | ---- | M] () -- C:\foo.txt
[2012/01/15 15:16:48 | 2133,676,031 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/10 22:02:53 | 000,000,500 | ---- | M] () -- C:\My Book (J) - Shortcut.lnk
[2012/01/15 15:16:48 | 4276,559,871 | -HS- | M] () -- C:\pagefile.sys
[2012/01/13 19:40:17 | 000,000,457 | ---- | M] () -- C:\rkill.log
[2011/09/10 12:02:52 | 000,000,757 | ---- | M] () -- C:\Sys_LogWin.log
[2012/01/13 19:43:16 | 000,079,218 | ---- | M] () -- C:\TDSSKiller.2.7.0.0_13.01.2012_19.42.50_log.txt
[2012/01/15 11:21:03 | 000,003,300 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_11.21.00_log.txt
[2012/01/15 11:45:26 | 000,080,244 | ---- | M] () -- C:\TDSSKiller.2.7.1.0_15.01.2012_11.21.05_log.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 16:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 16:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 16:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 16:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 07:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 16:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 15:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/08 00:13:09 | 000,000,221 | -HS- | M] () -- C:\Users\Elliot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/01/07 04:37:34 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\Elliot\Desktop\aswMBR.exe
[2010/10/14 01:11:10 | 001,153,912 | ---- | M] (Emsi Software GmbH) -- C:\Users\Elliot\Desktop\BlitzBlank.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\Elliot\Desktop\boot_cleaner.exe
[2012/01/14 09:02:10 | 004,383,253 | R--- | M] (Swearware) -- C:\Users\Elliot\Desktop\ComboFix.exe
[2011/06/08 15:46:12 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\Elliot\Desktop\FixTDSS.exe
[2012/01/10 04:42:36 | 000,334,125 | ---- | M] () -- C:\Users\Elliot\Desktop\FSS.exe
[2012/01/14 16:37:56 | 000,302,592 | ---- | M] () -- C:\Users\Elliot\Desktop\hwwu458l.exe
[2012/01/13 09:22:46 | 000,799,545 | ---- | M] () -- C:\Users\Elliot\Desktop\ListParts64.exe
[2011/12/13 04:06:28 | 007,956,512 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Elliot\Desktop\mbam-rules.exe
[2012/01/14 12:54:02 | 009,851,496 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Elliot\Desktop\mbam-setup.exe
[2011/12/27 21:45:48 | 000,396,071 | ---- | M] () -- C:\Users\Elliot\Desktop\MiniToolBox.exe
[2012/01/14 12:35:42 | 079,769,280 | ---- | M] (Microsoft Corporation) -- C:\Users\Elliot\Desktop\msert.exe
[2011/10/17 00:22:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Elliot\Desktop\OTL.exe
[2012/01/14 12:18:40 | 050,331,648 | ---- | M] () -- C:\Users\Elliot\Desktop\R282233.exe
[2012/01/13 23:02:08 | 001,972,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Elliot\Desktop\tdsskiller.exe
[2009/11/16 10:31:46 | 094,540,416 | ---- | M] (Western Digital) -- C:\Users\Elliot\Desktop\wdab_4.50.6554.exe
[2 C:\Users\Elliot\Desktop\*.tmp files -> C:\Users\Elliot\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/11 08:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/06/11 04:25:06 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/06/11 04:25:06 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/06/11 04:25:06 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/06/11 04:25:06 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/06/11 04:25:06 | 000,786,432 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
[2011/06/11 04:25:06 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/06/11 04:26:27 | 000,000,402 | -HS- | M] () -- C:\Users\Elliot\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2012/01/13 19:36:12 | 000,014,440 | -HS- | M] () -- C:\ProgramData\db2am60oby25758xy4e00f7d271u4p355010g2o2s7gsn
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011/02/13 15:18:27 | 000,095,329 | ---- | M] ()(C:\Users\Elliot\Desktop\??+???+??...pdf) -- C:\Users\Elliot\Desktop\בן+יפה+נו...pdf
[2011/02/13 15:18:26 | 000,095,329 | ---- | C] ()(C:\Users\Elliot\Desktop\??+???+??...pdf) -- C:\Users\Elliot\Desktop\בן+יפה+נו...pdf
========== Alternate Data Streams ==========
@Alternate Data Stream - 65 bytes -> C:\Users\Elliot\Desktop\Invoice – 241111-1.docx:com.dropbox.attributes
< End of report >