CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 30 Days ==========
[2010/07/11 07:26:53 | 000,000,000 | —D | C] – C:\6db783fe362b3fa5a448228fffc5
[2010/07/10 16:19:21 | 000,000,000 | -HSD | C] – C:\found.000
[2010/07/10 15:26:46 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/07/10 07:20:03 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\HP
[2010/07/10 06:46:39 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/07/09 16:51:59 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/07/09 16:51:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/07/09 16:40:24 | 000,017,744 | ---- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/07/09 16:40:23 | 000,165,456 | ---- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/07/09 16:40:23 | 000,023,376 | ---- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/07/09 16:40:22 | 000,046,672 | ---- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/07/09 16:40:21 | 000,100,176 | ---- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/07/09 16:40:21 | 000,094,544 | ---- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/07/09 16:40:21 | 000,028,880 | ---- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/07/09 16:40:02 | 000,165,032 | ---- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/07/09 16:40:02 | 000,038,848 | ---- | C] (ALWIL Software) – C:\WINDOWS\avastSS.scr
[2010/07/09 16:23:05 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/07/09 16:23:04 | 000,000,000 | --SD | C] – C:\ComboFix
[2010/07/09 16:18:10 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/09 12:56:15 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Auslogics
[2010/07/09 12:56:12 | 000,000,000 | —D | C] – C:\Program Files\Auslogics
[2010/07/09 12:52:33 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/07/09 12:45:37 | 000,038,224 | ---- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/09 12:45:32 | 000,020,952 | ---- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/09 12:31:18 | 000,000,000 | —D | C] – C:\Malware Removal Tools
[3 C:\WINDOWS*.tmp files → C:\WINDOWS*.tmp → ]
[13 C:\WINDOWS\System32*.tmp files → C:\WINDOWS\System32*.tmp → ]
========== Files - Modified Within 30 Days ==========
[2010/07/11 09:52:00 | 000,000,444 | -H-- | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{005FA7B1-60F5-44E9-A33B-3A8DF98FCC41}.job
[2010/07/11 09:45:00 | 000,001,022 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2159621661-3826989892-1658989840-1008UA.job
[2010/07/11 07:32:01 | 000,000,246 | ---- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2010/07/11 07:24:28 | 000,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/11 07:24:06 | 000,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/11 07:24:03 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2010/07/11 00:55:01 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\ntuser.ini
[2010/07/11 00:55:00 | 002,084,864 | ---- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\ntuser.dat
[2010/07/09 18:10:30 | 000,001,740 | ---- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/09 17:35:40 | 000,000,318 | ---- | M] () – C:\WINDOWS\WININIT.INI
[2010/07/09 16:52:03 | 000,000,962 | ---- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/09 16:52:03 | 000,000,944 | ---- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\Spybot - Search & Destroy.lnk
[2010/07/09 16:40:24 | 000,001,711 | ---- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/07/09 16:40:22 | 000,002,626 | ---- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/07/09 12:56:13 | 000,000,812 | ---- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\Auslogics Disk Defrag.lnk
[2010/07/09 12:52:34 | 000,000,693 | ---- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\CCleaner.lnk
[2010/07/09 12:45:39 | 000,000,707 | ---- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes’ Anti-Malware.lnk
[2010/07/09 12:45:00 | 000,000,970 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2159621661-3826989892-1658989840-1008Core.job
[2010/07/09 07:19:06 | 000,051,672 | ---- | M] () – C:\VETlog.dmp
[2010/07/09 07:19:05 | 000,000,697 | ---- | M] () – C:\WINDOWS\win.ini
[2010/07/08 22:21:21 | 000,001,158 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/28 15:57:33 | 000,038,848 | ---- | M] (ALWIL Software) – C:\WINDOWS\avastSS.scr
[2010/06/28 15:57:12 | 000,165,032 | ---- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/06/28 15:37:52 | 000,046,672 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/06/28 15:37:30 | 000,165,456 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/06/28 15:33:13 | 000,023,376 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/06/28 15:32:45 | 000,100,176 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/06/28 15:32:42 | 000,094,544 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/06/28 15:32:33 | 000,017,744 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/06/28 15:32:16 | 000,028,880 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/06/24 10:22:39 | 000,000,414 | -H-- | M] () – C:\IPH.PH
[2010/06/17 09:25:52 | 000,047,902 | ---- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\My Documents\Proof of Insurance 6-18-10.pdf
[3 C:\WINDOWS*.tmp files → C:\WINDOWS*.tmp → ]
[13 C:\WINDOWS\System32*.tmp files → C:\WINDOWS\System32*.tmp → ]