OTL.txt (2.cast):
O1 HOSTS File: ([2010.04.17 19:06:19 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Credential Manager for HP ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (NuSphere ToolBar) - {0F62D223-9206-4EA3-9EA8-D0F3C7C82ACA} - C:\Program Files\NuSphere\PhpED\NuSphereIEBar.dll ()
O4 - HKLM..\Run: [accrdsub] c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AT&T Communication Manager] c:\Program Files\AT&T\Communication Manager\ATTCM.exe (ATT)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CognizanceTS] C:\Program Files\Hewlett-Packard\IAM\Bin\ASTSVCC.dll (Cognizance Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PTHOSTTR] c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [RTBatteryMeter] C:\Program Files\VibrateGameDeviceDriver\rfpicon.exe (Ruling Tec Pte Ltd)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKCU..\Run: [QIP Internet Guardian] C:\Documents and Settings\Owner\Application Data\QipGuard\QipGuard.exe ()
O4 - HKCU..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - HKCU..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\8011.lnk = C:\DOCUME~1\Owner\LOCALS~1\Temp\mvNat.exe File not found
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Spoon Sandbox Manager 3.14.lnk = C:\Documents and Settings\Owner\Local Settings\Application Data\Spoon\3.14.0.5\Spoon-Sandbox.exe (Code Systems Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 18
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: verbosestatus = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: NuSphere PhpED :: Debug this page - C:\Program Files\NuSphere\PhpED\NuSphereIEBar.dll ()
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Nastavenia rozšírenia &Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/microsoftup ... 1506473359 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftup ... 1506464718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 158.195.4.3 158.195.2.6
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ackpbsc: DllName - c:\WINDOWS\system32\ackpbsc.dll - C:\WINDOWS\system32\ackpbsc.dll (ActivIdentity)
O20 - Winlogon\Notify\acunlock: DllName - c:\Program Files\ActivIdentity\ActivClient\acunlock.dll - c:\Program Files\ActivIdentity\ActivClient\acunlock.dll (ActivIdentity)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\DeviceNP: DllName - DeviceNP.dll - C:\WINDOWS\System32\DeviceNP.dll (Hewlett-Packard Limited)
O20 - Winlogon\Notify\OneCard: DllName - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll (Bioscrypt Inc.)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.07.16 04:04:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.04.20 16:15:52 | 000,562,176 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010.04.20 16:07:31 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.19 00:00:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Invazia- Blato nad zlato
[2010.04.18 21:32:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\INVAZIA - Raperi od hranic... Bez hranic
[2010.04.17 19:57:55 | 000,882,672 | ---- | C] (Duplex Secure Ltd.) -- C:\Documents and Settings\Owner\Desktop\SPTDinst-v169-x86.exe
[2010.04.17 18:51:40 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.04.17 18:42:05 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\wscntfy.exe
[2010.04.17 17:27:21 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2010.04.17 17:27:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2010.04.17 17:27:19 | 000,000,000 | ---D | C] -- C:\Program Files\windows nt
[2010.04.17 17:27:19 | 000,000,000 | ---D | C] -- C:\Program Files\outlook express
[2010.04.17 17:27:18 | 000,000,000 | ---D | C] -- C:\Program Files\netmeeting
[2010.04.17 17:27:18 | 000,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2010.04.17 17:27:18 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2010.04.17 17:27:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2010.04.17 17:07:16 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.04.17 17:07:16 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.04.17 17:07:15 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.04.17 17:07:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.04.17 17:07:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.17 17:02:55 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.04.17 16:04:24 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.17 14:19:49 | 000,178,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wintrust.dll
[2010.04.17 14:19:39 | 002,190,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2010.04.17 14:19:39 | 002,146,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2010.04.17 14:19:38 | 002,024,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2010.04.17 14:19:37 | 002,066,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2010.04.17 14:19:29 | 000,226,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip6.sys
[2010.04.17 14:19:29 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\6to4svc.dll
[2010.04.17 14:19:24 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vbscript.dll
[2010.04.17 14:19:15 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2010.04.17 14:19:08 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2010.04.17 14:19:07 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2010.04.17 14:19:07 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2010.04.17 14:19:07 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
[2010.04.17 14:19:07 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2010.04.17 14:18:37 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe
[2010.04.17 14:18:25 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
[2010.04.17 14:18:19 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iyuv_32.dll
[2010.04.17 14:18:19 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msvidc32.dll
[2010.04.17 14:18:19 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrle32.dll
[2010.04.17 14:18:19 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsbyuv.dll
[2010.04.17 14:18:10 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msyuv.dll
[2010.04.17 14:18:04 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\csrsrv.dll
[2010.04.17 14:17:58 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shlwapi.dll
[2010.04.17 14:17:41 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
[2010.04.17 14:17:37 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oakley.dll
[2010.04.17 14:17:31 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\raschap.dll
[2010.04.17 14:17:26 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winhttp.dll
[2010.04.17 14:17:19 | 000,265,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\http.sys
[2010.04.17 14:17:19 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\strmfilt.dll
[2010.04.17 14:17:19 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpapi.dll
[2010.04.17 14:17:13 | 001,447,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll
[2010.04.17 14:17:13 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml3.dll
[2010.04.17 14:16:59 | 001,435,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\query.dll
[2010.04.17 14:16:48 | 000,247,326 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\strmdll.dll
[2010.04.17 14:16:43 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msasn1.dll
[2010.04.17 14:16:11 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jscript.dll
[2010.04.17 14:14:59 | 000,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2010.04.17 14:14:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2010.04.17 02:31:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Invazia - Medzi Casom (2010)
[2010.04.13 17:31:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\temp
[2010.04.12 19:08:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\ReUpGang_Cracksploitation_Vol2
[2010.04.12 14:23:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Far20b1420.x86.20100225
[2010.04.12 14:22:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Documentation
[2010.04.12 13:29:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Masta_Ace_And_Edo_G-Arts_And_Entertainment-2009
[2010.04.11 01:01:51 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.04.11 01:01:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.04.11 01:01:51 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.04.11 01:01:51 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.04.08 20:57:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\cat
[2010.04.07 19:49:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\1. rocnik
[2010.04.02 20:26:23 | 000,000,000 | ---D | C] -- C:\Program Files\Buzzer Control
[2010.04.02 20:24:59 | 001,237,487 | ---- | C] (gardier ) -- C:\Documents and Settings\Owner\Desktop\BuzzerControl_setup_1.03.exe
[2010.03.31 19:15:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2010.03.31 18:40:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Avira
[2010.03.31 14:15:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Seiz - Minifunxtape (2008)
[2010.03.31 13:59:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\QipGuard
[2010.03.22 20:18:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\catalog
[2009.11.28 11:49:14 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\Documents and Settings\All Users\Application Data\hpe8.dll
[2009.08.14 12:09:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009.08.14 12:04:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009.07.17 12:19:14 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009.07.16 15:36:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2009.07.16 04:05:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009.07.16 04:05:36 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009.07.16 04:03:56 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.04.20 16:17:25 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5C46FB11-4F45-431C-BE9F-36C6B3934444}.job
[2010.04.20 16:15:53 | 000,562,176 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010.04.20 15:50:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1770027372-1801674531-1003UA.job
[2010.04.20 15:29:00 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.04.20 12:59:42 | 000,245,248 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.04.20 12:43:51 | 000,007,327 | ---- | M] () -- C:\Documents and Settings\Owner\.recently-used.xbel
[2010.04.20 12:23:04 | 000,028,428 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Dieta_a_rodina_960x100.swf
[2010.04.20 12:23:04 | 000,001,032 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Dieta_a_rodina_960x100.html
[2010.04.20 12:23:02 | 000,029,115 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\fwdfwdrebannerynaforbaby.zip
[2010.04.20 11:02:43 | 000,441,692 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.04.20 11:02:43 | 000,071,462 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.04.20 11:02:42 | 000,521,942 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.04.20 11:01:13 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.04.20 10:57:38 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.20 10:57:30 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.20 10:57:23 | 2549,403,648 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.20 01:31:52 | 008,126,464 | -H-- | M] () -- C:\Documents and Settings\Owner\NTUSER.DAT
[2010.04.20 01:31:52 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Owner\ntuser.ini
[2010.04.19 21:33:07 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.19 00:49:12 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\noname1.css
[2010.04.18 21:37:49 | 000,017,528 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\gdf.pdf
[2010.04.18 21:37:49 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\FOXIT_PDF
[2010.04.18 10:50:03 | 000,001,040 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1770027372-1801674531-1003Core.job
[2010.04.17 20:12:16 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010.04.17 20:10:46 | 000,077,312 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\mbr.exe
[2010.04.17 20:05:42 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Owner\defogger_reenable
[2010.04.17 20:05:13 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Defogger.exe
[2010.04.17 19:57:56 | 000,882,672 | ---- | M] (Duplex Secure Ltd.) -- C:\Documents and Settings\Owner\Desktop\SPTDinst-v169-x86.exe
[2010.04.17 19:06:19 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.04.17 18:51:49 | 000,000,293 | RHS- | M] () -- C:\boot.ini
[2010.04.17 18:41:44 | 000,007,120 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\wscntfy.zip
[2010.04.17 18:28:36 | 000,079,324 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\BuzzerBeater - BK Pendechos @ Roshtar BC - 17. 4. 2010 Ligový zápas_1271521714494.png
[2010.04.17 16:47:09 | 003,916,775 | R--- | M] () -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2010.04.17 16:04:04 | 000,781,909 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\RSIT.exe
[2010.04.17 14:42:52 | 002,122,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.17 14:15:53 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.17 12:12:13 | 003,819,559 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Luzer_-_stebu_sa_to_neda.mp3
[2010.04.17 11:56:11 | 000,141,668 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\BuzzerBeater - BK Pendechos @ Roshtar BC - 17. 4. 2010 Ligový zápas_1271498167473.png
[2010.04.17 02:31:08 | 007,921,479 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Invazia_-_Ataker.mp3
[2010.04.17 02:28:47 | 063,041,440 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Invazia - Medzi Casom (2010) up by djmirente.rar
[2010.04.17 02:23:29 | 004,647,706 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Daimonion_-_Sloboda.mp3
[2010.04.16 21:44:27 | 000,043,997 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Supernatural - 05x18 - Point of No Return.NoTV.Addic7ed.com.srt
[2010.04.16 16:35:09 | 000,002,269 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\index.html
[2010.04.16 10:39:18 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\winscp.rnd
[2010.04.15 13:57:49 | 000,000,598 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010.04.14 21:53:19 | 000,109,536 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\1271274844051.pdf
[2010.04.12 21:08:55 | 000,304,650 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\latex.pdf
[2010.04.12 16:19:31 | 000,205,150 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\transfer.ps.gz
[2010.04.12 14:22:38 | 003,302,648 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Far20b1420.x86.20100225.7z
[2010.04.12 14:11:48 | 000,047,135 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\1 - start.rar
[2010.04.12 11:00:33 | 000,117,563 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\1271062861641.pdf
[2010.04.12 00:04:16 | 000,135,000 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\11038859-1001-Movies-You-Must-See-Before-You-Die.pdf
[2010.04.11 01:01:28 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2010.04.11 01:01:28 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.04.11 01:01:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.04.11 01:01:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.04.11 01:01:28 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.04.10 11:02:03 | 000,001,511 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2010.04.09 12:03:45 | 000,371,461 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\adresar_skol.csv
[2010.04.08 23:35:19 | 009,216,962 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Barrington Levy feat_ Snoop Dogg _ Mims Watch Dem (Murderer).mp3
[2010.04.08 20:43:55 | 000,156,564 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\e-ubytovanie- Podanie žiadosti o ubytovanie_1270752232756.png
[2010.04.07 20:24:44 | 000,012,888 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\obrazok.gif
[2010.04.06 22:57:44 | 000,001,107 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\transparent2.gif
[2010.04.06 22:52:09 | 000,006,836 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\transgif-sample.gif
[2010.04.06 22:52:02 | 000,006,773 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\logopv.jpg
[2010.04.02 20:25:14 | 001,237,487 | ---- | M] (gardier ) -- C:\Documents and Settings\Owner\Desktop\BuzzerControl_setup_1.03.exe
[2010.03.31 17:53:29 | 042,281,152 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\avira_antivir_personal_en.exe
[2010.03.31 16:36:47 | 054,265,823 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\eReMeN - Volaj to jak chceš (2009) .rar
[2010.03.31 14:17:34 | 156,607,328 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\OOo_3.2.0_Win32Intel_install_wJRE_en-US.exe
[2010.03.29 12:21:14 | 001,290,714 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\temp.pdf
[2010.03.29 12:21:14 | 001,290,714 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\sample.pdf
[2010.03.26 15:51:55 | 000,002,319 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\confirm_button.png
[2010.03.26 11:20:59 | 001,071,290 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\100325213230.rar
[2010.03.26 11:20:24 | 014,110,856 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\100325213230.sql
[2010.03.26 10:27:10 | 000,001,657 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\dataSynchFloraDovolenka.npd
[2010.03.26 01:07:34 | 000,001,476 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\dovolenka-test.npd
[2010.03.24 22:04:45 | 000,008,927 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\foto_043004.jpg
[2010.03.23 14:16:57 | 000,021,744 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\1044.jpg
[2010.03.23 12:14:56 | 000,000,061 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\vgroup.xml
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.04.20 12:43:51 | 000,007,327 | ---- | C] () -- C:\Documents and Settings\Owner\.recently-used.xbel
[2010.04.20 12:23:13 | 000,028,428 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Dieta_a_rodina_960x100.swf
[2010.04.20 12:23:13 | 000,001,032 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Dieta_a_rodina_960x100.html
[2010.04.20 12:23:01 | 000,029,115 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\fwdfwdrebannerynaforbaby.zip
[2010.04.19 00:16:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\noname1.css
[2010.04.17 20:13:16 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\gmer.exe
[2010.04.17 20:12:15 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010.04.17 20:10:45 | 000,077,312 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\mbr.exe
[2010.04.17 20:05:42 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\defogger_reenable
[2010.04.17 20:05:12 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Defogger.exe
[2010.04.17 18:51:49 | 000,000,223 | ---- | C] () -- C:\Boot.bak
[2010.04.17 18:51:45 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010.04.17 18:41:43 | 000,007,120 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\wscntfy.zip
[2010.04.17 18:28:36 | 000,079,324 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\BuzzerBeater - BK Pendechos @ Roshtar BC - 17. 4. 2010 Ligový zápas_1271521714494.png
[2010.04.17 17:07:16 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.17 17:07:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.04.17 17:07:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.04.17 17:07:16 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.17 17:07:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.04.17 16:47:08 | 003,916,775 | R--- | C] () -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2010.04.17 16:04:03 | 000,781,909 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\RSIT.exe
[2010.04.17 12:07:18 | 003,819,559 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Luzer_-_stebu_sa_to_neda.mp3
[2010.04.17 11:56:10 | 000,141,668 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\BuzzerBeater - BK Pendechos @ Roshtar BC - 17. 4. 2010 Ligový zápas_1271498167473.png
[2010.04.17 02:27:12 | 063,041,440 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Invazia - Medzi Casom (2010) up by djmirente.rar
[2010.04.17 02:23:15 | 004,647,706 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Daimonion_-_Sloboda.mp3
[2010.04.17 02:21:13 | 007,921,479 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Invazia_-_Ataker.mp3
[2010.04.16 21:44:26 | 000,043,997 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Supernatural - 05x18 - Point of No Return.NoTV.Addic7ed.com.srt
[2010.04.16 16:02:39 | 000,017,528 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\gdf.pdf
[2010.04.16 10:39:15 | 000,221,883 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\slovbateri.inc.1
[2010.04.15 16:43:29 | 000,002,269 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\index.html
[2010.04.14 21:53:18 | 000,109,536 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\1271274844051.pdf
[2010.04.12 21:09:26 | 000,304,650 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\latex.pdf
[2010.04.12 16:19:37 | 000,879,830 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\transfer.ps
[2010.04.12 16:19:30 | 000,205,150 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\transfer.ps.gz
[2010.04.12 14:22:37 | 003,302,648 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Far20b1420.x86.20100225.7z
[2010.04.12 14:11:47 | 000,047,135 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\1 - start.rar
[2010.04.12 11:00:32 | 000,117,563 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\1271062861641.pdf
[2010.04.12 00:04:15 | 000,135,000 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\11038859-1001-Movies-You-Must-See-Before-You-Die.pdf
[2010.04.10 11:02:03 | 000,001,511 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2010.04.09 12:03:45 | 000,371,461 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\adresar_skol.csv
[2010.04.08 23:33:28 | 009,216,962 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Barrington Levy feat_ Snoop Dogg _ Mims Watch Dem (Murderer).mp3
[2010.04.08 20:43:54 | 000,156,564 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\e-ubytovanie- Podanie žiadosti o ubytovanie_1270752232756.png
[2010.04.06 22:57:44 | 000,001,107 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\transparent2.gif
[2010.04.06 22:52:09 | 000,006,836 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\transgif-sample.gif
[2010.04.06 22:52:01 | 000,006,773 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\logopv.jpg
[2010.04.06 22:31:56 | 000,012,888 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\obrazok.gif
[2010.03.31 17:44:41 | 042,281,152 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\avira_antivir_personal_en.exe
[2010.03.31 16:19:06 | 054,265,823 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\eReMeN - Volaj to jak chceš (2009) .rar
[2010.03.31 14:16:50 | 156,607,328 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\OOo_3.2.0_Win32Intel_install_wJRE_en-US.exe
[2010.03.29 12:22:25 | 001,290,714 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\sample.pdf
[2010.03.29 12:21:29 | 001,290,714 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\temp.pdf
[2010.03.26 15:51:55 | 000,002,319 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\confirm_button.png
[2010.03.26 11:43:06 | 000,001,657 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\dataSynchFloraDovolenka.npd
[2010.03.26 11:43:06 | 000,001,476 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\dovolenka-test.npd
[2010.03.26 11:43:04 | 000,000,061 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\vgroup.xml
[2010.03.26 11:24:08 | 014,110,856 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\100325213230.sql
[2010.03.26 11:21:55 | 001,071,290 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\100325213230.rar
[2010.03.24 22:04:45 | 000,008,927 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\foto_043004.jpg
[2010.03.23 14:16:57 | 000,021,744 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\1044.jpg
[2010.03.19 00:30:18 | 000,005,521 | ---- | C] () -- C:\Documents and Settings\Owner\search.png
[2010.03.06 23:26:17 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\PUTTY.RND
[2010.03.02 22:47:29 | 000,000,103 | ---- | C] () -- C:\WINDOWS\pro.INI
[2010.02.26 14:42:17 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\6eccrad1cq9167tty
[2010.01.18 16:51:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\.cvspass
[2010.01.08 01:32:40 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2009.12.10 23:44:20 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\FnF4.txt
[2009.10.27 00:01:50 | 000,003,654 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2009.10.27 00:00:22 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\globhist.htm
[2009.10.27 00:00:22 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\favorite.htm
[2009.10.20 20:19:30 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2009.10.13 23:17:18 | 001,589,248 | ---- | C] () -- C:\WINDOWS\System32\libmysql_d.dll
[2009.09.24 23:01:22 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009.09.15 22:20:46 | 000,000,146 | ---- | C] () -- C:\Documents and Settings\Owner\.appletviewer
[2009.07.29 10:39:23 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\.javafx_eula_accepted
[2009.07.17 14:45:22 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009.07.17 10:51:28 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Owner\ho.dir
[2009.07.16 14:10:43 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\winscp.rnd
[2009.07.16 12:04:55 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2009.07.16 12:04:54 | 000,753,664 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009.07.16 12:03:51 | 000,029,132 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2009.07.16 04:46:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\QSwitch.txt
[2009.07.16 04:46:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DSwitch.txt
[2009.07.16 04:46:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\AtStart.txt
[2009.07.16 04:18:47 | 000,245,248 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.07.16 04:15:04 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009.07.16 04:15:02 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2009.07.16 04:15:01 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009.07.16 04:15:01 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.07.16 04:15:01 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.07.16 04:15:00 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.07.16 04:15:00 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009.07.16 04:10:49 | 000,094,248 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009.07.16 04:05:54 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Owner\ntuser.ini
[2009.07.16 04:05:53 | 000,007,287 | ---- | C] () -- C:\Documents and Settings\Owner\ASPNETSetup.log
[2009.07.16 04:05:52 | 008,126,464 | -H-- | C] () -- C:\Documents and Settings\Owner\NTUSER.DAT
[2009.07.16 04:05:52 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Owner\NTUSER.DAT.LOG
[2009.04.20 20:25:16 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\msvcrt10.dll
[2007.06.08 16:05:38 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\flcdlmsg.dll
[2007.02.06 22:20:00 | 002,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007.02.06 21:55:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005.02.17 18:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 18:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001.11.14 19:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1998.05.07 10:10:00 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\ODMA32.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1DEE6B65
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6017A808
< End of report >