last Sunday the 28. I used my mobile HDD to help a friend reinstall his system as it was running quite slow. The Icon of my HDD changed when I was using his machine. After getting back home I checked the autorun.inf file to see why the Icon isn't showing anymore and found a reference to a hidden, unknown to me, file in:
X:\veliki\heroj.exe (checked in google translate and it means \great\hero.exe in Slovenian )
Both the directory and the file were hidden.
The autorun.inf contained every possible references and commands to the file including shell; open; shellexecute; icon
(included was also a command with a reference to a particular personal activity that was probably not meant for my PC )
I tried a scan with MSEssentials but the file was not recognized as a threat.
I then tried to rename it to .txt and open it with notepad, but the content was not readable that way.
Then I uploaded the file to virustotal.com and received positive identification as a threat from 30% of the software tools used to scan it.
Sadly I did not save a log file from virustotal and deleted the files personally. Only afterwards did I search on-line for help and stumbled upon "Geeks to go".
I also uninstalled MSEssentials and installed Avast free Antivirus.
Upon a deep scan with Avast two positive results came up and were both deleted by the program.
Here's a screen from the Scan log file:
http://dl.dropbox.co...51091/avast.JPG
I fear that I might have executed the virus file when I plugged my HDD, and therefore compromised my PC. And I need your help to find out for sure.
A few small bugs have popped up since the incident.
Once the space bar was not registering on my VLC player and at the same time I had zero traffic through my LAN connection (could not download or open any site). Both symptoms disappeared within a few hours.
There hasn't been anything else noteworthy.
Here is also my OTL log file
(scaning options set as in http://www.geekstogo...e_icons/otl.png):
====================================== OTL Log File ==============================================
OTL logfile created on: 05/03/2011 16:00:44 - Run 4
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\Dimitar\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 190.37 Gb Free Space | 63.86% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 226.38 Gb Free Space | 75.94% Space Free | Partition Type: NTFS
Computer Name: DIMI | User Name: Dimitar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dimitar\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Documents and Settings\Dimitar\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\Tvs\TvsTray.exe (TOSHIBA Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\TDispVol.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TCtrlIOHook.exe (TOSHIBA)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Dimitar\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\TDispVol.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) -- File not found
SRV - (AppMgmt) -- File not found
SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (FsUsbExService) -- C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
========== Driver Services (SafeList) ==========
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (aswSnx) -- C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (FsUsbExDisk) -- C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (ss_bmdm) -- C:\WINDOWS\system32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\WINDOWS\system32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (cpudrv) -- C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (hidusbf) -- C:\WINDOWS\system32\drivers\hidusbf.sys (SweetLow)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Tvs) -- C:\WINDOWS\system32\drivers\Tvs.sys (TOSHIBA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (w39n51) Intel® -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (TPwSav) -- C:\WINDOWS\system32\drivers\TPwSav.sys (TOSHIBA )
DRV - (tifm21) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (AR5211) -- C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (tosrfec) -- C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (Thpdrv) -- C:\WINDOWS\system32\DRIVERS\thpdrv.sys (TOSHIBA Corporation)
DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (Thpevm) -- C:\WINDOWS\system32\DRIVERS\Thpevm.SYS (TOSHIBA Corporation)
DRV - (Pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [email protected]:4.3
FF - prefs.js..extensions.enabledItems: [email protected]:5.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:2.0.2
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: [email protected]:2.0
FF - prefs.js..extensions.enabledItems: FasterFox_Lite@BigRedBrent:3.9.1Lite
FF - prefs.js..extensions.enabledItems: [email protected]:0.7.2.20110110
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.1
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - prefs.js..extensions.enabledItems: {61D0D7AF-4FF6-476a-B68F-6531F613A6D8}:0.2.2
FF - prefs.js..extensions.enabledItems: {966762eb-7132-4081-ac70-20d20161ad96}:3.2.1
FF - prefs.js..extensions.enabledItems: {21cfaec0-dbb3-11dc-95ff-0800200c9a66}:1.1.2.4
FF - prefs.js..extensions.enabledItems: {0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}:1.0.1
FF - prefs.js..extensions.enabledItems: {21e48e29-f574-4619-b65d-0f00eea92e5b}:1.85
FF - prefs.js..extensions.enabledItems: [email protected]:0.8.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.2
FF - prefs.js..extensions.enabledItems: [email protected]:2.6.5
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/02/22 10:43:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/02/28 14:21:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/19 22:10:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/22 10:44:36 | 000,000,000 | ---D | M]
[2011/02/22 21:17:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Extensions
[2011/02/22 21:17:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2011/03/05 15:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions
[2011/02/28 16:21:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{00352F14-3F76-4e4d-ACFF-9972D7E4B3B9}
[2011/02/28 11:35:43 | 000,000,000 | ---D | M] (Auto Copy) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}
[2011/02/27 00:47:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/27 04:15:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{20C3BDFF-DA68-468d-8D9A-F5A6C76B0F9E}
[2011/02/28 11:35:43 | 000,000,000 | ---D | M] (Easy DragToGo) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{21cfaec0-dbb3-11dc-95ff-0800200c9a66}
[2011/02/28 11:35:42 | 000,000,000 | ---D | M] ("GoogleEnhancer") -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{21e48e29-f574-4619-b65d-0f00eea92e5b}
[2011/02/26 17:02:03 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2011/02/27 04:13:51 | 000,000,000 | ---D | M] ("Stop-or-Reload Button") -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{61D0D7AF-4FF6-476a-B68F-6531F613A6D8}
[2011/02/28 16:17:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{6E1A2A2E-AE2A-4A26-A812-46F54288379E}
[2011/02/27 04:13:51 | 000,000,000 | ---D | M] (Clip to OneNote) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{966762eb-7132-4081-ac70-20d20161ad96}
[2011/02/25 10:04:41 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2011/02/21 01:38:07 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/02/19 02:45:08 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011/02/28 16:21:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\{d650973c-0444-4ac7-9d00-19e3613c83b9}
[2011/02/26 05:49:53 | 000,000,000 | ---D | M] (Add to Search Bar) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/24 11:01:31 | 000,000,000 | ---D | M] (Bulgarian Dictionary) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/27 00:47:50 | 000,000,000 | ---D | M] (InvisibleHand) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 16:20:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/24 11:01:31 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/24 11:01:31 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/26 17:02:04 | 000,000,000 | ---D | M] (Fasterfox Lite) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\FasterFox_Lite@BigRedBrent
[2011/02/27 00:47:50 | 000,000,000 | ---D | M] (FireGestures) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 11:35:41 | 000,000,000 | ---D | M] (Foxdie for Firefox) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 11:01:35 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 11:35:42 | 000,000,000 | ---D | M] ("Lazy Click") -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/27 00:26:04 | 000,000,000 | ---D | M] (Omnibar) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 16:19:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 11:35:42 | 000,000,000 | ---D | M] (Saved Passwords Button) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 16:21:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 10:57:53 | 000,000,000 | ---D | M] (Strata RELOADED) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]
[2011/02/28 10:57:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]\chrome\3.5x\mozapps\extensions
[2011/02/28 10:57:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]\chrome\3.6x\mozapps\extensions
[2011/02/28 10:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]\chrome\3.6x\mozapps_old\extensions
[2011/02/28 10:57:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]\chrome\4.0x\mozapps\extensions
[2011/02/28 10:57:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]\chrome\imageres\mozapps\extensions
[2011/02/28 10:57:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\extensions\[email protected]\chrome\imageres\mozapps\extensions\3.6
[2011/02/22 21:17:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\SeaMonkey\Profiles\msoh7otm.default\extensions
[2011/02/26 05:50:39 | 000,000,482 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\searchplugins\hyperdictionarycom.xml
[2011/02/21 03:00:33 | 000,012,703 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\searchplugins\imdb.xml
[2011/03/01 07:42:10 | 000,004,873 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\searchplugins\isohunt--bt-search.xml
[2011/03/01 13:50:08 | 000,002,612 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\searchplugins\kickasstorrents.xml
[2011/02/26 05:55:51 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\Mozilla\Firefox\Profiles\gn54bkxe.default\searchplugins\zamundanet.xml
[2011/03/05 15:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/02/20 08:31:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/02/20 08:31:13 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/20 08:31:12 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/03 19:47:02 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 19:47:02 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 19:47:02 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/03 19:47:02 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2011/02/22 10:33:59 | 000,000,764 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe (TOSHIBA CO.,LTD.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\System32\TCtrlIOHook.exe (TOSHIBA)
O4 - HKLM..\Run: [TDispVol] C:\WINDOWS\System32\TDispVol.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Zooming] C:\WINDOWS\System32\ZoomingHook.exe (TOSHIBA)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10m_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Dimitar\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Dimitar\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1298088958086 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...ri_4.4.21.0.cab (SysInfo Class)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dimitar\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dimitar\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/09 15:59:42 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2011/02/28 13:48:15 | 000,000,076 | R--- | M] () - E:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/03/04 19:40:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/03/04 16:42:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\dvdcss
[2011/03/03 12:26:43 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dimitar\Desktop\OTL.exe
[2011/03/03 11:09:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Intel Corporation
[2011/03/03 11:09:51 | 000,000,000 | ---D | C] -- C:\Program Files\Intel Corporation
[2011/03/02 15:24:25 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Dimitar\Recent
[2011/03/02 09:56:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/03/02 09:56:07 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/03/02 08:09:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/03/02 07:59:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Desktop\VirusScan
[2011/03/02 07:50:16 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/03/02 05:42:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\PayPal
[2011/03/02 05:11:15 | 000,000,000 | ---D | C] -- C:\Program Files\EASEUS
[2011/03/01 18:56:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\My Art
[2011/03/01 18:22:53 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\My Documents\Dropbox
[2011/03/01 18:21:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Dropbox
[2011/03/01 18:20:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Dropbox
[2011/02/28 14:21:20 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/02/28 14:21:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/02/28 14:21:19 | 000,301,528 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/02/28 14:21:18 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/02/28 14:21:17 | 000,371,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/02/28 14:21:17 | 000,049,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/02/28 14:21:16 | 000,102,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/02/28 14:21:16 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/02/28 14:21:15 | 000,030,680 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/02/28 14:21:04 | 000,190,016 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/02/28 14:21:04 | 000,040,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/02/28 14:21:00 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/02/28 14:21:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/02/26 08:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
[2011/02/26 07:31:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2011/02/26 07:31:16 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2011/02/26 07:31:08 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2011/02/26 07:27:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Games for Windows - LIVE
[2011/02/26 07:27:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xlive
[2011/02/26 07:27:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games for Windows - LIVE
[2011/02/25 11:06:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\EA Games
[2011/02/25 10:51:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\EA Games
[2011/02/25 10:20:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DeadSpace 2 Collectors Edition
[2011/02/25 10:16:56 | 000,000,000 | ---D | C] -- C:\Program Files\DeadSpace 2 Collectors Edition
[2011/02/25 08:58:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\Professional
[2011/02/25 08:36:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Jaangle
[2011/02/25 08:36:45 | 000,000,000 | ---D | C] -- C:\Program Files\Jaangle
[2011/02/25 08:05:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\Personal
[2011/02/24 01:14:53 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2011/02/24 01:14:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2011/02/24 01:08:30 | 000,000,000 | ---D | C] -- C:\Program Files\Trine
[2011/02/23 00:43:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\CV
[2011/02/23 00:24:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Temp
[2011/02/23 00:01:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/02/22 11:09:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\WebKit-r79284
[2011/02/22 10:58:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/02/22 10:44:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe LiveCycle ES2
[2011/02/22 01:47:59 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2011/02/22 01:47:42 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/02/21 18:42:14 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2011/02/21 18:34:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\SystemRequirementsLab
[2011/02/21 18:34:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2011/02/21 05:31:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\McAfee
[2011/02/20 08:31:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2011/02/20 08:30:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Sun
[2011/02/20 00:28:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Catalyst Control Center
[2011/02/19 23:39:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Apple Computer
[2011/02/19 22:00:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/02/19 22:00:32 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/02/19 22:00:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2011/02/19 22:00:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011/02/19 22:00:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Apple
[2011/02/19 21:59:59 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011/02/19 21:59:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2011/02/19 21:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Apple Computer
[2011/02/19 19:47:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Windows Search
[2011/02/19 19:40:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/02/19 19:40:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011/02/19 19:39:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Identities
[2011/02/19 19:39:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Windows Desktop Search
[2011/02/19 08:22:59 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2011/02/19 08:22:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2011/02/19 08:21:48 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2011/02/19 08:20:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2011/02/19 08:20:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2011/02/19 08:18:44 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\My Documents\My Videos
[2011/02/19 08:18:44 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2011/02/19 08:02:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2011/02/19 07:59:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/02/19 07:58:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2011/02/19 07:57:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2011/02/19 06:58:35 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2011/02/19 06:57:25 | 000,026,880 | ---- | C] (SRS Labs, Inc.) -- C:\WINDOWS\System32\drivers\WOWHD_kern_i386.sys
[2011/02/19 06:57:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2011/02/19 06:51:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011/02/19 06:22:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2011/02/19 06:21:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Samsung New PC Studio
[2011/02/19 06:20:39 | 000,123,648 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdm.sys
[2011/02/19 06:20:39 | 000,098,432 | ---- | C] (MCCI) -- C:\WINDOWS\System32\drivers\ss_bbus.sys
[2011/02/19 06:20:39 | 000,014,848 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdfl.sys
[2011/02/19 06:20:39 | 000,012,416 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcmnt.sys
[2011/02/19 06:20:39 | 000,012,416 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcm.sys
[2011/02/19 06:20:39 | 000,012,288 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwhnt.sys
[2011/02/19 06:20:39 | 000,012,288 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwh.sys
[2011/02/19 06:20:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2011/02/19 06:19:40 | 000,238,952 | ---- | C] (Teruten) -- C:\WINDOWS\System32\FsUsbExService.Exe
[2011/02/19 06:19:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Samsung
[2011/02/19 06:19:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\My NPS Files
[2011/02/19 06:19:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\Samsung
[2011/02/19 06:19:08 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
[2011/02/19 06:18:22 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2011/02/19 06:16:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Downloaded Installations
[2011/02/19 05:56:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011/02/19 05:56:06 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Dimitar\IECompatCache
[2011/02/19 05:54:56 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Dimitar\PrivacIE
[2011/02/19 05:53:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2011/02/19 05:44:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Thinstall
[2011/02/19 03:13:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\L&H
[2011/02/19 03:13:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2011/02/19 03:13:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011/02/19 03:13:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2011/02/19 03:12:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2011/02/19 03:12:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2011/02/19 03:05:45 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes
[2011/02/19 03:05:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes
[2011/02/19 03:05:02 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011/02/19 03:05:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2011/02/19 02:59:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2011/02/19 02:54:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\Downloads
[2011/02/19 02:53:25 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2011/02/19 02:52:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2011/02/19 02:52:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\uTorrent
[2011/02/19 02:51:50 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011/02/19 02:43:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Mozilla
[2011/02/19 02:43:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Mozilla
[2011/02/19 02:43:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/02/19 02:43:38 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/02/19 02:42:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\vlc
[2011/02/19 02:41:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011/02/19 02:41:33 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2011/02/19 02:41:16 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Dimitar\IETldCache
[2011/02/18 22:56:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/02/18 22:44:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\My Notebook
[2011/02/18 22:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\AdobeUM
[2011/02/18 22:39:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Nethood
[2011/02/18 22:39:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Intel PROSet Wireless
[2011/02/18 22:39:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intel
[2011/02/18 22:39:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Intel
[2011/02/18 22:39:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/02/18 22:37:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Macromedia
[2011/02/18 22:37:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Identities
[2011/02/18 22:37:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\ATI
[2011/02/18 22:37:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Adobe
[2011/02/18 22:37:24 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Dimitar\Application Data\Microsoft
[2011/02/18 22:37:24 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Dimitar\SendTo
[2011/02/18 22:37:24 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Dimitar\Application Data
[2011/02/18 22:37:24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Startup
[2011/02/18 22:37:24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\Start Menu
[2011/02/18 22:37:24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\My Documents\My Pictures
[2011/02/18 22:37:24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\My Documents\My Music
[2011/02/18 22:37:24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\My Documents
[2011/02/18 22:37:24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\Favorites
[2011/02/18 22:37:24 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Accessories
[2011/02/18 22:37:24 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Dimitar\Cookies
[2011/02/18 22:37:24 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Dimitar\Templates
[2011/02/18 22:37:24 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Dimitar\PrintHood
[2011/02/18 22:37:24 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Dimitar\Local Settings
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\WINDOWS
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\toshiba
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Application Data\Sonic
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Microsoft
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Desktop
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\ATI
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\ApplicationHistory
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\Adobe
[2011/02/18 22:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150040}
[2011/02/18 22:11:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dimitar\My Documents\My Received Files
[2011/02/18 22:10:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2011/02/18 22:10:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2011/02/18 22:10:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2011/02/18 22:10:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2011/02/18 22:10:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2011/02/18 22:09:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2011/02/18 22:08:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2011/02/18 22:06:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011/02/18 22:05:53 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2011/02/18 22:05:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2011/02/16 00:42:08 | 000,004,544 | ---- | C] (SweetLow) -- C:\WINDOWS\System32\drivers\hidusbf.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/03/05 03:50:12 | 000,016,896 | ---- | M] () -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/04 20:05:02 | 000,002,531 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Intel Processor Diagnostic Tool.lnk
[2011/03/04 19:41:04 | 000,279,712 | ---- | M] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2011/03/04 19:41:03 | 000,025,888 | ---- | M] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2011/03/04 17:22:43 | 000,562,393 | ---- | M] () -- C:\Documents and Settings\Dimitar\My Documents\GetTRDoc.pdf
[2011/03/04 09:29:39 | 000,201,666 | ---- | M] () -- C:\Documents and Settings\Dimitar\My Documents\Thermostatic Radiator Valve Heads RT56.05.pdf
[2011/03/03 12:26:50 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dimitar\Desktop\OTL.exe
[2011/03/03 10:35:40 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/03/03 09:32:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/03/03 09:32:52 | 3219,247,104 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/02 10:40:24 | 000,062,644 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/03/02 09:56:08 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/02 08:11:22 | 000,002,634 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MSN Search Toolbar Take a tour.lnk
[2011/03/02 08:11:22 | 000,001,832 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TOSHIBA Services and Options.lnk
[2011/03/02 08:11:22 | 000,001,726 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HDtogo.LNK
[2011/03/02 08:11:22 | 000,001,624 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Office OneNote 2003.lnk
[2011/03/02 08:11:22 | 000,001,537 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TOSHIBA Warranty.lnk
[2011/03/02 08:11:22 | 000,001,524 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Create Drivers & Tools CD-ROM.lnk
[2011/03/02 07:59:17 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Dimitar\defogger_reenable
[2011/03/02 07:57:42 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\Dimitar\Desktop\Defogger.exe
[2011/03/01 18:22:53 | 000,001,002 | ---- | M] () -- C:\Documents and Settings\Dimitar\Desktop\Dropbox.lnk
[2011/03/01 18:21:07 | 000,001,002 | ---- | M] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Startup\Dropbox.lnk
[2011/02/28 14:21:21 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/02/28 14:21:16 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/02/28 14:20:21 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/02/27 05:48:50 | 000,487,560 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/02/27 05:48:50 | 000,087,260 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/02/25 10:20:46 | 000,001,742 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Dead Space 2.lnk
[2011/02/25 10:01:46 | 000,000,782 | ---- | M] () -- C:\Documents and Settings\Dimitar\Desktop\Windows Media Player.lnk
[2011/02/25 08:46:17 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/02/25 08:36:50 | 000,000,684 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\Microsoft\Internet Explorer\Quick Launch\Jaangle.lnk
[2011/02/25 08:01:20 | 000,305,216 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/24 01:09:16 | 000,000,650 | ---- | M] () -- C:\Documents and Settings\Dimitar\Desktop\trine.lnk
[2011/02/23 17:04:21 | 000,040,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/02/23 17:04:17 | 000,190,016 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/02/23 16:56:55 | 000,371,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/02/23 16:56:45 | 000,301,528 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/02/23 16:55:49 | 000,049,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/02/23 16:55:47 | 000,102,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/02/23 16:55:44 | 000,096,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/02/23 16:55:10 | 000,025,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/02/23 16:54:57 | 000,030,680 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/02/23 16:54:55 | 000,019,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/02/22 21:33:10 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\Dimitar\Desktop\WebKit.lnk
[2011/02/22 10:44:36 | 000,001,741 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Acrobat X Pro.lnk
[2011/02/19 20:37:26 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/02/19 20:37:26 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/02/19 08:23:07 | 000,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/02/19 08:21:13 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2011/02/19 08:20:35 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2011/02/19 08:00:12 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/19 06:21:10 | 000,001,783 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Samsung New PC Studio.lnk
[2011/02/19 06:19:35 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\$_hpcst$.hpc
[2011/02/19 03:14:34 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2011/02/19 03:05:51 | 000,000,903 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Virtual CloneDrive.lnk
[2011/02/19 02:53:25 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2011/02/19 02:43:45 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2011/02/19 02:43:40 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Dimitar\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/19 02:43:40 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/18 22:44:54 | 000,000,873 | ---- | M] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
[2011/02/18 22:43:49 | 000,000,000 | ---- | M] () -- C:\WINDOWS\TPTray.INI
[2011/02/18 22:42:43 | 000,000,000 | ---- | M] () -- C:\WINDOWS\CeEKey.INI
[2011/02/18 22:40:07 | 000,000,130 | ---- | M] () -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\fusioncache.dat
[2011/02/18 22:39:48 | 000,000,000 | RHS- | M] () -- C:\WINDOWS\System32\drivers\TOSHIBA_SATELLITE M100_04139-G3_PSMA1E-01W00.MRK
[2011/02/18 22:37:05 | 000,000,445 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/02/18 22:37:02 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2011/02/18 22:08:03 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/02/18 20:13:27 | 000,040,517 | ---- | M] () -- C:\Documents and Settings\Dimitar\My Documents\DayX.html
[2011/02/07 17:35:50 | 000,123,165 | ---- | M] () -- C:\Documents and Settings\Dimitar\My Documents\bookmarks_09_02_2011.html
[2011/02/06 09:32:26 | 000,128,708 | ---- | M] () -- C:\Documents and Settings\Dimitar\My Documents\Zoho.com Whats-new.pdf
[2011/02/05 15:04:39 | 017,391,222 | ---- | M] () -- C:\Documents and Settings\Dimitar\My Documents\101223_energy_report_final_print_2.pdf
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/03/04 19:41:04 | 000,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2011/03/04 19:41:03 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2011/03/04 17:22:43 | 000,562,393 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\GetTRDoc.pdf
[2011/03/04 09:29:39 | 000,201,666 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\Thermostatic Radiator Valve Heads RT56.05.pdf
[2011/03/03 11:09:54 | 000,002,531 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Intel Processor Diagnostic Tool.lnk
[2011/03/02 09:56:08 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/02 07:59:17 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dimitar\defogger_reenable
[2011/03/02 07:57:42 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\Dimitar\Desktop\Defogger.exe
[2011/03/01 18:22:53 | 000,001,002 | ---- | C] () -- C:\Documents and Settings\Dimitar\Desktop\Dropbox.lnk
[2011/03/01 18:21:07 | 000,001,002 | ---- | C] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Startup\Dropbox.lnk
[2011/02/28 14:21:21 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/02/25 10:20:46 | 000,001,742 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Dead Space 2.lnk
[2011/02/25 08:36:50 | 000,000,684 | ---- | C] () -- C:\Documents and Settings\Dimitar\Application Data\Microsoft\Internet Explorer\Quick Launch\Jaangle.lnk
[2011/02/24 01:09:16 | 000,000,650 | ---- | C] () -- C:\Documents and Settings\Dimitar\Desktop\trine.lnk
[2011/02/22 21:33:10 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\Dimitar\Desktop\WebKit.lnk
[2011/02/22 10:44:36 | 000,002,331 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2011/02/22 10:44:36 | 000,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Acrobat X Pro.lnk
[2011/02/22 10:44:36 | 000,001,741 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Acrobat X Pro.lnk
[2011/02/22 01:48:05 | 000,002,187 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/02/22 01:48:05 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Safari.lnk
[2011/02/20 23:04:05 | 000,062,644 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/02/20 00:12:30 | 000,000,040 | ---- | C] () -- C:\WINDOWS\System32\drivers\RtkHDAud.dat
[2011/02/19 22:00:01 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/02/19 08:23:07 | 000,001,803 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2011/02/19 08:23:07 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/02/19 08:20:35 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2011/02/19 08:00:12 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/02/19 08:00:12 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/19 06:57:25 | 000,036,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2011/02/19 06:57:25 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2011/02/19 06:21:10 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Samsung New PC Studio.lnk
[2011/02/19 06:19:40 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2011/02/19 06:19:40 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2011/02/19 06:19:35 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Dimitar\Application Data\$_hpcst$.hpc
[2011/02/19 05:57:55 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/02/19 04:03:17 | 000,016,896 | ---- | C] () -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/19 03:05:51 | 000,000,903 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Virtual CloneDrive.lnk
[2011/02/19 02:53:25 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2011/02/19 02:43:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/02/19 02:43:40 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\Dimitar\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/19 02:43:40 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/18 22:44:54 | 000,000,873 | ---- | C] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
[2011/02/18 22:43:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\TPTray.INI
[2011/02/18 22:42:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CeEKey.INI
[2011/02/18 22:40:09 | 003,072,054 | ---- | C] () -- C:\WINDOWS\TOSHIBA SATELLITE.bmp
[2011/02/18 22:39:56 | 000,000,782 | ---- | C] () -- C:\Documents and Settings\Dimitar\Desktop\Windows Media Player.lnk
[2011/02/18 22:39:48 | 000,000,000 | RHS- | C] () -- C:\WINDOWS\System32\drivers\TOSHIBA_SATELLITE M100_04139-G3_PSMA1E-01W00.MRK
[2011/02/18 22:37:25 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Remote Assistance.lnk
[2011/02/18 22:37:25 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Internet Explorer.lnk
[2011/02/18 22:37:25 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Windows Media Player.lnk
[2011/02/18 22:37:25 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\Dimitar\Start Menu\Programs\Outlook Express.lnk
[2011/02/18 22:37:25 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Dimitar\Local Settings\Application Data\fusioncache.dat
[2011/02/18 22:37:25 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Dimitar\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/18 22:37:03 | 000,001,726 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HDtogo.LNK
[2011/02/18 22:30:13 | 3219,247,104 | -HS- | C] () -- C:\hiberfil.sys
[2011/02/18 22:08:13 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/02/18 22:08:13 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/02/18 22:08:12 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2011/02/18 20:16:03 | 000,040,517 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\DayX.html
[2011/02/07 17:35:49 | 000,123,165 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\bookmarks_09_02_2011.html
[2011/02/07 17:30:47 | 000,128,708 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\Zoho.com Whats-new.pdf
[2011/02/07 17:30:04 | 000,454,414 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\Brochure_BG.pdf
[2011/02/07 17:30:02 | 017,391,222 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\101223_energy_report_final_print_2.pdf
[2011/02/07 17:29:58 | 004,985,193 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\Mathematik_Stochastik.pdf
[2011/02/07 17:29:58 | 000,452,276 | ---- | C] () -- C:\Documents and Settings\Dimitar\My Documents\Fragenkatalog_mitAntwortenLWBMetall2Lj.pdf
[2010/04/02 17:17:34 | 000,179,091 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/02/13 14:36:10 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\TDispVol.dll
[2006/02/10 15:49:11 | 000,132,584 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/02/10 13:33:50 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/02/10 13:15:57 | 000,000,466 | ---- | C] () -- C:\WINDOWS\TBTdetect.ini
[2006/02/10 12:47:46 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/02/10 11:58:37 | 000,000,218 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/02/10 11:50:22 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/02/10 11:50:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/02/10 11:50:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/02/10 11:50:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/02/10 11:50:21 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/02/10 11:50:21 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/02/10 11:45:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2006/02/10 09:51:07 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\EBLib.DLL
[2006/02/10 09:22:42 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2006/02/10 09:22:42 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2006/02/10 09:22:42 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2006/02/10 09:22:42 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2006/02/10 09:20:44 | 000,000,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTHDAEQ1.dat
[2006/02/10 09:20:44 | 000,000,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTHDAEQ0.dat
[2006/02/10 09:20:41 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/02/10 09:20:41 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2006/02/09 16:02:36 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/02/09 16:01:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/02/09 15:57:43 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/02/09 15:52:16 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/02/09 15:51:26 | 000,305,216 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/02/09 14:46:02 | 000,159,744 | ---- | C] () -- C:\WINDOWS\MakeMrk.exe
[2006/02/09 14:46:02 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\ToshBIOS.dll
[2006/02/09 14:46:02 | 000,000,083 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/02/09 14:45:31 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/02/09 14:45:28 | 000,487,560 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/02/09 14:45:28 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/02/09 14:45:28 | 000,087,260 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/02/09 14:45:28 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/02/09 14:45:25 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/02/09 14:45:25 | 000,004,631 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/02/09 14:45:24 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/02/09 14:45:21 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/02/09 14:45:21 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/02/09 14:45:17 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/02/09 14:45:10 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2005/12/09 16:36:30 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\TPeculiarity.dll
[2005/11/29 05:33:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/11/23 15:41:28 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\HWS_Ctrl.dll
[2005/11/23 13:42:16 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\TCtrlIO.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2011/02/28 14:21:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/02/22 11:23:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/02/19 06:20:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2011/03/03 09:33:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\Dropbox
[2011/02/19 06:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\Samsung
[2011/03/03 10:51:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\SystemRequirementsLab
[2011/02/19 05:44:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\Thinstall
[2011/02/19 05:30:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\toshiba
[2011/03/05 16:03:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\uTorrent
[2011/02/19 19:39:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\Windows Desktop Search
[2011/02/19 19:47:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dimitar\Application Data\Windows Search
========== Purity Check ==========
< End of report >
Edited by vorazechul, 05 March 2011 - 09:54 AM.