So, I became more attention on Task Manager and yesterday I noticed that regedit32.exe was showing for a second. I searched all over my comp, but at least found it in the registry.
I deleted it, but my comp is still in the strange behaviour: The high consumption of PF usage is noticed and even, if I close all of the programs, there is activity in CPU Usage. The MS updates pops up occasionally.
I assume, that something is still left in my comp, but I can't find it.
Thank you in advance for your time and efford!
OTL logfile created on: 20.10.2011 9:24:54 - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Zofy\Desktop\Security
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000424 | Country: Slovenia | Language: SLV | Date Format: d.M.yyyy
503,36 Mb Total Physical Memory | 283,99 Mb Available Physical Memory | 56,42% Memory free
1,19 Gb Paging File | 0,81 Gb Available in Paging File | 68,00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67,69 Gb Total Space | 49,68 Gb Free Space | 73,40% Space Free | Partition Type: NTFS
Drive D: | 6,83 Gb Total Space | 0,68 Gb Free Space | 9,99% Space Free | Partition Type: FAT32
Computer Name: D | User Name: Zofy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.10.19 16:02:26 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Zofy\Desktop\Security\OTL.exe
PRC - [2011.04.24 23:15:02 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
PRC - [2011.04.12 22:40:58 | 000,660,848 | ---- | M] (Juniper Networks) -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
PRC - [2008.04.14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011.04.24 23:13:30 | 007,008,656 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtgui4.dll
MOD - [2011.04.24 23:13:28 | 000,192,912 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtsql4.dll
MOD - [2011.04.24 23:13:26 | 001,270,160 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtscript4.dll
MOD - [2011.04.24 23:13:26 | 000,758,160 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtnetwork4.dll
MOD - [2011.04.24 23:13:24 | 002,118,032 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtcore4.dll
MOD - [2011.04.24 23:13:24 | 002,089,360 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtdeclarative4.dll
MOD - [2011.04.20 19:56:28 | 000,025,088 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (astcc)
SRV - File not found [Disabled | Stopped] -- -- (aspnet_state)
SRV - [2011.04.24 23:15:02 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe -- (AVP)
SRV - [2011.04.12 22:40:58 | 000,660,848 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe -- (dsNcService)
SRV - [2004.08.11 09:46:56 | 000,483,328 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- c:\Program Files\Windows Media Connect\mswmccds.exe -- (WmcCds) Windows Media Connect (WMC)
SRV - [2004.08.11 06:50:42 | 000,028,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Connect\mswmcls.exe -- (WmcCdsLs) Windows Media Connect (WMC)
========== Driver Services (SafeList) ==========
DRV - [2011.10.19 16:58:23 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\utm5nzy2.sys -- (utm5nzy2)
DRV - [2011.09.28 10:37:54 | 000,565,552 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2011.04.12 22:10:02 | 000,026,624 | ---- | M] (Juniper Networks) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dsNcAdpt.sys -- (dsNcAdpt)
DRV - [2011.03.10 18:34:46 | 000,034,608 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2011.03.04 13:23:20 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2011.03.04 13:23:14 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\kl1.sys -- (KL1)
DRV - [2009.11.02 20:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009.06.22 13:48:44 | 000,091,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mqac.sys -- (MQAC)
DRV - [2008.05.08 16:02:52 | 000,203,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rmcast.sys -- (RMCAST)
DRV - [2006.07.31 03:00:08 | 001,155,584 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.02.16 09:45:26 | 000,057,096 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006.02.15 15:56:58 | 001,342,570 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006.02.06 04:00:06 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006.01.19 15:50:40 | 001,428,096 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2005.09.19 22:24:20 | 000,005,760 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb)
DRV - [2005.09.19 22:24:10 | 000,009,344 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2005.09.19 22:23:52 | 000,007,808 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2119758564-1861339448-2262761727-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-2119758564-1861339448-2262761727-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.type: 2
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\[email protected] [2011.10.07 08:33:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\[email protected] [2011.10.07 08:33:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\[email protected] [2011.10.07 08:33:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.09.27 09:55:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011.09.21 05:39:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Zofy\Application Data\Mozilla\Extensions
[2011.10.15 10:08:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Zofy\Application Data\Mozilla\Firefox\Profiles\alfwwljr.default\extensions
[2011.09.27 09:55:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\ZOFY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\ALFWWLJR.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2011.10.07 08:33:49 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FFEXT\[email protected]
[2011.10.07 08:33:49 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FFEXT\[email protected]
[2011.10.07 08:33:51 | 000,000,000 | ---D | M] (Kaspersky Virtual Keyboard) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FFEXT\[email protected]
[2011.09.03 08:18:14 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.09.03 02:25:08 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011.09.03 02:13:56 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.09.03 02:25:08 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011.09.03 02:25:08 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011.09.03 02:25:08 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Chrome\Application\14.0.835.186\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Chrome\Application\14.0.835.186\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Chrome\Application\14.0.835.186\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Kaspersky URL Advisor = C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.397_0\
CHR - Extension: Virtual Keyboard = C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.374_0\
CHR - Extension: Anti-Banner = C:\Documents and Settings\Zofy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\
O1 HOSTS File: ([2011.10.19 19:57:44 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - No CLSID value found.
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKU\S-1-5-21-2119758564-1861339448-2262761727-1005\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\S-1-5-21-2119758564-1861339448-2262761727-1005\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2119758564-1861339448-2262761727-1005\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2119758564-1861339448-2262761727-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://emea-access....SetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.223.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DA704859-3CB0-4949-B633-903F93252C97}: DhcpNameServer = 192.168.223.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2011.04.14 16:10:24 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2001.07.27 23:07:00 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.10.19 19:33:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Juniper Networks
[2011.10.19 19:33:23 | 000,406,896 | ---- | C] (Juniper Networks) -- C:\WINDOWS\System32\dsNcSmartCardProv.dll
[2011.10.19 19:33:23 | 000,361,840 | ---- | C] (Juniper Networks) -- C:\WINDOWS\System32\dsNcCredProv.dll
[2011.10.19 19:32:03 | 000,000,000 | ---D | C] -- C:\Program Files\Juniper Networks
[2011.10.19 14:47:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2011.10.19 14:47:27 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011.10.19 10:19:38 | 000,094,896 | ---- | C] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\44708738.sys
[2011.10.19 07:59:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011.10.19 07:47:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2011.10.19 07:47:41 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011.10.19 07:47:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2011.10.19 07:47:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Local Settings\Application Data\Adobe
[2011.10.18 19:57:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Zofy\Recent
[2011.10.18 19:57:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Adobe
[2011.10.18 11:56:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2011.10.18 09:50:14 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011.10.17 12:32:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Martau
[2011.10.17 12:31:57 | 000,000,000 | ---D | C] -- C:\Program Files\Total Uninstall 5
[2011.10.13 11:44:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2011.10.13 11:43:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\SampleView
[2011.10.10 12:35:36 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2011.10.10 12:35:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011.10.02 19:34:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Desktop\Marcantilaan
[2011.09.29 16:51:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Downloaded Installations
[2011.09.28 14:01:17 | 000,000,000 | ---D | C] -- C:\LAB
[2011.09.28 14:00:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.09.28 14:00:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011.09.28 14:00:16 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.09.28 14:00:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.09.28 10:39:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Kaspersky Internet Security 2012
[2011.09.28 10:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2011.09.28 10:38:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2011.09.28 10:37:54 | 000,565,552 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2011.09.27 09:55:55 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011.09.26 10:22:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Start Menu\Programs\Google Chrome
[2011.09.25 16:04:51 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\Start Menu\Programs\Administrative Tools
[2011.09.25 15:47:04 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Zofy\IECompatCache
[2011.09.25 11:55:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Start Menu\Programs\Unlocker
[2011.09.25 11:55:45 | 000,000,000 | ---D | C] -- C:\Program Files\Unlocker
[2011.09.24 16:46:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2011.09.24 16:45:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2011.09.24 16:45:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011.09.24 16:43:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2011.09.24 16:26:00 | 001,286,696 | ---- | C] (Juniper Networks) -- C:\Program Files\JuniperSetupClientInstaller.exe
[2011.09.24 16:16:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Start Menu\Programs\Juniper Networks
[2011.09.24 16:15:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011.09.24 16:15:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Juniper Networks
[2011.09.24 16:14:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2011.09.24 14:32:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2011.09.23 13:16:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\WinRAR
[2011.09.23 13:16:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2011.09.23 13:16:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Start Menu\Programs\WinRAR
[2011.09.23 13:16:17 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2011.09.23 10:25:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011.09.22 19:14:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011.09.22 18:40:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2011.09.22 18:40:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2011.09.22 18:40:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2011.09.22 18:40:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2011.09.22 18:35:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2011.09.22 17:46:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2011.09.22 11:04:06 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Zofy\PrivacIE
[2011.09.22 11:01:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Zofy\IETldCache
[2011.09.22 10:58:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2011.09.22 10:56:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2011.09.22 10:56:23 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011.09.22 10:56:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2011.09.22 10:33:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2011.09.22 10:22:45 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\My Documents\My Videos
[2011.09.22 07:52:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Malwarebytes
[2011.09.21 18:17:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011.09.21 17:04:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2011.09.21 16:44:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype
[2011.09.21 16:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Skype
[2011.09.21 14:20:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Macromedia
[2011.09.21 11:49:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Sun
[2011.09.21 05:50:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2011.09.21 05:49:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\My Documents\Downloads
[2011.09.21 05:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Local Settings\Application Data\Mozilla
[2011.09.21 05:39:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Mozilla
[2011.09.21 05:35:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Local Settings\Application Data\Google
[2011.09.21 05:32:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Bluetooth Software
[2011.09.21 05:29:13 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Zofy\Application Data\Microsoft
[2011.09.21 05:29:13 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Zofy\SendTo
[2011.09.21 05:29:13 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Zofy\Application Data
[2011.09.21 05:29:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\Start Menu\Programs\Startup
[2011.09.21 05:29:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\Start Menu
[2011.09.21 05:29:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\My Documents\My Pictures
[2011.09.21 05:29:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\My Documents\My Music
[2011.09.21 05:29:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\My Documents
[2011.09.21 05:29:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\Favorites
[2011.09.21 05:29:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zofy\Start Menu\Programs\Accessories
[2011.09.21 05:29:13 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Zofy\Cookies
[2011.09.21 05:29:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Zofy\Templates
[2011.09.21 05:29:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Zofy\PrintHood
[2011.09.21 05:29:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Zofy\NetHood
[2011.09.21 05:29:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Zofy\Local Settings
[2011.09.21 05:29:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Local Settings\Application Data\Microsoft
[2011.09.21 05:29:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Application Data\Identities
[2011.09.21 05:29:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Desktop
[2011.09.21 05:29:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zofy\Local Settings\Application Data\ApplicationHistory
[2011.09.21 05:22:25 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM
[2011.09.21 05:20:38 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011.09.21 05:16:07 | 000,000,000 | ---D | C] -- C:\Program Files\Program Shortcuts
[2011.09.21 05:12:40 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011.09.21 04:01:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\i386
[2011.09.21 03:37:22 | 000,000,000 | ---D | C] -- C:\WINDOWS
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.10.20 06:47:40 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.10.20 06:46:17 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.10.19 19:57:44 | 000,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011.10.19 16:58:23 | 000,007,168 | ---- | M] () -- C:\WINDOWS\System32\drivers\utm5nzy2.sys
[2011.10.19 10:19:38 | 000,094,896 | ---- | M] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\44708738.sys
[2011.10.19 08:19:10 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2011.10.17 14:05:34 | 000,348,204 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.10.17 14:05:34 | 000,054,620 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.10.17 12:31:58 | 000,000,731 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Total Uninstall 5.lnk
[2011.10.14 09:23:17 | 000,186,608 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.10.12 10:08:48 | 000,003,366 | ---- | M] () -- C:\Documents and Settings\Zofy\Desktop\keyword_ideas_20111012_0108609.csv
[2011.10.10 17:27:38 | 000,001,502 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Calculator (2).lnk
[2011.10.10 13:01:26 | 000,000,588 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Skyp.lnk
[2011.10.02 09:40:56 | 000,032,116 | ---- | M] () -- C:\Documents and Settings\Zofy\Desktop\SloPodjetja_Nizozemska.pdf
[2011.09.29 11:36:24 | 000,000,692 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\mbam.lnk
[2011.09.28 11:06:47 | 000,115,369 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat
[2011.09.28 11:06:47 | 000,097,961 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat
[2011.09.28 10:41:25 | 000,017,408 | ---- | M] () -- C:\Documents and Settings\Zofy\Local Settings\Application Data\WebpageIcons.db
[2011.09.28 10:37:54 | 000,565,552 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2011.09.27 09:55:59 | 000,000,746 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011.09.26 12:59:11 | 000,113,464 | ---- | M] () -- C:\cc_20110926_125905.reg
[2011.09.26 12:56:24 | 000,000,626 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\CCleaner.lnk
[2011.09.26 10:22:43 | 000,002,259 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011.09.24 16:47:25 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2011.09.24 16:26:10 | 001,286,696 | ---- | M] (Juniper Networks) -- C:\Program Files\JuniperSetupClientInstaller.exe
[2011.09.23 08:40:57 | 000,001,497 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\ExploDer.lnk
[2011.09.23 08:18:53 | 000,001,529 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Notepad.lnk
[2011.09.22 19:15:00 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2011.09.22 18:34:52 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011.09.22 11:01:49 | 000,000,819 | ---- | M] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011.09.21 05:16:16 | 000,002,970 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011.09.21 05:13:29 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.10.19 16:58:21 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\utm5nzy2.sys
[2011.10.19 08:00:42 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2011.10.17 12:31:58 | 000,000,731 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Total Uninstall 5.lnk
[2011.10.17 12:31:58 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Total Uninstall 5.lnk
[2011.10.12 10:08:46 | 000,003,366 | ---- | C] () -- C:\Documents and Settings\Zofy\Desktop\keyword_ideas_20111012_0108609.csv
[2011.10.10 17:27:38 | 000,001,502 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Calculator (2).lnk
[2011.10.10 13:01:26 | 000,000,588 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Skyp.lnk
[2011.10.02 09:40:56 | 000,032,116 | ---- | C] () -- C:\Documents and Settings\Zofy\Desktop\SloPodjetja_Nizozemska.pdf
[2011.09.29 11:36:24 | 000,000,692 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\mbam.lnk
[2011.09.28 10:41:23 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Zofy\Local Settings\Application Data\WebpageIcons.db
[2011.09.28 10:39:46 | 000,115,369 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2011.09.28 10:39:46 | 000,097,961 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2011.09.27 09:55:58 | 000,000,746 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011.09.26 12:59:08 | 000,113,464 | ---- | C] () -- C:\cc_20110926_125905.reg
[2011.09.26 12:56:24 | 000,000,626 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\CCleaner.lnk
[2011.09.26 10:22:43 | 000,002,259 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011.09.24 16:47:24 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011.09.22 12:18:17 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2011.09.22 12:16:50 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011.09.22 12:11:09 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2011.09.21 14:13:03 | 000,001,529 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Notepad.lnk
[2011.09.21 11:38:54 | 000,001,497 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\ExploDer.lnk
[2011.09.21 05:29:14 | 000,000,819 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011.09.21 05:29:14 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Zofy\Local Settings\Application Data\fusioncache.dat
[2011.09.21 05:29:14 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Zofy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011.09.21 05:29:13 | 000,001,603 | ---- | C] () -- C:\Documents and Settings\Zofy\Start Menu\Programs\Remote Assistance.lnk
[2011.09.21 05:29:13 | 000,001,491 | ---- | C] () -- C:\Documents and Settings\Zofy\Start Menu\Programs\Software Setup.lnk
[2011.09.21 05:29:13 | 000,000,807 | ---- | C] () -- C:\Documents and Settings\Zofy\Start Menu\Programs\Internet Explorer.lnk
[2011.09.21 05:29:13 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\Zofy\Start Menu\Programs\Windows Media Player.lnk
[2011.09.21 05:29:13 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Zofy\Start Menu\Programs\Outlook Express.lnk
[2011.09.21 05:13:29 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2011.03.11 12:43:54 | 000,029,763 | ---- | C] () -- C:\WINDOWS\System32\drivers\klopp.dat
[2009.06.17 10:13:30 | 000,508,224 | ---- | C] () -- C:\WINDOWS\System32\ICCProfiles.dll
[2006.08.21 04:49:30 | 000,000,175 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006.08.21 04:48:06 | 000,028,836 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006.02.15 16:04:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005.09.21 10:42:46 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005.09.21 10:42:38 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005.09.21 10:33:02 | 000,348,204 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005.09.21 10:33:02 | 000,054,620 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005.09.21 10:21:16 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005.09.21 10:18:40 | 000,186,608 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005.09.20 18:14:32 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005.09.20 18:12:40 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004.08.04 10:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004.08.04 10:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004.08.04 10:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004.08.04 10:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004.08.04 10:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004.08.04 10:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004.08.04 10:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004.08.04 10:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004.06.01 11:39:56 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2002.05.28 10:55:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002.05.28 10:54:40 | 000,004,605 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.11.14 12:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1998.05.07 04:10:00 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\ODMA32.dll
========== LOP Check ==========
[2006.08.21 05:24:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
[2011.09.24 16:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011.10.17 12:32:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Martau
[2006.08.21 05:24:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\SampleView
[2011.10.18 12:06:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zofy\Application Data\Downloaded Installations
[2011.10.19 19:22:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zofy\Application Data\Juniper Networks
[2011.10.13 11:43:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zofy\Application Data\SampleView
========== Purity Check ==========
< End of report >