nautilus808
Posts: 60 +0
\{B618B402-7A51-43F4-A4A2-71329BFDCF6D}
[2012/01/15 10:24:56 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{B5737D06-4454-4E95-86ED-6E2960A6EDFD}
[2012/01/14 10:16:04 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{6D8AB6BA-0D99-45FC-A95E-DBB35F0A5647}
[2012/01/13 20:16:14 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{4029C74A-DA00-460D-A613-403ED1FCB87F}
[2012/01/13 20:16:03 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{2AA391F5-986C-4729-BBAC-8E421F6F930F}
[2012/01/12 23:53:24 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{E5089D2B-4C83-4714-878D-7C5F362B8557}
[2012/01/12 11:53:00 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{E765F61E-74D9-4263-BF6C-7CF735AE2272}
[2012/01/12 11:52:49 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{8DF7660C-5269-4B67-B39C-803D25231594}
[2012/01/11 23:52:20 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{A6892FA6-0758-499A-875C-4365EECF9A6D}
[2012/01/11 23:52:07 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{CA7D01E5-D4E2-4A1A-953D-BE5D0A1F7B02}
[2001/04/02 01:49:16 | 000,423,936 | ---- | C] (Feñiz 2001) -- C:\Program Files\Conversor.exe
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/10 22:28:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Pondalex\Desktop\OTL.exe
[2012/02/10 22:11:30 | 000,001,356 | ---- | M] () -- C:\Users\Pondalex\AppData\Local\d3d9caps.dat
[2012/02/10 21:44:05 | 000,000,147 | ---- | M] () -- C:\Users\Pondalex\Desktop\rk-proxy.reg
[2012/02/10 21:40:03 | 000,002,855 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill - Shortcut.pif
[2012/02/10 21:36:52 | 001,008,141 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill.com
[2012/02/10 21:36:26 | 001,008,141 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill.exe
[2012/02/10 21:35:16 | 004,400,207 | R--- | M] (Swearware) -- C:\Users\Pondalex\Desktop\pondalex.exe.exe
[2012/02/10 20:38:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/10 20:37:23 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/10 20:37:23 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/10 20:34:10 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/02/10 20:30:43 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/02/10 20:30:43 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/10 20:30:39 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/02/10 20:30:39 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/02/10 20:30:39 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/09 23:16:31 | 000,667,260 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/02/09 23:16:31 | 000,127,148 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/02/09 23:09:58 | 000,000,862 | ---- | M] () -- C:\Windows\System32\tversity.cookies
[2012/02/09 22:29:49 | 000,000,512 | ---- | M] () -- C:\Users\Pondalex\Desktop\MBR.dat
[2012/02/09 21:37:06 | 307,695,254 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/02/09 21:12:45 | 000,000,299 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (4).lnk
[2012/02/09 21:10:38 | 000,000,715 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (3).lnk
[2012/02/09 20:59:49 | 000,000,715 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (2).lnk
[2012/02/09 20:54:19 | 000,000,299 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut.lnk
[2012/02/08 22:07:55 | 000,026,872 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\FixTDSS.sys
[2012/02/08 21:24:36 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Users\Pondalex\Desktop\aswMBR.exe
[2012/02/07 20:54:38 | 000,001,110 | ---- | M] () -- C:\Users\Pondalex\Desktop\Get Live PC Help Now.lnk
[2012/02/06 21:23:04 | 000,000,523 | ---- | M] () -- C:\Users\Pondalex\Desktop\The MUZIK - Shortcut.lnk
[2012/02/06 21:22:48 | 000,000,679 | ---- | M] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut (2).lnk
[2012/02/06 21:22:36 | 000,000,415 | ---- | M] () -- C:\Users\Pondalex\Desktop\Downloads - Shortcut.lnk
[2012/02/06 21:20:18 | 000,000,655 | ---- | M] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut.lnk
[2012/02/06 20:40:10 | 000,000,938 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Killer.lnk
[2012/02/06 08:55:53 | 000,000,286 | ---- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{480410F6-6C9D-4125-B8CE-8A1BB0B19D14}.job
[2012/02/05 10:47:55 | 000,000,448 | ---- | M] () -- C:\ProgramData\erFWlu6VTzaxlf
[2012/02/05 00:52:45 | 000,015,360 | ---- | M] () -- C:\Users\Pondalex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/04 22:58:14 | 000,000,341 | ---- | M] () -- C:\Users\Pondalex\Desktop\exefix.reg
[2012/02/04 18:41:44 | 000,000,474 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/04 18:33:52 | 000,001,649 | ---- | M] () -- C:\Users\Pondalex\Desktop\Check PC For Errors.lnk
[2012/02/04 15:56:13 | 000,000,607 | ---- | M] () -- C:\Users\Pondalex\Desktop\System Check.lnk
[2012/02/04 15:35:53 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2012/02/01 20:56:29 | 000,001,057 | ---- | M] () -- C:\Users\Pondalex\Desktop\Spybot - Search & Destroy.lnk
[2012/01/30 22:34:41 | 000,000,514 | ---- | M] () -- C:\Users\Pondalex\Desktop\Nubiles.net Member's Area - Home.website
[2012/01/30 21:14:32 | 000,006,035 | ---- | M] () -- C:\Users\Pondalex\secret-key-87623C84.asc
[2012/01/29 21:00:00 | 000,006,034 | ---- | M] () -- C:\Users\Pondalex\secret-key-F8B6DEB8.asc
[2012/01/29 20:50:56 | 000,006,035 | ---- | M] () -- C:\Users\Pondalex\secret-key-6C9A59A4.asc
[2012/01/29 19:14:51 | 000,000,436 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2012/01/29 16:45:40 | 000,231,376 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2012/01/21 14:53:36 | 000,130,834 | ---- | M] () -- C:\Windows\hpoins18.dat
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/10 21:40:22 | 001,008,141 | ---- | C] () -- C:\Users\Pondalex\Desktop\rkill.exe
[2012/02/10 21:40:08 | 001,008,141 | ---- | C] () -- C:\Users\Pondalex\Desktop\rkill.com
[2012/02/10 21:40:03 | 000,002,855 | ---- | C] () -- C:\Users\Pondalex\Desktop\rkill - Shortcut.pif
[2012/02/09 22:29:49 | 000,000,512 | ---- | C] () -- C:\Users\Pondalex\Desktop\MBR.dat
[2012/02/09 21:14:23 | 000,000,299 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (4).lnk
[2012/02/09 21:10:38 | 000,000,715 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (3).lnk
[2012/02/09 20:59:49 | 000,000,715 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (2).lnk
[2012/02/09 20:54:19 | 000,000,299 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut.lnk
[2012/02/07 23:20:54 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/07 23:20:51 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/07 20:54:38 | 000,001,110 | ---- | C] () -- C:\Users\Pondalex\Desktop\Get Live PC Help Now.lnk
[2012/02/06 21:23:04 | 000,000,523 | ---- | C] () -- C:\Users\Pondalex\Desktop\The MUZIK - Shortcut.lnk
[2012/02/06 21:22:48 | 000,000,679 | ---- | C] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut (2).lnk
[2012/02/06 21:22:36 | 000,000,415 | ---- | C] () -- C:\Users\Pondalex\Desktop\Downloads - Shortcut.lnk
[2012/02/06 20:40:10 | 000,000,938 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Killer.lnk
[2012/02/06 08:55:53 | 000,000,286 | ---- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{480410F6-6C9D-4125-B8CE-8A1BB0B19D14}.job
[2012/02/05 10:46:49 | 000,000,448 | ---- | C] () -- C:\ProgramData\erFWlu6VTzaxlf
[2012/02/04 23:03:20 | 000,000,341 | ---- | C] () -- C:\Users\Pondalex\Desktop\exefix.reg
[2012/02/04 18:41:44 | 000,000,474 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/04 18:33:52 | 000,001,649 | ---- | C] () -- C:\Users\Pondalex\Desktop\Check PC For Errors.lnk
[2012/02/04 18:20:33 | 000,000,147 | ---- | C] () -- C:\Users\Pondalex\Desktop\rk-proxy.reg
[2012/02/04 15:56:13 | 000,000,607 | ---- | C] () -- C:\Users\Pondalex\Desktop\System Check.lnk
[2012/02/01 20:56:29 | 000,001,057 | ---- | C] () -- C:\Users\Pondalex\Desktop\Spybot - Search & Destroy.lnk
[2012/01/30 21:14:31 | 000,006,035 | ---- | C] () -- C:\Users\Pondalex\secret-key-87623C84.asc
[2012/01/29 20:59:59 | 000,006,034 | ---- | C] () -- C:\Users\Pondalex\secret-key-F8B6DEB8.asc
[2012/01/29 20:50:56 | 000,006,035 | ---- | C] () -- C:\Users\Pondalex\secret-key-6C9A59A4.asc
[2012/01/28 11:33:46 | 000,000,940 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/01/28 11:33:46 | 000,000,918 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/01/23 22:43:33 | 000,000,655 | ---- | C] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut.lnk
[2011/12/17 02:29:57 | 000,201,116 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2011/06/09 16:59:08 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/06/09 16:57:12 | 000,002,888 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2010/11/25 19:15:14 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010/11/05 12:17:10 | 000,000,000 | ---- | C] () -- C:\Windows\hpqEmlSz.INI
[2010/10/10 08:26:28 | 018,527,244 | ---- | C] () -- C:\ProgramData\vlc-1.0.2-win32.exe
[2010/09/28 13:07:36 | 000,224,001 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2010/09/21 20:41:54 | 000,000,056 | ---- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/09/08 19:36:08 | 019,657,194 | ---- | C] () -- C:\ProgramData\vlc-1.1.4-win32.exe
[2010/08/21 21:37:06 | 019,563,096 | ---- | C] () -- C:\ProgramData\vlc-1.1.3-win32.exe
[2010/08/02 13:01:13 | 019,461,015 | ---- | C] () -- C:\ProgramData\vlc-1.1.2-win32.exe
[2010/07/25 00:31:55 | 019,473,201 | ---- | C] () -- C:\ProgramData\vlc-1.1.1-win32.exe
[2010/06/25 10:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2010/06/04 18:38:22 | 016,310,272 | ---- | C] () -- C:\ProgramData\vlc-1.0.5-win32.exe
[2010/05/08 11:38:53 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll.old
[2010/04/22 19:02:04 | 000,000,007 | ---- | C] () -- C:\Windows\treeskp.sys
[2010/04/22 19:02:04 | 000,000,007 | ---- | C] () -- C:\Windows\sbacknt.bin
[2010/04/04 20:58:19 | 000,009,584 | -HS- | C] () -- C:\Users\Pondalex\AppData\Local\VHx0W
[2010/04/04 20:58:19 | 000,009,584 | -HS- | C] () -- C:\ProgramData\VHx0W
[2010/04/03 21:33:42 | 000,003,604 | -HS- | C] () -- C:\Users\Pondalex\AppData\Local\8s32
[2010/04/03 21:33:42 | 000,003,604 | -HS- | C] () -- C:\ProgramData\8s32
[2010/03/29 21:34:59 | 000,000,579 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\AutoGK.ini
[2010/03/28 16:20:56 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/11/12 10:44:29 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/11/12 10:44:28 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/10/24 10:30:39 | 000,130,834 | ---- | C] () -- C:\Windows\hpoins18.dat
[2009/10/24 10:30:28 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2009/10/21 20:22:49 | 000,001,356 | ---- | C] () -- C:\Users\Pondalex\AppData\Local\d3d9caps.dat
[2009/09/15 16:02:36 | 018,015,723 | ---- | C] () -- C:\ProgramData\vlc-1.0.1-win32.exe
[2009/08/28 20:33:32 | 000,001,044 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\vso_ts_preview.xml
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/06 06:58:43 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2009/05/09 20:30:08 | 000,000,000 | ---- | C] () -- C:\Windows\System32\settings.dat
[2009/05/06 21:01:16 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/04/25 21:41:35 | 000,000,025 | ---- | C] () -- C:\Windows\cdplayer.ini
[2009/04/03 18:10:30 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/04/03 15:34:18 | 000,016,362 | ---- | C] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended-((Demonoid.com)).torrent
[2009/04/03 15:28:06 | 000,016,362 | ---- | C] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended_x-Demonoid.com-x.torrent
[2009/03/21 16:40:13 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2009/03/21 16:40:13 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2009/03/21 16:40:13 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2009/01/25 14:10:48 | 000,179,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/01/08 16:01:22 | 000,629,760 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008/12/16 21:58:54 | 000,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLgFT.dll
[2008/09/29 18:42:17 | 000,870,128 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\mcs.rma
[2008/09/29 18:42:17 | 000,000,004 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\1FAC5E
[2008/09/21 02:07:03 | 000,066,482 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2008/09/18 03:00:37 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/09/10 20:43:01 | 000,015,360 | ---- | C] () -- C:\Users\Pondalex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/09 22:34:46 | 000,001,468 | ---- | C] () -- C:\Windows\WININIT.INI
[2008/08/14 22:15:32 | 000,001,306 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\wklnhst.dat
[2008/08/06 12:39:55 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008/08/06 08:56:26 | 000,065,536 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008/08/06 08:56:25 | 000,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2008/08/06 08:52:19 | 000,101,376 | ---- | C] () -- C:\Windows\System32\APOMngr.dll
[2008/08/06 08:52:19 | 000,066,560 | ---- | C] () -- C:\Windows\System32\CmdRtr.dll
[2008/08/06 08:52:19 | 000,000,628 | ---- | C] () -- C:\Windows\System32\PCI_VEN_1102&DEV_FF05&SUBSYS_00001102.ini
[2006/11/02 05:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,436,592 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,667,260 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,127,148 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 03:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2003/10/28 10:07:20 | 000,372,736 | ---- | C] () -- C:\Windows\System32\ffvfw.dll
[2002/10/15 15:54:04 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2001/04/02 01:41:14 | 000,000,157 | ---- | C] () -- C:\Program Files\Perfiles.ini
========== LOP Check ==========
[2011/01/23 21:15:39 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\AVG
[2010/12/04 15:21:16 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\AVG10
[2011/12/11 10:42:40 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Azureus
[2010/08/14 08:36:27 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\BitTorrent
[2011/09/04 07:11:02 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Camfrog
[2011/02/04 15:38:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Canon
[2009/06/12 17:44:00 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\ChemBuddy
[2011/06/15 16:48:47 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\com.Shutterfly.ExpressUploader
[2008/09/09 23:22:13 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\DataSafeOnline
[2009/08/05 12:59:25 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Dylogic
[2009/05/05 20:17:34 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\eAcceleration
[2009/03/30 22:25:46 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\ExcelCube
[2012/02/08 22:07:55 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\FixTDSS
[2012/02/04 22:26:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\GetRightToGo
[2012/01/30 21:20:39 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\gnupg
[2012/01/30 21:14:31 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\gtk-2.0
[2011/03/21 21:39:03 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Image Zone Express
[2008/08/30 23:14:39 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Leadertech
[2010/06/13 21:03:44 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\LimeWire
[2012/02/03 23:54:31 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Nelyu
[2012/02/04 15:32:58 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Ota
[2009/11/01 12:08:08 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Printer Info Cache
[2010/06/13 21:03:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Raptr
[2010/12/30 23:27:07 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Registry Mechanic
[2011/02/24 23:11:00 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Sammsoft
[2009/07/09 12:05:48 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Snapfish
[2008/08/20 21:36:33 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Template
[2012/01/29 16:54:28 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\TrueCrypt
[2011/10/26 08:14:38 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Uniblue
[2010/04/22 19:01:59 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\vghd
[2009/08/28 23:25:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Vso
[2012/02/10 20:30:39 | 000,000,918 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/02/10 20:30:39 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/02/10 20:37:20 | 000,032,592 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/02/06 08:55:53 | 000,000,286 | ---- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{480410F6-6C9D-4125-B8CE-8A1BB0B19D14}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/01/01 02:51:21 | 000,000,078 | ---- | M] () -- C:\AEIusb.log
[2006/09/18 14:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2006/09/18 14:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2008/05/14 08:21:26 | 000,088,560 | ---- | M] (Sonic Solutions) -- C:\DC_ShellExt.dll
[2008/08/06 12:40:01 | 000,005,187 | R--- | M] () -- C:\dell.sdr
[2010/12/04 10:23:24 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012/02/07 20:44:28 | 000,047,516 | ---- | M] () -- C:\JavaRa.log
[2010/05/09 09:21:06 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2010/12/04 10:23:24 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/09/03 17:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\npbittorrent.dll
[2012/02/10 20:38:35 | 3532,881,920 | -HS- | M] () -- C:\pagefile.sys
[2012/02/10 21:46:46 | 000,000,467 | ---- | M] () -- C:\rkill.log
[2009/03/28 21:40:24 | 000,000,232 | ---- | M] () -- C:\sqmdata00.sqm
[2009/03/29 09:12:33 | 000,000,268 | ---- | M] () -- C:\sqmdata01.sqm
[2009/03/28 21:40:24 | 000,000,244 | ---- | M] () -- C:\sqmnoopt00.sqm
[2009/03/29 09:12:33 | 000,000,244 | ---- | M] () -- C:\sqmnoopt01.sqm
[2012/02/09 21:34:26 | 000,086,456 | ---- | M] () -- C:\TDSSKiller.2.7.11.0_09.02.2012_21.32.57_log.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/01/01 22:57:22 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/02/02 10:26:36 | 000,273,920 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\1_hpzpp4v2.dll
[2007/02/02 10:26:36 | 000,273,920 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\2_hpzpp4v2.dll
[2006/04/10 15:02:32 | 000,074,240 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2007/02/02 10:26:36 | 000,273,920 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\hpzpp4v2.dll
[2006/11/02 05:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 14:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2008/08/21 19:12:10 | 000,001,682 | ---- | M] () -- C:\Users\Pondalex\AppData\Roaming\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2010/03/30 20:43:24 | 000,423,936 | ---- | M] (Feñiz 2001) -- C:\Program Files\Conversor.exe
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
[2009/04/03 15:34:20 | 000,016,362 | ---- | M] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended-((Demonoid.com)).torrent
[2009/04/03 15:28:17 | 000,016,362 | ---- | M] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended_x-Demonoid.com-x.torrent
[2010/03/30 20:43:24 | 000,000,157 | ---- | M] () -- C:\Program Files\Perfiles.ini
[2009/04/09 23:46:14 | 000,012,092 | ---- | M] () -- C:\Program Files\Self-made media for NM-122708.xlsx
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2011/01/23 22:11:58 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2011/01/23 22:11:58 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2011/01/23 22:11:59 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2011/01/23 22:11:59 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2011/01/23 22:11:59 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/04 17:21:17 | 000,000,087 | -HS- | M] () -- C:\Users\Pondalex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/02/08 21:24:36 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Users\Pondalex\Desktop\aswMBR.exe
[2012/02/10 22:28:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Pondalex\Desktop\OTL.exe
[2012/02/10 21:35:16 | 004,400,207 | R--- | M] (Swearware) -- C:\Users\Pondalex\Desktop\pondalex.exe.exe
[2007/09/17 19:28:30 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\Users\Pondalex\Desktop\recdisc.exe
[2012/02/10 21:36:26 | 001,008,141 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
[2008/09/09 22:43:49 | 000,061,224 | ---- | M] () -- C:\Users\Pondalex\GoToAssistDownloadHelper.exe
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/01/23 22:10:32 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
[2011/01/23 22:10:32 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2008/08/13 22:45:10 | 000,000,402 | -HS- | M] () -- C:\Users\Pondalex\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/04/04 00:39:44 | 000,003,604 | -HS- | M] () -- C:\ProgramData\8s32
[2012/02/05 10:47:55 | 000,000,448 | ---- | M] () -- C:\ProgramData\erFWlu6VTzaxlf
[2012/01/21 14:53:37 | 000,004,264 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2010/04/04 21:58:34 | 000,009,584 | -HS- | M] () -- C:\ProgramData\VHx0W
[2009/09/15 16:17:05 | 018,015,723 | ---- | M] () -- C:\ProgramData\vlc-1.0.1-win32.exe
[2010/10/10 08:26:28 | 018,527,244 | ---- | M] () -- C:\ProgramData\vlc-1.0.2-win32.exe
[2011/01/23 21:49:00 | 016,310,272 | ---- | M] () -- C:\ProgramData\vlc-1.0.5-win32.exe
[2010/07/25 00:34:20 | 019,473,201 | ---- | M] () -- C:\ProgramData\vlc-1.1.1-win32.exe
[2010/08/02 13:03:42 | 019,461,015 | ---- | M] () -- C:\ProgramData\vlc-1.1.2-win32.exe
[2010/08/21 21:39:34 | 019,563,096 | ---- | M] () -- C:\ProgramData\vlc-1.1.3-win32.exe
[2010/09/08 19:39:32 | 019,657,194 | ---- | M] () -- C:\ProgramData\vlc-1.1.4-win32.exe
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$] -> -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP
FC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP
1B5B4F1
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
[2012/01/15 10:24:56 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{B5737D06-4454-4E95-86ED-6E2960A6EDFD}
[2012/01/14 10:16:04 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{6D8AB6BA-0D99-45FC-A95E-DBB35F0A5647}
[2012/01/13 20:16:14 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{4029C74A-DA00-460D-A613-403ED1FCB87F}
[2012/01/13 20:16:03 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{2AA391F5-986C-4729-BBAC-8E421F6F930F}
[2012/01/12 23:53:24 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{E5089D2B-4C83-4714-878D-7C5F362B8557}
[2012/01/12 11:53:00 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{E765F61E-74D9-4263-BF6C-7CF735AE2272}
[2012/01/12 11:52:49 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{8DF7660C-5269-4B67-B39C-803D25231594}
[2012/01/11 23:52:20 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{A6892FA6-0758-499A-875C-4365EECF9A6D}
[2012/01/11 23:52:07 | 000,000,000 | ---D | C] -- C:\Users\Pondalex\AppData\Local\{CA7D01E5-D4E2-4A1A-953D-BE5D0A1F7B02}
[2001/04/02 01:49:16 | 000,423,936 | ---- | C] (Feñiz 2001) -- C:\Program Files\Conversor.exe
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/10 22:28:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Pondalex\Desktop\OTL.exe
[2012/02/10 22:11:30 | 000,001,356 | ---- | M] () -- C:\Users\Pondalex\AppData\Local\d3d9caps.dat
[2012/02/10 21:44:05 | 000,000,147 | ---- | M] () -- C:\Users\Pondalex\Desktop\rk-proxy.reg
[2012/02/10 21:40:03 | 000,002,855 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill - Shortcut.pif
[2012/02/10 21:36:52 | 001,008,141 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill.com
[2012/02/10 21:36:26 | 001,008,141 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill.exe
[2012/02/10 21:35:16 | 004,400,207 | R--- | M] (Swearware) -- C:\Users\Pondalex\Desktop\pondalex.exe.exe
[2012/02/10 20:38:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/10 20:37:23 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/10 20:37:23 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/10 20:34:10 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/02/10 20:30:43 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/02/10 20:30:43 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/10 20:30:39 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/02/10 20:30:39 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/02/10 20:30:39 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/09 23:16:31 | 000,667,260 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/02/09 23:16:31 | 000,127,148 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/02/09 23:09:58 | 000,000,862 | ---- | M] () -- C:\Windows\System32\tversity.cookies
[2012/02/09 22:29:49 | 000,000,512 | ---- | M] () -- C:\Users\Pondalex\Desktop\MBR.dat
[2012/02/09 21:37:06 | 307,695,254 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/02/09 21:12:45 | 000,000,299 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (4).lnk
[2012/02/09 21:10:38 | 000,000,715 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (3).lnk
[2012/02/09 20:59:49 | 000,000,715 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (2).lnk
[2012/02/09 20:54:19 | 000,000,299 | ---- | M] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut.lnk
[2012/02/08 22:07:55 | 000,026,872 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\FixTDSS.sys
[2012/02/08 21:24:36 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Users\Pondalex\Desktop\aswMBR.exe
[2012/02/07 20:54:38 | 000,001,110 | ---- | M] () -- C:\Users\Pondalex\Desktop\Get Live PC Help Now.lnk
[2012/02/06 21:23:04 | 000,000,523 | ---- | M] () -- C:\Users\Pondalex\Desktop\The MUZIK - Shortcut.lnk
[2012/02/06 21:22:48 | 000,000,679 | ---- | M] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut (2).lnk
[2012/02/06 21:22:36 | 000,000,415 | ---- | M] () -- C:\Users\Pondalex\Desktop\Downloads - Shortcut.lnk
[2012/02/06 21:20:18 | 000,000,655 | ---- | M] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut.lnk
[2012/02/06 20:40:10 | 000,000,938 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Killer.lnk
[2012/02/06 08:55:53 | 000,000,286 | ---- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{480410F6-6C9D-4125-B8CE-8A1BB0B19D14}.job
[2012/02/05 10:47:55 | 000,000,448 | ---- | M] () -- C:\ProgramData\erFWlu6VTzaxlf
[2012/02/05 00:52:45 | 000,015,360 | ---- | M] () -- C:\Users\Pondalex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/04 22:58:14 | 000,000,341 | ---- | M] () -- C:\Users\Pondalex\Desktop\exefix.reg
[2012/02/04 18:41:44 | 000,000,474 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/04 18:33:52 | 000,001,649 | ---- | M] () -- C:\Users\Pondalex\Desktop\Check PC For Errors.lnk
[2012/02/04 15:56:13 | 000,000,607 | ---- | M] () -- C:\Users\Pondalex\Desktop\System Check.lnk
[2012/02/04 15:35:53 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2012/02/01 20:56:29 | 000,001,057 | ---- | M] () -- C:\Users\Pondalex\Desktop\Spybot - Search & Destroy.lnk
[2012/01/30 22:34:41 | 000,000,514 | ---- | M] () -- C:\Users\Pondalex\Desktop\Nubiles.net Member's Area - Home.website
[2012/01/30 21:14:32 | 000,006,035 | ---- | M] () -- C:\Users\Pondalex\secret-key-87623C84.asc
[2012/01/29 21:00:00 | 000,006,034 | ---- | M] () -- C:\Users\Pondalex\secret-key-F8B6DEB8.asc
[2012/01/29 20:50:56 | 000,006,035 | ---- | M] () -- C:\Users\Pondalex\secret-key-6C9A59A4.asc
[2012/01/29 19:14:51 | 000,000,436 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2012/01/29 16:45:40 | 000,231,376 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2012/01/21 14:53:36 | 000,130,834 | ---- | M] () -- C:\Windows\hpoins18.dat
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/10 21:40:22 | 001,008,141 | ---- | C] () -- C:\Users\Pondalex\Desktop\rkill.exe
[2012/02/10 21:40:08 | 001,008,141 | ---- | C] () -- C:\Users\Pondalex\Desktop\rkill.com
[2012/02/10 21:40:03 | 000,002,855 | ---- | C] () -- C:\Users\Pondalex\Desktop\rkill - Shortcut.pif
[2012/02/09 22:29:49 | 000,000,512 | ---- | C] () -- C:\Users\Pondalex\Desktop\MBR.dat
[2012/02/09 21:14:23 | 000,000,299 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (4).lnk
[2012/02/09 21:10:38 | 000,000,715 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (3).lnk
[2012/02/09 20:59:49 | 000,000,715 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut (2).lnk
[2012/02/09 20:54:19 | 000,000,299 | ---- | C] () -- C:\Users\Pondalex\Desktop\recdisc - Shortcut.lnk
[2012/02/07 23:20:54 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/07 23:20:51 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/07 20:54:38 | 000,001,110 | ---- | C] () -- C:\Users\Pondalex\Desktop\Get Live PC Help Now.lnk
[2012/02/06 21:23:04 | 000,000,523 | ---- | C] () -- C:\Users\Pondalex\Desktop\The MUZIK - Shortcut.lnk
[2012/02/06 21:22:48 | 000,000,679 | ---- | C] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut (2).lnk
[2012/02/06 21:22:36 | 000,000,415 | ---- | C] () -- C:\Users\Pondalex\Desktop\Downloads - Shortcut.lnk
[2012/02/06 20:40:10 | 000,000,938 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Killer.lnk
[2012/02/06 08:55:53 | 000,000,286 | ---- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{480410F6-6C9D-4125-B8CE-8A1BB0B19D14}.job
[2012/02/05 10:46:49 | 000,000,448 | ---- | C] () -- C:\ProgramData\erFWlu6VTzaxlf
[2012/02/04 23:03:20 | 000,000,341 | ---- | C] () -- C:\Users\Pondalex\Desktop\exefix.reg
[2012/02/04 18:41:44 | 000,000,474 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/04 18:33:52 | 000,001,649 | ---- | C] () -- C:\Users\Pondalex\Desktop\Check PC For Errors.lnk
[2012/02/04 18:20:33 | 000,000,147 | ---- | C] () -- C:\Users\Pondalex\Desktop\rk-proxy.reg
[2012/02/04 15:56:13 | 000,000,607 | ---- | C] () -- C:\Users\Pondalex\Desktop\System Check.lnk
[2012/02/01 20:56:29 | 000,001,057 | ---- | C] () -- C:\Users\Pondalex\Desktop\Spybot - Search & Destroy.lnk
[2012/01/30 21:14:31 | 000,006,035 | ---- | C] () -- C:\Users\Pondalex\secret-key-87623C84.asc
[2012/01/29 20:59:59 | 000,006,034 | ---- | C] () -- C:\Users\Pondalex\secret-key-F8B6DEB8.asc
[2012/01/29 20:50:56 | 000,006,035 | ---- | C] () -- C:\Users\Pondalex\secret-key-6C9A59A4.asc
[2012/01/28 11:33:46 | 000,000,940 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/01/28 11:33:46 | 000,000,918 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/01/23 22:43:33 | 000,000,655 | ---- | C] () -- C:\Users\Pondalex\Desktop\Start Tor Browser - Shortcut.lnk
[2011/12/17 02:29:57 | 000,201,116 | ---- | C] () -- C:\Windows\System32\mlfcache.dat
[2011/06/09 16:59:08 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/06/09 16:57:12 | 000,002,888 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2010/11/25 19:15:14 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010/11/05 12:17:10 | 000,000,000 | ---- | C] () -- C:\Windows\hpqEmlSz.INI
[2010/10/10 08:26:28 | 018,527,244 | ---- | C] () -- C:\ProgramData\vlc-1.0.2-win32.exe
[2010/09/28 13:07:36 | 000,224,001 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2010/09/21 20:41:54 | 000,000,056 | ---- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/09/08 19:36:08 | 019,657,194 | ---- | C] () -- C:\ProgramData\vlc-1.1.4-win32.exe
[2010/08/21 21:37:06 | 019,563,096 | ---- | C] () -- C:\ProgramData\vlc-1.1.3-win32.exe
[2010/08/02 13:01:13 | 019,461,015 | ---- | C] () -- C:\ProgramData\vlc-1.1.2-win32.exe
[2010/07/25 00:31:55 | 019,473,201 | ---- | C] () -- C:\ProgramData\vlc-1.1.1-win32.exe
[2010/06/25 10:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2010/06/04 18:38:22 | 016,310,272 | ---- | C] () -- C:\ProgramData\vlc-1.0.5-win32.exe
[2010/05/08 11:38:53 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll.old
[2010/04/22 19:02:04 | 000,000,007 | ---- | C] () -- C:\Windows\treeskp.sys
[2010/04/22 19:02:04 | 000,000,007 | ---- | C] () -- C:\Windows\sbacknt.bin
[2010/04/04 20:58:19 | 000,009,584 | -HS- | C] () -- C:\Users\Pondalex\AppData\Local\VHx0W
[2010/04/04 20:58:19 | 000,009,584 | -HS- | C] () -- C:\ProgramData\VHx0W
[2010/04/03 21:33:42 | 000,003,604 | -HS- | C] () -- C:\Users\Pondalex\AppData\Local\8s32
[2010/04/03 21:33:42 | 000,003,604 | -HS- | C] () -- C:\ProgramData\8s32
[2010/03/29 21:34:59 | 000,000,579 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\AutoGK.ini
[2010/03/28 16:20:56 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/11/12 10:44:29 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/11/12 10:44:28 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/10/24 10:30:39 | 000,130,834 | ---- | C] () -- C:\Windows\hpoins18.dat
[2009/10/24 10:30:28 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2009/10/21 20:22:49 | 000,001,356 | ---- | C] () -- C:\Users\Pondalex\AppData\Local\d3d9caps.dat
[2009/09/15 16:02:36 | 018,015,723 | ---- | C] () -- C:\ProgramData\vlc-1.0.1-win32.exe
[2009/08/28 20:33:32 | 000,001,044 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\vso_ts_preview.xml
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/06 06:58:43 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2009/05/09 20:30:08 | 000,000,000 | ---- | C] () -- C:\Windows\System32\settings.dat
[2009/05/06 21:01:16 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/04/25 21:41:35 | 000,000,025 | ---- | C] () -- C:\Windows\cdplayer.ini
[2009/04/03 18:10:30 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/04/03 15:34:18 | 000,016,362 | ---- | C] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended-((Demonoid.com)).torrent
[2009/04/03 15:28:06 | 000,016,362 | ---- | C] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended_x-Demonoid.com-x.torrent
[2009/03/21 16:40:13 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2009/03/21 16:40:13 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2009/03/21 16:40:13 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2009/01/25 14:10:48 | 000,179,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/01/08 16:01:22 | 000,629,760 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008/12/16 21:58:54 | 000,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLgFT.dll
[2008/09/29 18:42:17 | 000,870,128 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\mcs.rma
[2008/09/29 18:42:17 | 000,000,004 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\1FAC5E
[2008/09/21 02:07:03 | 000,066,482 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2008/09/18 03:00:37 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/09/10 20:43:01 | 000,015,360 | ---- | C] () -- C:\Users\Pondalex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/09 22:34:46 | 000,001,468 | ---- | C] () -- C:\Windows\WININIT.INI
[2008/08/14 22:15:32 | 000,001,306 | ---- | C] () -- C:\Users\Pondalex\AppData\Roaming\wklnhst.dat
[2008/08/06 12:39:55 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008/08/06 08:56:26 | 000,065,536 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008/08/06 08:56:25 | 000,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2008/08/06 08:52:19 | 000,101,376 | ---- | C] () -- C:\Windows\System32\APOMngr.dll
[2008/08/06 08:52:19 | 000,066,560 | ---- | C] () -- C:\Windows\System32\CmdRtr.dll
[2008/08/06 08:52:19 | 000,000,628 | ---- | C] () -- C:\Windows\System32\PCI_VEN_1102&DEV_FF05&SUBSYS_00001102.ini
[2006/11/02 05:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,436,592 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,667,260 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,127,148 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 03:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2003/10/28 10:07:20 | 000,372,736 | ---- | C] () -- C:\Windows\System32\ffvfw.dll
[2002/10/15 15:54:04 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2001/04/02 01:41:14 | 000,000,157 | ---- | C] () -- C:\Program Files\Perfiles.ini
========== LOP Check ==========
[2011/01/23 21:15:39 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\AVG
[2010/12/04 15:21:16 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\AVG10
[2011/12/11 10:42:40 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Azureus
[2010/08/14 08:36:27 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\BitTorrent
[2011/09/04 07:11:02 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Camfrog
[2011/02/04 15:38:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Canon
[2009/06/12 17:44:00 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\ChemBuddy
[2011/06/15 16:48:47 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\com.Shutterfly.ExpressUploader
[2008/09/09 23:22:13 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\DataSafeOnline
[2009/08/05 12:59:25 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Dylogic
[2009/05/05 20:17:34 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\eAcceleration
[2009/03/30 22:25:46 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\ExcelCube
[2012/02/08 22:07:55 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\FixTDSS
[2012/02/04 22:26:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\GetRightToGo
[2012/01/30 21:20:39 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\gnupg
[2012/01/30 21:14:31 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\gtk-2.0
[2011/03/21 21:39:03 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Image Zone Express
[2008/08/30 23:14:39 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Leadertech
[2010/06/13 21:03:44 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\LimeWire
[2012/02/03 23:54:31 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Nelyu
[2012/02/04 15:32:58 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Ota
[2009/11/01 12:08:08 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Printer Info Cache
[2010/06/13 21:03:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Raptr
[2010/12/30 23:27:07 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Registry Mechanic
[2011/02/24 23:11:00 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Sammsoft
[2009/07/09 12:05:48 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Snapfish
[2008/08/20 21:36:33 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Template
[2012/01/29 16:54:28 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\TrueCrypt
[2011/10/26 08:14:38 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Uniblue
[2010/04/22 19:01:59 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\vghd
[2009/08/28 23:25:52 | 000,000,000 | ---D | M] -- C:\Users\Pondalex\AppData\Roaming\Vso
[2012/02/10 20:30:39 | 000,000,918 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000Core.job
[2012/02/10 20:30:39 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2359270729-473054158-1944764805-1000UA.job
[2012/02/10 20:37:20 | 000,032,592 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/02/06 08:55:53 | 000,000,286 | ---- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{480410F6-6C9D-4125-B8CE-8A1BB0B19D14}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/01/01 02:51:21 | 000,000,078 | ---- | M] () -- C:\AEIusb.log
[2006/09/18 14:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2006/09/18 14:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2008/05/14 08:21:26 | 000,088,560 | ---- | M] (Sonic Solutions) -- C:\DC_ShellExt.dll
[2008/08/06 12:40:01 | 000,005,187 | R--- | M] () -- C:\dell.sdr
[2010/12/04 10:23:24 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012/02/07 20:44:28 | 000,047,516 | ---- | M] () -- C:\JavaRa.log
[2010/05/09 09:21:06 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2010/12/04 10:23:24 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/09/03 17:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\npbittorrent.dll
[2012/02/10 20:38:35 | 3532,881,920 | -HS- | M] () -- C:\pagefile.sys
[2012/02/10 21:46:46 | 000,000,467 | ---- | M] () -- C:\rkill.log
[2009/03/28 21:40:24 | 000,000,232 | ---- | M] () -- C:\sqmdata00.sqm
[2009/03/29 09:12:33 | 000,000,268 | ---- | M] () -- C:\sqmdata01.sqm
[2009/03/28 21:40:24 | 000,000,244 | ---- | M] () -- C:\sqmnoopt00.sqm
[2009/03/29 09:12:33 | 000,000,244 | ---- | M] () -- C:\sqmnoopt01.sqm
[2012/02/09 21:34:26 | 000,086,456 | ---- | M] () -- C:\TDSSKiller.2.7.11.0_09.02.2012_21.32.57_log.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/01/01 22:57:22 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/02/02 10:26:36 | 000,273,920 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\1_hpzpp4v2.dll
[2007/02/02 10:26:36 | 000,273,920 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\2_hpzpp4v2.dll
[2006/04/10 15:02:32 | 000,074,240 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2007/02/02 10:26:36 | 000,273,920 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\hpzpp4v2.dll
[2006/11/02 05:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 14:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2008/08/21 19:12:10 | 000,001,682 | ---- | M] () -- C:\Users\Pondalex\AppData\Roaming\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2010/03/30 20:43:24 | 000,423,936 | ---- | M] (Feñiz 2001) -- C:\Program Files\Conversor.exe
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
[2009/04/03 15:34:20 | 000,016,362 | ---- | M] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended-((Demonoid.com)).torrent
[2009/04/03 15:28:17 | 000,016,362 | ---- | M] () -- C:\Program Files\Microsoft_Office_2003_Pro_Unattended_x-Demonoid.com-x.torrent
[2010/03/30 20:43:24 | 000,000,157 | ---- | M] () -- C:\Program Files\Perfiles.ini
[2009/04/09 23:46:14 | 000,012,092 | ---- | M] () -- C:\Program Files\Self-made media for NM-122708.xlsx
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2011/01/23 22:11:58 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2011/01/23 22:11:58 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2011/01/23 22:11:59 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2011/01/23 22:11:59 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2011/01/23 22:11:59 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/04 17:21:17 | 000,000,087 | -HS- | M] () -- C:\Users\Pondalex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/02/08 21:24:36 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Users\Pondalex\Desktop\aswMBR.exe
[2012/02/10 22:28:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Pondalex\Desktop\OTL.exe
[2012/02/10 21:35:16 | 004,400,207 | R--- | M] (Swearware) -- C:\Users\Pondalex\Desktop\pondalex.exe.exe
[2007/09/17 19:28:30 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\Users\Pondalex\Desktop\recdisc.exe
[2012/02/10 21:36:26 | 001,008,141 | ---- | M] () -- C:\Users\Pondalex\Desktop\rkill.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
[2008/09/09 22:43:49 | 000,061,224 | ---- | M] () -- C:\Users\Pondalex\GoToAssistDownloadHelper.exe
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/01/23 22:10:32 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/01/23 22:10:32 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
[2011/01/23 22:10:32 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2008/08/13 22:45:10 | 000,000,402 | -HS- | M] () -- C:\Users\Pondalex\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/04/04 00:39:44 | 000,003,604 | -HS- | M] () -- C:\ProgramData\8s32
[2012/02/05 10:47:55 | 000,000,448 | ---- | M] () -- C:\ProgramData\erFWlu6VTzaxlf
[2012/01/21 14:53:37 | 000,004,264 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2010/04/04 21:58:34 | 000,009,584 | -HS- | M] () -- C:\ProgramData\VHx0W
[2009/09/15 16:17:05 | 018,015,723 | ---- | M] () -- C:\ProgramData\vlc-1.0.1-win32.exe
[2010/10/10 08:26:28 | 018,527,244 | ---- | M] () -- C:\ProgramData\vlc-1.0.2-win32.exe
[2011/01/23 21:49:00 | 016,310,272 | ---- | M] () -- C:\ProgramData\vlc-1.0.5-win32.exe
[2010/07/25 00:34:20 | 019,473,201 | ---- | M] () -- C:\ProgramData\vlc-1.1.1-win32.exe
[2010/08/02 13:03:42 | 019,461,015 | ---- | M] () -- C:\ProgramData\vlc-1.1.2-win32.exe
[2010/08/21 21:39:34 | 019,563,096 | ---- | M] () -- C:\ProgramData\vlc-1.1.3-win32.exe
[2010/09/08 19:39:32 | 019,657,194 | ---- | M] () -- C:\ProgramData\vlc-1.1.4-win32.exe
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB45409$] -> -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >