O32 - AutoRun File - [2009/01/10 17:40:20 | 000,000,050 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/06/02 16:40:48 | 000,000,000 | ---- | M] () - K:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1f4fe29c-df67-11dd-bc5a-0016761f2be5}\Shell\AutoRun\command - "" = H:\Setup_FlipShare.exe
O33 - MountPoints2\{1f4fe29c-df67-11dd-bc5a-0016761f2be5}\Shell\Setup FlipShare\command - "" = H:\Setup_FlipShare.exe
O33 - MountPoints2\{3c140f92-0cf9-11de-bc95-0016761f2be5}\Shell - "" = AutoRun
O33 - MountPoints2\{3c140f92-0cf9-11de-bc95-0016761f2be5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3c140f92-0cf9-11de-bc95-0016761f2be5}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{3c140f94-0cf9-11de-bc95-0016761f2be5}\Shell\Auto\command - "" = tel.xls.exe
O33 - MountPoints2\{3c140f94-0cf9-11de-bc95-0016761f2be5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3c140f94-0cf9-11de-bc95-0016761f2be5}\Shell\AutoRun\command - "" = D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tel.xls.exe
O33 - MountPoints2\{54c9ba1c-70c9-11de-ba0c-0016761f2be5}\Shell - "" = AutoRun
O33 - MountPoints2\{54c9ba1c-70c9-11de-ba0c-0016761f2be5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{54c9ba1c-70c9-11de-ba0c-0016761f2be5}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O33 - MountPoints2\{54c9ba1e-70c9-11de-ba0c-0016761f2be5}\Shell - "" = AutoRun
O33 - MountPoints2\{54c9ba1e-70c9-11de-ba0c-0016761f2be5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{54c9ba1e-70c9-11de-ba0c-0016761f2be5}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{812628c4-7138-11de-ba0d-0016761f2be5}\Shell - "" = AutoRun
O33 - MountPoints2\{812628c4-7138-11de-ba0d-0016761f2be5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{812628c4-7138-11de-ba0d-0016761f2be5}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{ab54e614-c9f8-11dc-872f-0016761f2be5}\Shell - "" = AutoRun
O33 - MountPoints2\{ab54e614-c9f8-11dc-872f-0016761f2be5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ab54e614-c9f8-11dc-872f-0016761f2be5}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\{bbbf7e65-c814-11dc-b3cc-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{bbbf7e65-c814-11dc-b3cc-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{bbbf7e65-c814-11dc-b3cc-806d6172696f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{cf650308-b2a9-11df-bb48-0016761f2be5}\Shell - "" = AutoRun
O33 - MountPoints2\{cf650308-b2a9-11df-bb48-0016761f2be5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cf650308-b2a9-11df-bb48-0016761f2be5}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O33 - MountPoints2\{f2ddbb13-5a9b-11dd-bbaf-0016761f2be5}\Shell\AutoRun\command - "" = G:\JDSecure\Windows\JDSecure31.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012/02/17 16:33:15 | 000,584,192 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\1Gustavo\Desktop\OTL.exe
[2012/02/17 16:02:50 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Application Data\QuickScan
[2012/02/17 12:47:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Application Data\Malwarebytes
[2012/02/17 12:47:25 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/17 12:47:20 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
[2012/02/17 12:47:17 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2012/02/17 12:47:17 | 000,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware
[2012/02/17 12:45:15 | 009,502,424 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\1Gustavo\Desktop\mbam--setup-1.60.1.1000.exe
[2012/02/17 12:02:21 | 000,446,464 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\1Gustavo\Desktop\TFC.exe
[2012/02/17 11:32:32 | 000,234,752 | ---- | C] (Acronis) -- D:\WINDOWS\System32\drivers\afcdp.sys
[2012/02/17 11:31:48 | 000,766,208 | ---- | C] (Acronis) -- D:\WINDOWS\System32\drivers\tdrpman.sys
[2012/02/17 11:30:56 | 000,126,112 | ---- | C] (Acronis) -- D:\WINDOWS\System32\drivers\vididr.sys
[2012/02/17 11:30:56 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Application Data\30E56105-8D4E-4EFE-B61C-1E55A5433C4F
[2012/02/17 11:30:51 | 000,084,512 | ---- | C] (Acronis) -- D:\WINDOWS\System32\drivers\vsflt58.sys
[2012/02/17 11:30:30 | 000,076,768 | ---- | C] (Acronis) -- D:\WINDOWS\System32\drivers\fltsrv.sys
[2012/02/17 11:29:49 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Acronis
[2012/02/17 11:29:43 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Start Menu\Programs\Acronis
[2012/02/17 11:28:08 | 000,000,000 | ---D | C] -- D:\Program Files\Acronis
[2012/02/17 11:28:06 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Acronis
[2012/02/17 11:05:59 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Application Data\Acronis
[2012/02/17 11:05:58 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Acronis
[2012/02/10 05:59:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\WEBREG
[2012/02/10 05:54:04 | 000,123,904 | ---- | C] (Hewlett-Packard Company) -- D:\WINDOWS\System32\hpf3l70w.dll
[2012/02/10 05:53:07 | 000,315,392 | R--- | C] (Hewlett-Packard Co.) -- D:\WINDOWS\System32\hpwvst01.dll
[2012/02/10 05:53:06 | 000,966,656 | R--- | C] (Hewlett-Packard Co.) -- D:\WINDOWS\System32\hpwtiop5.dll
[2012/02/10 05:53:06 | 000,749,568 | R--- | C] (Hewlett-Packard) -- D:\WINDOWS\System32\hpwwiax6.dll
[2012/02/09 23:01:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
[2012/02/09 23:01:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Application Data\Yahoo!
[2012/02/09 23:01:22 | 000,000,000 | ---D | C] -- D:\Program Files\Yahoo!
[2012/02/09 20:44:58 | 000,000,000 | ---D | C] -- D:\WINDOWS\hpoj4500g510g-m
[2012/01/26 13:52:40 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\ATI
[2012/01/26 13:52:40 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Local Settings\Application Data\ATI
[2012/01/26 13:52:40 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Application Data\ATI
[2012/01/26 13:41:26 | 000,000,000 | ---D | C] -- D:\Program Files\AMD APP
[2012/01/26 13:41:00 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Catalyst Control Center
[2012/01/26 13:35:28 | 000,000,000 | ---D | C] -- D:\Program Files\ATI
[2012/01/26 13:34:56 | 000,000,000 | ---D | C] -- D:\Program Files\ATI Technologies
[2012/01/26 13:28:01 | 000,000,000 | ---D | C] -- D:\AMD
[2012/01/26 08:30:57 | 000,311,296 | ---- | C] (ATI Technologies Inc.) -- D:\WINDOWS\System32\atiiiexx.dll
[2012/01/26 08:30:40 | 000,466,944 | ---- | C] (Advanced Micro Devices, Inc.) -- D:\WINDOWS\System32\ATIDEMGX.dll
[2012/01/26 08:28:52 | 000,100,368 | ---- | C] (Advanced Micro Devices) -- D:\WINDOWS\System32\drivers\AtihdXP3.sys
[2012/01/23 21:08:58 | 000,000,000 | ---D | C] -- D:\Documents and Settings\1Gustavo\Application Data\Windows Search
[2008/07/23 17:44:29 | 000,964,218 | ---- | C] (Click2learn, Inc.) -- D:\Program Files\OTSMENU.exe
[2008/07/23 17:44:29 | 000,717,965 | ---- | C] (click2learn.com, inc.) -- D:\Program Files\InstallTest.exe
[2008/07/23 17:44:28 | 002,036,730 | ---- | C] (click2learn.com, inc.) -- D:\Program Files\Givetest.EXE
[2008/07/23 17:44:27 | 000,760,758 | ---- | C] (click2learn.com, inc.) -- D:\Program Files\EditTaskList.exe
[2008/07/23 17:44:26 | 001,546,606 | ---- | C] (click2learn.com, inc.) -- D:\Program Files\CreateQuestions.exe
[2008/07/23 17:44:26 | 000,943,546 | ---- | C] (click2learn.com, inc.) -- D:\Program Files\AssessResults.exe
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012/02/17 16:33:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\1Gustavo\Desktop\OTL.exe
[2012/02/17 16:33:00 | 000,000,890 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/17 15:51:00 | 000,002,422 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2012/02/17 15:50:03 | 000,000,284 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1220945662-1454471165-839522115-1003.job
[2012/02/17 15:49:52 | 000,000,882 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/17 15:49:11 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2012/02/17 15:48:38 | 3486,871,552 | -HS- | M] () -- D:\hiberfil.sys
[2012/02/17 15:48:35 | 000,000,000 | ---- | M] () -- D:\WINDOWS\System32\drivers\lvuvc.hs
[2012/02/17 12:47:29 | 000,000,793 | ---- | M] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/17 12:45:35 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\1Gustavo\Desktop\mbam--setup-1.60.1.1000.exe
[2012/02/17 12:02:32 | 000,772,954 | ---- | M] () -- D:\WINDOWS\System32\drivers\N360\0502000.00D\Cat.DB
[2012/02/17 12:02:22 | 000,446,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\1Gustavo\Desktop\TFC.exe
[2012/02/17 11:32:32 | 000,234,752 | ---- | M] (Acronis) -- D:\WINDOWS\System32\drivers\afcdp.sys
[2012/02/17 11:31:48 | 000,766,208 | ---- | M] (Acronis) -- D:\WINDOWS\System32\drivers\tdrpman.sys
[2012/02/17 11:31:32 | 000,609,760 | ---- | M] (Acronis) -- D:\WINDOWS\System32\drivers\timntr.sys
[2012/02/17 11:30:56 | 000,126,112 | ---- | M] (Acronis) -- D:\WINDOWS\System32\drivers\vididr.sys
[2012/02/17 11:30:51 | 000,084,512 | ---- | M] (Acronis) -- D:\WINDOWS\System32\drivers\vsflt58.sys
[2012/02/17 11:30:30 | 000,076,768 | ---- | M] (Acronis) -- D:\WINDOWS\System32\drivers\fltsrv.sys
[2012/02/17 11:29:44 | 000,000,873 | ---- | M] () -- D:\Documents and Settings\1Gustavo\Desktop\Acronis True Image Home 2012.lnk
[2012/02/12 23:05:00 | 000,000,254 | ---- | M] () -- D:\WINDOWS\tasks\NUSchedule.job
[2012/02/12 19:26:00 | 000,000,292 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1220945662-1454471165-839522115-1003.job
[2012/02/10 05:57:58 | 000,205,440 | ---- | M] () -- D:\WINDOWS\hpwins26.dat
[2012/02/09 21:11:11 | 000,001,817 | ---- | M] () -- D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/09 19:51:44 | 000,204,970 | ---- | M] () -- D:\WINDOWS\hpwins26.dat.temp
[2012/02/07 09:07:36 | 000,000,508 | ---- | M] () -- D:\Documents and Settings\1Gustavo\Desktop\terminate.vbs
[2012/02/06 20:48:03 | 000,000,290 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1220945662-1454471165-839522115-1006.job
[2012/02/03 21:01:28 | 000,180,224 | ---- | M] () -- D:\Documents and Settings\1Gustavo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/03 05:59:56 | 000,028,401 | ---- | M] () -- D:\Documents and Settings\1Gustavo\Desktop\PlacementEntry.pub
[2012/02/02 06:01:51 | 000,001,909 | ---- | M] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\Norton 360.LNK
[2012/01/28 00:27:32 | 000,000,172 | ---- | M] () -- D:\WINDOWS\System32\drivers\N360\0502000.00D\isolate.ini
[2012/01/26 08:25:08 | 000,001,324 | ---- | M] () -- D:\WINDOWS\System32\d3d9caps.dat
[2012/01/26 07:55:33 | 000,000,059 | ---- | M] () -- D:\WINDOWS\WININIT.INI
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012/02/17 12:47:28 | 000,000,793 | ---- | C] () -- D:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/17 11:29:44 | 000,000,873 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Desktop\Acronis True Image Home 2012.lnk
[2012/02/09 22:17:47 | 000,000,731 | ---- | C] () -- D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2012/02/09 21:11:10 | 000,001,817 | ---- | C] () -- D:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/09 20:14:48 | 000,204,970 | ---- | C] () -- D:\WINDOWS\hpwins26.dat.temp
[2012/02/09 20:14:48 | 000,000,370 | ---- | C] () -- D:\WINDOWS\hpwmdl26.dat.temp
[2012/02/09 19:20:13 | 000,205,440 | ---- | C] () -- D:\WINDOWS\hpwins26.dat
[2012/02/09 19:20:12 | 000,000,370 | ---- | C] () -- D:\WINDOWS\hpwmdl26.dat
[2012/02/07 09:07:36 | 000,000,508 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Desktop\terminate.vbs
[2012/01/26 08:30:58 | 000,036,338 | ---- | C] () -- D:\WINDOWS\atiogl.xml
[2012/01/26 08:30:32 | 000,219,080 | ---- | C] () -- D:\WINDOWS\System32\atiapfxx.blb
[2012/01/26 08:30:26 | 000,887,724 | ---- | C] () -- D:\WINDOWS\System32\ativva6x.dat
[2012/01/26 08:30:25 | 000,608,507 | ---- | C] () -- D:\WINDOWS\System32\atiicdxx.dat
[2012/01/26 08:30:25 | 000,000,003 | ---- | C] () -- D:\WINDOWS\System32\ativva5x.dat
[2012/01/14 12:18:15 | 000,077,421 | ---- | C] () -- D:\WINDOWS\hpqins05.dat
[2012/01/11 15:27:50 | 000,110,592 | ---- | C] () -- D:\WINDOWS\System32\FsUsbExDevice.Dll
[2012/01/11 15:27:50 | 000,036,608 | ---- | C] () -- D:\WINDOWS\System32\FsUsbExDisk.Sys
[2011/12/23 20:58:28 | 000,030,568 | ---- | C] () -- D:\WINDOWS\MusiccityDownload.exe
[2011/12/23 20:58:24 | 000,974,848 | ---- | C] () -- D:\WINDOWS\System32\cis-2.4.dll
[2011/12/23 20:58:24 | 000,081,920 | ---- | C] () -- D:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/12/23 20:58:24 | 000,065,536 | ---- | C] () -- D:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/12/23 20:58:24 | 000,057,344 | ---- | C] () -- D:\WINDOWS\System32\issacapi_se-2.3.dll
[2011/12/05 22:04:00 | 000,059,904 | ---- | C] () -- D:\WINDOWS\System32\OpenVideo.dll
[2011/12/05 22:03:52 | 000,054,784 | ---- | C] () -- D:\WINDOWS\System32\OVDecode.dll
[2011/08/12 12:20:14 | 000,015,896 | ---- | C] () -- D:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/06 15:24:18 | 000,036,712 | ---- | C] () -- D:\WINDOWS\System32\CleanMFT32.exe
[2011/04/07 07:20:36 | 000,000,754 | ---- | C] () -- D:\WINDOWS\WORDPAD.INI
[2011/03/26 09:17:17 | 003,161,760 | ---- | C] () -- D:\WINDOWS\System32\WTMKM.exe
[2011/03/26 09:17:17 | 000,180,224 | ---- | C] () -- D:\WINDOWS\System32\ATWTINK.DLL
[2011/03/26 09:17:17 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\InstallService.exe
[2011/03/26 09:17:16 | 000,010,251 | ---- | C] () -- D:\WINDOWS\System32\Vista.ini
[2011/03/26 09:17:16 | 000,009,868 | ---- | C] () -- D:\WINDOWS\System32\XP_2000.ini
[2011/03/26 09:17:16 | 000,000,593 | ---- | C] () -- D:\WINDOWS\System32\MKProfile.ini
[2011/01/20 22:05:02 | 000,179,718 | ---- | C] () -- D:\WINDOWS\hpwins14.dat
[2011/01/20 22:05:01 | 000,001,108 | R--- | C] () -- D:\WINDOWS\hpwmdl14.dat
[2011/01/04 19:11:38 | 000,001,940 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/11/16 14:21:55 | 000,007,378 | ---- | C] () -- D:\WINDOWS\System32\makobbot.dll
[2010/11/16 14:21:55 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\voxigker.dll
[2010/11/16 14:21:55 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\mekires.exe
[2010/11/16 14:21:55 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\delokapp.dll
[2010/11/16 14:21:55 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\conansec.dll
[2010/11/16 14:21:55 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\drivers\binuvmag.sys
[2010/11/16 14:21:55 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\apixont.dll
[2010/08/25 20:30:25 | 000,000,000 | ---- | C] () -- D:\WINDOWS\DVEdit.INI
[2010/08/25 16:14:13 | 000,354,816 | ---- | C] () -- D:\WINDOWS\System32\psisdecd.dll
[2010/08/25 16:13:12 | 000,124,264 | R--- | C] () -- D:\WINDOWS\System32\mp3dec.dll
[2010/08/25 16:13:12 | 000,081,920 | R--- | C] () -- D:\WINDOWS\System32\dsp_trc.dll
[2010/08/25 16:13:12 | 000,010,600 | R--- | C] () -- D:\WINDOWS\System32\IcdSptSvps.dll
[2010/05/14 16:56:06 | 010,898,456 | ---- | C] () -- D:\WINDOWS\System32\LogiDPP.dll
[2010/05/14 16:56:06 | 000,104,472 | ---- | C] () -- D:\WINDOWS\System32\LogiDPPApp.exe
[2010/05/14 16:55:58 | 000,336,408 | ---- | C] () -- D:\WINDOWS\System32\DevManagerCore.dll
[2010/05/14 16:47:00 | 000,028,418 | ---- | C] () -- D:\WINDOWS\System32\lvcoinst.ini
[2010/05/07 17:43:30 | 000,025,824 | ---- | C] () -- D:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2010/02/22 18:34:16 | 000,001,324 | ---- | C] () -- D:\WINDOWS\System32\d3d9caps.dat
[2010/02/12 10:40:36 | 006,344,704 | ---- | C] () -- D:\WINDOWS\System32\botavsec.exe
[2010/02/11 13:41:56 | 006,631,424 | ---- | C] () -- D:\WINDOWS\System32\sndiwchk.exe
[2010/02/11 12:02:20 | 000,017,959 | ---- | C] () -- D:\WINDOWS\System32\dskakdel.dll
[2009/12/13 13:55:44 | 000,217,088 | ---- | C] () -- D:\WINDOWS\System32\qtmlClient.dll
[2009/12/11 14:27:34 | 000,323,006 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Application Data\speech.wav
[2009/11/07 17:47:47 | 000,000,437 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Application Data\spell.cfg
[2009/11/07 17:47:47 | 000,000,145 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Application Data\userdata2.adl
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- D:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- D:\WINDOWS\System32\OGAEXEC.exe
[2009/04/30 04:54:51 | 000,000,035 | ---- | C] () -- D:\WINDOWS\A6W.INI
[2009/04/25 11:34:39 | 000,012,717 | R--- | C] () -- D:\WINDOWS\hpwscr14.dat
[2008/12/31 10:07:05 | 000,388,768 | ---- | C] () -- D:\WINDOWS\System32\atwtusb.exe
[2008/12/31 10:07:05 | 000,102,048 | ---- | C] () -- D:\WINDOWS\RmTablet.exe
[2008/12/31 10:07:05 | 000,061,440 | ---- | C] () -- D:\WINDOWS\System32\tblmouse.exe
[2008/12/31 10:07:05 | 000,023,168 | ---- | C] () -- D:\WINDOWS\System32\drivers\aiptektp.sys
[2008/12/31 10:07:05 | 000,007,323 | ---- | C] () -- D:\WINDOWS\aiptbl.ini
[2008/12/31 10:04:54 | 000,000,046 | ---- | C] () -- D:\WINDOWS\RmFile.ini
[2008/12/31 10:04:36 | 000,053,728 | ---- | C] () -- D:\WINDOWS\rmfile.exe
[2008/12/31 10:04:36 | 000,043,664 | ---- | C] () -- D:\WINDOWS\addrun.exe
[2008/12/26 22:25:20 | 000,000,256 | ---- | C] () -- D:\WINDOWS\System32\pool.bin
[2008/12/02 18:06:11 | 000,000,000 | ---- | C] () -- D:\WINDOWS\flowview.INI
[2008/10/22 19:50:31 | 000,000,237 | ---- | C] () -- D:\WINDOWS\swacnfg.ini
[2008/09/30 11:00:04 | 000,088,536 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Local Settings\Application Data\rx_audio.Cache
[2008/09/02 08:17:02 | 000,000,056 | -H-- | C] () -- D:\WINDOWS\System32\ezsidmv.dat
[2008/08/26 05:37:17 | 000,001,304 | ---- | C] () -- D:\WINDOWS\checkip.dat
[2008/07/29 15:30:48 | 000,480,688 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Local Settings\Application Data\rx_image.Cache
[2008/07/23 17:44:47 | 000,000,233 | ---- | C] () -- D:\WINDOWS\asym.ini
[2008/07/23 17:44:31 | 000,173,612 | ---- | C] () -- D:\Program Files\SNDTEST.WAV
[2008/07/23 17:44:30 | 000,314,924 | ---- | C] () -- D:\Program Files\INSTRUCT.WAV
[2008/07/23 17:44:30 | 000,226,860 | ---- | C] () -- D:\Program Files\ENDTEST.WAV
[2008/07/23 17:44:30 | 000,004,640 | ---- | C] () -- D:\Program Files\NATURE.WAV
[2008/07/23 17:44:25 | 000,009,757 | ---- | C] () -- D:\Program Files\DeIsL1.isu
[2008/07/06 08:53:22 | 001,513,984 | ---- | C] () -- D:\WINDOWS\System32\Mgxrdr32.dll
[2008/07/06 08:53:21 | 000,306,688 | ---- | C] () -- D:\WINDOWS\System32\LFFPX7.DLL
[2008/07/06 08:53:21 | 000,095,232 | ---- | C] () -- D:\WINDOWS\System32\LFKODAK.DLL
[2008/07/06 08:50:48 | 000,082,944 | ---- | C] () -- D:\WINDOWS\System32\Ppiv20.dll
[2008/05/26 20:59:42 | 000,018,904 | ---- | C] () -- D:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | ---- | C] () -- D:\WINDOWS\System32\structuredqueryschema.bin
[2008/03/24 20:53:22 | 000,002,528 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Application Data\$_hpcst$.hpc
[2008/03/22 11:38:31 | 000,000,129 | ---- | C] () -- D:\WINDOWS\MSPublisher_Quark Converter.INI
[2008/03/22 08:29:15 | 000,486,704 | ---- | C] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2008/03/21 15:50:44 | 000,000,510 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2008/03/21 15:42:08 | 000,042,483 | ---- | C] () -- D:\WINDOWS\ICCCODES.DAT
[2008/03/21 15:42:08 | 000,039,095 | ---- | C] () -- D:\WINDOWS\Iccsigs.dat
[2008/03/21 15:42:08 | 000,000,156 | ---- | C] () -- D:\WINDOWS\KPCMS.INI
[2008/03/21 15:41:46 | 000,210,944 | ---- | C] () -- D:\WINDOWS\System32\MSVCRT10.DLL
[2008/03/19 09:53:53 | 000,000,134 | ---- | C] () -- D:\WINDOWS\Readiris.ini
[2008/03/19 09:53:44 | 000,023,040 | ---- | C] () -- D:\WINDOWS\System32\irisco32.dll
[2008/03/13 14:58:31 | 000,002,071 | ---- | C] () -- D:\WINDOWS\panose.bin
[2008/02/19 01:33:34 | 000,446,352 | ---- | C] () -- D:\WINDOWS\System32\OpenQuicktimeLib.dll
[2008/02/03 10:52:13 | 000,000,207 | ---- | C] () -- D:\WINDOWS\cdplayer.ini
[2008/02/03 09:19:07 | 000,180,224 | ---- | C] () -- D:\Documents and Settings\1Gustavo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/31 18:05:01 | 000,000,035 | ---- | C] () -- D:\WINDOWS\webica.ini
[2008/01/28 15:33:46 | 000,001,485 | ---- | C] () -- D:\WINDOWS\MTB30.INI
[2008/01/26 15:06:50 | 000,000,059 | ---- | C] () -- D:\WINDOWS\WININIT.INI
[2008/01/25 17:44:54 | 000,000,165 | ---- | C] () -- D:\WINDOWS\Quicken.ini
[2008/01/25 16:08:08 | 000,210,456 | ---- | C] () -- D:\WINDOWS\System32\IVIresizeW7.dll
[2008/01/25 16:08:08 | 000,206,360 | ---- | C] () -- D:\WINDOWS\System32\IVIresizeA6.dll
[2008/01/25 16:08:08 | 000,198,168 | ---- | C] () -- D:\WINDOWS\System32\IVIresizeP6.dll
[2008/01/25 16:08:08 | 000,198,168 | ---- | C] () -- D:\WINDOWS\System32\IVIresizeM6.dll
[2008/01/25 16:08:08 | 000,194,072 | ---- | C] () -- D:\WINDOWS\System32\IVIresizePX.dll
[2008/01/25 16:08:08 | 000,026,136 | ---- | C] () -- D:\WINDOWS\System32\IVIresize.dll
[2008/01/24 19:21:14 | 000,001,167 | ---- | C] () -- D:\WINDOWS\mozver.dat
[2008/01/21 21:53:53 | 000,000,063 | ---- | C] () -- D:\WINDOWS\sbwin.ini
[2008/01/21 16:10:06 | 000,001,839 | ---- | C] () -- D:\WINDOWS\TT3.INI
[2008/01/21 15:37:54 | 000,002,048 | --S- | C] () -- D:\WINDOWS\bootstat.dat
[2008/01/21 15:26:21 | 000,021,640 | ---- | C] () -- D:\WINDOWS\System32\emptyregdb.dat
[2008/01/21 15:02:25 | 000,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat
[2008/01/21 14:20:57 | 000,000,000 | ---- | C] () -- D:\WINDOWS\ativpsrm.bin
[2008/01/21 07:02:34 | 000,004,346 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- D:\WINDOWS\System32\drivers\StarOpen.sys
[2007/09/27 09:51:02 | 000,020,698 | ---- | C] () -- D:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | ---- | C] () -- D:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | ---- | C] () -- D:\WINDOWS\System32\gthrctr.ini
[2005/12/01 14:05:44 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\px.ini
[2005/11/14 14:40:28 | 000,204,800 | ---- | C] () -- D:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/11/10 11:30:04 | 003,596,288 | R--- | C] () -- D:\WINDOWS\System32\qt-dx331.dll
[2005/11/10 11:30:02 | 000,524,288 | R--- | C] () -- D:\WINDOWS\System32\divxsm.exe
[2005/10/14 16:09:48 | 000,051,304 | ---- | C] () -- D:\WINDOWS\System32\drivers\atnt40k.sys
[2005/07/15 13:35:56 | 000,831,488 | ---- | C] () -- D:\WINDOWS\System32\libeay32.dll
[2005/07/15 13:35:56 | 000,159,744 | ---- | C] () -- D:\WINDOWS\System32\ssleay32.dll
[2005/04/27 22:24:20 | 000,120,128 | ---- | C] () -- D:\WINDOWS\System32\drivers\USBAV191.SYS
[2004/11/30 04:10:00 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\besch.exe
[2004/11/30 04:10:00 | 000,028,672 | ---- | C] () -- D:\WINDOWS\System32\besched.dll
[2004/08/04 07:00:00 | 013,107,200 | ---- | C] () -- D:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 006,627,328 | ---- | C] () -- D:\WINDOWS\System32\verixget.exe
[2004/08/04 07:00:00 | 001,691,648 | ---- | C] () -- D:\WINDOWS\System32\keraglib.dll
[2004/08/04 07:00:00 | 001,683,456 | ---- | C] () -- D:\WINDOWS\System32\selesreg.dll
[2004/08/04 07:00:00 | 000,755,200 | ---- | C] () -- D:\WINDOWS\System32\ir50_32.dll
[2004/08/04 07:00:00 | 000,673,088 | ---- | C] () -- D:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,457,016 | ---- | C] () -- D:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,338,432 | ---- | C] () -- D:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 07:00:00 | 000,272,128 | ---- | C] () -- D:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | ---- | C] () -- D:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,200,192 | ---- | C] () -- D:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 07:00:00 | 000,183,808 | ---- | C] () -- D:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 07:00:00 | 000,156,765 | ---- | C] () -- D:\WINDOWS\System32\mp4obver32.dll
[2004/08/04 07:00:00 | 000,156,765 | ---- | C] () -- D:\WINDOWS\System32\kbdahxml32.dll
[2004/08/04 07:00:00 | 000,153,765 | ---- | C] () -- D:\WINDOWS\System32\vipipkey32.dll
[2004/08/04 07:00:00 | 000,120,320 | ---- | C] () -- D:\WINDOWS\System32\ir41_qc.dll
[2004/08/04 07:00:00 | 000,075,922 | ---- | C] () -- D:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | ---- | C] () -- D:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | ---- | C] () -- D:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | ---- | C] () -- D:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | ---- | C] () -- D:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | ---- | C] () -- D:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | ---- | C] () -- D:\WINDOWS\System32\noise.dat
[2004/04/14 10:40:32 | 000,001,417 | ---- | C] () -- D:\WINDOWS\System32\WD.ini
[2003/12/15 15:42:52 | 000,000,232 | ---- | C] () -- D:\WINDOWS\SwapDrvrSP3.ini
[2003/12/15 15:42:36 | 000,000,233 | ---- | C] () -- D:\WINDOWS\SwapDrvrSP2.ini
[2003/10/02 01:00:00 | 000,208,896 | ---- | C] () -- D:\WINDOWS\System32\lockout.dll
[2003/10/02 01:00:00 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\lockres.dll
[1998/12/08 17:53:58 | 000,116,736 | ---- | C] () -- D:\WINDOWS\System32\PCDLIB32.DLL
[color=#E56717]========== LOP Check ==========[/color]
[2012/02/17 11:31:03 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\30E56105-8D4E-4EFE-B61C-1E55A5433C4F
[2009/10/31 22:27:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Acapela Group
[2012/02/17 11:05:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Acronis
[2011/01/27 17:59:31 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Ahnenblatt
[2010/10/10 11:39:35 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Alien Skin
[2008/07/01 09:11:42 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Blender Foundation
[2009/12/13 18:28:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Digidesign
[2012/01/21 09:18:31 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Dropbox
[2008/02/20 21:47:34 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\GetRight
[2008/02/21 07:44:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\GetRightToGo
[2008/03/10 15:11:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\gtk-2.0
[2009/12/05 17:54:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\hm8platform
[2008/01/31 18:14:31 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\ICAClient
[2008/07/01 11:38:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Inspiration Software
[2012/01/13 15:33:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Juniper Networks
[2011/01/27 18:24:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Lala Music Mover
[2010/07/16 16:45:15 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Leadertech
[2010/07/21 16:50:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\ManyCam
[2009/03/01 12:20:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\MyHeritage
[2009/12/11 22:20:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\NCH Swift Sound
[2008/01/26 15:49:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Nvu
[2010/09/08 06:28:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\OpenOffice.org
[2008/03/20 11:51:12 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Org Professional
[2009/12/13 15:04:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\PACE Anti-Piracy
[2012/02/17 16:09:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\QuickScan
[2011/03/26 13:46:01 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Research In Motion
[2012/01/01 19:26:50 | 000,000,000 | -H-D | M] -- D:\Documents and Settings\1Gustavo\Application Data\RPPrivate
[2012/01/11 16:19:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Samsung
[2009/07/21 17:53:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\SnapKast
[2009/12/13 14:08:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Structure
[2008/12/17 15:19:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\System Tweaker
[2010/12/25 15:20:46 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\TomTom
[2010/02/18 19:00:33 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Ulead Systems
[2008/12/17 15:10:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Uniblue
[2009/07/13 14:01:28 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\webex
[2011/07/30 09:47:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Windows Desktop Search
[2012/01/23 21:08:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Windows Search
[2009/10/31 22:27:45 | 000,000,000 | ---D | M] -- D:\Documents and Settings\1Gustavo\Application Data\Xtranormal
[2012/02/17 11:05:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Acronis
[2008/07/01 09:11:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Blender Foundation
[2011/05/16 12:46:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\FileCure
[2009/11/04 17:39:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Flip Video
[2008/03/08 17:21:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\GetRight
[2009/09/19 11:52:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\GetRightToGo
[2008/01/25 16:08:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\InterVideo
[2012/01/13 15:31:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Juniper Networks
[2009/01/10 17:45:15 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\muvee Technologies
[2009/03/01 12:25:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\MyHeritage
[2011/03/05 16:10:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\NCH Swift Sound
[2008/01/21 23:26:35 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\OLYMPUS
[2009/12/13 15:04:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\PACE Anti-Piracy
[2009/09/24 17:45:24 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\PCSettings
[2012/02/12 06:08:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Retrospect
[2012/01/11 16:11:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Samsung
[2008/01/23 18:07:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Seagate
[2010/02/18 18:59:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\SmartSound Software Inc
[2011/03/26 13:05:29 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Tablet
[2012/02/12 23:05:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/12/25 15:27:23 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\TomTom
[2011/03/26 13:56:07 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems
[2012/01/09 16:13:55 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\Western Digital
[2009/02/01 14:03:24 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/12/17 15:10:19 | 000,000,000 | -H-D | M] -- D:\Documents and Settings\All Users.WINDOWS\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2012/02/12 23:05:00 | 000,000,254 | ---- | M] () -- D:\WINDOWS\Tasks\NUSchedule.job
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 76 bytes -> D:\Documents and Settings\1Gustavo\My Documents\Ulead VideoStudio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> D:\Documents and Settings\1Gustavo\My Documents\SPAN 336:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> D:\Documents and Settings\1Gustavo\My Documents\Retrospect Catalog Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> D:\Documents and Settings\1Gustavo\My Documents\My Webs:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> D:\Documents and Settings\1Gustavo\My Documents\My Videos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> D:\Documents and Settings\1Gustavo\My Documents\My FormTool Forms:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> D:\Documents and Settings\1Gustavo\My Documents\HotPotatoes:Roxio EMC Stream
@Alternate Data Stream - 184 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D3A96964
@Alternate Data Stream - 180 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DA868A70
@Alternate Data Stream - 1512 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft:Q7Abz9DjFukR9Xe1WEG
@Alternate Data Stream - 1511 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft:2KQrSCYcI6F9PW5XV4DPYnQe6Z
@Alternate Data Stream - 1368 bytes -> D:\Documents and Settings\1Gustavo\Local Settings\Application Data\oJGxA50O6HnN:eeSe0gjisR9Hvow9surbHxB
@Alternate Data Stream - 1296 bytes -> D:\Program Files\Common Files\System:0qItaC4876ZsWaJlxnL
@Alternate Data Stream - 1271 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft:TKjTVnyVfcMClvmLo3USazYjrey
@Alternate Data Stream - 1256 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft:vfKkAgpy1Na8PP9mvg
@Alternate Data Stream - 1251 bytes -> D:\Program Files\Common Files\System:xf3uajAjpZ4lDNvp4H7sn912GN
@Alternate Data Stream - 1244 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft:zxc1xI1P4INzcPsDhu
@Alternate Data Stream - 1200 bytes -> D:\Program Files\Outlook Express:RiGIYXjREiW8DiCuqREkxx
@Alternate Data Stream - 102 bytes -> D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D287FACF
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~