OTL.txt part 2:
========== Files/Folders - Created Within 30 Days ==========
[2010/12/16 23:11:20 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\מתן\שולחן העבודה\OTL.exe
[2010/12/16 07:05:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/12/10 19:01:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\מתן\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/12/10 19:01:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\מתן\Application Data\Adobe Mini Bridge CS5
[2010/12/09 14:02:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/12/09 13:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe Media Player
[2010/12/07 05:42:26 | 000,000,000 | ---D | C] -- C:\BrowserPlusPlugins
[2010/12/07 05:42:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\מתן\Local Settings\Application Data\Yahoo!
[2010/11/27 16:00:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\מתן\Application Data\pdf995
[2010/11/27 15:51:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\pdf995
[2010/11/27 15:51:54 | 000,249,856 | ---- | C] (TODO: ) -- C:\WINDOWS\System32\pdfmona.dll
[2010/11/27 15:51:54 | 000,000,000 | ---D | C] -- C:\Program Files\pdf995
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\מתן\My Documents\*.tmp files -> C:\Documents and Settings\מתן\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/16 23:27:00 | 000,000,876 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/16 23:11:15 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\מתן\שולחן העבודה\OTL.exe
[2010/12/16 22:54:00 | 000,000,960 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-764733703-839522115-1004UA.job
[2010/12/16 17:00:02 | 000,000,386 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2010/12/16 15:54:00 | 000,000,908 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-764733703-839522115-1004Core.job
[2010/12/16 14:00:10 | 000,001,042 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/16 12:48:21 | 000,121,344 | ---- | M] () -- C:\Documents and Settings\מתן\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/16 12:42:13 | 000,001,456 | ---- | M] () -- C:\Documents and Settings\מתן\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2010/12/16 09:50:26 | 000,000,368 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2010/12/16 08:27:00 | 000,000,872 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/16 04:31:34 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\All Users\שולחן העבודה\McAfee Total Protection.lnk
[2010/12/16 02:00:00 | 000,000,338 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-MATAN-מתן.job
[2010/12/15 11:29:20 | 000,665,600 | ---- | M] () -- C:\Documents and Settings\מתן\שולחן העבודה\לכתוב לשבוע הבא.doc
[2010/12/14 22:04:15 | 000,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2010/12/14 09:54:53 | 000,002,272 | ---- | M] () -- C:\Documents and Settings\מתן\שולחן העבודה\Google Chrome.lnk
[2010/12/14 09:54:53 | 000,002,250 | ---- | M] () -- C:\Documents and Settings\מתן\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/13 09:42:48 | 000,000,374 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2010/12/13 07:59:17 | 000,432,928 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/12/13 07:59:17 | 000,346,216 | ---- | M] () -- C:\WINDOWS\System32\perfh00d.dat
[2010/12/13 07:59:17 | 000,067,884 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/12/13 07:59:17 | 000,067,868 | ---- | M] () -- C:\WINDOWS\System32\perfc00d.dat
[2010/12/13 07:54:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/12/13 06:35:12 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/12/12 18:29:29 | 000,031,799 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\1000-subscribers.gif
[2010/12/12 02:54:57 | 003,610,232 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/12 02:54:44 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/12/09 14:02:36 | 000,000,854 | ---- | M] () -- C:\Documents and Settings\מתן\שולחן העבודה\Adobe Photoshop CS5.lnk
[2010/12/08 19:20:00 | 000,169,593 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\comic3.png
[2010/12/08 19:16:09 | 000,316,776 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\comic2.png
[2010/12/08 19:15:28 | 000,211,014 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\comic1.png
[2010/12/08 12:56:27 | 000,426,675 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\matan3.png
[2010/12/08 12:55:15 | 000,338,982 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\matan2.png
[2010/12/08 12:51:14 | 000,194,546 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\moral-dilemas-work-file.png
[2010/12/08 12:50:03 | 000,093,872 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\matan1.jpg
[2010/12/08 12:48:58 | 064,861,182 | ---- | M] () -- C:\Documents and Settings\מתן\שולחן העבודה\moral dilemas work file.psd
[2010/12/07 21:19:33 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\מתן\שולחן העבודה\dropbox.db
[2010/12/07 19:55:05 | 000,048,640 | ---- | M] () -- C:\Documents and Settings\מתן\My Documents\דהמרקר.doc
[2010/11/29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/27 16:01:14 | 000,000,059 | ---- | M] () -- C:\WINDOWS\wpd99.drv
[2010/11/27 16:00:06 | 000,000,028 | ---- | M] () -- C:\WINDOWS\pdf995.ini
[2010/11/27 15:51:54 | 000,249,856 | ---- | M] (TODO: ) -- C:\WINDOWS\System32\pdfmona.dll
[2010/11/27 15:51:54 | 000,051,716 | ---- | M] () -- C:\WINDOWS\System32\pdf995mon.dll
[2010/11/26 08:07:20 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\שולחן העבודה\Adobe Reader 9.lnk
[2010/11/23 13:21:15 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\מתן\שולחן העבודה\cv-matan.doc
[2010/11/19 18:23:44 | 007,574,476 | ---- | M] () -- C:\Documents and Settings\מתן\שולחן העבודה\מיקי קם-שיר אהובת הסוכן.mp3
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\מתן\My Documents\*.tmp files -> C:\Documents and Settings\מתן\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/12 18:29:29 | 000,031,799 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\1000-subscribers.gif
[2010/12/09 15:50:00 | 000,001,456 | ---- | C] () -- C:\Documents and Settings\מתן\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2010/12/09 14:17:19 | 000,000,338 | ---- | C] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-MATAN-מתן.job
[2010/12/09 14:02:36 | 000,000,854 | ---- | C] () -- C:\Documents and Settings\מתן\שולחן העבודה\Adobe Photoshop CS5.lnk
[2010/12/08 19:19:57 | 000,169,593 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\comic3.png
[2010/12/08 19:16:07 | 000,316,776 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\comic2.png
[2010/12/08 19:15:27 | 000,211,014 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\comic1.png
[2010/12/08 12:56:26 | 000,426,675 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\matan3.png
[2010/12/08 12:55:15 | 000,338,982 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\matan2.png
[2010/12/08 12:51:10 | 000,194,546 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\moral-dilemas-work-file.png
[2010/12/08 12:49:58 | 000,093,872 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\matan1.jpg
[2010/12/08 12:48:53 | 064,861,182 | ---- | C] () -- C:\Documents and Settings\מתן\שולחן העבודה\moral dilemas work file.psd
[2010/12/07 21:19:33 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\מתן\שולחן העבודה\dropbox.db
[2010/12/07 13:41:53 | 000,048,640 | ---- | C] () -- C:\Documents and Settings\מתן\My Documents\דהמרקר.doc
[2010/11/27 16:00:06 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2010/11/27 15:51:55 | 000,000,059 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2010/11/27 15:51:54 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2010/11/23 13:21:14 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\מתן\שולחן העבודה\cv-matan.doc
[2010/11/19 18:07:32 | 007,574,476 | ---- | C] () -- C:\Documents and Settings\מתן\שולחן העבודה\מיקי קם-שיר אהובת הסוכן.mp3
[2010/09/17 06:39:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DbgOut.INI
[2010/08/17 11:14:45 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\pdfppt2.dll
[2010/08/17 11:13:24 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfmonnt.dll
[2010/08/17 11:13:18 | 000,000,164 | ---- | C] () -- C:\WINDOWS\System32\psconv.ini
[2010/06/26 07:45:09 | 000,051,370 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/02/05 18:09:37 | 000,000,119 | ---- | C] () -- C:\WINDOWS\PhEdit.INI
[2010/02/05 18:02:42 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009/11/15 16:31:14 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2009/10/17 21:27:01 | 000,272,739 | ---- | C] () -- C:\Documents and Settings\מתן\Application Data\mdbu.bin
[2009/09/27 23:14:11 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/08/20 19:14:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX.INI
[2009/08/20 19:08:20 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdx.DAT
[2009/08/20 19:08:20 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\מתן\Application Data\Flange Saw
[2009/08/20 19:07:19 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Fruit
[2009/08/20 19:07:19 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\מתן\Application Data\Font Book
[2009/08/20 19:07:19 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLeq.DAT
[2009/08/20 19:06:59 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\מתן\Application Data\Organic
[2009/08/20 19:06:55 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLbx.DAT
[2009/08/20 18:48:26 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Font Book
[2009/08/20 18:48:26 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\מתן\Application Data\Flanger
[2009/08/20 18:48:26 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
[2009/08/20 18:47:14 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Folder Actions
[2009/08/20 18:47:14 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\מתן\Application Data\Flags
[2009/08/20 18:47:14 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2009/08/20 14:55:07 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/08/20 12:22:27 | 000,000,385 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/08/20 12:15:15 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/08/20 09:09:23 | 000,121,344 | ---- | C] () -- C:\Documents and Settings\מתן\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/20 01:52:57 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/08/19 23:56:19 | 000,005,651 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/02/19 08:33:34 | 000,446,352 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2008/02/05 13:28:20 | 000,000,051 | ---- | C] () -- C:\Documents and Settings\מתן\Local Settings\Application Data\setup.txt
[2007/11/07 01:00:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/03/06 16:50:30 | 001,669,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
========== Custom Scans ==========
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 03:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 03:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010/07/28 14:17:39 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2009/08/20 01:49:50 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/08/20 01:49:50 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/08/20 01:49:50 | 000,454,656 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2006/03/02 14:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2006/03/02 14:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2006/03/02 14:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2006/03/02 14:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2006/03/02 14:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2006/03/02 14:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2006/03/02 14:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2006/03/02 14:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2006/03/02 14:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2006/03/02 14:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2006/03/02 14:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2006/03/02 14:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2006/03/02 14:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2006/03/02 14:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2006/03/02 14:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/09/25 21:07:08 | 000,045,056 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\PhDi2.sys
[2008/04/13 20:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2010/09/01 09:57:21 | 001,852,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
[2008/04/14 04:17:17 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/14 04:17:17 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/14 04:17:17 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/14 04:17:17 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/14 04:17:17 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/14 04:17:17 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/14 04:17:17 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/14 04:17:17 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/14 04:17:17 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/14 04:17:17 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/14 04:17:17 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/14 04:17:17 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/14 04:17:18 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/14 04:17:29 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/14 04:17:30 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %SYSTEMDRIVE%\*.* >
[2009/10/29 05:38:15 | 000,000,050 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/10/13 09:50:29 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/08/04 16:06:51 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/06/12 10:24:47 | 000,026,138 | ---- | M] () -- C:\ComboFix.txt
[2009/08/20 00:02:24 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/08/20 00:02:24 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/06/11 14:24:56 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2009/08/20 00:02:24 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006/03/02 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/08/20 08:52:40 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/12/13 07:54:35 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2009/08/20 00:14:36 | 000,000,206 | ---- | M] () -- C:\realtek.log
[2009/08/20 00:14:36 | 000,000,581 | ---- | M] () -- C:\RHDSetup.log
[2009/09/28 16:48:50 | 001,971,662 | ---- | M] () -- C:\TravelersChoiceAwards2009.pdf
[2010/02/05 18:23:57 | 000,000,026 | ---- | M] () -- C:\UpdaterforApp.ini
[2010/02/20 09:36:40 | 000,000,002 | ---- | M] () -- C:\vdir
< %PROGRAMFILES%\*. >
[2009/10/29 05:48:27 | 000,000,000 | ---D | M] -- C:\Program Files\3ivx
[2010/12/09 14:01:44 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2010/12/09 13:59:34 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe Media Player
[2010/05/06 00:00:42 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/02/05 18:03:49 | 000,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2010/01/02 09:14:59 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk
[2010/10/09 18:35:56 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2009/08/23 21:19:50 | 000,000,000 | ---D | M] -- C:\Program Files\Canon
[2010/08/28 07:15:53 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2010/05/23 10:33:20 | 000,000,000 | ---D | M] -- C:\Program Files\Citrix
[2010/12/09 12:55:06 | 000,000,000 | R--D | M] -- C:\Program Files\Common Files
[2009/08/20 00:00:03 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010/07/28 14:17:40 | 000,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Lite
[2009/08/20 12:17:41 | 000,000,000 | ---D | M] -- C:\Program Files\DAEMON Tools Toolbar
[2010/03/26 12:24:34 | 000,000,000 | ---D | M] -- C:\Program Files\DIFX
[2009/08/20 15:00:42 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/11/06 19:03:17 | 000,000,000 | ---D | M] -- C:\Program Files\Documents To Go Desktop for Android
[2010/03/28 13:01:28 | 000,000,000 | ---D | M] -- C:\Program Files\FeedDemon
[2009/08/20 09:35:00 | 000,000,000 | ---D | M] -- C:\Program Files\FileZilla FTP Client
[2010/09/18 16:25:22 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2010/09/06 13:06:06 | 000,000,000 | ---D | M] -- C:\Program Files\GRETECH
[2009/08/20 00:28:17 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2009/08/19 23:59:20 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2010/10/23 12:35:12 | 000,000,000 | ---D | M] -- C:\Program Files\HTC
[2010/07/28 14:28:10 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/08/20 00:17:45 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2010/10/14 03:05:55 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/08/20 06:04:31 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/10/12 19:59:42 | 000,000,000 | ---D | M] -- C:\Program Files\Jawbone
[2010/07/18 13:52:27 | 000,000,000 | ---D | M] -- C:\Program Files\K-Lite Codec Pack
[2010/06/26 07:44:35 | 000,000,000 | ---D | M] -- C:\Program Files\Labtec
[2010/12/15 10:17:02 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/11/02 23:40:23 | 000,000,000 | ---D | M] -- C:\Program Files\MathType
[2010/04/23 19:44:54 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee
[2010/04/26 12:16:35 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee.com
[2009/08/20 08:59:29 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/08/20 11:01:09 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2009/08/20 12:22:06 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2009/08/20 00:02:36 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/09/10 18:06:05 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2010/01/27 14:54:32 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SDKs
[2010/01/27 14:58:24 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server
[2010/09/05 19:31:27 | 000,000,000 | ---D | M] -- C:\Program Files\mIRC
[2010/08/13 02:01:16 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/12/11 09:57:25 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010/02/13 13:26:39 | 000,000,000 | ---D | M] -- C:\Program Files\Mr Tracker Google SMS Tracking
[2009/08/24 10:34:03 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2009/09/10 18:05:58 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2009/08/19 23:59:33 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2010/10/23 12:34:04 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2010/04/17 08:21:18 | 000,000,000 | ---D | M] -- C:\Program Files\Multi-Browser Viewer
[2009/10/29 05:38:08 | 000,000,000 | ---D | M] -- C:\Program Files\muvee Technologies
[2009/08/19 23:45:19 | 000,000,000 | ---D | M] -- C:\Program Files\Nero
[2009/08/20 08:55:03 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010/11/06 08:56:54 | 000,000,000 | ---D | M] -- C:\Program Files\Nikon
[2010/07/10 07:27:46 | 000,000,000 | ---D | M] -- C:\Program Files\Nokia
[2010/04/13 23:15:46 | 000,000,000 | ---D | M] -- C:\Program Files\Notepad++
[2010/07/30 10:28:46 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2009/08/20 00:01:37 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/05/12 02:00:38 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/02/05 18:01:59 | 000,000,000 | ---D | M] -- C:\Program Files\Panasonic
[2010/07/10 07:28:12 | 000,000,000 | ---D | M] -- C:\Program Files\PC Connectivity Solution
[2010/08/17 11:13:24 | 000,000,000 | ---D | M] -- C:\Program Files\PDF-Convert
[2010/11/27 15:53:03 | 000,000,000 | ---D | M] -- C:\Program Files\pdf995
[2009/10/30 11:58:35 | 000,000,000 | ---D | M] -- C:\Program Files\PellesC
[2010/09/16 09:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Pidgin
[2010/04/04 10:41:27 | 000,000,000 | ---D | M] -- C:\Program Files\Poedit
[2010/10/09 18:35:35 | 000,000,000 | ---D | M] -- C:\Program Files\PrinterShare
[2010/08/17 11:13:16 | 000,000,000 | ---D | M] -- C:\Program Files\psconvert
[2010/03/06 17:42:52 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/08/20 00:13:44 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek
[2009/08/24 10:33:58 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/02/27 19:16:42 | 000,000,000 | ---D | M] -- C:\Program Files\ReflexiveArcade
[2010/06/24 05:20:06 | 000,000,000 | ---D | M] -- C:\Program Files\RegCure
[2009/08/30 15:53:39 | 000,000,000 | ---D | M] -- C:\Program Files\Runtime Software
[2009/11/20 12:48:38 | 000,000,000 | ---D | M] -- C:\Program Files\Samsung
[2009/10/05 17:02:25 | 000,000,000 | R--D | M] -- C:\Program Files\Skype
[2010/08/17 11:25:51 | 000,000,000 | ---D | M] -- C:\Program Files\Softland
[2010/10/02 08:42:52 | 000,000,000 | ---D | M] -- C:\Program Files\Spirent Communications
[2010/10/26 19:43:45 | 000,000,000 | ---D | M] -- C:\Program Files\Spyware Doctor
[2010/12/04 11:07:33 | 000,000,000 | ---D | M] -- C:\Program Files\StarCraft II
[2010/01/28 19:10:59 | 000,000,000 | ---D | M] -- C:\Program Files\Trackstick Manager
[2010/01/06 20:14:15 | 000,000,000 | ---D | M] -- C:\Program Files\TrendMicro
[2009/08/20 00:09:17 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/08/23 22:56:37 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2009/11/20 12:45:16 | 000,000,000 | ---D | M] -- C:\Program Files\VS Revo Group
[2009/08/20 11:01:04 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2009/08/20 11:00:53 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2009/10/14 20:53:32 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/10/15 03:06:37 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/08/20 08:54:59 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/08/20 00:01:40 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2009/08/20 10:11:26 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2010/05/27 18:13:14 | 000,000,000 | ---D | M] -- C:\Program Files\Xenocode
[2009/08/20 00:02:36 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2010/06/25 10:35:53 | 000,000,000 | ---D | M] -- C:\Program Files\Zooma_Heb
[2010/03/03 18:40:58 | 000,000,000 | ---D | M] -- C:\Program Files\Zuma Deluxe
< %appdata%\*.* >
[2009/08/20 01:52:22 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\מתן\Application Data\desktop.ini
[2009/08/20 18:47:14 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\מתן\Application Data\Flags
[2009/08/29 06:37:08 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\מתן\Application Data\Flange Saw
[2009/08/20 18:48:26 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\מתן\Application Data\Flanger
[2009/08/20 19:07:19 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\מתן\Application Data\Font Book
[2010/11/12 17:55:19 | 000,272,739 | ---- | M] () -- C:\Documents and Settings\מתן\Application Data\mdbu.bin
[2010/04/04 07:02:15 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\מתן\Application Data\Organic
< MD5 for: AGP440.SYS >
[2006/03/02 14:00:00 | 018,773,911 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2006/03/02 14:00:00 | 018,773,911 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2006/03/02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\ATAPI.SYS
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2006/03/02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >
[2006/03/02 14:00:00 | 018,773,911 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2006/03/02 14:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\DISK.SYS
[2006/03/02 14:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 20:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 20:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >
[2006/03/02 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=2DCCBF3AF0DE3AB8C8889BD577FFE4E1 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008/04/14 04:17:19 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=8BCD6F104BED7F1F1513584E9F56B69E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 04:17:19 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=8BCD6F104BED7F1F1513584E9F56B69E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 04:17:19 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=8BCD6F104BED7F1F1513584E9F56B69E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2006/03/02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=7548247ECB9BBF590430B54E29448B9D -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\NETLOGON.DLL
[2006/03/02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=7548247ECB9BBF590430B54E29448B9D -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008/04/14 04:17:25 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=89AC5ED8D0D035A9F9F2B10C51A76706 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 04:17:25 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=89AC5ED8D0D035A9F9F2B10C51A76706 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 04:17:25 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=89AC5ED8D0D035A9F9F2B10C51A76706 -- C:\WINDOWS\system32\netlogon.dll
[2009/02/06 20:46:48 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=DB06BAF4E42D8EE49DD6D0C6E0141B0D -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006/03/02 14:00:00 | 000,182,784 | ---- | M] (Microsoft Corporation) MD5=B1A3BACF38964D06DE7BD42762DB8420 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\SCECLI.DLL
[2006/03/02 14:00:00 | 000,182,784 | ---- | M] (Microsoft Corporation) MD5=B1A3BACF38964D06DE7BD42762DB8420 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 04:17:28 | 000,183,808 | ---- | M] (Microsoft Corporation) MD5=E48B4FA40B6952B768A3AE0E9AAC5268 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 04:17:28 | 000,183,808 | ---- | M] (Microsoft Corporation) MD5=E48B4FA40B6952B768A3AE0E9AAC5268 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 04:17:28 | 000,183,808 | ---- | M] (Microsoft Corporation) MD5=E48B4FA40B6952B768A3AE0E9AAC5268 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2006/03/02 14:00:00 | 018,773,911 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2009/08/20 08:49:25 | 023,886,227 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2006/03/02 14:00:00 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\pebuilder3110a\BartPE\I386\SYSTEM32\DRIVERS\USBSTOR.SYS
[2006/03/02 14:00:00 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 20:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 20:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 01:04:45
========== Alternate Data Streams ==========
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >