and the second half...........
========== Files/Folders - Created Within 30 Days ==========
[2011/05/05 00:54:08 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
[2011/05/04 23:23:04 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/05/04 23:05:37 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/05/04 21:59:57 | 000,000,000 | ---D | C] -- C:\Program Files\Market Samurai
[2011/05/04 21:57:09 | 000,000,000 | ---D | C] -- C:\Users\Peter\.ranktracker
[2011/05/04 19:58:58 | 000,000,000 | ---D | C] -- C:\Users\Peter\.seospyglass
[2011/05/04 19:27:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flying Logic Pro
[2011/05/04 19:24:12 | 000,000,000 | ---D | C] -- C:\Program Files\Flying Logic Pro
[2011/05/04 15:51:30 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Skype and Pamela
[2011/05/04 11:01:50 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\E342D1DAEC6FE24738CB292987A90C74
[2011/05/03 11:04:56 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Radialpoint
[2011/05/03 10:35:57 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\temp
[2011/05/03 10:17:37 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/05/03 09:51:52 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/05/03 09:51:52 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/05/03 09:51:52 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/05/02 23:17:18 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/02 23:16:59 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/02 23:01:12 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/05/02 22:53:29 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/04/28 16:26:26 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Avira
[2011/04/28 16:21:42 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/04/28 16:21:42 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/04/28 16:21:42 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011/04/28 16:21:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/04/28 16:21:41 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/04/25 19:28:21 | 000,000,000 | -HSD | C] -- C:\DrWeb Quarantine
[2011/04/25 18:54:44 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/25 18:26:54 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\GetRightToGo
[2011/04/25 15:49:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Doctor Web
[2011/04/25 11:18:37 | 000,000,000 | ---D | C] -- C:\Program Files\Exterminate It!
[2011/04/24 15:40:43 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Registry Mechanic
[2011/04/22 08:26:38 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\DDMSettings
[2011/04/21 00:04:16 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Allscoop RSS Submit Pro
[2011/04/21 00:04:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allscoop RSS Submit Pro
[2011/04/21 00:04:15 | 000,434,688 | ---- | C] (Virtualzone.de) -- C:\Windows\System32\ss2uinst.exe
[2011/04/21 00:04:15 | 000,000,000 | ---D | C] -- C:\Program Files\Allscoop RSS Submit Pro
[2011/04/16 12:06:30 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\PackageAware
[2011/04/13 22:09:37 | 000,000,000 | ---D | C] -- C:\ProgramData\RoboTask
[2011/04/13 22:00:07 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\RoboTask
[2011/04/13 22:00:07 | 000,000,000 | ---D | C] -- C:\Program Files\RoboTask
[2011/04/11 01:11:29 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Perfect memory
[2011/04/11 01:11:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect memory
[2011/04/11 01:11:17 | 000,000,000 | ---D | C] -- C:\Program Files\Memorisation master
[2011/04/07 09:05:20 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\SENukeX
[2011/04/07 09:05:08 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SENukeX
[2011/04/05 15:34:00 | 000,000,000 | ---D | C] -- C:\Windows\Panther
========== Files - Modified Within 30 Days ==========
[2011/05/05 00:54:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
[2011/05/05 00:39:07 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/04 23:38:02 | 000,013,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/04 23:38:02 | 000,013,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/04 23:29:42 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/04 23:29:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/04 23:17:39 | 001,075,200 | ---- | M] () -- C:\Users\Peter\Documents\Sales training.msam
[2011/05/04 23:09:43 | 000,002,012 | -H-- | M] () -- C:\Users\Peter\Documents\Default.rdp
[2011/05/04 23:05:27 | 004,337,362 | R--- | M] () -- C:\Users\Peter\Desktop\ComboFix.exe
[2011/05/04 21:57:24 | 000,409,668 | ---- | M] () -- C:\Users\Peter\.ranktracker.properties
[2011/05/04 20:05:59 | 000,001,024 | ---- | M] () -- C:\Users\Peter\Desktop\Keyword Elite 2.0.lnk
[2011/05/04 19:59:17 | 000,462,128 | ---- | M] () -- C:\Users\Peter\.spyglass.properties
[2011/05/04 19:25:38 | 000,002,220 | ---- | M] () -- C:\Users\Peter\Desktop\SEO SpyGlass.lnk
[2011/05/04 16:10:17 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/05/04 16:08:58 | 179,843,104 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.dat
[2011/05/04 16:08:58 | 002,110,700 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.idx
[2011/05/03 19:45:54 | 000,002,080 | ---- | M] () -- C:\Users\Public\Desktop\Micro Niche Finder 5.0.lnk
[2011/05/03 17:30:13 | 000,002,033 | ---- | M] () -- C:\Users\Peter\Desktop\SENukeX.lnk
[2011/05/03 16:56:44 | 006,254,592 | ---- | M] () -- C:\Users\Peter\s-1-5-21-1867113323-2075334900-1738569641-1000.rrr
[2011/05/03 15:29:37 | 000,792,666 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/05/03 15:29:37 | 000,179,292 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/05/03 09:19:11 | 000,001,376 | ---- | M] () -- C:\Users\Peter\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/02 22:37:26 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2011/05/02 22:29:11 | 000,002,503 | ---- | M] () -- C:\Users\Peter\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/02 21:02:17 | 000,034,560 | ---- | M] () -- C:\Windows\System32\drivers\Normandy.sys
[2011/05/02 20:32:59 | 000,000,000 | ---- | M] () -- C:\Users\Peter\AppData\Local\{ED4928FE-0BED-4C1A-A89E-2F88249DF065}
[2011/05/02 20:29:03 | 000,000,000 | ---- | M] () -- C:\Users\Peter\AppData\Local\{60E0E245-BE22-408C-B7BE-2AF01E6DD026}
[2011/05/02 20:24:58 | 000,000,000 | ---- | M] () -- C:\Users\Peter\AppData\Local\{35E2D860-2A7C-40F3-97BE-EE2D8E1921C6}
[2011/04/28 18:41:30 | 000,001,036 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/26 19:15:38 | 000,003,408 | ---- | M] () -- C:\bootsqm.dat
[2011/04/25 23:49:38 | 000,000,000 | ---- | M] () -- C:\Users\Peter\AppData\Local\{1EB2C635-5AB2-455A-8B12-274CFF65F8DC}
[2011/04/25 23:43:52 | 000,000,000 | ---- | M] () -- C:\Users\Peter\AppData\Local\{3D86D2B9-1D41-4F49-AA09-AE88BE6DA26F}
[2011/04/25 19:45:26 | 000,024,448 | ---- | M] () -- C:\Windows\System32\drivers\rkhdrv40.sys
[2011/04/21 00:04:16 | 000,001,965 | ---- | M] () -- C:\Users\Peter\Desktop\RSS Announcer.lnk
[2011/04/21 00:04:09 | 000,434,688 | ---- | M] (Virtualzone.de) -- C:\Windows\System32\ss2uinst.exe
[2011/04/17 13:16:36 | 000,440,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/04/16 18:49:54 | 000,000,976 | ---- | M] () -- C:\Users\Peter\Application Data\Microsoft\Internet Explorer\Quick Launch\Traffic Travis.lnk
[2011/04/11 19:29:29 | 001,877,005 | ---- | M] () -- C:\Users\Peter\Documents\
www.salesdnaltd.com.stk
[2011/04/11 01:11:52 | 000,131,584 | ---- | M] () -- C:\Windows\System32\SpoonUninstall.exe
[2011/04/11 01:11:52 | 000,009,905 | ---- | M] () -- C:\Windows\System32\SpoonUninstall-MMaster.dat
[2011/04/11 01:11:10 | 000,058,554 | ---- | M] () -- C:\Windows\System32\SpoonUninstall-MMaster.bmp
[2011/04/11 00:51:18 | 000,095,232 | ---- | M] () -- C:\Users\Peter\Documents\experiential training.msam
[2011/04/06 17:51:56 | 000,000,236 | -H-- | M] () -- C:\Users\Peter\AppData\Roaming\ee6fe4d84748049fa23c8b8638a22cacf0cffd15
[2011/04/06 17:51:56 | 000,000,236 | -H-- | M] () -- C:\ProgramData\ee6fe4d84748049fa23c8b8638a22cacf0cffd15
[2011/04/05 09:15:18 | 000,002,649 | ---- | M] () -- C:\Users\Peter\Desktop\Magic Article Rewriter.lnk
========== Files Created - No Company Name ==========
[2011/05/04 22:01:49 | 000,000,878 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Market Samurai.lnk
[2011/05/04 20:04:18 | 000,001,024 | ---- | C] () -- C:\Users\Peter\Desktop\Keyword Elite 2.0.lnk
[2011/05/04 19:25:38 | 000,002,220 | ---- | C] () -- C:\Users\Peter\Desktop\SEO SpyGlass.lnk
[2011/05/04 15:24:51 | 004,337,362 | R--- | C] () -- C:\Users\Peter\Desktop\ComboFix.exe
[2011/05/03 16:56:38 | 006,254,592 | ---- | C] () -- C:\Users\Peter\s-1-5-21-1867113323-2075334900-1738569641-1000.rrr
[2011/05/03 09:51:52 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/05/03 09:51:52 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/05/03 09:51:52 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/05/03 09:51:52 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/05/03 09:51:52 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/05/02 22:37:26 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011/05/02 22:29:11 | 000,002,503 | ---- | C] () -- C:\Users\Peter\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/02 22:29:11 | 000,002,491 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2011/05/02 21:02:14 | 000,034,560 | ---- | C] () -- C:\Windows\System32\drivers\Normandy.sys
[2011/05/02 20:32:59 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{ED4928FE-0BED-4C1A-A89E-2F88249DF065}
[2011/05/02 20:29:03 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{60E0E245-BE22-408C-B7BE-2AF01E6DD026}
[2011/05/02 20:24:58 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{35E2D860-2A7C-40F3-97BE-EE2D8E1921C6}
[2011/04/28 18:41:30 | 000,001,036 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/26 19:15:38 | 000,003,408 | ---- | C] () -- C:\bootsqm.dat
[2011/04/25 23:49:22 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{1EB2C635-5AB2-455A-8B12-274CFF65F8DC}
[2011/04/25 23:43:36 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{3D86D2B9-1D41-4F49-AA09-AE88BE6DA26F}
[2011/04/25 19:24:28 | 179,843,104 | -HS- | C] () -- C:\Windows\System32\drivers\fidbox.dat
[2011/04/25 19:24:28 | 002,110,700 | -HS- | C] () -- C:\Windows\System32\drivers\fidbox.idx
[2011/04/25 11:21:59 | 000,024,448 | ---- | C] () -- C:\Windows\System32\drivers\rkhdrv40.sys
[2011/04/21 00:04:16 | 000,001,965 | ---- | C] () -- C:\Users\Peter\Desktop\RSS Announcer.lnk
[2011/04/11 01:11:52 | 000,131,584 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2011/04/11 01:11:52 | 000,058,554 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-MMaster.bmp
[2011/04/11 01:11:52 | 000,009,905 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-MMaster.dat
[2011/04/10 23:29:08 | 000,095,232 | ---- | C] () -- C:\Users\Peter\Documents\experiential training.msam
[2011/04/10 23:24:17 | 000,000,878 | ---- | C] () -- C:\Users\Peter\Desktop\Market Samurai.lnk
[2011/04/10 23:01:36 | 000,002,080 | ---- | C] () -- C:\Users\Public\Desktop\Micro Niche Finder 5.0.lnk
[2011/04/07 09:07:35 | 000,002,033 | ---- | C] () -- C:\Users\Peter\Desktop\SENukeX.lnk
[2011/04/05 09:15:18 | 000,002,649 | ---- | C] () -- C:\Users\Peter\Desktop\Magic Article Rewriter.lnk
[2011/03/23 14:44:28 | 000,000,056 | ---- | C] () -- C:\Windows\LiveUpdate.INI
[2010/09/26 11:55:58 | 000,016,968 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2010/09/25 12:49:31 | 000,000,265 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/09/04 16:35:12 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2010/09/03 22:31:20 | 000,000,236 | -H-- | C] () -- C:\Users\Peter\AppData\Roaming\ee6fe4d84748049fa23c8b8638a22cacf0cffd15
[2010/09/03 22:31:20 | 000,000,236 | -H-- | C] () -- C:\ProgramData\ee6fe4d84748049fa23c8b8638a22cacf0cffd15
[2010/09/03 15:25:54 | 000,021,316 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2010/09/01 17:21:22 | 000,055,808 | ---- | C] () -- C:\Windows\System32\zlib1.dll
[2010/09/01 17:16:46 | 000,333,288 | ---- | C] () -- C:\Windows\System32\sqlite3.dll
[2010/08/27 19:06:06 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/08/16 01:08:37 | 000,000,005 | ---- | C] () -- C:\Windows\Windows9XP.dat
[2010/08/16 01:05:09 | 000,028,672 | ---- | C] () -- C:\Windows\System32\SRISLogger.dll
[2010/08/16 01:05:08 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ToolsDll_v3.dll
[2010/08/16 01:05:08 | 000,044,544 | ---- | C] () -- C:\Windows\System32\Gprcore.dll
[2010/08/16 01:05:07 | 000,081,920 | ---- | C] () -- C:\Windows\System32\ExProwl.dll
[2010/08/16 01:05:06 | 000,192,512 | ---- | C] () -- C:\Windows\System32\DomainEMail.dll
[2010/04/06 18:53:17 | 000,000,232 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2010/01/12 15:27:47 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
[2009/11/06 22:34:10 | 000,000,119 | ---- | C] () -- C:\Windows\System32\messages.dat
[2009/11/06 20:23:39 | 000,000,000 | ---- | C] () -- C:\Windows\System32\twitter_profiles.dat
[2009/11/06 19:28:53 | 000,001,000 | ---- | C] () -- C:\Windows\System32\tw_auto.dat
[2009/09/23 19:16:08 | 002,050,952 | ---- | C] () -- C:\Windows\System32\igkrng400.bin
[2009/09/17 19:36:37 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2009/09/15 10:20:58 | 000,000,463 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2009/09/15 10:20:58 | 000,000,030 | ---- | C] () -- C:\Windows\System32\brss01a.ini
[2009/09/15 10:20:58 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2009/09/15 10:19:05 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
[2009/09/15 10:13:04 | 000,000,226 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2009/09/15 10:13:04 | 000,000,094 | ---- | C] () -- C:\Windows\brpcfx.ini
[2009/09/15 10:13:04 | 000,000,050 | ---- | C] () -- C:\Windows\System32\BRIDF04A.dat
[2009/09/15 10:10:57 | 000,000,066 | ---- | C] () -- C:\Windows\Brfaxrx.ini
[2009/09/15 10:10:56 | 000,106,496 | ---- | C] () -- C:\Windows\System32\BrMuSNMP.dll
[2009/09/11 17:49:44 | 000,000,040 | ---- | C] () -- C:\Windows\submitequalizer.ini
[2009/09/07 18:44:23 | 000,000,635 | ---- | C] () -- C:\Windows\System32\OEMINFO.INI
[2009/09/07 18:32:40 | 000,000,000 | ---- | C] () -- C:\Windows\ToDisc.INI
[2009/09/04 22:51:37 | 000,000,073 | ---- | C] () -- C:\Windows\pressequalizer.ini
[2009/09/04 17:29:16 | 000,213,768 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2009/08/25 18:12:44 | 000,004,096 | ---- | C] () -- C:\Windows\System32\tuelz.dat
[2009/08/14 09:20:51 | 002,139,136 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\TweetAdder
[2009/08/09 18:10:17 | 000,003,120 | ---- | C] () -- C:\Windows\sptm.dll
[2009/08/09 08:51:57 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/08/06 21:28:06 | 000,131,072 | ---- | C] () -- C:\Windows\System32\EnumDevLib.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 000,440,104 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,792,666 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,179,292 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/01/13 17:01:26 | 000,015,840 | ---- | C] () -- C:\Windows\System32\Machnm1.exe
[2009/01/13 17:01:26 | 000,002,304 | ---- | C] () -- C:\Windows\System32\Machnm32.sys
[2008/03/19 14:11:08 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/03/18 14:23:10 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2008/03/18 14:23:10 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2008/03/18 14:23:10 | 000,009,484 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2008/03/18 14:23:10 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2008/03/18 14:18:01 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/03/18 13:51:25 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2008/02/19 07:33:34 | 000,446,352 | ---- | C] () -- C:\Windows\System32\OpenQuicktimeLib.dll
[2007/12/21 17:46:32 | 000,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2005/07/22 22:30:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
[2004/02/28 05:30:12 | 000,049,152 | ---- | C] () -- C:\Windows\System32\TrustSupport.dll
[2002/09/10 17:50:22 | 000,036,864 | ---- | C] () -- C:\Windows\System32\DiskID32.dll
========== LOP Check ==========
[2010/09/03 15:14:35 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Affilorama
[2010/09/03 15:16:43 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Bookmarkwiz
[2010/09/03 15:16:43 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/03/19 16:57:33 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\CommissionBlueprint.KeywordBlueprint2.E611A7DFA7A14643DD636F3114ECD771F85A61E0.1
[2011/05/04 23:30:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Dropbox
[2011/05/04 11:05:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\E342D1DAEC6FE24738CB292987A90C74
[2011/02/05 16:38:50 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\EasyLeadFinderv2
[2011/03/23 14:44:17 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\eGrabber
[2011/05/04 15:39:12 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\FileZilla
[2011/01/10 16:45:38 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Flickr
[2011/04/25 23:09:33 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GetRightToGo
[2010/11/24 21:20:31 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GoodSync
[2011/03/23 11:12:56 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GPScraper 2011
[2011/03/23 11:27:11 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GPScraper.com
[2010/09/05 22:13:19 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GrabPro
[2010/11/15 12:46:18 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Green Parrots Software
[2010/09/03 15:16:44 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\gtk-2.0
[2010/09/03 15:16:44 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Helios
[2010/09/03 15:16:45 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Hide IP NG
[2011/05/04 21:49:55 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\IBP
[2010/09/03 15:16:52 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\iSpring Solutions
[2010/11/08 22:58:16 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\LinkBounder
[2010/09/03 15:16:52 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\LinkedIn
[2010/09/03 15:16:53 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\MAPILab Ltd
[2010/09/03 15:16:53 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/05/02 23:36:21 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Mipony
[2010/09/03 15:17:15 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Moyea
[2010/12/10 20:22:18 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\NCH Swift Sound
[2010/09/18 13:13:48 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\northworks.biz
[2010/09/12 22:05:22 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Nuance
[2010/09/03 15:17:23 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Pamela
[2010/09/03 15:17:23 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\pinpoint Marketing tool
[2010/09/05 22:13:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\ProgSense
[2011/05/03 11:04:56 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Radialpoint
[2011/05/02 23:58:35 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Registry Mechanic
[2010/09/18 12:15:40 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\ScrapePro.Designer
[2011/03/28 19:25:05 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Sick Marketing
[2010/11/15 13:53:43 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Snoworange
[2010/09/03 15:17:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Software Defender
[2010/09/03 15:17:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Sony
[2011/02/01 01:35:22 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\SpeedPPC4
[2010/09/03 15:17:32 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\SQLite Administrator
[2011/01/27 13:33:50 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Thinstall
[2010/09/03 15:17:33 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Toshiba
[2011/02/05 16:44:34 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Touche Software
[2011/04/02 17:39:22 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TrafficAnarchy
[2010/09/03 15:17:33 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/04/20 18:09:07 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Virgin Media
[2010/09/11 20:31:47 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\VSO
[2011/03/03 00:35:22 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\WinBatch
[2010/09/03 15:17:34 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Xtranormal
[2011/04/25 13:41:17 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2010/09/03 23:44:59 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011/04/26 19:15:38 | 000,003,408 | ---- | M] () -- C:\bootsqm.dat
[2011/05/04 23:25:17 | 000,018,598 | ---- | M] () -- C:\ComboFix.txt
[2009/06/10 22:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2011/04/01 09:04:10 | 000,116,174 | ---- | M] () -- C:\Copy of Peters sick - url list.xlsx
[2009/10/27 22:04:03 | 000,003,502 | ---- | M] () -- C:\Enlish.lng
[2008/03/18 15:08:41 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/10/24 20:35:54 | 000,001,015 | R--- | M] () -- C:\logFile.xsl
[2008/03/18 15:08:41 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/05/04 23:29:19 | 2137,448,448 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/02/09 00:00:00 | 000,026,364 | ---- | M] (Brother Industries ,Ltd ) -- C:\Windows\System32\spool\prtprocs\w32x86\brmfpp1.dll
[2008/10/24 12:48:38 | 000,321,536 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\hpzpp696.dll
[2009/07/14 02:15:35 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 02:16:19 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/11/09 22:25:57 | 000,001,654 | -HS- | M] () -- C:\Users\Peter\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/25 20:07:32 | 000,000,480 | -HS- | M] () -- C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/05/03 09:19:11 | 000,000,221 | -HS- | M] () -- C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/05/04 23:05:27 | 004,337,362 | R--- | M] () -- C:\Users\Peter\Desktop\ComboFix.exe
[2011/05/05 00:54:16 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 22:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/09/04 16:35:41 | 000,000,402 | -HS- | M] () -- C:\Users\Peter\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/04/06 17:51:56 | 000,000,236 | -H-- | M] () -- C:\ProgramData\ee6fe4d84748049fa23c8b8638a22cacf0cffd15
[2010/10/11 09:12:47 | 000,000,265 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Windows\System32\€ó:pctlsp.log
@Alternate Data Stream - 236 bytes -> C:\ProgramData:iSpring Presenter 4
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP

FC5A2B2
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:F35A93AD
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP

1B5B4F1
< End of report >