OTL Part 2
========== Files/Folders - Created Within 30 Days ==========
[2011/04/11 09:04:33 | 000,000,000 | ---D | C] -- C:\Users\Nader\Desktop\New folder
[2011/04/11 01:36:09 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Nader\My Documents\REAPER Media
[2011/04/11 00:50:38 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\REAPER
[2011/04/11 00:50:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REAPER
[2011/04/11 00:50:26 | 000,000,000 | ---D | C] -- C:\Program Files\REAPER
[2011/04/10 11:33:46 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
[2011/04/10 10:40:02 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Celemony Software GmbH
[2011/04/10 10:40:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Celemony Software GmbH
[2011/04/09 17:25:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSPaudioware
[2011/04/09 16:04:49 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Celemony
[2011/04/09 16:04:45 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\VST3
[2011/04/07 22:53:25 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Nader\Desktop\OTL.exe
[2011/04/07 09:45:24 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/04/07 09:45:24 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Local\temp
[2011/04/07 09:45:23 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/04/07 09:27:57 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/04/07 09:27:57 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/04/07 09:27:57 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/04/07 09:27:36 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/04/07 09:27:35 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/04/07 09:26:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/07 09:25:56 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/04/07 09:25:53 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2011/04/03 16:40:52 | 000,656,320 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2011/04/03 16:40:52 | 000,338,880 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
[2011/04/03 16:40:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2011/04/03 15:51:06 | 002,000,848 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2011/04/03 15:51:06 | 001,533,904 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2011/04/03 15:51:06 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2011/04/03 15:44:46 | 000,251,560 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2011/04/03 15:44:46 | 000,103,232 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2011/04/03 15:44:43 | 000,239,168 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2011/04/03 15:44:43 | 000,160,448 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2011/04/03 15:44:39 | 000,070,536 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2011/04/03 15:44:29 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\PC Tools
[2011/04/03 15:44:29 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\PC Tools
[2011/04/03 15:44:29 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2011/04/03 13:05:36 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Nader\My Documents\Electronic Arts
[2011/04/03 11:50:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE
[2011/04/03 08:38:26 | 000,000,000 | ---D | C] -- C:\Users\Nader\Desktop\Tabs and Notes
[2011/04/02 11:44:25 | 000,000,000 | ---D | C] -- C:\Users\Nader\Desktop\Can Torkgoz
[2011/04/02 00:08:47 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Guitar Pro 6
[2011/04/02 00:08:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Guitar Pro 6
[2011/04/01 23:18:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guitar Pro 6
[2011/04/01 20:29:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/03/30 09:24:09 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Avira
[2011/03/30 09:19:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/03/30 09:19:09 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/03/30 09:19:09 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/03/30 09:19:09 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011/03/30 09:19:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/03/28 23:21:41 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/03/28 23:21:40 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\SUPERAntiSpyware.com
[2011/03/28 11:18:41 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Malwarebytes
[2011/03/28 11:18:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/03/27 15:34:03 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sonalksis
[2011/03/27 15:26:12 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Sonalksis
[2011/03/27 13:46:33 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NINJAM
[2011/03/27 13:46:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NINJAM
[2011/03/27 11:01:25 | 000,000,000 | ---D | C] -- C:\AVG10
[2011/03/26 00:12:34 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Nader\My Documents\reading the mind_files
[2011/03/25 09:07:38 | 000,000,000 | ---D | C] -- C:\Users\Nader\Desktop\Fatal Placard
[2011/03/24 19:03:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZSoft
[2011/03/24 07:14:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/03/24 07:14:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011/03/23 21:01:57 | 000,000,000 | ---D | C] -- C:\Users\Nader\dwhelper
[2011/03/21 23:05:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/03/21 23:04:29 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/03/21 23:03:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/03/21 23:02:10 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/03/21 21:00:38 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sample Modeling Mr. Sax T
[2011/03/21 21:00:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sample Modeling Mr. Sax T
[2011/03/21 21:00:16 | 000,393,216 | ---- | C] (Native Instruments Software GmbH) -- C:\Windows\System32\NI_IRC_1_2.dll
[2011/03/21 21:00:16 | 000,061,440 | ---- | C] (Native Instruments Software GmbH) -- C:\Windows\System32\NI_DFD_1_5.dll
[2011/03/21 19:39:18 | 000,000,000 | ---D | C] -- C:\Users\Nader\Desktop\AKAI EWI
[2011/03/15 23:25:35 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Nader\My Documents\KMPlayer
[2011/03/13 12:34:10 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Nader\My Documents\Virtual Machines
[2011/03/13 10:01:39 | 000,000,000 | ---D | C] -- C:\Users\Nader\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Press Training Kit Exam Prep
[2011/03/13 10:01:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\WinNTDlls
[2011/03/13 10:01:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\Win98Dlls
[2010/09/17 18:47:05 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Nader\AppData\Roaming\pcouffin.sys
[2009/06/04 01:57:38 | 000,060,928 | ---- | C] ( ) -- C:\Windows\System32\a3d.dll
[2009/06/04 01:32:54 | 000,012,800 | ---- | C] ( ) -- C:\Windows\System32\killapps.exe
========== Files - Modified Within 30 Days ==========
[2011/04/11 12:12:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1781405395-3741976201-142666947-1000UA.job
[2011/04/11 11:46:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/11 08:13:25 | 000,000,434 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2011/04/11 08:13:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/11 02:00:38 | 000,055,756 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000005-00000000-0000000A-00001102-00000005-00211102}.rfx
[2011/04/11 02:00:38 | 000,055,756 | ---- | M] () -- C:\Windows\System32\BMXState-{00000005-00000000-0000000A-00001102-00000005-00211102}.rfx
[2011/04/11 02:00:38 | 000,001,080 | ---- | M] () -- C:\Windows\System32\settingsbkup.sfm
[2011/04/11 02:00:38 | 000,001,080 | ---- | M] () -- C:\Windows\System32\settings.sfm
[2011/04/11 02:00:38 | 000,000,788 | ---- | M] () -- C:\Windows\System32\DVCState-{00000005-00000000-0000000A-00001102-00000005-00211102}.rfx
[2011/04/11 01:19:27 | 000,784,396 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/04/11 01:19:27 | 000,516,558 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2011/04/11 01:19:27 | 000,166,074 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/04/11 01:19:27 | 000,165,738 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2011/04/11 01:19:22 | 000,010,208 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/11 01:19:22 | 000,010,208 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/11 01:14:22 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/11 01:13:59 | 2213,441,536 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/11 01:09:03 | 000,000,072 | ---- | M] () -- C:\Users\Nader\Desktop\Reaper NINJAM Setup - Cockos Confederated Forums.URL
[2011/04/11 00:50:29 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\REAPER.lnk
[2011/04/10 20:12:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1781405395-3741976201-142666947-1000Core.job
[2011/04/09 17:25:05 | 006,617,600 | ---- | M] () -- C:\Windows\System32\PSP VintageWarmer2.dll
[2011/04/09 17:25:05 | 006,578,688 | ---- | M] () -- C:\Windows\System32\PSP MicroWarmer.dll
[2011/04/09 17:25:04 | 006,610,432 | ---- | M] () -- C:\Windows\System32\PSP VintageWarmer.dll
[2011/04/08 21:55:17 | 001,346,650 | ---- | M] () -- C:\Users\Nader\Desktop\dd65_en_om.pdf
[2011/04/07 22:53:26 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Nader\Desktop\OTL.exe
[2011/04/07 18:54:33 | 000,868,704 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB
[2011/04/07 09:41:06 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/04/06 22:09:45 | 000,000,756 | ---- | M] () -- C:\Program Files\CoreTemp.ini
[2011/04/06 09:08:50 | 000,000,869 | ---- | M] () -- C:\Users\Nader\Desktop\Downloads.lnk
[2011/04/05 23:31:25 | 000,000,068 | ---- | M] () -- C:\Users\Nader\Desktop\UPDATED 8-step VirusesSpywareMalware Preliminary Removal Instructions - TechSpot OpenBoards.URL
[2011/04/05 21:57:23 | 000,000,117 | ---- | M] () -- C:\Users\Nader\Desktop\Reddit, what's a little-known site you think everyone should know about AskReddit.URL
[2011/04/04 20:09:49 | 000,000,050 | ---- | M] () -- C:\Users\Nader\Desktop\Eric Whitacre – Composer and Conductor.URL
[2011/04/04 08:55:46 | 000,765,107 | ---- | M] () -- C:\Users\Nader\Desktop\simple recipes.jpg
[2011/04/03 15:51:45 | 000,011,444 | -HS- | M] () -- C:\ProgramData\7s2pe1q5j6f2k0cn2w6ndd0asw4fv7j73kk2gs86
[2011/04/01 23:18:56 | 000,000,654 | ---- | M] () -- C:\Users\Public\Desktop\Guitar Pro 6.lnk
[2011/04/01 20:29:12 | 000,012,804 | -HS- | M] () -- C:\Users\Nader\AppData\Local\7s2pe1q5j6f2k0cn2w6ndd0asw4fv7j73kk2gs86
[2011/04/01 19:14:34 | 000,012,804 | -HS- | M] () -- C:\ProgramData\2562034582
[2011/03/30 09:14:30 | 000,001,333 | ---- | M] () -- C:\Users\Nader\Desktop\credentials.lnk
[2011/03/30 09:09:36 | 000,001,621 | ---- | M] () -- C:\Users\Nader\Desktop\secure.lnk
[2011/03/26 21:56:38 | 003,682,096 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/03/26 00:12:34 | 000,059,176 | ---- | M] () -- E:\Documents and Settings\Nader\My Documents\reading the mind.html
[2011/03/18 23:11:02 | 000,002,671 | ---- | M] () -- C:\Users\Nader\Desktop\Microsoft Office Word Viewer 2003.lnk
[2011/03/14 01:10:45 | 000,000,023 | ---- | M] () -- C:\Windows\BlendSettings.ini
========== Files Created - No Company Name ==========
[2011/04/11 01:09:03 | 000,000,072 | ---- | C] () -- C:\Users\Nader\Desktop\Reaper NINJAM Setup - Cockos Confederated Forums.URL
[2011/04/11 00:50:29 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\REAPER.lnk
[2011/04/09 17:25:05 | 006,578,688 | ---- | C] () -- C:\Windows\System32\PSP MicroWarmer.dll
[2011/04/09 17:25:04 | 006,617,600 | ---- | C] () -- C:\Windows\System32\PSP VintageWarmer2.dll
[2011/04/09 17:25:04 | 006,610,432 | ---- | C] () -- C:\Windows\System32\PSP VintageWarmer.dll
[2011/04/08 21:55:29 | 001,346,650 | ---- | C] () -- C:\Users\Nader\Desktop\dd65_en_om.pdf
[2011/04/07 09:27:57 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/04/07 09:27:57 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/04/07 09:27:57 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/04/07 09:27:57 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/04/07 09:27:57 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/04/06 09:08:50 | 000,000,869 | ---- | C] () -- C:\Users\Nader\Desktop\Downloads.lnk
[2011/04/05 23:31:25 | 000,000,068 | ---- | C] () -- C:\Users\Nader\Desktop\UPDATED 8-step VirusesSpywareMalware Preliminary Removal Instructions - TechSpot OpenBoards.URL
[2011/04/05 21:57:23 | 000,000,117 | ---- | C] () -- C:\Users\Nader\Desktop\Reddit, what's a little-known site you think everyone should know about AskReddit.URL
[2011/04/04 20:09:49 | 000,000,050 | ---- | C] () -- C:\Users\Nader\Desktop\Eric Whitacre – Composer and Conductor.URL
[2011/04/04 08:55:45 | 000,765,107 | ---- | C] () -- C:\Users\Nader\Desktop\simple recipes.jpg
[2011/04/03 16:40:53 | 000,868,704 | ---- | C] () -- C:\Windows\System32\drivers\Cat.DB
[2011/04/03 16:38:51 | 000,001,111 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/03 15:51:06 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011/04/03 15:51:06 | 000,002,125 | ---- | C] () -- C:\Windows\UDB.zip
[2011/04/03 15:51:06 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2011/04/03 15:51:06 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2011/04/03 15:51:06 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2011/04/03 15:44:46 | 000,007,387 | ---- | C] () -- C:\Windows\System32\drivers\pctgntdi.cat
[2011/04/03 15:44:39 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctplsg.cat
[2011/04/01 23:18:56 | 000,000,654 | ---- | C] () -- C:\Users\Public\Desktop\Guitar Pro 6.lnk
[2011/04/01 09:46:02 | 000,012,804 | -HS- | C] () -- C:\Users\Nader\AppData\Local\7s2pe1q5j6f2k0cn2w6ndd0asw4fv7j73kk2gs86
[2011/04/01 09:46:02 | 000,012,804 | -HS- | C] () -- C:\ProgramData\2562034582
[2011/04/01 09:45:55 | 000,011,444 | -HS- | C] () -- C:\ProgramData\7s2pe1q5j6f2k0cn2w6ndd0asw4fv7j73kk2gs86
[2011/03/31 21:34:19 | 000,001,258 | ---- | C] () -- E:\Documents and Settings\Nader\My Documents\hosts
[2011/03/30 09:14:30 | 000,001,333 | ---- | C] () -- C:\Users\Nader\Desktop\credentials.lnk
[2011/03/30 09:09:36 | 000,001,621 | ---- | C] () -- C:\Users\Nader\Desktop\secure.lnk
[2011/03/26 00:12:33 | 000,059,176 | ---- | C] () -- E:\Documents and Settings\Nader\My Documents\reading the mind.html
[2011/03/18 23:24:18 | 000,002,671 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk
[2011/03/18 23:13:13 | 000,002,671 | ---- | C] () -- C:\Users\Nader\Desktop\Microsoft Office Word Viewer 2003.lnk
[2011/02/16 21:00:28 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2011/02/13 17:06:26 | 000,001,456 | ---- | C] () -- C:\Users\Nader\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/02/06 01:04:04 | 000,004,608 | ---- | C] () -- C:\Users\Nader\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/22 15:42:31 | 000,047,104 | ---- | C] () -- C:\Windows\System32\KMVIDC32.DLL
[2010/12/25 17:50:14 | 000,000,005 | ---- | C] () -- C:\Windows\pellnoba.ini
[2010/12/10 20:13:52 | 000,823,296 | ---- | C] () -- C:\Windows\j3dcore-d3d.dll
[2010/12/10 20:13:52 | 000,163,840 | ---- | C] () -- C:\Windows\j3dcore-ogl.dll
[2010/12/10 20:13:52 | 000,049,152 | ---- | C] () -- C:\Windows\j3dcore-ogl-chk.dll
[2010/12/10 20:13:52 | 000,040,960 | ---- | C] () -- C:\Windows\j3dcore-ogl-cg.dll
[2010/11/25 21:12:48 | 000,000,093 | ---- | C] () -- C:\Users\Nader\AppData\Local\fusioncache.dat
[2010/11/21 17:10:25 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/11/18 21:11:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/11/01 08:49:25 | 000,000,565 | ---- | C] () -- C:\Users\Nader\AppData\Roaming\myMPQ.ini
[2010/10/27 03:13:04 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010/09/22 19:27:52 | 000,223,990 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2010/09/19 22:40:57 | 000,000,005 | ---- | C] () -- C:\Windows\ljndfenn.ini
[2010/09/17 19:17:02 | 000,002,888 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2010/09/17 18:47:35 | 000,001,057 | ---- | C] () -- C:\Users\Nader\AppData\Roaming\vso_ts_preview.xml
[2010/09/17 18:47:05 | 000,007,887 | ---- | C] () -- C:\Users\Nader\AppData\Roaming\pcouffin.cat
[2010/09/17 18:47:05 | 000,001,144 | ---- | C] () -- C:\Users\Nader\AppData\Roaming\pcouffin.inf
[2010/09/06 16:31:51 | 000,000,056 | ---- | C] () -- C:\Windows\System32\nets12.dll
[2010/09/01 07:07:07 | 000,000,622 | ---- | C] () -- C:\Windows\DMN.INI
[2010/08/31 22:19:24 | 000,209,040 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2010/08/31 22:19:24 | 000,204,944 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2010/08/31 22:19:24 | 000,196,752 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2010/08/31 22:19:24 | 000,196,752 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2010/08/31 22:19:24 | 000,192,656 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2010/08/31 22:19:24 | 000,024,720 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2010/08/29 19:55:25 | 000,000,005 | ---- | C] () -- C:\Windows\apneilka.ini
[2010/06/19 10:31:15 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2010/04/17 15:07:47 | 000,053,248 | ---- | C] () -- C:\Windows\System32\zlib.dll
[2010/03/30 20:07:58 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat
[2010/03/30 20:07:57 | 000,516,558 | ---- | C] () -- C:\Windows\System32\perfh011.dat
[2010/03/30 20:07:57 | 000,165,738 | ---- | C] () -- C:\Windows\System32\perfc011.dat
[2010/03/30 20:07:57 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat
[2010/03/25 01:18:57 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/03/22 22:44:22 | 000,001,029 | ---- | C] () -- C:\Windows\ARPR.INI
[2010/03/18 21:24:40 | 000,000,005 | ---- | C] () -- C:\Windows\knplpkmm.ini
[2010/03/16 08:50:36 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2010/03/05 21:05:12 | 000,000,011 | ---- | C] () -- C:\Program Files\Plugins.ini
[2010/03/05 21:05:11 | 000,000,756 | ---- | C] () -- C:\Program Files\CoreTemp.ini
[2010/03/05 20:59:43 | 000,378,384 | ---- | C] () -- C:\Program Files\Core Temp.exe
[2010/03/01 23:20:17 | 000,000,048 | ---- | C] () -- C:\Windows\msocreg32.dat
[2010/02/27 00:34:50 | 000,055,856 | ---- | C] () -- C:\Windows\System32\vnetinst.dll
[2010/02/10 08:37:25 | 000,001,025 | ---- | C] () -- C:\Windows\System32\grcauth2.dll
[2010/02/10 08:37:25 | 000,001,025 | ---- | C] () -- C:\Windows\System32\grcauth1.dll
[2010/02/10 08:37:25 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth2.dll
[2010/02/10 08:37:25 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth1.dll
[2010/02/10 08:37:25 | 000,001,025 | ---- | C] () -- C:\Windows\System32\a69u0zk.dll
[2010/02/10 08:37:25 | 000,000,204 | ---- | C] () -- C:\Windows\System32\i6u1wqr.dll
[2010/02/10 08:37:25 | 000,000,100 | ---- | C] () -- C:\Windows\System32\prsgrc.dll
[2010/02/10 08:37:25 | 000,000,072 | ---- | C] () -- C:\Windows\System32\ssprs.dll
[2010/02/10 08:37:25 | 000,000,016 | -H-- | C] () -- C:\Windows\System32\qmtn7ft.dll
[2010/02/10 08:37:25 | 000,000,016 | -H-- | C] () -- C:\Windows\System32\jm1ixs2.dll
[2010/02/10 08:37:25 | 000,000,000 | ---- | C] () -- C:\Windows\System32\serauth2.dll
[2010/02/10 08:37:25 | 000,000,000 | ---- | C] () -- C:\Windows\System32\serauth1.dll
[2010/02/10 08:37:25 | 000,000,000 | ---- | C] () -- C:\Windows\System32\nsprs.dll
[2010/01/20 10:33:08 | 000,430,080 | ---- | C] () -- C:\Windows\System32\ZSHP1020.EXE
[2010/01/20 00:35:18 | 003,682,096 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/01/19 23:28:46 | 000,148,480 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2010/01/19 23:28:46 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2010/01/19 21:41:10 | 000,000,600 | ---- | C] () -- C:\Users\Nader\AppData\Roaming\winscp.rnd
[2010/01/19 21:40:28 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/11/06 11:58:04 | 000,178,975 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2009/09/01 16:27:32 | 000,319,488 | ---- | C] () -- C:\Windows\win-get.exe
[2009/09/01 16:27:30 | 000,324,608 | ---- | C] () -- C:\Windows\wget.exe
[2009/09/01 13:09:07 | 000,031,232 | ---- | C] () -- C:\Windows\System32\cmdow.exe
[2009/09/01 13:09:07 | 000,026,013 | ---- | C] () -- C:\Windows\System32\sleep.exe
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:05:48 | 000,784,396 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,166,074 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/06/04 02:37:08 | 000,021,093 | ---- | C] () -- C:\Windows\System32\instwdm.ini
[2009/06/04 02:37:06 | 000,000,054 | ---- | C] () -- C:\Windows\System32\ctzapxx.ini
[2009/06/04 01:55:20 | 000,002,560 | ---- | C] () -- C:\Windows\System32\CtxfiRes.dll
[2009/06/04 01:55:20 | 000,002,560 | ---- | C] () -- C:\Windows\CTXFIRES.DLL
[2009/06/04 01:40:44 | 000,321,512 | ---- | C] () -- C:\Windows\System32\ctdlang.dat
[2009/06/04 01:40:44 | 000,056,509 | ---- | C] () -- C:\Windows\System32\ctdnlstr.dat
[2009/06/04 01:36:30 | 000,016,384 | ---- | C] () -- C:\Windows\System32\regplib.exe
[2009/06/04 01:33:04 | 000,007,680 | ---- | C] () -- C:\Windows\System32\enlocstr.exe
[2009/05/27 10:49:00 | 000,000,285 | ---- | C] () -- C:\Windows\System32\kill.ini
[2007/07/23 10:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 10:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007/07/23 10:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007/07/23 10:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 10:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007/07/23 10:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007/07/23 10:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007/07/23 10:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007/07/23 10:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2006/07/17 07:57:40 | 000,069,632 | ---- | C] () -- C:\Windows\System32\FxShared.dll
[2006/07/17 07:57:40 | 000,069,632 | ---- | C] () -- C:\Windows\System32\com.fxpansion.fxshared.dll
[2005/01/31 09:37:58 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2002/09/18 00:45:00 | 000,119,808 | ---- | C] () -- C:\Windows\lsb_un20.exe
========== LOP Check ==========
[2010/06/26 22:57:41 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\.anki
[2011/02/22 23:38:42 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\.minecraft
[2010/05/30 19:19:26 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Ableton
[2011/02/12 09:56:14 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Antares
[2010/12/19 09:59:09 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Ashampoo
[2011/04/02 09:12:00 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Audacity
[2010/11/28 12:19:58 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\AVG10
[2010/03/08 23:51:38 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\AVG9
[2010/02/10 10:09:23 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Bioshock2
[2011/01/03 21:12:08 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Braid
[2010/06/19 10:31:28 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Canneverbe Limited
[2011/04/10 10:40:02 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Celemony Software GmbH
[2010/07/08 09:00:21 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Curl Corporation
[2010/11/21 17:37:33 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\DAEMON Tools
[2010/11/21 17:46:47 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\DAEMON Tools Pro
[2011/04/11 01:35:28 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Digidesign
[2010/12/26 23:24:33 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Downloaded Installations
[2010/11/13 16:30:07 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Dropbox
[2010/01/19 21:44:57 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\ESET
[2010/01/31 10:00:31 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\FabFilter
[2010/07/10 10:39:32 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Folding@home-x86
[2011/04/11 08:27:55 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\foobar2000
[2010/03/25 20:56:08 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Foxit Software
[2010/02/04 19:59:58 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\freephoneline.ca
[2010/10/18 23:52:55 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\GrabPro
[2011/04/02 00:10:08 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Guitar Pro 6
[2010/01/25 10:29:52 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Helios
[2010/02/24 01:13:16 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\ICSharpCode
[2010/10/19 09:35:08 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\ID3 renamer
[2010/12/20 23:36:37 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\IObit
[2010/02/27 11:51:38 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\iZotope
[2010/02/10 09:50:01 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\JAM Software
[2010/03/31 23:14:50 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\JetBrains
[2010/02/27 16:14:58 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Leadertech
[2010/12/12 10:32:58 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\LimeWire
[2010/11/24 21:53:38 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\LINQPad
[2010/03/26 22:15:19 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Movienizer
[2010/06/26 09:56:06 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\mplayer
[2010/12/27 00:38:58 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Mumble
[2011/01/06 19:03:55 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\MusicLab
[2010/10/10 22:43:50 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Neuratron
[2010/09/12 23:57:30 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Nik Software
[2010/02/24 01:05:06 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Nokia
[2011/02/14 21:19:50 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Notepad++
[2010/12/21 22:06:47 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Octoshape
[2011/04/03 16:36:42 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Orbit
[2010/12/24 10:07:29 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\PACE Anti-Piracy
[2010/03/26 21:29:44 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Personal Video Database
[2010/02/07 01:25:27 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Polynomial
[2010/10/18 23:25:45 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\ProgSense
[2010/09/20 22:15:22 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Publish Providers
[2010/12/12 10:51:14 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Python-Eggs
[2010/12/21 21:35:49 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\RayV
[2011/04/11 01:55:20 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\REAPER
[2011/01/22 16:28:02 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Red Alert 3
[2011/03/27 15:27:25 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Sonalksis
[2010/09/20 23:30:14 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Sony
[2010/11/25 09:17:38 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Stardock
[2010/05/24 20:54:53 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Steinberg
[2010/02/23 10:11:09 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Subversion
[2011/01/16 01:06:01 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Telerik
[2011/02/09 21:41:13 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Thinstall
[2011/01/12 22:04:03 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\TileRacer
[2010/12/24 10:08:48 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Trillium Lane
[2010/03/30 19:56:27 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\TrueCrypt
[2010/11/25 22:31:29 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Ubisoft
[2010/09/02 06:31:54 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Ulead Systems
[2011/04/11 12:17:08 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\uTorrent
[2010/12/21 21:31:24 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Vso
[2010/01/30 10:51:33 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Waves
[2010/01/30 10:40:50 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Waves Audio
[2010/01/30 10:51:42 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Waves Preferences
[2011/02/06 20:44:48 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\Wing IDE 3
[2010/09/20 10:35:11 | 000,000,000 | ---D | M] -- C:\Users\Nader\AppData\Roaming\ZumoDrive
[2011/04/05 23:32:51 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2009/06/05 02:08:09 | 000,000,068 | ---- | M] ()(E:\Documents and Settings\Nader\My Documents\YouTube - ??????????? Sugar Blessing singing ?????.url) -- E:\Documents and Settings\Nader\My Documents\YouTube - シュガーブレッシングは Sugar Blessing singing かえりみち.url
[2009/06/05 02:08:09 | 000,000,068 | ---- | C] ()(E:\Documents and Settings\Nader\My Documents\YouTube - ??????????? Sugar Blessing singing ?????.url) -- E:\Documents and Settings\Nader\My Documents\YouTube - シュガーブレッシングは Sugar Blessing singing かえりみち.url
========== Alternate Data Streams ==========
@Alternate Data Stream - 182 bytes -> C:\ProgramData\TEMP

FC5A2B2
@Alternate Data Stream - 1376 bytes -> D:\Program Files\Common Files\microsoft shared

h452BqwAkc38Virok8CNEZ
@Alternate Data Stream - 1371 bytes -> D:\Program Files\Common Files\microsoft shared:OiggSqmLGjWPvIbcpHjYmKJ5jUA
@Alternate Data Stream - 1363 bytes -> C:\ProgramData\Microsoft:iKNP3W7pXupY60tGak
@Alternate Data Stream - 1356 bytes -> C:\ProgramData\Microsoft:sP6DlGvCY6WZUpwUSDX
@Alternate Data Stream - 1301 bytes -> C:\ProgramData\Microsoft:KorUr2LVku3POKIGi7LF0jhVxB
@Alternate Data Stream - 1281 bytes -> C:\ProgramData\Microsoft:CakalxSobwG50d8blSBD4or
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 1229 bytes -> D:\Program Files\Common Files\microsoft shared:j65njlSI1R8g4i6s3iAEenVbA
@Alternate Data Stream - 1184 bytes -> C:\ProgramData\Microsoft:gbvCqLZkLJr1PrIEDZGsxqtY4s
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP

74B6CF5
< End of report >