OTL logfile created on: 11/29/2010 11:35:14 PM - Run
OTLPE by OldTimer - Version 3.1.43.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,023.00 Mb Total Physical Memory | 828.00 Mb Available Physical Memory | 81.00% Memory free
907.00 Mb Paging File | 852.00 Mb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 11.71 Gb Free Space | 20.95% Space Free | Partition Type: NTFS
Drive X: | 282.52 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ========== SRV - File not found [Auto] -- C:\WINDOWS\System32\S24EvMon.exe -- (S24EventMonitor)
SRV - File not found [Auto] -- C:\WINDOWS\System32\RegSrvc.exe -- (RegSrvc)
SRV - File not found [Auto] -- C:\Combo-Fix18819C\PEV.cfx -- (PEVSystemStart)
SRV - File not found [On_Demand] -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)
SRV - [2010/10/27 13:23:16 | 001,483,072 | ---- | M] (TuneUp Software) [Auto] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/10/27 13:21:08 | 000,029,504 | ---- | M] (TuneUp Software) [Auto] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010/09/30 20:52:50 | 000,067,904 | ---- | M] (Nalpeiron Ltd.) [Auto] -- C:\WINDOWS\system32\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2010/09/30 20:52:40 | 000,196,928 | ---- | M] (Nitro PDF Software) [Auto] -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe -- (NitroDriverReadSpool)
SRV - [2010/06/24 04:27:54 | 000,033,584 | ---- | M] (ESET) [On_Demand] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/06/24 04:27:12 | 000,810,144 | ---- | M] (ESET) [Auto] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2010/05/07 13:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) [Auto] -- C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2010/05/04 06:07:22 | 000,503,080 | ---- | M] (Nero AG) [Disabled] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2010/04/29 09:39:34 | 000,304,464 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/04/17 05:56:06 | 000,073,960 | ---- | M] (tzuk) [Auto] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2010/01/28 19:43:12 | 000,634,488 | ---- | M] (eBoostr.com) [Disabled] -- C:\Program Files\eBoostr\EBstrSvc.exe -- (EBOOSTRSVC)
SRV - [2009/11/26 02:59:56 | 000,261,456 | ---- | M] () [Auto] -- C:\Program Files\USB Safely Remove\USBSRService.exe -- (USBSafelyRemoveService)
SRV - [2009/07/17 06:10:18 | 001,033,480 | ---- | M] (Raxco Software, Inc.) [Disabled] -- C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe -- (PDEngine)
SRV - [2009/07/17 06:10:16 | 000,931,080 | ---- | M] (Raxco Software, Inc.) [Disabled] -- C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe -- (PDAgent)
SRV - [2009/03/13 08:13:12 | 000,513,536 | ---- | M] (Hagel Technologies Ltd.) [Disabled] -- C:\Program Files\DU Meter\DUMeterSvc.exe -- (DUMeterSvc)
SRV - [2008/10/20 16:18:26 | 000,071,096 | ---- | M] () [Disabled] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2007/01/08 11:08:10 | 000,094,208 | ---- | M] () [Disabled] -- C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe -- (MA_CMIDI_InstallerService)
SRV - [2005/07/18 13:27:42 | 000,069,632 | ---- | M] (FarStone Technology Inc.) [Disabled] -- C:\Program Files\Farstone\HackerSmacker\FWCOM.exe -- (FWCOM)
SRV - [2003/11/26 16:44:19 | 000,061,440 | ---- | M] (CrypKey (Canada) Ltd.) [Auto] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\systemprofile_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Voodoo_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
www.google.comIE - HKU\Voodoo_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Restore =
www.google.comIE - HKU\Voodoo_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 07:26:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 07:26:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/11/21 19:00:44 | 000,000,000 | ---D | M]
[2010/11/28 12:57:55 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/26 18:01:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/22 19:49:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/14 06:50:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/14 22:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/06 18:09:52 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/03/19 15:15:22 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010/10/21 08:25:38 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/10/21 08:25:39 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/10/21 08:25:39 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/10/21 08:25:39 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/05/06 16:39:33 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (HookIe Class) - {F0CABD54-804C-452A-AAA0-C8264997FC6D} - C:\Program Files\Farstone\HackerSmacker\webflt.dll (FarStone Technology Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKU\Voodoo_ON_C\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKU\Voodoo_ON_C..\Run: [Directory Opus Desktop Dblclk] C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe (GP Software)
O4 - HKU\Voodoo_ON_C..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd.)
O4 - HKU\Voodoo_ON_C..\Run: [USB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe ()
O4 - Startup: C:\Documents and Settings\Voodoo\Start Menu\Programs\Startup\Malwarebytes' Anti-Malware.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\Voodoo\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 43 01 00 00 [binary data]
O7 - HKU\systemprofile_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Voodoo_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Voodoo_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\Voodoo_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Voodoo_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7}
http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll (GP Software)
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/13 07:05:59 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/03/13 07:37:17 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/11/29 17:55:23 | 098,217,771 | ---- | C] (Igor Pavlov) -- C:\Documents and Settings\Voodoo\Desktop\OTLPEStd.exe
[2010/11/29 05:35:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32\config\systemprofile\Application Data\Nitro PDF
[2010/11/27 23:18:25 | 000,000,000 | --SD | C] -- C:\Combo-Fix18819C
[2010/11/27 06:46:02 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/11/27 06:46:02 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/11/27 06:46:02 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/11/27 06:46:02 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/11/26 10:29:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Local Settings\Application Data\PC_Drivers_Headquarters
[2010/11/26 10:26:37 | 000,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters
[2010/11/24 18:10:10 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010/11/24 18:10:06 | 000,000,000 | ---D | C] -- C:\rsit
[2010/11/23 07:44:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Voodoo\Recent
[2010/11/23 07:44:22 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010/11/20 09:36:00 | 000,000,000 | ---D | C] -- C:\Music Label Databases
[2010/11/20 09:35:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Application Data\Music Label
[2010/11/20 09:34:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\My Documents\Music Label Reports
[2010/11/20 09:34:05 | 000,000,000 | ---D | C] -- C:\Program Files\Music Label 2011
[2010/11/12 11:38:58 | 000,000,000 | ---D | C] -- C:\sd card formatter
[2010/11/10 06:28:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Application Data\ESET
[2010/11/10 06:14:16 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/11/10 05:35:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32\config\systemprofile\Application Data\ESET
[2010/11/07 16:56:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Application Data\AccurateRip
[2010/11/07 16:55:38 | 000,000,000 | ---D | C] -- C:\Program Files\Exact Audio Copy
[2010/11/07 13:40:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\logishrd
[2010/11/07 13:39:09 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LWS
[2010/11/05 09:26:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\LocalService\Recent
[2010/11/05 09:26:41 | 000,000,000 | R--D | C] -- C:\Documents and Settings\LocalService\My Documents
[2010/11/05 08:47:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Application Data\ProgSense
[2010/11/05 08:33:23 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/11/04 21:26:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Jasc Software Inc
[2010/11/04 21:25:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\My Documents\My PSP Files
[2010/11/04 21:25:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Application Data\Jasc Software Inc
[2010/11/04 18:51:08 | 000,000,000 | ---D | C] -- C:\Program Files\Jasc Software Inc
[2010/11/04 07:01:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\My Documents\SightSpeed Recordings
[2010/11/04 06:57:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Hagel Technologies
[2010/11/04 06:57:17 | 000,000,000 | ---D | C] -- C:\Program Files\DU Meter
[2010/11/04 06:36:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Local Settings\Application Data\LogiShrd
[2010/11/04 06:35:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Application Data\Leadertech
[2010/11/04 06:34:30 | 000,543,328 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\LVUI2.dll
[2010/11/04 06:34:30 | 000,539,232 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\LVUI2RC.dll
[2010/11/04 06:34:30 | 000,416,352 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\lvcodec2.dll
[2010/11/04 06:34:28 | 006,842,464 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\drivers\lvuvc.sys
[2010/11/04 06:33:34 | 000,199,192 | R--- | C] (Logitech Inc.) -- C:\WINDOWS\System32\lvci12101110.dll
[2010/11/04 06:33:33 | 000,282,336 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\drivers\lvrs.sys
[2010/11/04 06:33:32 | 000,114,784 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\drivers\lvpopflt.sys
[2010/11/04 06:32:19 | 000,023,904 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\drivers\lvuvcflt.sys
[2010/11/04 06:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LogiShrd
[2010/11/04 06:26:25 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstee.sys
[2010/11/04 06:26:16 | 000,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndisip.sys
[2010/11/04 06:26:13 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsink.ax
[2010/11/04 06:26:13 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsink.ax
[2010/11/04 06:26:13 | 000,015,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\streamip.sys
[2010/11/04 06:26:10 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\slip.sys
[2010/11/04 06:26:06 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wstcodec.sys
[2010/11/04 06:26:03 | 000,085,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nabtsfec.sys
[2010/11/04 06:26:00 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ccdecode.sys
[2010/11/04 06:25:36 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kswdmcap.ax
[2010/11/04 06:25:36 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kswdmcap.ax
[2010/11/04 06:25:35 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kstvtune.ax
[2010/11/04 06:25:35 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kstvtune.ax
[2010/11/04 06:25:33 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll
[2010/11/04 06:25:33 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2010/11/04 06:25:32 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksxbar.ax
[2010/11/04 06:25:32 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksxbar.ax
[2010/11/04 06:25:32 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dshowext.ax
[2010/11/04 06:25:32 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dshowext.ax
[2010/10/31 19:52:35 | 000,031,552 | ---- | C] (TuneUp Software) -- C:\WINDOWS\System32\TURegOpt.exe
[2010/10/31 19:52:33 | 000,029,504 | ---- | C] (TuneUp Software) -- C:\WINDOWS\System32\uxtuneup.dll
[2010/10/31 19:52:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Application Data\TuneUp Software
[2010/10/31 19:51:45 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2011
[2010/10/31 16:35:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voodoo\Desktop\Power Defrag
[2009/09/10 13:47:16 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Voodoo\Application Data\pcouffin.sys
========== Files - Modified Within 30 Days ========== [2010/11/29 18:24:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/29 18:07:15 | 098,217,771 | ---- | M] (Igor Pavlov) -- C:\Documents and Settings\Voodoo\Desktop\OTLPEStd.exe
[2010/11/28 20:01:00 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\MBRCheck.exe
[2010/11/28 18:50:50 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\gkyx.sys
[2010/11/28 06:05:50 | 000,951,586 | ---- | M] () -- C:\Documents and Settings\Voodoo\My Documents\Ham in Coke « Gastronomy Do...pdf
[2010/11/28 05:13:31 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/28 05:13:01 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\WECPUpdate.job
[2010/11/27 22:59:22 | 000,000,765 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\rkill.rtf
[2010/11/27 22:53:25 | 000,364,032 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\rkill.com
[2010/11/27 07:20:54 | 003,932,214 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\error.bmp
[2010/11/27 06:45:12 | 003,910,097 | R--- | M] () -- C:\Documents and Settings\Voodoo\Desktop\Combo-Fix.exe
[2010/11/26 15:37:37 | 000,142,526 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\instant-batman-costume-win.jpg
[2010/11/24 18:08:27 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\RSIT.exe
[2010/11/24 15:44:03 | 002,941,726 | ---- | M] () -- C:\Documents and Settings\Voodoo\My Documents\AutoRunsvoodootest.arn
[2010/11/24 15:32:08 | 000,620,277 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\Autoruns.zip
[2010/11/23 08:03:37 | 000,630,272 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\dds.scr
[2010/11/20 09:34:16 | 000,000,748 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\Music Label 2011.lnk
[2010/11/16 10:37:15 | 000,002,322 | ---- | M] () -- C:\Documents and Settings\Voodoo\My Documents\Thomas D.A Tellefsen,.cue
[2010/11/14 07:11:20 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/11/13 12:10:33 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2010/11/11 08:55:09 | 000,008,704 | ---- | M] () -- C:\Documents and Settings\Voodoo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/08 17:21:22 | 000,372,969 | ---- | M] () -- C:\Documents and Settings\Voodoo\My Documents\Recipes - Stir Fried Eggpla...pdf
[2010/11/07 20:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2010/11/07 16:55:40 | 000,000,707 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\Exact Audio Copy.lnk
[2010/11/07 11:28:07 | 000,422,538 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\wrapper.bmp
[2010/11/07 11:23:22 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\watch.wtc
[2010/11/05 14:32:38 | 005,515,930 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\Video0018.3gp
[2010/11/05 08:39:47 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\Orbit.lnk
[2010/11/04 21:25:12 | 000,002,828 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2010/11/04 18:01:56 | 000,396,658 | ---- | M] () -- C:\Documents and Settings\Voodoo\Desktop\untitled.bmp
[2010/11/03 19:16:03 | 000,001,789 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2010/11/02 19:38:51 | 000,188,066 | ---- | M] () -- C:\Documents and Settings\Voodoo\My Documents\japanese soy sauces.pdf
[2010/11/02 18:59:51 | 000,312,680 | ---- | M] () -- C:\Documents and Settings\Voodoo\My Documents\Wonton dipping sauces.pdf
[2010/11/02 14:15:21 | 000,484,256 | ---- | M] () -- C:\Documents and Settings\Voodoo\My Documents\70s Recipes - Chicken Chasseur.pdf
[2010/10/31 06:32:23 | 000,441,252 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/31 06:32:23 | 000,071,404 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
========== Files Created - No Company Name ========== [2010/11/28 20:01:00 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\MBRCheck.exe
[2010/11/28 18:50:50 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\gkyx.sys
[2010/11/28 06:05:42 | 000,951,586 | ---- | C] () -- C:\Documents and Settings\Voodoo\My Documents\Ham in Coke « Gastronomy Do...pdf
[2010/11/27 22:59:22 | 000,000,765 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\rkill.rtf
[2010/11/27 22:53:18 | 000,364,032 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\rkill.com
[2010/11/27 07:20:53 | 003,932,214 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\error.bmp
[2010/11/27 06:46:02 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/11/27 06:46:02 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/11/27 06:46:02 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/11/27 06:46:02 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/11/27 06:46:02 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/11/27 06:45:03 | 003,910,097 | R--- | C] () -- C:\Documents and Settings\Voodoo\Desktop\Combo-Fix.exe
[2010/11/26 15:37:33 | 000,142,526 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\instant-batman-costume-win.jpg
[2010/11/24 18:08:23 | 000,339,991 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\RSIT.exe
[2010/11/24 15:44:02 | 002,941,726 | ---- | C] () -- C:\Documents and Settings\Voodoo\My Documents\AutoRunsvoodootest.arn
[2010/11/24 15:31:56 | 000,620,277 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\Autoruns.zip
[2010/11/23 08:03:26 | 000,630,272 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\dds.scr
[2010/11/20 09:34:16 | 000,000,748 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\Music Label 2011.lnk
[2010/11/16 10:37:15 | 000,002,322 | ---- | C] () -- C:\Documents and Settings\Voodoo\My Documents\Thomas D.A Tellefsen,.cue
[2010/11/11 08:54:27 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\Voodoo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/08 17:21:11 | 000,372,969 | ---- | C] () -- C:\Documents and Settings\Voodoo\My Documents\Recipes - Stir Fried Eggpla...pdf
[2010/11/07 16:55:40 | 000,000,707 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\Exact Audio Copy.lnk
[2010/11/07 11:28:07 | 000,422,538 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\wrapper.bmp
[2010/11/07 11:23:22 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\watch.wtc
[2010/11/05 14:30:42 | 005,515,930 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\Video0018.3gp
[2010/11/04 21:16:26 | 000,002,828 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2010/11/04 18:01:56 | 000,396,658 | ---- | C] () -- C:\Documents and Settings\Voodoo\Desktop\untitled.bmp
[2010/11/04 06:34:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/11/04 06:34:30 | 000,266,828 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVAFT.cfg
[2010/11/04 06:33:35 | 000,090,411 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/11/04 06:33:35 | 000,037,518 | ---- | C] () -- C:\WINDOWS\System32\Repository.reg
[2010/11/04 06:32:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2010/11/02 19:38:51 | 000,188,066 | ---- | C] () -- C:\Documents and Settings\Voodoo\My Documents\japanese soy sauces.pdf
[2010/11/02 18:59:39 | 000,312,680 | ---- | C] () -- C:\Documents and Settings\Voodoo\My Documents\Wonton dipping sauces.pdf
[2010/11/02 14:15:21 | 000,484,256 | ---- | C] () -- C:\Documents and Settings\Voodoo\My Documents\70s Recipes - Chicken Chasseur.pdf
[2010/10/21 16:26:35 | 000,000,218 | ---- | C] () -- C:\Documents and Settings\Voodoo\.recently-used.xbel
[2010/09/06 12:20:44 | 000,000,990 | -HS- | C] () -- C:\Documents and Settings\Voodoo\Application Data\systemfl.$dk
[2010/07/28 13:49:00 | 000,000,118 | ---- | C] () -- C:\WINDOWS\Podcasts.INI
[2010/07/27 03:03:20 | 010,829,656 | ---- | C] () -- C:\WINDOWS\System32\LogiDPP.dll
[2010/07/27 03:03:18 | 000,290,648 | ---- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll
[2010/06/30 08:56:51 | 000,306,688 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/06/17 10:00:00 | 002,761,119 | ---- | C] () -- C:\WINDOWS\System32\Melodyne editor.dll
[2010/06/10 09:53:40 | 000,000,205 | ---- | C] () -- C:\WINDOWS\hbcikrnl.ini
[2010/06/01 08:55:46 | 000,000,032 | ---- | C] () -- C:\WINDOWS\Menu.INI
[2010/05/21 08:05:02 | 000,000,032 | ---- | C] () -- C:\WINDOWS\System32\msvcsv60.dll
[2010/05/10 14:14:12 | 000,001,018 | ---- | C] () -- C:\WINDOWS\ARPR.INI
[2010/05/07 13:46:36 | 000,014,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2010/05/07 13:43:30 | 000,025,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2010/04/30 14:48:41 | 000,000,043 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2010/04/30 14:48:30 | 000,028,518 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2010/04/30 14:48:23 | 000,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll
[2010/04/19 04:32:24 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/04/03 07:47:51 | 000,055,808 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2010/03/30 16:09:50 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\GIF89.DLL
[2010/03/30 16:09:06 | 000,000,495 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2010/03/19 20:20:50 | 000,000,020 | ---- | C] () -- C:\WINDOWS\CROCCLIP.INI
[2010/03/17 12:08:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WB.ini
[2010/03/06 09:41:47 | 008,676,883 | ---- | C] () -- C:\WINDOWS\System32\mp3Media2.dll
[2010/03/02 19:00:00 | 004,555,278 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2010/03/02 19:00:00 | 001,449,935 | ---- | C] () -- C:\WINDOWS\System32\ffmpegmt.dll
[2010/03/02 19:00:00 | 000,882,688 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/03/02 19:00:00 | 000,877,385 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2010/03/02 19:00:00 | 000,556,491 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2010/03/02 19:00:00 | 000,336,384 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2010/03/02 19:00:00 | 000,324,096 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/03/02 19:00:00 | 000,248,320 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/03/02 19:00:00 | 000,216,576 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2010/03/02 19:00:00 | 000,169,984 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2010/03/02 19:00:00 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2010/03/02 19:00:00 | 000,145,408 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/03/02 19:00:00 | 000,121,856 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2010/03/02 19:00:00 | 000,116,736 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2010/03/02 19:00:00 | 000,100,864 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2010/03/02 19:00:00 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2010/02/28 14:00:16 | 000,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2010/01/25 10:25:40 | 000,000,123 | ---- | C] () -- C:\WINDOWS\rootkitno.ini
[2009/11/25 07:40:50 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/11/14 13:37:08 | 000,154,112 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2009/11/14 13:33:38 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2009/11/14 13:11:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2009/11/14 13:11:42 | 000,150,016 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2009/11/14 13:11:42 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2009/11/14 13:11:40 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2009/11/14 13:11:40 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2009/11/14 13:11:38 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2009/11/14 13:11:32 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 13:11:32 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2009/10/01 17:07:53 | 000,286,648 | ---- | C] () -- C:\Documents and Settings\Voodoo\Application Data\ReplayMusicLog.log
[2009/09/25 06:56:34 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2009/09/16 11:27:58 | 000,508,224 | ---- | C] () -- C:\WINDOWS\System32\ICCProfiles.dll
[2009/09/10 13:48:32 | 000,000,671 | ---- | C] () -- C:\Documents and Settings\Voodoo\Application Data\vso_ts_preview.xml
[2009/09/10 13:47:44 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\Voodoo\Application Data\pcouffin.log
[2009/09/10 13:47:16 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Voodoo\Application Data\pcouffin.cat
[2009/09/10 13:47:16 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Voodoo\Application Data\pcouffin.inf
[2009/07/30 20:58:42 | 000,000,314 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2009/07/24 09:08:51 | 000,000,188 | ---- | C] () -- C:\WINDOWS\js2.ini
[2009/07/13 19:20:03 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2009/07/13 19:20:03 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNRAR3.dll
[2009/07/13 19:20:03 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2009/07/13 19:20:03 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll
[2009/06/19 10:46:01 | 000,003,840 | ---- | C] () -- C:\WINDOWS\DellBIOS.Sys
[2009/06/07 11:24:04 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/05/14 09:46:54 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/04/05 06:46:51 | 000,006,945 | ---- | C] () -- C:\Documents and Settings\Voodoo\Application Data\PrimoPDFSet.xml
[2009/04/05 06:45:44 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2009/03/22 10:11:30 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009/03/14 09:03:32 | 000,000,152 | ---- | C] () -- C:\WINDOWS\System32\sysplog2.dll._rb
[2009/03/14 09:03:30 | 000,000,152 | ---- | C] () -- C:\WINDOWS\System32\sysplog.dll._rb
[2009/03/13 10:06:57 | 000,001,602 | ---- | C] () -- C:\WINDOWS\Sandboxie.ini
[2009/03/13 06:49:51 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/01/10 17:15:44 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
[2008/11/06 11:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/10/13 04:30:20 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2006/12/08 07:58:14 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\FxShared.dll
[2006/12/07 20:52:50 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\com.fxpansion.fxshared.dll
[2002/10/15 17:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2001/03/13 23:22:21 | 000,000,080 | --S- | C] () -- C:\WINDOWS\System32\argtmp39.dll
[1999/03/23 11:59:29 | 000,000,775 | ---- | C] () -- C:\WINDOWS\System32\FSFW32.SYS
========== LOP Check ========== [2010/11/10 05:35:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\ESET
[2010/04/08 07:01:29 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\Foxit Software
[2010/11/29 05:35:10 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\Nitro PDF
[2010/10/11 09:34:21 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\PrimoPDF
[2010/02/01 17:42:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Foxit Software
[2010/10/21 17:02:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\.purple
[2010/04/02 12:43:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\ACAMPREF
[2009/07/21 15:10:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Applied Acoustics Systems
[2009/09/11 05:07:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\avidemux
[2010/11/03 18:34:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Azureus
[2009/06/11 12:16:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Camfrog
[2009/06/19 10:40:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Canneverbe_Limited
[2010/10/02 09:23:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Celemony Software GmbH
[2010/05/05 04:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Codemonster
[2009/04/28 18:32:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\DAEMON Tools
[2010/05/20 10:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\DAEMON Tools Lite
[2009/04/28 18:32:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\DAEMON Tools Pro
[2010/10/25 11:39:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Downloaded Installations
[2010/11/10 06:28:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\ESET
[2010/09/13 12:42:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\FILEminimizerPictures
[2009/03/31 10:21:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\FLVPlayer4Free
[2010/03/08 18:26:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\FMZilla
[2010/11/25 15:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\foobar2000
[2009/05/17 06:30:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\ForgottenRiddles2
[2009/03/22 15:01:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Foxit
[2010/10/14 14:09:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Foxit Software
[2010/07/23 09:38:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\GPSoftware
[2010/03/06 09:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\GrabPro
[2010/10/21 16:25:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\gtk-2.0
[2010/08/20 12:03:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Intermedia Software
[2009/03/13 14:41:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\IObit
[2009/11/11 11:35:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\KRKsoft
[2010/11/04 06:35:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Leadertech
[2010/09/10 07:14:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Livestation
[2010/09/10 07:14:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Mchid
[2010/11/20 09:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Music Label
[2009/10/07 06:26:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Neuratron
[2010/11/28 06:05:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Nitro PDF
[2010/04/11 09:00:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Noteworthy Software
[2010/03/08 18:21:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\OpenCandy
[2010/10/26 18:06:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\OpenOffice.org
[2010/11/29 13:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Orbit
[2010/04/03 07:52:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\PACE Anti-Piracy
[2010/01/08 15:11:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\PPStream
[2010/10/26 18:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\PrimoPDF
[2010/11/05 08:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\ProgSense
[2010/09/28 11:06:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Radical Software Ltd
[2010/04/19 05:22:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Samsung
[2009/05/28 09:20:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Screaming Bee
[2010/01/25 11:10:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Simply Super Software
[2010/10/19 17:36:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Spotify
[2010/04/02 17:10:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Steinberg
[2009/04/14 16:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\STOPzilla!
[2010/09/11 08:23:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Thinstall
[2010/02/28 14:03:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\TrojanHunter
[2010/10/31 19:52:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\TuneUp Software
[2009/06/24 06:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/12/23 20:50:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Uniblue
[2010/07/01 05:57:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\USBSafelyRemove
[2010/09/22 19:45:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\uTorrent
[2009/11/07 10:27:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\VirSyn Software Synthesizer
[2009/10/19 17:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Vso
[2010/04/30 18:38:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\Waves Audio
[2010/11/09 16:45:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\WebStripper
[2010/06/07 04:56:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\WordWeb
[2010/04/11 10:53:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voodoo\Application Data\XYplorer
[2010/11/28 05:13:01 | 000,000,350 | ---- | M] () -- C:\WINDOWS\Tasks\WECPUpdate.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 128 bytes -> C:\WINDOWS:nlsPreferences
@Alternate Data Stream - 1066 bytes -> C:\Documents and Settings\Voodoo\Local Settings\Application Data\XENDgOfk:L50FgNexydoJsd2xWFWtBFFplz
< End of report >