2nd half
====================================
[color=#E56717]========== Chrome ==========[/color]
CHR - default_search_provider: Funmoods ()
CHR - default_search_provider: search_url = »
searchfunmoods.com/results.php?f···38355344CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: »
securesearch.lavasoft.com/?sourc···2CADC2ADCHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Microsoft® DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft® DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Messenger\2.1.4590.0\npFbDesktopPlugin.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: FortiClient SSL VPN CacheClean Service (Enabled) = C:\Program Files\Fortinet\SslvpnClient\npccplugin.dll
CHR - plugin: FortiClient SSL VPN Tunnel Service (Enabled) = C:\Program Files\Fortinet\SslvpnClient\nptcplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Error reading preferences file
CHR - Extension: Supreme Savings = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ihkeoookbpemkdccdccdmacnidhooohk\1.22.44_0\crossrider
CHR - Extension: Supreme Savings = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ihkeoookbpemkdccdccdmacnidhooohk\1.22.44_0\
O1 HOSTS File: ([2013/03/02 09:37:14 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (MixiDJ V6 Toolbar) - {833a69c9-38a7-4536-99a1-48709f645f17} - C:\Program Files\MixiDJ_V6\prxtbMixi.dll (Conduit Ltd.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O3 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\..\Toolbar\WebBrowser: (MixiDJ V6 Toolbar) - {833A69C9-38A7-4536-99A1-48709F645F17} - C:\Program Files\MixiDJ_V6\prxtbMixi.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\S-1-5-21-2215482205-997936350-1451151502-500..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-21-2215482205-997936350-1451151502-500..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-2215482205-997936350-1451151502-500..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKU\S-1-5-21-2215482205-997936350-1451151502-500\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} »
www.update.microsoft.com/microso···56308966 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} »
download.eset.com/special/eos/On···nner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = talbant.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{24A77AA5-54EE-4FE7-A7E6-245D39EBBF1D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9A2CBEB6-BD25-4CD5-8BB7-B72ECE3564E9}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ckpNotify: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\PCANotify: DllName - (PCANotify.dll) - C:\WINDOWS\System32\PCANotify.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2013/03/14 18:43:54 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/03/13 11:03:01 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2013/03/12 21:42:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2013/03/12 09:20:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2013/03/12 09:19:36 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/03/12 09:19:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/03/11 21:38:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\PetesSecurity
[2013/03/11 21:37:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\.cisco monitor manager
[2013/03/09 09:10:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2013/03/09 09:10:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2013/03/09 09:10:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2013/03/09 09:10:30 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2013/03/02 12:20:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013/03/02 08:42:14 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013/03/02 08:32:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013/02/28 21:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013/02/27 21:26:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\HiJackThis
[2013/02/27 21:26:55 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2013/02/26 07:44:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2013/02/26 07:43:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ad-Aware Antivirus
[2013/02/26 07:43:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\LavasoftStatistics
[2013/02/26 07:43:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Search Protection
[2013/02/26 07:43:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\adawarebp
[2013/02/26 07:43:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2013/02/26 07:43:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\adawaretb
[2013/02/26 07:43:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2013/02/26 07:42:57 | 000,000,000 | ---D | C] -- C:\Program Files\Toolbar Cleaner
[2013/02/26 07:42:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\SecureSearch
[2013/02/26 07:42:43 | 000,000,000 | ---D | C] -- C:\Program Files\adawaretb
[2013/02/26 07:42:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\adawaretb
[2013/02/26 07:42:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Ad-Aware Antivirus
[2013/02/26 07:42:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2013/02/26 07:42:33 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Aware Antivirus
[2013/02/26 07:42:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2013/02/26 07:41:23 | 000,044,424 | ---- | C] (GFI Software) -- C:\WINDOWS\System32\sbbd.exe
[2013/02/26 07:41:23 | 000,013,560 | ---- | C] (GFI Software) -- C:\WINDOWS\System32\drivers\gfibto.sys
[2013/02/26 07:41:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Ad-Aware Antivirus
[2013/02/25 21:49:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2013/02/25 21:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2013/02/25 21:49:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2013/02/25 21:41:46 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2013/02/25 21:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\MixiDJ_V6
[2013/02/25 21:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Conduit
[2013/02/25 21:41:44 | 000,000,000 | ---D | C] -- C:\Program Files\MixiDJ_V6
[2013/02/25 21:41:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\CRE
[2013/02/25 21:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Updater19962
[2013/02/25 21:41:27 | 000,000,000 | ---D | C] -- C:\Program Files\Supreme Savings
[2013/02/25 21:41:26 | 000,000,000 | ---D | C] -- C:\Program Files\DefaultTab
[2013/02/25 21:41:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\DefaultTab
[2013/02/25 14:06:26 | 000,927,912 | ---- | C] (W3i, LLC) -- C:\OfferBrokerage_14003.exe
[2013/02/25 14:06:26 | 000,153,440 | ---- | C] (Amonetize) -- C:\setup__120.exe
[2013/02/24 22:58:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/24 22:58:53 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013/02/24 22:58:53 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/02/24 21:36:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\HP
[2013/02/24 21:36:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP
[2013/02/24 20:30:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2013/02/24 20:16:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\Unused Desktop Shortcuts
[2013/02/24 11:05:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2013/02/21 16:10:34 | 000,000,000 | ---D | C] -- C:\InstallShield
[2013/02/20 20:04:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2013/02/20 19:59:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/08/15 22:00:07 | 001,512,448 | ---- | C] (Irfan Skiljan) -- C:\Program Files\iview430_setup.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2013/03/14 19:46:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA1cc523a4a9c9aff.job
[2013/03/14 19:45:00 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{21D9544E-1C9F-4D56-A6BB-69B4FD53DD35}.job
[2013/03/14 19:40:06 | 000,001,615 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware Antivirus.lnk
[2013/03/14 19:39:55 | 000,402,491 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2013/03/14 19:39:55 | 000,190,150 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2013/03/14 19:39:29 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc523a4a90b1f9.job
[2013/03/14 19:39:24 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/03/14 19:39:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/03/14 19:39:06 | 3745,406,976 | -HS- | M] () -- C:\hiberfil.sys
[2013/03/14 19:22:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-183765059-261963331-840782136-5411UA.job
[2013/03/14 18:11:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/03/14 18:09:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/03/14 11:22:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-183765059-261963331-840782136-5411Core.job
[2013/03/13 20:34:47 | 000,403,120 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/03/13 19:30:20 | 000,271,360 | ---- | M] () -- C:\archive.pst
[2013/03/13 13:11:10 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/03/13 13:11:10 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/03/13 11:02:15 | 000,003,676 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20130313_110209.reg
[2013/03/13 10:03:08 | 000,529,928 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/03/13 10:03:08 | 000,098,208 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/03/12 21:42:58 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/03/12 09:20:15 | 000,001,542 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2013/03/09 11:20:50 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2013/03/09 11:13:14 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/03/02 09:37:14 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013/03/02 08:42:21 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013/02/28 23:09:36 | 000,001,644 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20130228_220926.reg
[2013/02/28 21:33:07 | 006,011,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/02/27 23:09:18 | 000,376,678 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20130227_220858.reg
[2013/02/27 00:06:30 | 000,445,671 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130228-220650.backup
[2013/02/26 07:46:29 | 000,000,960 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2013/02/26 07:41:22 | 000,044,424 | ---- | M] (GFI Software) -- C:\WINDOWS\System32\sbbd.exe
[2013/02/26 07:41:22 | 000,013,560 | ---- | M] (GFI Software) -- C:\WINDOWS\System32\drivers\gfibto.sys
[2013/02/25 22:32:07 | 000,000,884 | RHS- | M] () -- C:\Documents and Settings\Administrator\ntuser.pol
[2013/02/25 21:49:57 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/02/25 21:41:50 | 000,000,009 | ---- | M] () -- C:\END
[2013/02/25 14:06:26 | 000,927,912 | ---- | M] (W3i, LLC) -- C:\OfferBrokerage_14003.exe
[2013/02/25 14:06:26 | 000,153,440 | ---- | M] (Amonetize) -- C:\setup__120.exe
[2013/02/21 17:06:00 | 000,002,459 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Microsoft Excel 2010.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2013/03/13 11:02:13 | 000,003,676 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20130313_110209.reg
[2013/03/12 21:42:58 | 000,002,315 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/03/12 21:42:58 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/03/12 09:20:15 | 000,001,542 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2013/03/11 21:23:15 | 3745,406,976 | -HS- | C] () -- C:\hiberfil.sys
[2013/03/09 11:20:50 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2013/03/02 08:42:20 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013/03/02 08:42:15 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2013/02/28 23:09:29 | 000,001,644 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20130228_220926.reg
[2013/02/27 23:09:09 | 000,376,678 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20130227_220858.reg
[2013/02/26 07:46:29 | 000,000,960 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2013/02/26 07:42:40 | 000,001,615 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware Antivirus.lnk
[2013/02/25 22:32:07 | 000,000,884 | RHS- | C] () -- C:\Documents and Settings\Administrator\ntuser.pol
[2013/02/25 21:49:57 | 000,000,951 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/02/25 21:41:22 | 000,000,009 | ---- | C] () -- C:\END
[2013/01/13 01:41:34 | 001,148,952 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/09/27 10:59:25 | 002,447,334 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\[j0013]-[p28].bmp
[2012/09/04 08:43:42 | 000,000,574 | ---- | C] () -- C:\WINDOWS\hpomdl46.dat.temp
[2012/02/15 23:31:43 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/09/22 16:09:02 | 000,000,064 | ---- | C] () -- C:\WINDOWS\qwimp.ini
[2011/09/22 16:09:01 | 000,000,518 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2011/09/22 15:56:33 | 000,001,241 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2011/07/28 08:00:22 | 000,207,014 | ---- | C] () -- C:\WINDOWS\hpoins46.dat
[2011/07/28 08:00:21 | 000,000,574 | ---- | C] () -- C:\WINDOWS\hpomdl46.dat
[2011/07/20 21:31:10 | 000,060,416 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/26 15:31:51 | 000,000,008 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2009/01/28 04:05:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\WavXMapDrive.bat
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2004/08/11 18:21:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 19:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 19:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[color=#E56717]========== LOP Check ==========[/color]
[2013/02/27 20:49:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Ad-Aware Antivirus
[2013/02/26 07:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\adawaretb
[2012/07/28 11:51:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Astrology_4a
[2011/09/15 17:23:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Blackberry Desktop
[2013/03/02 09:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\DefaultTab
[2013/02/24 12:20:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Dropbox
[2011/10/14 21:17:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ElevatedDiagnostics
[2011/07/14 15:02:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\FileOpen
[2011/10/28 23:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Flip Video
[2012/12/02 21:20:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Funmoods
[2012/07/28 10:54:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ID Vault
[2012/11/22 15:17:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Macroplant LLC
[2011/09/15 08:39:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Research In Motion
[2013/02/26 07:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SecureSearch
[2011/07/14 13:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Smart PDF Converter
[2011/07/20 18:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Sync App Settings
[2011/08/15 21:28:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Visan
[2009/01/28 04:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Wave Systems Corp
[2011/09/07 12:07:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2011/09/14 10:42:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Search
[2013/03/12 09:20:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/02/26 07:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ad-Aware Antivirus
[2013/02/26 07:43:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2013/02/26 07:43:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\adawaretb
[2009/06/08 11:00:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2013/02/26 07:43:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2012/03/16 16:25:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2013/02/26 07:42:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2012/02/04 12:38:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Manager
[2009/07/17 16:42:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileOpen
[2010/12/27 16:20:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flip Video
[2012/07/28 07:49:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2011/02/20 13:25:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2013/02/26 07:43:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Search Protection
[2010/04/14 11:43:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Smart Soft
[2009/09/24 11:32:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sync App Settings
[2012/02/04 12:38:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UAB
[2009/03/14 13:45:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/08/15 21:28:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Visan
[2009/02/09 09:11:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2012/07/28 07:47:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\White Sky, Inc
[2010/05/04 09:28:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/04/09 08:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/11 10:49:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/07 14:51:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/01 12:23:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cehelpdesk\Application Data\VZSMBTB
[2009/01/28 04:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cehelpdesk\Application Data\Wave Systems Corp
[2009/01/28 04:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Wave Systems Corp
[2011/10/05 08:31:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Flip Video
[2012/07/28 07:55:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\ID Vault
[2009/10/12 09:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Amazon
[2009/07/27 11:14:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/06/23 20:53:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Facebook
[2009/07/17 16:42:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\FileOpen
[2009/05/15 08:08:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\ICAClient
[2010/04/14 12:48:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\PrimoPDF
[2009/09/30 15:09:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Research In Motion
[2010/04/14 11:43:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Smart PDF Converter
[2011/04/11 13:46:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Smilebox
[2009/09/24 11:33:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Sync App Settings
[2009/04/01 16:21:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\TeamViewer
[2010/08/02 23:16:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Viewpoint
[2009/04/01 13:11:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\VZSMBTB
[2009/01/28 04:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loseen\Application Data\Wave Systems Corp
[2009/03/09 17:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nancy Losee\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/03/31 17:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nancy Losee\Application Data\TeamViewer
[2009/03/19 15:22:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nancy Losee\Application Data\vzsmbtb
[2009/01/28 04:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nancy Losee\Application Data\Wave Systems Corp
[2011/10/04 13:27:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Flip Video
[color=#E56717]========== Purity Check ==========[/color]
=====================
Virus Total Report
Virsutotal Rpt for Offerebroker file
»
www.virustotal.com/en/file/00419···nalysis/Virustotal Rpt for Setup__120.exe
»
www.virustotal.com/en/file/ec4ab···nalysis/