It just all of a sudden started redirecting my Google results.
I'm running Microsoft Security Essentials and it's not detecting anything. But malwarebytes is detecting a Trojan.Tracur.Gen.
OTL logfile created on: 6/16/2011 3:15:44 AM - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = E:\Desktop Junk ( 2 )
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
11.98 Gb Total Physical Memory | 8.04 Gb Available Physical Memory | 67.05% Memory free
29.98 Gb Paging File | 25.59 Gb Available in Paging File | 85.34% Paging File free
Paging file location(s): c:\pagefile.sys 18432 24576 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.50 Gb Total Space | 257.89 Gb Free Space | 27.69% Space Free | Partition Type: NTFS
Drive E: | 1863.01 Gb Total Space | 265.71 Gb Free Space | 14.26% Space Free | Partition Type: NTFS
Computer Name: Z600 | User Name: BIG-FELLA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/16 03:14:05 | 000,580,608 | ---- | M] (OldTimer Tools) -- E:\Desktop Junk ( 2 )\OTL.exe
PRC - [2011/06/16 00:17:43 | 007,603,712 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Local\SENukeX\SENuke.exe
PRC - [2011/06/16 00:17:43 | 000,110,080 | ---- | M] (Microsoft) -- C:\Users\BIG-FELLA\AppData\Local\SENukeX\SENukeRecovery.exe
PRC - [2011/06/13 11:29:08 | 000,788,992 | ---- | M] (Dmitry Streblechenko) -- C:\Windows\SysWOW64\PresentationNative_v030032.exe
PRC - [2011/06/13 11:29:08 | 000,788,992 | ---- | M] (Dmitry Streblechenko) -- C:\ProgramData\icm3232.exe
PRC - [2011/05/29 09:11:28 | 000,449,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/05/29 09:11:22 | 001,047,656 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/05/27 18:46:17 | 002,712,384 | ---- | M] (Softtouch Software Design) -- E:\2 TeraByte Folder\ScrapeBox - Application\scrapebox.exe
PRC - [2011/05/11 14:12:36 | 000,186,760 | ---- | M] () -- C:\Program Files (x86)\Photodex\ProShow Producer\scsiaccess.exe
PRC - [2011/04/29 08:00:55 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/03/03 05:39:10 | 003,278,232 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2011/02/17 13:40:10 | 000,107,000 | ---- | M] (Siber Systems) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2010/11/30 12:16:10 | 011,299,328 | ---- | M] (Network Automation, Inc.) -- C:\Program Files (x86)\AutoMate 8\AMTS.exe
PRC - [2010/11/30 12:16:08 | 005,429,760 | ---- | M] (Network Automation, Inc.) -- C:\Program Files (x86)\AutoMate 8\AMEM.exe
PRC - [2010/09/20 18:55:58 | 000,094,040 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Camtasia Studio 7\TscHelp.exe
PRC - [2010/09/20 18:55:34 | 006,775,128 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Camtasia Studio 7\CamtasiaStudio.exe
PRC - [2010/09/20 18:55:32 | 004,441,944 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Camtasia Studio 7\CamRecorder.exe
PRC - [2010/08/02 23:08:20 | 000,023,040 | ---- | M] (Brian Apps Products) -- C:\Program Files (x86)\Sizer\sizer.exe
PRC - [2010/05/25 09:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
PRC - [2010/05/14 12:44:46 | 000,501,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2010/04/13 20:01:58 | 000,094,024 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\TscHelp.exe
PRC - [2010/04/13 20:01:56 | 000,079,688 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\SnagPriv.exe
PRC - [2010/04/13 20:01:52 | 007,046,984 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\Snagit32.exe
PRC - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2009/07/20 05:00:00 | 000,077,824 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
PRC - [2009/06/08 15:17:00 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\IPFax\FaxMonitor.exe
PRC - [2007/10/25 11:47:06 | 000,353,976 | ---- | M] (X1 Technologies, Inc.) -- C:\Program Files (x86)\X1\X1Systray.exe
PRC - [2007/10/10 21:16:58 | 009,677,232 | ---- | M] (Adobe Systems®, Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Audition 3.0\Audition.exe
========== Modules (SafeList) ==========
MOD - [2011/06/16 03:14:05 | 000,580,608 | ---- | M] (OldTimer Tools) -- E:\Desktop Junk ( 2 )\OTL.exe
MOD - [2011/06/15 23:15:52 | 000,173,056 | ---- | M] (Malwarebytes Corporation) -- C:\ProgramData\api-ms-win-core-localregistry-l1-1-032.dll
MOD - [2011/06/15 22:59:17 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll
MOD - [2011/04/15 07:32:06 | 000,038,304 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\idmmkb.dll
MOD - [2010/11/12 12:41:08 | 000,406,528 | ---- | M] (Network Automation, Inc.) -- C:\Program Files (x86)\AutoMate 8\AM8TrgHk.dll
MOD - [2010/08/21 00:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2010/08/02 23:08:18 | 000,013,312 | ---- | M] (Brian Apps Products) -- C:\Program Files (x86)\Sizer\sizer.dll
MOD - [2009/07/20 05:00:00 | 000,038,912 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\x86\lgscroll.dll
MOD - [2009/07/13 20:16:19 | 000,156,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2010/11/11 15:36:38 | 000,282,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2010/11/11 15:36:38 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/07/20 13:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/06/13 11:29:08 | 000,788,992 | ---- | M] (Dmitry Streblechenko) [Auto | Running] -- C:\Windows\SysWOW64\PresentationNative_v030032.exe -- (clr_optimization_v2.0.50727_3232)
SRV - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/05/11 14:12:36 | 000,186,760 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Photodex\ProShow Producer\scsiaccess.exe -- (ScsiAccess)
SRV - [2011/05/03 17:31:48 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/03/09 19:07:10 | 000,083,456 | ---- | M] () [Disabled | Stopped] -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\[email protected]\svc.exe -- (Firefox Service)
SRV - [2011/02/11 20:52:17 | 003,975,088 | ---- | M] (Acronis) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2011/01/14 09:55:57 | 002,250,616 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010/12/31 08:39:54 | 008,133,120 | ---- | M] () [Disabled | Stopped] -- c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe -- (wampmysqld)
SRV - [2010/12/31 08:39:42 | 000,020,549 | ---- | M] (Apache Software Foundation) [Disabled | Stopped] -- c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe -- (wampapache)
SRV - [2010/11/30 12:16:10 | 011,299,328 | ---- | M] (Network Automation, Inc.) [Auto | Running] -- C:\Program Files (x86)\AutoMate 8\AMTS.exe -- (AutoMate8)
SRV - [2010/08/21 14:16:42 | 001,078,952 | ---- | M] (Acronis) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010/07/23 13:24:48 | 000,296,808 | ---- | M] (Nuance Communications, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe -- (DragonSvc)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/03/28 12:46:40 | 000,146,568 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
DRV:64bit: - [2011/02/11 20:52:20 | 000,279,136 | ---- | M] (Acronis) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2011/02/11 20:52:14 | 001,263,200 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm273.sys -- (tdrpman273) Acronis Try&Decide and Restore Points filter (build 273)
DRV:64bit: - [2011/02/11 20:52:12 | 000,970,336 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2011/02/11 20:52:03 | 000,277,088 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2011/01/12 04:42:16 | 000,016,376 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TVMonitor.sys -- (MonitorFunction)
DRV:64bit: - [2011/01/12 04:42:12 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:64bit: - [2011/01/07 02:34:03 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2010/10/24 22:25:38 | 000,072,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2010/07/12 13:36:10 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/07/13 20:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 20:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/17 11:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2009/06/17 11:54:38 | 000,112,144 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouKE.Sys -- (LMouKE)
DRV:64bit: - [2009/06/17 11:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009/06/17 11:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009/06/17 11:53:42 | 000,089,616 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L8042mou.Sys -- (L8042mou)
DRV:64bit: - [2009/06/17 11:53:34 | 000,030,736 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/02/05 20:45:32 | 000,015,208 | ---- | M] (deepxw) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tcpz-x64d.sys -- (TCPZ) TCP Half Open Limited Patcher ( TCP-Z)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BE 83 42 34 D8 D2 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 52 91 2F 00 E2 B8 4B 41 86 97 D6 75 92 89 60 0C [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 76.73.25.214:52931
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Search-Results"
FF - prefs.js..browser.search.defaultenginename: "Search-Results"
FF - prefs.js..browser.search.order.1: "Search-Results"
FF - prefs.js..browser.search.selectedEngine: "Search-Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-US.start3....en-US:official"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:7.1.9
FF - prefs.js..extensions.enabledItems: [email protected]:3.4.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.1
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: {d57c9ff1-6389-48fc-b770-f78bd89b6e8a}:1.34
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: [email protected]:0.7.2.5
FF - prefs.js..extensions.enabledItems: {5C46D283-ABDE-4dce-B83C-08881401921C}:2.1.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.1
FF - prefs.js..extensions.enabledItems: {EDA7B1D7-F793-4e03-B074-E6F303317FB0}:1.2.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.6.8
FF - prefs.js..extensions.enabledItems: [email protected]:1.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:6.9.8
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.2
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.5
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="
FF - prefs.js..network.proxy.http: "173.208.100.233"
FF - prefs.js..network.proxy.http_port: 13574
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011/01/07 03:51:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/01/21 23:53:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/01/24 14:03:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/01/24 14:03:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2011/02/17 13:40:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/29 08:00:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/10 00:43:35 | 000,000,000 | ---D | M]
[2011/01/18 12:36:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Extensions
[2011/01/18 12:36:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Extensions\[email protected]
[2011/06/13 11:29:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions
[2011/06/13 17:14:53 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\{220927fe-0336-4313-afbb-584997d6e20d}
[2011/01/07 02:14:03 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2011/01/08 03:06:02 | 000,000,000 | ---D | M] (User Agent Switcher) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/01/15 22:39:35 | 000,000,000 | ---D | M] (Make Address Bar Font Size Bigger) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\[email protected]
[2011/01/16 03:38:04 | 000,000,000 | ---D | M] (Chromifox Basic) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\[email protected]
[2011/05/12 23:27:14 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\[email protected]
[2011/03/13 16:22:51 | 000,000,000 | ---D | M] (Link Gopher) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\[email protected]
[2011/03/23 01:18:51 | 000,000,000 | ---D | M] (startup.service) -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\extensions\[email protected]
[2011/03/13 19:29:07 | 000,003,361 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\searchplugins\search-results.xml
[2011/03/24 16:06:47 | 000,002,193 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\Mozilla\Firefox\Profiles\157e1nb7.default\searchplugins\whois-whois.xml
[2011/05/09 22:46:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/13 00:46:14 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/02/14 10:08:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/07 20:42:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) --
[2011/02/17 13:40:28 | 000,000,000 | ---D | M] (Roboform Toolbar for Firefox) -- C:\PROGRAM FILES (X86)\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\{317B5128-0B0B-49B2-B2DB-1E7560E16C74}.XPI
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\{5C46D283-ABDE-4DCE-B83C-08881401921C}.XPI
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\{D57C9FF1-6389-48FC-B770-F78BD89B6E8A}.XPI
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\{EDA7B1D7-F793-4E03-B074-E6F303317FB0}.XPI
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\BIG-FELLA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\157E1NB7.DEFAULT\EXTENSIONS\[email protected]
[2011/04/29 08:00:55 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/03/27 19:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npContribute.dll
[2011/01/07 20:42:07 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/04/05 21:12:14 | 000,000,953 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 95.169.190.220 botmasternet.com
O1 - Hosts: 95.169.190.220 www.botmasternet.com
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - File not found
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (a85e4e23) - {B7AE28D3-883B-8B05-74FA-9A52D019E8AC} - C:\ProgramData\api-ms-win-core-localregistry-l1-1-032.dll (Malwarebytes Corporation)
O2 - BHO: (a85e4e23) - {E5549D37-6EC1-C9D5-2651-3D9EBD8CC982} - C:\ProgramData\api-ms-win-core-localregistry-l1-1-032.dll (Malwarebytes Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [FaxMonitor] C:\Program Files (x86)\IPFax\FaxMonitor.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SEnukeX] C:\Users\BIG-FELLA\AppData\Local\SENukeX\SENuke.exe ()
O4 - HKCU..\Run: [X1FileMonitor.exe] C:\Program Files (x86)\X1\X1FileMonitor.exe ()
O4 - Startup: C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\BIG-FELLA\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launchy.lnk = C:\Program Files (x86)\Launchy\Launchy.exe ()
O4 - Startup: C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\X1 System Tray.lnk = C:\Program Files (x86)\X1\X1Systray.exe (X1 Technologies, Inc.)
O4 - Startup: C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\X1.lnk = C:\Program Files (x86)\X1\X1.exe (X1 Technologies, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionName = Google Search
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionAction = http://www.google.com/search?q=%w
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: RoboForm Editor - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComEditIdent.html ()
O8:64bit: - Extra context menu item: RoboForm Options - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComOptions.html ()
O8:64bit: - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8:64bit: - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Editor - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComEditIdent.html ()
O8 - Extra context menu item: RoboForm Options - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComOptions.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComOptions.html ()
O9 - Extra 'Tools' menuitem : RoboForm Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComOptions.html ()
O9 - Extra Button: Editor - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComEditIdent.html ()
O9 - Extra 'Tools' menuitem : RoboForm Editor - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComEditIdent.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\ProgramData\api-ms-win-core-localregistry-l1-1-032.dll) - C:\ProgramData\api-ms-win-core-localregistry-l1-1-032.dll (Malwarebytes Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/06 22:17:34 | 018,866,176 | ---- | M] () - E:\Autospin[1].avi -- [ NTFS ]
O32 - AutoRun File - [2011/04/06 22:04:01 | 010,826,391 | ---- | M] () - E:\Autospin[1].swf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/15 23:15:52 | 000,173,056 | ---- | C] (Malwarebytes Corporation) -- C:\ProgramData\api-ms-win-core-localregistry-l1-1-032.dll
[2011/06/15 23:06:58 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/06/15 17:13:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Market Samurai
[2011/06/14 08:13:26 | 009,435,312 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\BIG-FELLA\Desktop\mbam-setup-1.51.0.1200.exe
[2011/06/13 11:29:09 | 000,788,992 | ---- | C] (Dmitry Streblechenko) -- C:\ProgramData\icm3232.exe
[2011/06/13 11:29:08 | 000,788,992 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\PresentationNative_v030032.exe
[2011/06/12 22:52:21 | 000,000,000 | ---D | C] -- C:\My eBooks
[2011/06/12 13:43:54 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Roaming\Launchy
[2011/06/12 13:43:52 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Launchy
[2011/06/12 13:43:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Launchy
[2011/06/12 13:32:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickOutlookToDo
[2011/06/05 16:52:49 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\New folder (3)
[2011/06/03 19:06:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartSound
[2011/06/03 10:20:07 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\2
[2011/06/01 13:35:55 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\eBook Testing
[2011/06/01 06:53:52 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\ebook compile
[2011/06/01 06:52:30 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\brian_ebook1
[2011/05/31 18:49:13 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\keywords
[2011/05/28 11:45:49 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\zvprt50
[2011/05/28 11:45:45 | 000,022,528 | ---- | C] (ZAN) -- C:\Windows\SysNative\zvprtmon5.dll
[2011/05/28 11:45:45 | 000,016,384 | ---- | C] (ZAN) -- C:\Windows\SysNative\zvprtmonui5.dll
[2011/05/28 11:45:41 | 000,000,000 | ---D | C] -- C:\Program Files\zvprt50
[2011/05/28 11:45:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IPFax
[2011/05/28 11:44:36 | 012,198,520 | ---- | C] (Acresso Software Inc.) -- C:\Users\BIG-FELLA\Desktop\IPFax14b1.exe
[2011/05/27 00:24:21 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Local\JonathanLeger.com
[2011/05/27 00:24:15 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Roaming\JonathanLeger.com
[2011/05/27 00:23:37 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheBestSpinner3
[2011/05/27 00:23:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TheBestSpinner3
[2011/05/27 00:23:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TheBestSpinner3
[2011/05/26 14:38:01 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\1
[2011/05/25 11:24:44 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Roaming\dvdcss
[2011/05/24 19:38:08 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\lower third
[2011/05/23 10:18:40 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\PushButtonBacklinksBlueprint
[2011/05/23 03:00:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011/05/22 16:17:59 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\Test Instruction
[2011/05/22 16:17:56 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\New folder (2)
[2011/05/22 10:17:40 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\AVI Backup
[2011/05/22 03:41:13 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2011/05/22 03:41:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2011/05/21 13:20:58 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\instantindexer
[2011/05/21 09:56:39 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\TVB
[2011/05/21 07:02:46 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\Videos
[2011/05/18 20:47:12 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Roaming\Broderbund
[2011/05/18 20:47:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Broderbund
[2011/05/18 20:46:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broderbund
[2011/05/18 20:46:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Broderbund
[2011/05/18 13:09:40 | 000,029,184 | ---- | C] (Arcamis Pty. Ltd.) -- C:\Users\BIG-FELLA\Desktop\yelper.exe
[2011/05/18 12:29:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuclear Ping Scheduler
[2011/05/18 12:29:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nuclear Ping Scheduler
[2011/05/18 10:29:20 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\AppData\Roaming\Adobe Mini Bridge CS5
[2011/05/18 10:19:17 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\sales page images
[2011/05/17 19:34:07 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\Credit Score
[2011/05/17 04:13:12 | 000,000,000 | ---D | C] -- C:\Users\BIG-FELLA\Desktop\images
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\BIG-FELLA\Desktop\*.tmp files -> C:\Users\BIG-FELLA\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/16 03:16:08 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/16 03:16:08 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/16 02:20:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1578988565-738332488-1354322868-1000UA.job
[2011/06/16 02:15:05 | 000,019,456 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/16 00:30:14 | 000,000,872 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1578988565-738332488-1354322868-1000Core.job
[2011/06/16 00:22:09 | 000,002,689 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\KeywordSnatcher.exe - Shortcut.lnk
[2011/06/16 00:17:47 | 000,002,029 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\SENukeX.lnk
[2011/06/15 23:16:01 | 000,000,362 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011/06/15 23:15:52 | 000,173,056 | ---- | M] (Malwarebytes Corporation) -- C:\ProgramData\api-ms-win-core-localregistry-l1-1-032.dll
[2011/06/15 23:15:52 | 000,000,135 | ---- | M] () -- C:\Windows\SysWow64\579012865
[2011/06/15 23:15:39 | 005,855,192 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/15 23:15:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/15 23:15:14 | 1060,544,510 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/15 23:07:17 | 000,799,252 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/15 23:07:17 | 000,664,638 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/06/15 23:07:17 | 000,122,406 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/06/15 07:02:53 | 000,002,034 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\SAS7_000.DAT
[2011/06/14 10:51:03 | 000,001,252 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/06/14 08:13:30 | 009,435,312 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\BIG-FELLA\Desktop\mbam-setup-1.51.0.1200.exe
[2011/06/14 07:28:19 | 000,000,019 | ---- | M] () -- C:\ProgramData\8ad1971
[2011/06/13 11:29:08 | 000,788,992 | ---- | M] (Dmitry Streblechenko) -- C:\Windows\SysWow64\PresentationNative_v030032.exe
[2011/06/13 11:29:08 | 000,788,992 | ---- | M] (Dmitry Streblechenko) -- C:\ProgramData\icm3232.exe
[2011/06/13 02:41:54 | 000,000,504 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\youtube.html
[2011/06/12 13:46:47 | 000,000,987 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launchy.lnk
[2011/06/11 13:15:03 | 000,017,772 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\Nemo.jpg
[2011/06/06 19:29:32 | 000,004,757 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\juicing for analysis.csv
[2011/06/06 13:18:36 | 000,246,198 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\_error.jpg
[2011/06/06 10:29:18 | 000,852,249 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\ebook-ads.jpg
[2011/06/05 19:52:25 | 013,682,804 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\valentine-homewood-rental.pdf
[2011/06/05 13:06:48 | 000,000,132 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011/06/05 11:04:53 | 000,002,836 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\theblackbox.rar
[2011/06/04 11:31:16 | 000,928,070 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\link-pyramid-original.psd
[2011/06/03 19:06:29 | 000,002,133 | ---- | M] () -- C:\Users\Public\Desktop\Sonicfire Pro 5.lnk
[2011/06/03 10:50:24 | 000,198,813 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\video.png
[2011/06/03 09:25:15 | 000,140,079 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\image-placeholder.jpg
[2011/06/01 08:29:35 | 000,293,026 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\picnic2.pdf
[2011/06/01 08:27:56 | 015,138,552 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\picnic1.pdf
[2011/06/01 06:36:51 | 001,494,891 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\brian_ebook1.zip
[2011/06/01 00:42:50 | 022,967,529 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\picnic.psd
[2011/06/01 00:39:31 | 020,579,119 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\picnic.pdf
[2011/06/01 00:11:04 | 000,052,353 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\picnic.jpg
[2011/05/31 18:51:44 | 000,004,786 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\breville juice fountain analysis.csv
[2011/05/31 18:48:59 | 000,048,328 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\keywords.zip
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/05/28 11:51:46 | 000,023,147 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\inbox.pdf
[2011/05/28 11:45:41 | 000,000,608 | -HS- | M] () -- C:\Windows\SysNative\winzvprt5.sys
[2011/05/28 11:45:41 | 000,000,160 | ---- | M] () -- C:\Windows\SysNative\zvprt5.ini
[2011/05/28 11:44:38 | 012,198,520 | ---- | M] (Acresso Software Inc.) -- C:\Users\BIG-FELLA\Desktop\IPFax14b1.exe
[2011/05/28 07:37:34 | 002,743,265 | ---- | M] () -- C:\Users\BIG-FELLA\.websiteauditor.properties
[2011/05/28 06:36:44 | 002,118,589 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\yelper.rar
[2011/05/26 16:59:49 | 000,236,243 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\C2CApp_Legal5.pdf
[2011/05/26 14:49:15 | 000,246,240 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/05/26 13:49:42 | 000,001,005 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/05/26 13:39:20 | 000,001,994 | -H-- | M] () -- C:\Users\BIG-FELLA\Documents\Default.rdp
[2011/05/24 23:20:30 | 000,008,573 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\test-intro.camproj
[2011/05/24 19:30:06 | 000,073,150 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\green screen.psd
[2011/05/23 11:41:58 | 007,266,635 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\sqlitebrowser_200_b1_win.zip
[2011/05/23 11:29:20 | 000,268,920 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\main_header.png
[2011/05/23 10:17:31 | 000,043,988 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\PushButtonBacklinksBlueprint.zip
[2011/05/23 10:15:01 | 000,062,407 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\Push Button Backlinks Blueprint.pdf
[2011/05/23 10:14:45 | 000,045,049 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\Push Button Backlinks Blueprint.mmap
[2011/05/23 09:20:24 | 000,444,417 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\21-premium-buttons-with-awesome-icons.zip
[2011/05/22 18:58:10 | 003,070,806 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\thanku1a.psd
[2011/05/22 18:55:02 | 000,439,073 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\thanku1.jpg
[2011/05/22 17:38:43 | 000,000,447 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\Untitled-1.html
[2011/05/22 16:49:55 | 002,355,618 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\thanku1.psd
[2011/05/22 16:28:11 | 000,300,510 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\snagit-snippet.bmp
[2011/05/22 16:14:23 | 004,848,871 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\Test-Video-Book.zip
[2011/05/22 16:07:17 | 001,262,805 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\emailebook.ebk
[2011/05/22 14:59:32 | 002,227,933 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\thanku.psd
[2011/05/22 03:06:12 | 000,772,802 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/21 14:56:36 | 000,000,542 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\push-button.xml
[2011/05/21 13:20:36 | 000,031,135 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\instantindexer.zip
[2011/05/20 19:56:06 | 000,500,195 | ---- | M] () -- C:\Users\BIG-FELLA\.spyglass.properties
[2011/05/20 14:35:31 | 000,207,703 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\2011-04-24_bill.pdf
[2011/05/19 10:14:58 | 000,000,132 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/05/18 13:09:49 | 000,029,184 | ---- | M] (Arcamis Pty. Ltd.) -- C:\Users\BIG-FELLA\Desktop\yelper.exe
[2011/05/18 12:48:33 | 000,001,456 | ---- | M] () -- C:\Users\BIG-FELLA\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/05/18 12:29:33 | 000,001,284 | ---- | M] () -- C:\Users\Public\Desktop\Nuclear Ping Scheduler.lnk
[2011/05/18 12:19:49 | 010,999,766 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\sales_HTML.psd
[2011/05/18 12:14:49 | 002,111,238 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\5-18-2011 12-13-14 PM.bmp
[2011/05/18 10:53:09 | 004,107,431 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\sales_HTML.zip
[2011/05/17 14:46:55 | 005,444,608 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\q.avi
[2011/05/17 04:22:45 | 000,004,168 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\affiliate.php
[2011/05/17 04:00:29 | 000,006,542 | ---- | M] () -- C:\Users\BIG-FELLA\Desktop\page_fullwidth.php
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\BIG-FELLA\Desktop\*.tmp files -> C:\Users\BIG-FELLA\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/15 17:13:26 | 000,000,903 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Market Samurai.lnk
[2011/06/13 16:29:55 | 000,000,019 | ---- | C] () -- C:\ProgramData\8ad1971
[2011/06/13 11:29:08 | 000,000,135 | ---- | C] () -- C:\Windows\SysWow64\579012865
[2011/06/13 02:41:54 | 000,000,504 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\youtube.html
[2011/06/12 13:43:52 | 000,000,987 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launchy.lnk
[2011/06/11 14:16:39 | 000,002,689 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\KeywordSnatcher.exe - Shortcut.lnk
[2011/06/11 13:15:03 | 000,017,772 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\Nemo.jpg
[2011/06/06 19:29:32 | 000,004,757 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\juicing for analysis.csv
[2011/06/06 13:18:23 | 000,246,198 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\_error.jpg
[2011/06/06 10:20:32 | 000,852,249 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\ebook-ads.jpg
[2011/06/05 19:52:23 | 013,682,804 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\valentine-homewood-rental.pdf
[2011/06/05 11:04:53 | 000,002,836 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\theblackbox.rar
[2011/06/04 11:31:14 | 000,928,070 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\link-pyramid-original.psd
[2011/06/03 19:06:29 | 000,002,133 | ---- | C] () -- C:\Users\Public\Desktop\Sonicfire Pro 5.lnk
[2011/06/03 10:50:17 | 000,198,813 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\video.png
[2011/06/03 09:25:04 | 000,140,079 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\image-placeholder.jpg
[2011/06/01 08:29:35 | 000,293,026 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\picnic2.pdf
[2011/06/01 08:27:51 | 015,138,552 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\picnic1.pdf
[2011/06/01 06:36:16 | 001,494,891 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\brian_ebook1.zip
[2011/06/01 00:42:48 | 022,967,529 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\picnic.psd
[2011/06/01 00:39:20 | 020,579,119 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\picnic.pdf
[2011/06/01 00:11:02 | 000,052,353 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\picnic.jpg
[2011/05/31 18:51:44 | 000,004,786 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\breville juice fountain analysis.csv
[2011/05/31 18:48:58 | 000,048,328 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\keywords.zip
[2011/05/30 11:42:10 | 000,859,541 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\TCP-Z-Patch.zip
[2011/05/28 11:51:46 | 000,023,147 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\inbox.pdf
[2011/05/28 11:45:41 | 000,000,608 | -HS- | C] () -- C:\Windows\SysNative\winzvprt5.sys
[2011/05/28 11:45:41 | 000,000,160 | ---- | C] () -- C:\Windows\SysNative\zvprt5.ini
[2011/05/28 06:36:16 | 002,118,589 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\yelper.rar
[2011/05/26 16:59:48 | 000,236,243 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\C2CApp_Legal5.pdf
[2011/05/24 23:20:29 | 000,008,573 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\test-intro.camproj
[2011/05/24 19:30:05 | 000,073,150 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\green screen.psd
[2011/05/23 11:41:56 | 007,266,635 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\sqlitebrowser_200_b1_win.zip
[2011/05/23 11:29:12 | 000,268,920 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\main_header.png
[2011/05/23 10:17:31 | 000,043,988 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\PushButtonBacklinksBlueprint.zip
[2011/05/23 10:14:56 | 000,062,407 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\Push Button Backlinks Blueprint.pdf
[2011/05/23 10:14:45 | 000,045,049 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\Push Button Backlinks Blueprint.mmap
[2011/05/23 09:20:23 | 000,444,417 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\21-premium-buttons-with-awesome-icons.zip
[2011/05/22 18:58:09 | 003,070,806 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\thanku1a.psd
[2011/05/22 18:55:01 | 000,439,073 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\thanku1.jpg
[2011/05/22 17:38:43 | 000,000,447 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\Untitled-1.html
[2011/05/22 16:47:48 | 002,355,618 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\thanku1.psd
[2011/05/22 16:20:20 | 000,300,510 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\snagit-snippet.bmp
[2011/05/22 16:07:15 | 001,262,805 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\emailebook.ebk
[2011/05/22 14:58:44 | 002,227,933 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\thanku.psd
[2011/05/21 14:56:35 | 000,000,542 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\push-button.xml
[2011/05/21 13:20:35 | 000,031,135 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\instantindexer.zip
[2011/05/20 14:29:58 | 000,207,703 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\2011-04-24_bill.pdf
[2011/05/18 12:29:33 | 000,001,284 | ---- | C] () -- C:\Users\Public\Desktop\Nuclear Ping Scheduler.lnk
[2011/05/18 12:19:45 | 010,999,766 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\sales_HTML.psd
[2011/05/18 12:13:14 | 002,111,238 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\5-18-2011 12-13-14 PM.bmp
[2011/05/18 10:51:45 | 004,107,431 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\sales_HTML.zip
[2011/05/17 14:46:39 | 005,444,608 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\q.avi
[2011/05/17 04:22:45 | 000,004,168 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\affiliate.php
[2011/05/17 04:00:29 | 000,006,542 | ---- | C] () -- C:\Users\BIG-FELLA\Desktop\page_fullwidth.php
[2011/05/11 14:04:54 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/05/11 10:14:17 | 000,001,456 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/04/09 19:43:10 | 000,000,175 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Local\TheBestSpinner_Export.dat
[2011/03/30 00:45:56 | 000,540,216 | ---- | C] () -- C:\Windows\SysWow64\amasrb32.dll
[2011/02/19 19:41:57 | 000,000,135 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2011/02/17 22:53:08 | 000,000,126 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2011/02/09 12:06:10 | 000,000,132 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011/02/02 03:22:36 | 000,000,024 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Roaming\Final Draft Tagger Preferences
[2011/01/28 17:47:38 | 000,025,004 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Roaming\QuickPreferences.xml
[2011/01/28 17:03:03 | 000,000,026 | -H-- | C] () -- C:\ProgramData\.811261211181235583101118113995
[2011/01/24 10:40:16 | 000,000,132 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/01/19 18:56:13 | 000,019,456 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/08 01:40:00 | 000,000,362 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/01/08 00:04:32 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2011/01/07 23:42:06 | 000,246,240 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/01/07 12:44:00 | 000,002,034 | ---- | C] () -- C:\Users\BIG-FELLA\AppData\Roaming\SAS7_000.DAT
[2011/01/07 02:48:37 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/01/07 02:23:15 | 000,772,802 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2008/01/08 11:47:54 | 002,143,112 | ---- | C] () -- C:\Windows\SysWow64\ambpa32.exe
========== LOP Check ==========
[2011/01/15 11:54:15 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\59108B17-78CB-4CA0-9273-8F2034A12930
[2011/01/08 14:40:07 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Acronis
[2011/01/20 14:26:52 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Babylon
[2011/05/18 20:47:12 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Broderbund
[2011/04/27 09:00:26 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/01/08 15:00:37 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\ConceptDraw Project 6
[2011/01/07 02:36:40 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\DAEMON Tools Lite
[2011/06/14 09:26:17 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\DMCache
[2011/01/07 23:31:01 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\DomainSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/06/15 23:17:20 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Dropbox
[2011/06/13 17:18:52 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\eBookPro6
[2011/03/18 21:53:55 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\EurekaLog
[2011/01/15 21:31:08 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Extrapolator
[2011/06/13 16:24:20 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\FileZilla
[2011/01/28 17:03:17 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Final Draft
[2011/01/07 20:12:58 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\GlobalSCAPE
[2011/05/11 12:26:40 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\HandBrake
[2011/04/23 01:02:59 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\IDM
[2011/04/07 15:32:43 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\ImTOO
[2011/01/24 09:30:01 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\ImTOO Software Studio
[2011/05/27 00:24:15 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\JonathanLeger.com
[2011/06/12 13:46:28 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Launchy
[2011/01/07 11:01:31 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Leadertech
[2011/01/24 14:03:20 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Local
[2011/01/07 03:03:40 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/01/09 16:05:28 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\NCH Swift Sound
[2011/05/11 14:12:51 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Netscape
[2011/03/22 09:43:31 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Niche
[2011/01/07 15:29:21 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Notepad++
[2011/01/07 12:15:26 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Nuance
[2011/02/14 10:31:44 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\OpenOffice.org
[2011/01/08 00:04:32 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\PACE Anti-Piracy
[2011/01/19 13:02:16 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Photodex
[2011/06/12 15:56:09 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\ScrapeBoard
[2011/03/22 14:26:46 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Sincell
[2011/01/08 00:03:05 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/01/28 17:46:32 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\StoryBoard Quick
[2011/05/18 13:40:15 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\TeamViewer
[2011/02/01 07:19:53 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Thinstall
[2011/02/11 20:35:13 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Toon Boom Animation
[2011/01/07 03:35:57 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\ubot
[2011/05/17 01:18:35 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Windows Live Writer
[2011/03/13 11:06:41 | 000,000,000 | -HSD | M] -- C:\Users\BIG-FELLA\AppData\Roaming\wyUpdate AU
[2011/03/24 15:59:02 | 000,000,000 | ---D | M] -- C:\Users\BIG-FELLA\AppData\Roaming\Xilisoft
[2011/05/11 13:58:41 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 906 bytes -> C:\ProgramData\Microsoft:eDonaRieGv2masdDaZy7
@Alternate Data Stream - 905 bytes -> C:\Users\BIG-FELLA\AppData\Local\4Lqk3QFWjQE:Q3HAw0YZDviX3Rrv7Y2anxDwt
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:0FF263E8
@Alternate Data Stream - 1145 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:ZdImm42dTvdHOoTrG3RdIL4dc8K
@Alternate Data Stream - 1119 bytes -> C:\ProgramData\Microsoft:t4XyDzPIRSStKOodd
@Alternate Data Stream - 1091 bytes -> C:\ProgramData\Microsoft:0fMRyQxzzmKFcCHzKHFzgVDNd
@Alternate Data Stream - 1006 bytes -> C:\ProgramData\Microsoft:zM25r3uAmoa3qDJ1VvHYqMe
< End of report >