Part two:
O1 HOSTS File: ([2010/06/13 16:42:52 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [dldtamon] C:\Program Files\Dell V305\dldtamon.exe ()
O4 - HKLM..\Run: [dldtmon.exe] C:\Program Files\Dell V305\dldtmon.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSN Toolbar] C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident\4.0; GTB6.4; Mozilla\4.0 ( File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE}
http://www.worldwinner.com/games/v47/scrabblecubes/scrabblecubes.cab (ScrabbleCubes Control)
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1}
http://www.worldwinner.com/games/v50/pool/pool.cab (Pool Control)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158}
http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B}
http://www.worldwinner.com/games/v56/spidersolitaire/spidersolitaire.cab (SpiderSolitaire Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB}
http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280}
http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B}
http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (WordMojo Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03}
http://www.worldwinner.com/games/v51/bejeweledtwist/bejeweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39}
http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47}
http://www.worldwinner.com/games/v52/dinerdash/dinerdash.cab (DinerDash Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916}
http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-us.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Forest Flowers.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Forest Flowers.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ==========
[2010/06/13 16:38:03 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/06/13 16:34:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/06/13 13:13:13 | 000,572,416 | ---- | C] (OldTimer Tools) -- C:\Users\Sandy\Desktop\OTL.exe
[2010/06/13 12:54:20 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/06/13 12:54:20 | 000,000,000 | ---D | C] -- C:\Users\Sandy\AppData\Local\temp
[2010/06/13 12:53:36 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/06/13 12:15:16 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/06/13 12:15:12 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/06/13 11:14:26 | 000,000,000 | ---D | C] -- C:\ProgramData\WinZip
[2010/06/13 11:14:24 | 000,000,000 | ---D | C] -- C:\Program Files\WinZip
[2010/06/13 10:07:04 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2010/06/13 10:06:59 | 000,124,784 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2010/06/13 10:06:58 | 000,060,936 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2010/06/13 10:06:58 | 000,051,992 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntdd.sys
[2010/06/13 10:06:58 | 000,017,016 | ---- | C] (AVIRA GmbH) -- C:\Windows\System32\drivers\avgntmgr.sys
[2010/06/13 10:06:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2010/06/13 10:06:56 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2010/05/31 10:41:12 | 000,998,736 | ---- | C] (Kaspersky Lab) -- C:\Users\Sandy\Desktop\TDSSKiller.exe
[2010/05/14 12:04:31 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/05/14 09:10:35 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2010/05/14 09:10:35 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2010/05/14 09:10:33 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2010/05/12 15:00:02 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2010/05/12 12:43:25 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2010/05/12 11:06:46 | 000,000,000 | ---D | C] -- C:\Users\Sandy\AppData\Roaming\Malwarebytes
[2010/05/12 11:06:35 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/12 11:06:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/05/12 11:06:33 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/05/12 11:06:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/12 10:23:11 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Sandy\Desktop\mbam-setup.exe
[2010/05/12 10:19:23 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Users\Sandy\Desktop\TFC.exe
[2010/05/12 10:00:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2010/05/12 10:00:14 | 000,000,000 | ---D | C] -- C:\Users\Sandy\Office Genuine Advantage
[2010/04/12 09:37:00 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/04/12 09:36:57 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/12 09:33:52 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/03/18 14:35:52 | 000,987,136 | ---- | C] (Creative Development LTD) -- C:\Windows\System32\CRDE2000.dll
[2010/03/18 14:35:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Cosmi
[2010/03/18 14:35:12 | 000,000,000 | ---D | C] -- C:\Program Files\Cosmi
[2010/03/18 14:34:51 | 000,299,520 | ---- | C] (InstallShield Corporation, Inc.) -- C:\Windows\uninst.exe
[2010/03/17 17:14:58 | 000,000,000 | ---D | C] -- C:\Users\Sandy\Desktop\Documents\My Games
[2010/03/17 17:14:46 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/03/17 17:00:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2010/03/17 17:00:04 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar
[2010/03/17 16:59:18 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar Installer
[2010/03/17 16:59:04 | 000,000,000 | ---D | C] -- C:\Program Files\Nick Arcade
[2009/06/23 08:28:49 | 000,438,272 | ---- | C] ( ) -- C:\Windows\System32\DLDThcp.dll
[2009/06/23 08:28:48 | 000,843,776 | ---- | C] ( ) -- C:\Windows\System32\dldtusb1.dll
[2009/06/23 08:28:48 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\dldtinpa.dll
[2009/06/23 08:28:48 | 000,339,968 | ---- | C] ( ) -- C:\Windows\System32\dldtiesc.dll
[2009/06/23 08:28:47 | 001,105,920 | ---- | C] ( ) -- C:\Windows\System32\dldtserv.dll
[2009/06/23 08:28:47 | 000,647,168 | ---- | C] ( ) -- C:\Windows\System32\dldtpmui.dll
[2009/06/23 08:28:47 | 000,569,344 | ---- | C] ( ) -- C:\Windows\System32\dldtlmpm.dll
[2009/06/23 08:28:47 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\dldtprox.dll
[2009/06/23 08:28:45 | 000,663,552 | ---- | C] ( ) -- C:\Windows\System32\dldthbn3.dll
[2009/06/23 08:28:43 | 000,851,968 | ---- | C] ( ) -- C:\Windows\System32\dldtcomc.dll
[2009/06/23 08:28:43 | 000,376,832 | ---- | C] ( ) -- C:\Windows\System32\dldtcomm.dll
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/06/13 16:45:42 | 005,505,024 | -HS- | M] () -- C:\Users\Sandy\NTUSER.DAT
[2010/06/13 16:44:02 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/13 16:43:58 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 16:43:58 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 16:43:55 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/06/13 16:43:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/06/13 16:43:05 | 000,524,288 | -HS- | M] () -- C:\Users\Sandy\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2010/06/13 16:43:05 | 000,065,536 | -HS- | M] () -- C:\Users\Sandy\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2010/06/13 16:42:52 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2010/06/13 16:13:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/13 13:23:16 | 000,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/06/13 13:23:16 | 000,595,446 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/06/13 13:23:16 | 000,101,144 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/06/13 13:14:54 | 001,690,291 | -H-- | M] () -- C:\Users\Sandy\AppData\Local\IconCache.db
[2010/06/13 13:13:13 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Users\Sandy\Desktop\OTL.exe
[2010/06/13 12:51:52 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/06/13 12:01:18 | 000,966,213 | ---- | M] () -- C:\Users\Sandy\Desktop\tdsskiller.zip
[2010/06/13 11:17:14 | 000,003,792 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\attach.zip
[2010/06/13 11:14:35 | 000,001,816 | ---- | M] () -- C:\Users\Public\Desktop\WinZip.lnk
[2010/06/13 11:13:07 | 014,501,192 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\winzip145.exe
[2010/06/13 10:24:23 | 001,374,664 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\MCPR.exe
[2010/06/13 10:07:16 | 000,001,809 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010/06/13 07:47:43 | 000,000,680 | ---- | M] () -- C:\Users\Sandy\AppData\Local\d3d9caps.dat
[2010/06/13 07:10:52 | 216,767,264 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/05/31 10:41:12 | 000,998,736 | ---- | M] (Kaspersky Lab) -- C:\Users\Sandy\Desktop\TDSSKiller.exe
[2010/05/25 15:22:14 | 000,104,448 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\Budget 2010.xls
[2010/05/19 01:32:31 | 000,012,455 | ---- | M] () -- C:\Users\Sandy\Desktop\TO DO for new house.docx
[2010/05/19 01:16:46 | 000,293,376 | ---- | M] () -- C:\Users\Sandy\Desktop\q2uropj4.exe
[2010/05/14 09:14:42 | 000,345,400 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/05/12 11:06:37 | 000,000,820 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/12 10:23:14 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Sandy\Desktop\mbam-setup.exe
[2010/05/12 10:19:07 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Users\Sandy\Desktop\TFC.exe
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/24 06:11:41 | 000,002,627 | ---- | M] () -- C:\Users\Sandy\Desktop\Word.lnk
[2010/04/23 06:59:20 | 000,012,748 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\camp list.docx
[2010/04/13 20:01:03 | 000,649,245 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\2010_Parent_Packet.docx
[2010/04/12 09:38:01 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/04/12 09:34:29 | 000,001,728 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/03/29 07:56:19 | 000,060,928 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\address label list.DOC
[2010/03/25 14:22:53 | 000,042,066 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\ScoutRegForm-Zoo.pdf
[2010/03/23 19:32:50 | 000,040,258 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\yoda.docx
[2010/03/16 00:34:48 | 000,020,992 | ---- | M] () -- C:\Users\Sandy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/15 23:50:35 | 000,076,191 | ---- | M] () -- C:\Windows\System32\LexFiles.ulf
[2010/03/15 23:49:10 | 082,457,840 | ---- | M] () -- C:\Users\Sandy\Desktop\Documents\R190176.exe
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[10 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]