Part#2
========== Chrome ==========
CHR - homepage:
http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Mary Furlani\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Angry Birds = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: YouTube = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: FARMERAMA = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\clkfdgnfefjmciocbhnffnbpkjpdleca\1.0.2_0\
CHR - Extension: Black Op 2 [Aero] = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\coaadeeafmpgfdphmnbedkjigaekbjhi\2.5_0\
CHR - Extension: Ricerca Google = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Smiley Bar for Facebook = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgojaaaiddhmiiakpejiklijbalpckih\1.0.0.3_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Skype Click to Call = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: Gmail = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Angry Birds = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: YouTube = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: FARMERAMA = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\clkfdgnfefjmciocbhnffnbpkjpdleca\1.0.2_0\
CHR - Extension: Black Op 2 [Aero] = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\coaadeeafmpgfdphmnbedkjigaekbjhi\2.5_0\
CHR - Extension: Ricerca Google = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Smiley Bar for Facebook = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgojaaaiddhmiiakpejiklijbalpckih\1.0.0.3_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Skype Click to Call = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: Gmail = C:\Users\Mary Furlani\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2012/12/16 03:41:04 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [Acer ePower Management] C:\Programmi\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-3803936383-525343685-1314348786-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3803936383-525343685-1314348786-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3803936383-525343685-1314348786-1000..\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe ()
O4 - HKU\S-1-5-21-3803936383-525343685-1314348786-1000..\RunOnce: [spchecker] "C:\Program Files (x86)\AVG\AVG10\Notification\SPCheckerTE.exe" File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3803936383-525343685-1314348786-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3803936383-525343685-1314348786-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3803936383-525343685-1314348786-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programmi\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programmi\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.101.93.101 83.103.25.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2188C499-947A-420C-899F-3EC090128049}: NameServer = 193.70.152.25 212.52.97.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4126A863-A29A-4790-897D-CE73BCDA9E5E}: NameServer = 193.70.152.25 212.52.97.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{66E43F8C-E5CD-454F-83ED-7080475BFC5C}: DhcpNameServer = 62.101.93.101 83.103.25.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FAAD2573-63F5-426F-99D8-C9EAEC636ED8}: NameServer = 212.52.97.25 193.70.152.25
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmi\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/12/16 12:52:34 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mary Furlani\Desktop\OTL.exe
[2012/12/16 05:53:09 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/12/16 05:11:04 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\AVG2013
[2012/12/16 05:10:05 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\TuneUp Software
[2012/12/16 05:10:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/12/16 05:08:31 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/12/16 05:08:30 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2012/12/16 05:06:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2012/12/16 05:03:45 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012/12/16 04:05:28 | 011,563,944 | ---- | C] (OPSWAT, Inc.) -- C:\Users\Mary Furlani\Desktop\AppRemover.exe
[2012/12/16 03:25:51 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/12/16 03:25:51 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/12/16 03:25:51 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/12/16 03:23:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/12/16 03:22:51 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/12/16 03:13:56 | 005,010,912 | R--- | C] (Swearware) -- C:\Users\Mary Furlani\Desktop\ComboFix.exe
[2012/12/16 00:37:27 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\Desktop\RK_Quarantine
[2012/12/16 00:30:09 | 004,732,416 | ---- | C] (AVAST Software) -- C:\Users\Mary Furlani\Desktop\aswMBR.exe
[2012/12/15 23:04:31 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\Desktop\mbar-1.01.0.1011
[2012/12/15 22:36:26 | 000,000,000 | R--D | C] -- C:\Users\Mary Furlani\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/12/15 22:36:26 | 000,000,000 | R--D | C] -- C:\Users\Mary Furlani\Documents
[2012/12/15 22:32:10 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Local\{93FF7903-ABCA-4ED0-8869-CCABD082B294}
[2012/12/15 08:14:35 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\Malwarebytes
[2012/12/14 23:54:31 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/12/14 23:36:06 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\LeeGT-Games
[2012/12/14 04:05:23 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\PerformerSoft
[2012/12/14 04:05:21 | 000,019,000 | ---- | C] (PerformerSoft LLC) -- C:\Windows\SysNative\roboot64.exe
[2012/12/14 04:05:19 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\StatusWinks
[2012/12/14 04:05:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\File Scout
[2012/12/13 02:24:24 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\WiiSports101in1
[2012/12/13 02:24:24 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\Jewels of the East India Company
[2012/12/12 14:54:33 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Local\{FBC755B0-8465-42F3-BA28-4104ACDACE5C}
[2012/12/03 14:15:06 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Delicious 7- Emilys True Love - Premium Edition
[2012/12/01 01:15:13 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Delicious 8- Emily's Wonder Wedding Premium Edition
[2012/12/01 01:14:48 | 000,000,000 | ---D | C] -- C:\Windows\Delicious 8- Emily's Wonder Wedding Premium Edition
[2012/12/01 01:14:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Delicious 8- Emily's Wonder Wedding Premium Edition
[2012/11/30 10:02:52 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Local\{A961CD49-8822-4B65-BCDA-9F959A15EA76}
[2012/11/27 03:03:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Islands
[2012/11/26 19:19:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/11/26 19:19:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/11/26 15:35:15 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Local\{6D30398F-6381-4383-BFF5-4D2F6B5FFD1B}
[2012/11/25 02:15:41 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\Realore All My Gods
[2012/11/23 22:48:22 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\EscapeTheMuseum2
[2012/11/23 21:46:15 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\ShockwaveAllMyGods
[2012/11/19 13:29:01 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Local\{DCB35AD6-CC98-4D04-BA39-5B4306729BF6}
[2012/11/18 23:19:07 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\BlamGames
[2012/11/18 23:17:59 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1017
[2012/11/18 23:17:32 | 000,000,000 | ---D | C] -- C:\Windows\A Gnome's Home - The Great Crystal Crusade
[2012/11/17 02:12:15 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\northern_tale_realore_en
[2012/11/17 02:11:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxy Games
[2012/11/17 01:11:21 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Roaming\northerntale_shockwave_en
[2012/11/16 14:44:31 | 000,000,000 | ---D | C] -- C:\Users\Mary Furlani\AppData\Local\{5904247A-BED9-45E0-88E9-284F45283FB9}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/12/16 13:02:17 | 001,541,444 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/12/16 13:02:17 | 000,698,804 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat
[2012/12/16 13:02:17 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/12/16 13:02:17 | 000,127,998 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat
[2012/12/16 13:02:17 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/12/16 12:55:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/12/16 12:55:13 | 2962,259,968 | -HS- | M] () -- C:\hiberfil.sys
[2012/12/16 12:51:57 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mary Furlani\Desktop\OTL.exe
[2012/12/16 12:51:51 | 000,545,819 | ---- | M] () -- C:\Users\Mary Furlani\Desktop\adwcleaner.exe
[2012/12/16 12:51:02 | 000,001,188 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3803936383-525343685-1314348786-1001UA.job
[2012/12/16 12:50:53 | 000,000,978 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/16 04:22:21 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/16 04:22:21 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/16 04:05:34 | 000,000,009 | ---- | M] () -- C:\END
[2012/12/16 04:05:01 | 011,563,944 | ---- | M] (OPSWAT, Inc.) -- C:\Users\Mary Furlani\Desktop\AppRemover.exe
[2012/12/16 03:41:04 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/12/16 03:13:16 | 005,010,912 | R--- | M] (Swearware) -- C:\Users\Mary Furlani\Desktop\ComboFix.exe
[2012/12/16 02:55:49 | 000,000,512 | ---- | M] () -- C:\Users\Mary Furlani\Desktop\MBR.dat
[2012/12/16 00:49:39 | 538,975,332 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/12/16 00:29:39 | 004,732,416 | ---- | M] (AVAST Software) -- C:\Users\Mary Furlani\Desktop\aswMBR.exe
[2012/12/16 00:28:20 | 000,755,712 | ---- | M] () -- C:\Users\Mary Furlani\Desktop\RogueKiller.exe
[2012/12/15 18:15:53 | 000,001,136 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3803936383-525343685-1314348786-1001Core.job
[2012/12/15 08:22:44 | 005,072,424 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/11 11:32:30 | 010,998,441 | ---- | M] () -- C:\Users\Mary Furlani\Desktop\Celtic Woman - You Raise Me Up - Instrumental with lyrics (Karaoke) - YouTube.mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/16 12:52:34 | 000,545,819 | ---- | C] () -- C:\Users\Mary Furlani\Desktop\adwcleaner.exe
[2012/12/16 04:05:32 | 000,000,009 | ---- | C] () -- C:\END
[2012/12/16 03:25:51 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/12/16 03:25:51 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/12/16 03:25:51 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/12/16 03:25:51 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/12/16 03:25:51 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/12/16 02:28:10 | 000,000,512 | ---- | C] () -- C:\Users\Mary Furlani\Desktop\MBR.dat
[2012/12/16 00:28:40 | 000,755,712 | ---- | C] () -- C:\Users\Mary Furlani\Desktop\RogueKiller.exe
[2012/12/11 11:32:25 | 010,998,441 | ---- | C] () -- C:\Users\Mary Furlani\Desktop\Celtic Woman - You Raise Me Up - Instrumental with lyrics (Karaoke) - YouTube.mp3
[2012/09/14 17:31:31 | 000,805,888 | -H-- | C] () -- C:\Users\Mary Furlani\AppData\Roaming\base_en.db
[2012/08/25 02:40:10 | 000,001,978 | ---- | C] () -- C:\Program Files\Adobe Reader 9.lnk
[2012/07/29 22:01:45 | 000,001,062 | ---- | C] () -- C:\Users\Mary Furlani\Musica - collegamento.lnk
[2012/07/24 23:14:38 | 000,001,079 | ---- | C] () -- C:\Users\Mary Furlani\Immagini - collegamento.lnk
[2012/03/16 15:03:30 | 000,602,638 | ---- | C] () -- C:\Windows\SysWow64\avformat-52.dll
[2012/03/16 15:03:30 | 000,168,462 | ---- | C] () -- C:\Windows\SysWow64\swscale-0.dll
[2012/03/16 15:03:30 | 000,052,750 | ---- | C] () -- C:\Windows\SysWow64\avutil-50.dll
[2012/03/16 15:03:30 | 000,012,302 | ---- | C] () -- C:\Windows\SysWow64\avdevice-52.dll
[2012/03/16 15:03:29 | 003,511,822 | ---- | C] () -- C:\Windows\SysWow64\avcodec-52.dll
[2012/02/06 14:11:12 | 000,000,020 | ---- | C] () -- C:\Windows\mafosav.INI
[2012/01/20 02:45:52 | 000,003,584 | ---- | C] () -- C:\Users\Mary Furlani\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/08 01:28:23 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
========== ZeroAccess Check ==========
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/11/05 00:20:51 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\A Princess Tale
[2012/09/08 01:29:54 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\adelantado_shockwave_en
[2011/10/06 17:07:17 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Alawar
[2012/10/27 23:11:15 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Alawar Stargaze
[2012/11/19 22:42:30 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\AlawarEntertainment
[2011/08/31 20:11:39 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\AlderGames
[2012/04/05 21:17:54 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Anarchy
[2011/06/16 09:48:46 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Anthropics
[2012/10/14 21:57:41 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Anuman
[2012/01/13 01:10:53 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\AVG
[2012/12/16 05:11:04 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\AVG2013
[2011/08/11 01:43:52 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\avidemux
[2012/11/18 23:19:07 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\BlamGames
[2012/05/19 12:15:30 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Blue Cat Audio
[2012/10/28 17:57:47 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Boolat Games
[2011/08/05 22:46:52 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\BowWow
[2012/05/29 22:19:12 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\casualArts
[2011/06/21 22:59:36 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/15 12:10:46 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/08/05 23:52:59 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Crown
[2011/11/19 14:33:33 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\DAEMON Tools Lite
[2011/09/22 00:13:22 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\DragonsEye Studios
[2011/08/10 21:36:18 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\EleFun Games
[2011/12/25 23:18:35 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\elvesinc
[2011/12/28 21:58:18 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\ERS G-Studio
[2012/11/23 22:48:22 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\EscapeTheMuseum2
[2011/09/26 12:00:41 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Farm Mania 2
[2011/09/27 00:53:09 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Farm Mania 2.1
[2012/01/14 17:36:47 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\FileZilla
[2011/10/06 15:49:15 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\freshgames
[2011/10/09 09:58:07 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Friday's games
[2012/08/29 22:11:43 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\funkitron
[2011/10/07 00:43:09 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\GreenSauceGames
[2012/10/07 22:35:21 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Happy Artist Studio
[2012/01/25 00:37:33 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Happy Chef
[2012/07/28 13:54:40 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Hidden Objects 80days
[2012/10/18 00:07:24 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Hidden Objects Adventure
[2012/07/27 17:40:04 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Hidden Objects Alice
[2012/05/19 12:15:46 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\HighAndes
[2011/12/26 22:58:12 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\JaiboGames
[2011/09/06 22:02:50 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Jane s Hotel 3
[2012/12/13 02:24:28 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Jewels of the East India Company
[2012/01/09 00:51:04 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\JQ
[2012/06/28 23:02:09 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Jumb-O-Fun Games
[2012/12/14 23:36:06 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\LeeGT-Games
[2012/05/27 17:20:02 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\LegacyGames
[2011/07/14 00:08:58 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Ludia
[2012/01/20 03:37:04 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\MAGIX
[2011/06/21 21:30:41 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Manifesto Games
[2012/08/30 00:49:03 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Maximize Games
[2011/06/15 13:38:07 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Media Get LLC
[2012/11/27 03:07:12 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Merscom
[2012/11/06 23:56:24 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\MumboJumbo
[2012/06/24 01:26:03 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\MusicNet
[2011/07/13 02:36:53 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\NevoSoft
[2012/11/17 01:11:37 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\northerntale_shockwave_en
[2012/11/17 08:12:49 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\northern_tale_realore_en
[2012/03/23 15:05:07 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\nswb
[2012/10/08 11:23:25 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Oberon Media
[2012/09/14 00:04:44 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Peace Craft
[2012/09/14 01:17:17 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\PeaceCraft3
[2012/12/14 04:50:45 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\PerformerSoft
[2011/09/14 01:20:06 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Ph03nixNewMedia
[2012/11/27 15:15:15 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\PlayFirst
[2011/10/28 00:29:36 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\playmink
[2012/01/20 03:17:44 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Publish Providers
[2012/07/27 16:00:53 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Shockwave
[2012/11/23 21:49:31 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\ShockwaveAllMyGods
[2011/07/31 01:45:54 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Shockwave_DressUpRush
[2012/01/20 03:20:58 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Sony
[2011/07/13 23:19:34 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\SpinTop Games
[2011/07/13 01:21:29 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Stand O'Food 3
[2012/12/14 04:05:19 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\StatusWinks
[2012/10/07 23:56:14 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\SulusGames
[2012/12/16 05:10:05 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\TuneUp Software
[2011/10/06 16:18:07 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Twilight Games
[2012/01/11 23:53:25 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\URSE Games
[2011/08/03 00:26:20 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Vasilek Games
[2011/06/29 21:36:08 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\ViquaSoft
[2012/06/09 02:28:21 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\WeatherLord
[2012/12/13 02:24:24 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\WiiSports101in1
[2011/06/20 00:23:32 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\Windows Live Writer
[2012/08/25 22:20:57 | 000,000,000 | ---D | M] -- C:\Users\Mary Furlani\AppData\Roaming\YoudaGames
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp

F01DCBC
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:3ABC2192
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:F6A0889A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:EB68CA55
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:77183025
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:3B07E6F4
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:E153075C
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:A1CD17F9
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:0B9176C0
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:E5BA9ADD
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:28819F45
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:E3C56885
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:3B5038B1
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:E40EED9B
< End of report >