This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

malware, homepage redirect - flyingincognitosleep.com

45 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

We seem to be having a pretty major malware problem. Avira started detecting events this morning and there is a long list I can post here. We have at least one unwanted program that downloaded while we were at work- whitesmoke translator. IE has been blocked by the windows firewall and mozilla homepage has been redirected to www.flyingincognitosleep.com

I will post the avira info then follow your directions.

Any help would be greatly appreciated.



Exported events:

1/19/2011 8:03 PM [Scanner] Malware found
The file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\18\1a3207d2-2f51718d'
contained a virus or unwanted program 'JAVA/Small.Z' [virus]
Action(s) taken:
The file was moved to the quarantine directory under the name '47a93cdd.qua'.

1/19/2011 6:44 PM [Scanner] Malware found
The file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\58\1554d1ba-6119eb31'
contained a virus or unwanted program 'JAVA/OpenConnect.AI' [virus]
Action(s) taken:
The file was moved to the quarantine directory under the name '47aa2137.qua'.

1/19/2011 8:20 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ihnj\setup.exe.
Action performed: Allow access

1/19/2011 8:20 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ihnj\setup.exe.
Action performed: Deny access

1/19/2011 8:20 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ihnj\setup.exe.
Action performed: Deny access

1/19/2011 8:10 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ppju\setup.exe.
Action performed: Allow access

1/19/2011 8:10 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ppju\setup.exe.
Action performed: Deny access

1/19/2011 8:10 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ppju\setup.exe.
Action performed: Deny access

1/19/2011 8:00 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\nfpw\setup.exe.
Action performed: Allow access

1/19/2011 8:00 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\nfpw\setup.exe.
Action performed: Deny access

1/19/2011 8:00 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\nfpw\setup.exe.
Action performed: Deny access

1/19/2011 7:50 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ahrx\setup.exe.
Action performed: Allow access

1/19/2011 7:50 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ahrx\setup.exe.
Action performed: Deny access

1/19/2011 7:50 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ahrx\setup.exe.
Action performed: Deny access

1/19/2011 7:40 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\vkyq\setup.exe.
Action performed: Allow access

1/19/2011 7:40 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\vkyq\setup.exe.
Action performed: Deny access

1/19/2011 7:40 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\vkyq\setup.exe.
Action performed: Deny access

1/19/2011 7:30 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\pash\setup.exe.
Action performed: Allow access

1/19/2011 7:30 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\pash\setup.exe.
Action performed: Deny access

1/19/2011 7:30 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\pash\setup.exe.
Action performed: Deny access

1/19/2011 7:20 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\kgtr\setup.exe.
Action performed: Allow access

1/19/2011 7:20 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\kgtr\setup.exe.
Action performed: Deny access

1/19/2011 7:20 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\kgtr\setup.exe.
Action performed: Deny access

1/19/2011 7:10 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ggsn\setup.exe.
Action performed: Allow access

1/19/2011 7:10 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ggsn\setup.exe.
Action performed: Deny access

1/19/2011 7:10 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\ggsn\setup.exe.
Action performed: Deny access

1/19/2011 7:00 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\batf\setup.exe.
Action performed: Allow access

1/19/2011 7:00 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\batf\setup.exe.
Action performed: Deny access

1/19/2011 7:00 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\batf\setup.exe.
Action performed: Deny access

1/19/2011 6:50 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\iyuq\setup.exe.
Action performed: Deny access

1/19/2011 6:50 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\iyuq\setup.exe.
Action performed: Deny access

1/19/2011 6:50 AM [Guard] Malware found
Virus or unwanted program 'TR/Dldr.Harnig.S.14 [trojan]'
detected in file 'C:\WINDOWS\temp\iyuq\setup.exe.
Action performed: Allow access

1/19/2011 6:48 AM [Scanner] Malware found
The file 'C:\WINDOWS\temp\0.9508023469067646.exe'
contained a virus or unwanted program 'TR/Vundo.Gen' [trojan]
Action(s) taken:
The file was moved to the quarantine directory under the name '574f531c.qua'.

1/19/2011 6:48 AM [Scanner] Malware found
The file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\34\67113ae2-5ce8fd2d'
contained a virus or unwanted program 'TR/Vundo.Gen' [trojan]
Action(s) taken:
The file was moved to the quarantine directory under the name '4fd07c83.qua'.

1/19/2011 6:47 AM [Guard] Malware found
Virus or unwanted program 'TR/Vundo.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.9508023469067646.exe.
Action performed: Deny access

1/19/2011 6:47 AM [Guard] Malware found
Virus or unwanted program 'TR/Vundo.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.9508023469067646.exe.
Action performed: Allow access

1/19/2011 6:47 AM [Guard] Malware found
Virus or unwanted program 'TR/Vundo.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.9508023469067646.exe.
Action performed: Deny access

1/19/2011 6:47 AM [Guard] Malware found
Virus or unwanted program 'TR/Vundo.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\jar_cache7313325374916226741.tmp.
Action performed: Allow access

1/19/2011 6:47 AM [Guard] Malware found
Virus or unwanted program 'TR/Vundo.Gen [trojan]'
detected in file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\34\67113ae2-5ce8fd2d-temp.
Action performed: Allow access

1/19/2011 6:47 AM [Guard] Malware found
Virus or unwanted program 'TR/Vundo.Gen [trojan]'
detected in file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\34\67113ae2-5ce8fd2d.
Action performed: Allow access

1/19/2011 6:35 AM [Scanner] Malware found
The file 'C:\WINDOWS\temp\21.862796099677823.exe'
contained a virus or unwanted program 'TR/Dropper.Gen' [trojan]
Action(s) taken:
An error has occurred and the file was not deleted. ErrorID: 26004.
The source file could not be found.
Attempting to perform action using the ARK library.
The file could not be copied to quarantine!
The file does not exist!

1/19/2011 6:31 AM [Scanner] Malware found
The file 'C:\WINDOWS\temp\0.26533051345930936.exe'
contained a virus or unwanted program 'TR/Dropper.Gen' [trojan]
Action(s) taken:
The file was moved to the quarantine directory under the name '0d660864.qua'.

1/19/2011 6:31 AM [Scanner] Malware found
The file 'C:\WINDOWS\temp\0.5336287408281505.exe'
contained a virus or unwanted program 'TR/Dropper.Gen' [trojan]
Action(s) taken:
The file was moved to the quarantine directory under the name '5f3a528c.qua'.

1/19/2011 6:31 AM [Scanner] Malware found
The file 'C:\WINDOWS\temp\21.862796099677823.exe'
contained a virus or unwanted program 'TR/Dropper.Gen' [trojan]
Action(s) taken:
The file was moved to the quarantine directory under the name '47a27d28.qua'.

1/19/2011 6:31 AM [Scanner] Malware found
The file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\9\58413909-786b27d6'
contained a virus or unwanted program 'JAVA/Agent.AD.1' [virus]
Action(s) taken:
The file was moved to the quarantine directory under the name '6b5347dc.qua'.

1/19/2011 6:31 AM [Scanner] Malware found
The file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\10\4c562fca-430b006f'
contained a virus or unwanted program 'JAVA/OpenStream.AB.1' [virus]
Action(s) taken:
The file was moved to the quarantine directory under the name '51cd58b4.qua'.

1/19/2011 6:31 AM [Scanner] Malware found
The file 'C:\Documents and Settings\NetworkService\Application
Data\Sun\Java\Deployment\cache\6.0\50\170b44f2-5b95de1f'
contained a virus or unwanted program 'JAVA/CV-2010-0094.E' [virus]
Action(s) taken:
The file was moved to the quarantine directory under the name '2edb6ae1.qua'.

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.26533051345930936.exe.
Action performed: Deny access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\21.862796099677823.exe.
Action performed: Deny access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\21.862796099677823.exe.
Action performed: Allow access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.26533051345930936.exe.
Action performed: Allow access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.26533051345930936.exe.
Action performed: Deny access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.5336287408281505.exe.
Action performed: Deny access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.5336287408281505.exe.
Action performed: Deny access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\21.862796099677823.exe.
Action performed: Deny access

1/18/2011 10:52 PM [Guard] Malware found
Virus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\WINDOWS\temp\0.5336287408281505.exe.
Action performed: Allow access

OTL logfile created on: 1/19/2011 9:40:37 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Jennifer\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.77 Gb Total Space | 178.37 Gb Free Space | 76.63% Space Free | Partition Type: NTFS

Computer Name: JENS-OFFICE | User Name: Jennifer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/19 21:36:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
PRC - [2010/12/08 05:19:45 | 000,267,944 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/11/02 05:02:04 | 000,403,624 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2010/11/02 05:02:04 | 000,339,624 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
PRC - [2010/11/02 05:02:04 | 000,281,768 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/11/02 05:02:04 | 000,135,336 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010/10/27 19:17:52 | 000,207,424 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/08/25 10:27:44 | 000,309,824 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/03/24 05:04:16 | 000,076,968 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/01/22 08:56:24 | 000,112,592 | —- | M] (Threat Expert Ltd.) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009/12/03 15:52:32 | 001,980,560 | R— | M] (Carbonite, Inc. (www.carbonite.com)) – C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
PRC - [2009/12/03 15:52:32 | 000,670,864 | R— | M] (Carbonite, Inc.) – C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2009/02/23 07:05:34 | 000,111,856 | —- | M] (Yahoo! Inc) – C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/11/03 18:57:20 | 001,185,680 | —- | M] (American Express) – C:\Program Files\American Express Online Assistant\OnlineAssistant.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/19 11:16:56 | 008,253,440 | —- | M] (Netscape) – C:\Program Files\Netscape\Navigator 9\navigator.exe
PRC - [2007/05/25 09:38:46 | 000,112,176 | —- | M] (SingleClick Systems) – C:\Program Files\Dell Network Assistant\hnm_svc.exe
PRC - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/09/11 03:40:32 | 000,218,032 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2005/11/22 11:44:44 | 005,245,952 | —- | M] (Linksys) – C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
PRC - [2005/07/04 15:46:04 | 000,053,307 | —- | M] (GEMTEKS) – C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe


========== Modules (SafeList) ==========

MOD - [2011/01/19 21:36:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Running] – – (WUSB54GCSVC)
SRV - File not found [Auto | Stopped] – – (RoxLiveShare9)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/01/19 10:48:40 | 000,053,248 | —- | M] () [Auto | Stopped] – C:\WINDOWS\system32\6to4v32.dll – (6to4)
SRV - [2010/12/08 05:19:45 | 000,267,944 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2010/11/02 05:02:04 | 000,403,624 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE – (AntiVirWebService)
SRV - [2010/11/02 05:02:04 | 000,339,624 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe – (AntiVirMailService)
SRV - [2010/11/02 05:02:04 | 000,135,336 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2010/03/15 10:50:36 | 001,142,224 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\Spyware Doctor\pctsSvc.exe – (sdCoreService)
SRV - [2010/03/11 10:09:22 | 000,366,840 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\Spyware Doctor\pctsAuxs.exe – (sdAuxService)
SRV - [2010/02/02 08:13:54 | 000,070,928 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files\Spyware Doctor\TFEngine\TFService.exe – (ThreatFire)
SRV - [2010/01/22 08:56:24 | 000,112,592 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2009/12/03 15:52:32 | 001,980,560 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe – (CarboniteService)
SRV - [2008/12/07 15:09:38 | 000,085,096 | —- | M] (Autodesk) [On_Demand | Stopped] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2007/05/25 09:38:46 | 000,112,176 | —- | M] (SingleClick Systems) [Auto | Running] – C:\Program Files\Dell Network Assistant\hnm_svc.exe – (hnmsvc)
SRV - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)


========== Driver Services (SafeList) ==========

DRV - [2010/12/20 04:44:38 | 000,135,096 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2010/11/22 05:42:16 | 000,061,960 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2010/05/10 12:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/04/08 13:29:32 | 000,063,360 | —- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\pctplsg.sys – (pctplsg)
DRV - [2010/03/29 09:06:14 | 000,218,592 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2010/02/17 12:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2010/02/05 09:17:56 | 000,233,136 | —- | M] (PC Tools) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\pctgntdi.sys – (pctgntdi)
DRV - [2010/02/02 08:13:54 | 000,059,664 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\TfSysMon.sys – (TfSysMon)
DRV - [2010/02/02 08:13:54 | 000,051,984 | –S- | M] (PC Tools) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\TfFsMon.sys – (TfFsMon)
DRV - [2010/02/02 08:13:54 | 000,033,552 | –S- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\TfNetMon.sys – (TfNetMon)
DRV - [2009/06/09 02:29:50 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2009/06/02 07:25:00 | 000,011,608 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Program Files\Avira\AntiVir Desktop\avgio.sys – (avgio)
DRV - [2009/02/19 13:13:54 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2009/02/19 13:13:38 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2008/04/13 12:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 12:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/13 10:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/06/26 12:06:20 | 000,254,872 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\e1e5132.sys – (e1express) Intel®
DRV - [2007/06/13 18:41:44 | 004,403,712 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/06/13 17:25:14 | 000,304,920 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2007/06/13 17:21:16 | 005,760,096 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2006/08/18 11:18:08 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/08/18 11:17:46 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/08/18 11:17:44 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/08/18 11:17:44 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/08/18 11:17:42 | 000,026,008 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/08/18 11:17:40 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/08/18 11:17:38 | 000,104,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/08/18 11:17:38 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/08/11 09:05:58 | 000,051,768 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\DRVNDDM.SYS – (DRVNDDM)
DRV - [2006/08/11 08:35:18 | 000,012,920 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/08/11 08:35:16 | 000,028,184 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2006/07/21 09:21:26 | 000,099,176 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB)
DRV - [2005/11/03 19:39:02 | 000,245,504 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt73.sys – (RT73)
DRV - [2004/08/03 20:29:56 | 001,897,408 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2001/08/17 12:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 12:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 12:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 12:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 12:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 11:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 11:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 11:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 11:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 11:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 11:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 11:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 11:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 11:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 11:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080510
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080510


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080510
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form;=ZGAPHP
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080510
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form;=ZGAPHP
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://flyingincognitosleep.com/cgi-bin/h.pl
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;="
FF - prefs.js..browser.search.selectedEngine: "AIM Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://flyingincognitosleep.com/cgi-bin/h.pl"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {C73D32D1-835F-43B6-8151-8C5365059C66}:1.9.1
FF - prefs.js..extensions.enabledItems: {CE1701E9-00FA-4AB3-88AC-0E424249F7A4}:1.9.1
FF - prefs.js..extensions.enabledItems: {214F2009-B770-4270-9860-89CD8A50478F}:1.9.1
FF - prefs.js..extensions.enabledItems: {EA4C5146-8C4C-449A-9C25-4C435C87694A}:1.9.1
FF - prefs.js..extensions.enabledItems: {AF45588C-2174-415C-8493-40DAC4AB1C62}:1.9.1
FF - prefs.js..extensions.enabledItems: {5CDC00D3-983D-42BB-A673-966E5B0E2306}:1.9.1
FF - prefs.js..extensions.enabledItems: {87CA3053-8530-4233-A6C9-8D18285FB1E7}:1.9.1
FF - prefs.js..extensions.enabledItems: {C3F91810-FD9C-47BA-BF56-523B99848792}:1.9.1
FF - prefs.js..extensions.enabledItems: {86AE899F-3B6E-42D0-B054-301B77859398}:1.9.1
FF - prefs.js..extensions.enabledItems: {24AF10CD-D80F-4A93-B763-2B7CD1E15410}:1.9.1
FF - prefs.js..extensions.enabledItems: {EC6A3E63-0817-49DA-95A6-A23140F0FC7F}:1.9.1
FF - prefs.js..extensions.enabledItems: {538C6ACE-FB87-474C-A103-46FB5832D8BD}:1.9.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;="

FF - user.js..browser.startup.homepage: "http://flyingincognitosleep.com/cgi-bin/h.pl"

FF - HKLM\software\mozilla\Firefox\Extensions\\{C73D32D1-835F-43B6-8151-8C5365059C66}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{C73D32D1-835F-43B6-8151-8C5365059C66} [2009/12/26 15:27:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4} [2009/12/26 16:45:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{214F2009-B770-4270-9860-89CD8A50478F}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{214F2009-B770-4270-9860-89CD8A50478F} [2010/01/16 08:46:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{EA4C5146-8C4C-449A-9C25-4C435C87694A}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{EA4C5146-8C4C-449A-9C25-4C435C87694A}\ [2010/01/22 06:04:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{AF45588C-2174-415C-8493-40DAC4AB1C62}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{AF45588C-2174-415C-8493-40DAC4AB1C62} [2010/01/23 08:40:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{5CDC00D3-983D-42BB-A673-966E5B0E2306}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{5CDC00D3-983D-42BB-A673-966E5B0E2306}\ [2010/01/30 08:24:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{87CA3053-8530-4233-A6C9-8D18285FB1E7}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{87CA3053-8530-4233-A6C9-8D18285FB1E7}\ [2010/02/05 08:30:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{C3F91810-FD9C-47BA-BF56-523B99848792}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{C3F91810-FD9C-47BA-BF56-523B99848792}\ [2010/02/10 07:04:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{86AE899F-3B6E-42D0-B054-301B77859398}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{86AE899F-3B6E-42D0-B054-301B77859398} [2010/02/15 15:30:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}\ [2010/02/21 09:44:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F} [2010/02/24 07:39:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{538C6ACE-FB87-474C-A103-46FB5832D8BD}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{538C6ACE-FB87-474C-A103-46FB5832D8BD}\ [2010/02/27 08:27:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/05/10 12:32:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/04 08:43:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/26 13:57:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Components: C:\Program Files\Netscape\Navigator 9\components [2010/12/26 13:57:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Plugins: C:\Program Files\Netscape\Navigator 9\plugins [2010/12/26 13:57:02 | 000,000,000 | —D | M]

[2008/06/17 18:02:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Extensions
[2011/01/19 07:30:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions
[2009/09/02 07:29:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/19 13:56:28 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/07/22 18:57:34 | 000,000,000 | —D | M] (Power Twitter) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions\{b2509cd4-17cd-45ed-8146-a82af038f493}
[2009/01/06 18:22:48 | 000,001,739 | —- | M] () – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\searchplugins\aim-search.xml
[2011/01/19 07:30:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/11/25 09:40:13 | 000,000,000 | —D | M] (American Express Online Assistant) – C:\Program Files\Mozilla Firefox\extensions\{6bae2634-6076-40a2-be93-600b67061f6c}
[2010/01/16 08:46:42 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{214F2009-B770-4270-9860-89CD8A50478F}
[2010/02/21 09:44:33 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}
[2010/02/27 08:27:13 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{538C6ACE-FB87-474C-A103-46FB5832D8BD}
[2010/01/30 08:24:20 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{5CDC00D3-983D-42BB-A673-966E5B0E2306}
[2010/02/15 15:30:43 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{86AE899F-3B6E-42D0-B054-301B77859398}
[2010/02/05 08:30:41 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{87CA3053-8530-4233-A6C9-8D18285FB1E7}
[2010/01/23 08:40:32 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{AF45588C-2174-415C-8493-40DAC4AB1C62}
[2010/02/10 07:04:46 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{C3F91810-FD9C-47BA-BF56-523B99848792}
[2009/12/26 15:27:03 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{C73D32D1-835F-43B6-8151-8C5365059C66}
[2009/12/26 16:45:42 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4}
[2010/01/22 06:04:55 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{EA4C5146-8C4C-449A-9C25-4C435C87694A}
[2010/02/24 07:39:59 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F}
[2008/12/12 23:43:17 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2011/01/19 06:50:25 | 000,001,919 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing-zugo.xml

O1 HOSTS File: ([2009/07/30 10:38:01 | 000,000,022 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Online Assistant) - {F997ACBD-1292-4c74-B96B-83BA5665E260} - C:\Program Files\American Express Online Assistant\ietoolbar.dll (American Express)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
O3 - HKLM\..\Toolbar: (Online Assistant) - {D79C4ACF-F903-4854-95CA-CDE413AC7E18} - C:\Program Files\American Express Online Assistant\ietoolbar.dll (American Express)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\..\Toolbar\WebBrowser: (Online Assistant) - {D79C4ACF-F903-4854-95CA-CDE413AC7E18} - C:\Program Files\American Express Online Assistant\ietoolbar.dll (American Express)
O3 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006..\Run: [{E3004CF3-65FE-B391-A4F3-F679A94B72C5}] C:\Documents and Settings\Jennifer\Application Data\Irba\rakib.exe ()
O4 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006..\Run: [Aim6] File not found
O4 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006..\RunOnce: [Shockwave Updater] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk = C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk = C:\Program Files\Whitesmoke Translator\WSTrayDictMode.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Online Assistant.lnk = C:\Program Files\American Express Online Assistant\OnlineAssistant.exe (American Express)
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\efsoyb.exe ()
O4 - Startup: C:\Documents and Settings\Jennifer\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKLM\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://www.shockwave.com/content/chainz2/sis/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (GTGina.dll) - C:\WINDOWS\System32\GTGina.dll (Gemtek)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jennifer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jennifer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 11:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{54b6bb08-3dd1-11df-b8c2-001d0992444b}\Shell - "" = AutoRun
O33 - MountPoints2\{54b6bb08-3dd1-11df-b8c2-001d0992444b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{54b6bb08-3dd1-11df-b8c2-001d0992444b}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\{d6bcafaa-626b-11de-b847-0016b654bb60}\Shell - "" = AutoRun
O33 - MountPoints2\{d6bcafaa-626b-11de-b847-0016b654bb60}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{d6bcafaa-626b-11de-b847-0016b654bb60}\Shell\AutoRun\command - "" = J:\StarterOfficeGuardian.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - C:\WINDOWS\system32\6to4v32.dll ()
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (183790240530432)

========== Files/Folders - Created Within 30 Days ==========

[2011/01/19 21:36:42 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
[2011/01/19 20:14:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Jennifer\Application Data\whitesmoketoolbar
[2011/01/19 09:17:34 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Unity
[2011/01/19 07:40:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/01/19 07:40:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Apple Computer
[2011/01/19 06:51:25 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2011/01/19 06:51:21 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\whitesmoketoolbar
[2011/01/19 06:51:02 | 000,000,000 | —D | C] – C:\Program Files\Whitesmoke Translator
[2011/01/19 06:51:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WhiteSmoke Translator
[2011/01/19 06:50:59 | 000,000,000 | —D | C] – C:\Program Files\whitesmoketoolbar
[2011/01/19 06:50:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\%APPDATA%
[2011/01/19 06:47:57 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/01/18 23:10:05 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/01/18 22:52:43 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/01/18 22:51:04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/01/18 22:51:03 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/12/26 13:58:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2010/12/26 13:57:50 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/12/26 13:57:48 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/12/26 13:57:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/12/26 13:56:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2010/12/26 13:56:37 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/12/26 13:55:49 | 004,184,352 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2010/12/26 13:55:32 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/12/26 13:55:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/19 21:42:05 | 000,359,929 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\dds.scr
[2011/01/19 21:36:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
[2011/01/19 21:08:54 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/19 20:12:31 | 000,000,854 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Online Assistant.lnk
[2011/01/19 20:12:23 | 000,002,333 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk
[2011/01/19 20:11:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/19 20:11:44 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2011/01/19 10:48:40 | 000,053,248 | —- | M] () – C:\WINDOWS\System32\6to4v32.dll
[2011/01/19 06:51:29 | 000,001,356 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Buy Whitesmoke Translator.lnk
[2011/01/19 06:51:28 | 000,001,725 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
[2011/01/19 06:51:02 | 000,001,453 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Launch WhiteSmoke Translator.lnk
[2011/01/18 10:31:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/16 19:05:16 | 000,026,624 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs 2010 week 2.xls
[2011/01/16 18:47:43 | 000,152,064 | —- | M] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/15 16:08:10 | 001,215,575 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02857.JPG
[2011/01/15 16:08:02 | 001,253,441 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02856.JPG
[2011/01/15 16:06:58 | 001,302,227 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02855.JPG
[2011/01/15 16:06:46 | 001,305,501 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02854.JPG
[2011/01/15 16:06:24 | 000,385,706 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.MPG
[2011/01/15 16:06:24 | 000,004,820 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.THM
[2011/01/15 15:58:48 | 001,250,047 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02852.JPG
[2011/01/15 15:58:40 | 001,295,990 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02851.JPG
[2011/01/15 15:58:34 | 001,271,654 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02850.JPG
[2011/01/15 15:58:24 | 001,331,685 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02849.JPG
[2011/01/15 15:58:20 | 001,295,900 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02848.JPG
[2011/01/15 15:58:12 | 001,273,346 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02847.JPG
[2011/01/15 15:57:54 | 001,177,578 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02846.JPG
[2011/01/15 15:57:52 | 001,179,039 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02845.JPG
[2011/01/15 15:57:46 | 001,286,640 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02844.JPG
[2011/01/15 15:57:36 | 001,217,236 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02843.JPG
[2011/01/15 15:57:30 | 001,295,288 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02842.JPG
[2011/01/15 15:57:18 | 001,279,824 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02841.JPG
[2011/01/15 15:57:14 | 001,270,977 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02840.JPG
[2011/01/15 15:57:10 | 001,258,607 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02839.JPG
[2011/01/15 15:57:00 | 001,298,489 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02838.JPG
[2011/01/15 15:56:52 | 001,271,700 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02837.JPG
[2011/01/15 15:56:46 | 001,201,755 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02836.JPG
[2011/01/15 15:56:40 | 001,291,402 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02835.JPG
[2011/01/15 15:56:28 | 001,244,135 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02834.JPG
[2011/01/15 15:56:18 | 001,292,795 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02833.JPG
[2011/01/15 15:56:12 | 001,300,180 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02832.JPG
[2011/01/15 15:56:04 | 001,223,818 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02831.JPG
[2011/01/15 15:55:56 | 001,278,536 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02830.JPG
[2011/01/15 13:42:36 | 001,188,762 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02829.JPG
[2011/01/15 13:42:34 | 001,178,407 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02828.JPG
[2011/01/15 13:42:30 | 001,317,772 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02827.JPG
[2011/01/15 13:42:24 | 001,260,728 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02826.JPG
[2011/01/15 13:42:14 | 001,189,786 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02825.JPG
[2011/01/15 13:42:06 | 001,227,793 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02824.JPG
[2011/01/15 13:42:04 | 001,248,037 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02823.JPG
[2011/01/15 13:41:26 | 001,207,968 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02822.JPG
[2011/01/15 13:41:20 | 001,219,691 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02821.JPG
[2011/01/15 13:41:16 | 001,186,309 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02820.JPG
[2011/01/15 13:40:40 | 001,261,162 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02819.JPG
[2011/01/15 13:40:30 | 001,165,114 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02818.JPG
[2011/01/15 13:40:18 | 001,316,342 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02817.JPG
[2011/01/15 13:40:14 | 001,262,093 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02816.JPG
[2011/01/15 13:40:08 | 001,185,058 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02815.JPG
[2011/01/15 13:39:54 | 001,210,183 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02814.JPG
[2011/01/15 13:39:50 | 001,230,519 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02813.JPG
[2011/01/15 13:39:40 | 001,303,196 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02812.JPG
[2011/01/15 13:39:22 | 001,290,235 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02811.JPG
[2011/01/15 13:39:04 | 001,200,639 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02810.JPG
[2011/01/15 13:39:00 | 001,241,495 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02809.JPG
[2011/01/15 13:38:56 | 001,255,950 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02808.JPG
[2011/01/15 13:38:46 | 000,646,697 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.MPG
[2011/01/15 13:38:46 | 000,007,464 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.THM
[2011/01/15 13:05:38 | 001,232,889 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02806.JPG
[2011/01/15 13:05:26 | 001,265,191 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02805.JPG
[2011/01/15 13:05:18 | 001,232,785 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02804.JPG
[2011/01/15 13:04:00 | 001,301,496 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02803.JPG
[2011/01/15 13:03:58 | 001,267,995 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02802.JPG
[2011/01/15 13:03:52 | 001,326,501 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02801.JPG
[2011/01/10 07:47:57 | 000,024,576 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs.xls
[2011/01/04 08:30:59 | 000,037,376 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\Jaymes christmas List.doc
[2010/12/26 13:58:34 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/26 13:56:55 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/12/25 08:39:13 | 000,000,043 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\watch pic.gif
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/19 21:42:16 | 000,359,929 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\dds.scr
[2011/01/19 10:48:40 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2011/01/19 06:51:29 | 000,001,356 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Buy Whitesmoke Translator.lnk
[2011/01/19 06:51:28 | 000,001,725 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
[2011/01/19 06:51:02 | 000,001,453 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Launch WhiteSmoke Translator.lnk
[2011/01/18 22:51:22 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/16 19:04:46 | 000,026,624 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs 2010 week 2.xls
[2011/01/15 17:14:26 | 001,331,685 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02849.JPG
[2011/01/15 17:14:26 | 001,305,501 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02854.JPG
[2011/01/15 17:14:26 | 001,302,227 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02855.JPG
[2011/01/15 17:14:26 | 001,295,990 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02851.JPG
[2011/01/15 17:14:26 | 001,271,654 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02850.JPG
[2011/01/15 17:14:26 | 001,253,441 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02856.JPG
[2011/01/15 17:14:26 | 001,250,047 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02852.JPG
[2011/01/15 17:14:26 | 001,215,575 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02857.JPG
[2011/01/15 17:14:26 | 000,646,697 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.MPG
[2011/01/15 17:14:26 | 000,385,706 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.MPG
[2011/01/15 17:14:26 | 000,007,464 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.THM
[2011/01/15 17:14:26 | 000,004,820 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.THM
[2011/01/15 17:14:25 | 001,300,180 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02832.JPG
[2011/01/15 17:14:25 | 001,298,489 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02838.JPG
[2011/01/15 17:14:25 | 001,295,900 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02848.JPG
[2011/01/15 17:14:25 | 001,295,288 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02842.JPG
[2011/01/15 17:14:25 | 001,292,795 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02833.JPG
[2011/01/15 17:14:25 | 001,291,402 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02835.JPG
[2011/01/15 17:14:25 | 001,286,640 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02844.JPG
[2011/01/15 17:14:25 | 001,279,824 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02841.JPG
[2011/01/15 17:14:25 | 001,278,536 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02830.JPG
[2011/01/15 17:14:25 | 001,273,346 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02847.JPG
[2011/01/15 17:14:25 | 001,271,700 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02837.JPG
[2011/01/15 17:14:25 | 001,270,977 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02840.JPG
[2011/01/15 17:14:25 | 001,258,607 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02839.JPG
[2011/01/15 17:14:25 | 001,244,135 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02834.JPG
[2011/01/15 17:14:25 | 001,223,818 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02831.JPG
[2011/01/15 17:14:25 | 001,217,236 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02843.JPG
[2011/01/15 17:14:25 | 001,201,755 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02836.JPG
[2011/01/15 17:14:25 | 001,188,762 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02829.JPG
[2011/01/15 17:14:25 | 001,179,039 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02845.JPG
[2011/01/15 17:14:25 | 001,178,407 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02828.JPG
[2011/01/15 17:14:25 | 001,177,578 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02846.JPG
[2011/01/15 17:14:24 | 001,317,772 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02827.JPG
[2011/01/15 17:14:24 | 001,260,728 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02826.JPG
[2011/01/15 17:14:24 | 001,248,037 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02823.JPG
[2011/01/15 17:14:24 | 001,227,793 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02824.JPG
[2011/01/15 17:14:24 | 001,207,968 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02822.JPG
[2011/01/15 17:14:24 | 001,189,786 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02825.JPG
[2011/01/15 17:14:23 | 001,316,342 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02817.JPG
[2011/01/15 17:14:23 | 001,261,162 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02819.JPG
[2011/01/15 17:14:23 | 001,219,691 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02821.JPG
[2011/01/15 17:14:23 | 001,186,309 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02820.JPG
[2011/01/15 17:14:23 | 001,165,114 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02818.JPG
[2011/01/15 17:14:22 | 001,303,196 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02812.JPG
[2011/01/15 17:14:22 | 001,290,235 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02811.JPG
[2011/01/15 17:14:22 | 001,262,093 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02816.JPG
[2011/01/15 17:14:22 | 001,230,519 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02813.JPG
[2011/01/15 17:14:22 | 001,210,183 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02814.JPG
[2011/01/15 17:14:22 | 001,185,058 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02815.JPG
[2011/01/15 17:14:21 | 001,265,191 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02805.JPG
[2011/01/15 17:14:21 | 001,255,950 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02808.JPG
[2011/01/15 17:14:21 | 001,241,495 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02809.JPG
[2011/01/15 17:14:21 | 001,232,889 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02806.JPG
[2011/01/15 17:14:21 | 001,232,785 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02804.JPG
[2011/01/15 17:14:21 | 001,200,639 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02810.JPG
[2011/01/15 17:14:20 | 001,326,501 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02801.JPG
[2011/01/15 17:14:20 | 001,301,496 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02803.JPG
[2011/01/15 17:14:20 | 001,267,995 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02802.JPG
[2011/01/10 07:47:57 | 000,024,576 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs.xls
[2010/12/26 13:58:34 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/26 13:56:55 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/12/25 08:39:12 | 000,000,043 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\watch pic.gif
[2010/03/01 22:38:12 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll.old
[2010/03/01 22:38:12 | 000,763,832 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/03/01 22:25:09 | 000,016,924 | -HS- | C] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\GyBl5ci
[2009/04/19 12:32:35 | 000,000,022 | —- | C] () – C:\WINDOWS\iexplore.ini
[2009/02/24 08:21:40 | 000,000,131 | —- | C] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\fusioncache.dat
[2009/01/17 18:43:38 | 000,002,582 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/05/26 08:01:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/05/20 17:59:21 | 000,152,064 | —- | C] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/14 21:23:43 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2008/05/14 21:23:29 | 000,001,361 | —- | C] () – C:\WINDOWS\System32\WLAN.INI
[2008/05/09 19:28:11 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/05/09 19:25:28 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/05/09 19:23:58 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/05/09 19:23:58 | 000,000,118 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/05/09 19:04:57 | 000,876,544 | —- | C] () – C:\WINDOWS\System32\TEACico2.dll
[2008/05/09 19:04:42 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/05/09 19:03:39 | 000,001,124 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/08/06 13:17:40 | 000,019,456 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/08/06 12:07:30 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/08/02 18:11:28 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2007/08/02 18:11:14 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2007/07/27 15:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 15:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2006/11/07 02:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/16 21:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 21:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/12/05 20:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 13:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 11:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 11:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 10:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/01/06 18:22:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/11/25 09:41:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\American Express Online Assistant
[2010/04/01 15:42:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2010/04/28 12:02:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2009/08/02 17:39:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Merscom
[2009/04/19 12:32:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/08/01 21:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NetZero
[2008/11/11 23:45:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/05/09 19:25:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2008/05/09 19:26:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/01/19 21:29:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/27 05:44:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/12/26 13:58:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/08/07 09:05:43 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Jennifer\Application Data\.#
[2009/01/06 18:27:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\acccore
[2009/06/10 20:31:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Amazon
[2010/04/01 15:42:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Autodesk
[2009/01/11 19:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\AutoSync for Yahoo
[2010/05/01 14:32:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Facebook
[2009/07/08 09:30:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Irba
[2009/07/13 08:57:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\iWin
[2008/05/16 07:26:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Netscape
[2009/01/28 10:35:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Opera
[2009/02/16 22:16:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\TeamViewer
[2009/01/02 13:48:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Unity
[2011/01/19 20:14:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\whitesmoketoolbar
[2011/01/19 14:56:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jennifer\Application Data\Wovo
[2011/01/19 06:51:26 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\whitesmoketoolbar

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 11:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/09/19 21:19:25 | 000,000,211 | —- | M] () – C:\Boot.bak
[2009/12/26 17:00:00 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2004/08/10 11:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/05/09 19:05:48 | 000,007,072 | RH– | M] () – C:\dell.sdr
[2011/01/19 20:11:44 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2008/05/14 20:25:57 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 11:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/06/27 05:45:14 | 000,000,740 | -H– | M] () – C:\IPH.PH
[2008/12/12 23:40:38 | 000,010,118 | —- | M] () – C:\JavaRa.log
[2011/01/19 20:51:52 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2004/08/10 11:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/11/16 23:21:51 | 000,250,048 | —- | M] () – C:\ntldr
[2011/01/19 20:11:43 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/02/15 15:46:51 | 000,000,390 | —- | M] () – C:\rkill.log
[2009/02/18 14:22:59 | 000,000,594 | —- | M] () – C:\updatedatfix.log
[2008/05/14 21:47:51 | 000,000,146 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 11:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/03/28 13:57:34 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[2008/10/28 12:49:30 | 000,321,536 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp696.dll
[2003/06/18 16:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 10:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 10:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 10:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/11/16 23:25:07 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/05/14 20:07:05 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Jennifer\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 11:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jennifer\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/03/01 22:43:48 | 034,596,344 | —- | M] (PC Tools ) – C:\Documents and Settings\Jennifer\Desktop\7.0.0.538f-sdasetup.exe
[2008/12/12 23:38:04 | 035,124,856 | —- | M] ( ) – C:\Documents and Settings\Jennifer\Desktop\AdbeRdr90_en_US.exe
[2009/06/21 06:58:28 | 000,606,168 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\AmazonMP3Installer(2).exe
[2009/06/10 20:30:18 | 000,606,168 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\AmazonMP3Installer.exe
[2008/05/16 19:43:25 | 022,311,160 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\antivir_workstation_winu_en_h.exe
[2009/01/11 19:04:57 | 018,062,232 | —- | M] (Nokia ) – C:\Documents and Settings\Jennifer\Desktop\autosync_1049.exe
[2009/07/22 18:24:19 | 008,117,208 | —- | M] (Mozilla) – C:\Documents and Settings\Jennifer\Desktop\Firefox Setup 3.5.1.exe
[2009/12/18 10:25:09 | 008,086,544 | —- | M] (Mozilla) – C:\Documents and Settings\Jennifer\Desktop\Firefox Setup 3.5.6.exe
[2010/09/06 09:36:17 | 008,573,648 | —- | M] (Mozilla) – C:\Documents and Settings\Jennifer\Desktop\Firefox Setup 3.6.8.exe
[2008/08/01 22:49:32 | 000,208,384 | —- | M] (Paul McLain and Fred de Vries) – C:\Documents and Settings\Jennifer\Desktop\JavaRa.exe
[2008/11/25 09:39:15 | 003,091,808 | —- | M] (American Express) – C:\Documents and Settings\Jennifer\Desktop\online_assistant.exe
[2011/01/19 21:36:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
[2008/12/09 12:29:05 | 000,305,705 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\RSIT.exe
[2010/03/01 22:34:21 | 034,870,008 | —- | M] (PC Tools ) – C:\Documents and Settings\Jennifer\Desktop\sdasetup_aff.exe
[2009/06/19 18:36:38 | 001,490,672 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\TeamViewerQS(2).exe
[2009/06/19 16:54:48 | 001,490,672 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\TeamViewerQS.exe
[2009/06/19 18:37:27 | 002,042,328 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\TeamViewer_Setup.exe
[2009/01/02 13:41:45 | 003,292,936 | —- | M] (Unity Technologies ApS) – C:\Documents and Settings\Jennifer\Desktop\UnityWebPlayer.exe
[2009/06/26 10:16:36 | 000,897,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jennifer\Desktop\WGAPluginInstall.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-12 09:02:14

========== Alternate Data Streams ==========

@Alternate Data Stream - 292 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7715B65F
@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 162 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6D6C4572
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F38450C8
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B211CA64

< End of report >



OTL Extras logfile created on: 1/19/2011 9:40:37 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Jennifer\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.77 Gb Total Space | 178.37 Gb Free Space | 76.63% Space Free | Partition Type: NTFS

Computer Name: JENS-OFFICE | User Name: Jennifer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = NavigatorHTML] – C:\Program Files\Netscape\Navigator 9\navigator.exe (Netscape)

[HKEY_USERS\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – C:\PROGRA~1\NETSCAPE\NAVIGA~1\NAVIGA~1.EXE -requestPending -osint -url "%1" (Netscape)
https [open] – C:\PROGRA~1\NETSCAPE\NAVIGA~1\NAVIGA~1.EXE -requestPending -osint -url "%1" (Netscape)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX – (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" = C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program – (CyberLink Corp.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX – (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" = C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program – (CyberLink Corp.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" = C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe:*:Enabled:AppleMobileDeviceService
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant – (SingleClick Systems)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe" = C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application – (TeamViewer GmbH)
"C:\Documents and Settings\Jennifer\Desktop\tbzip\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\tbzip\TicketBuy.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\tbzip\TicketBuyEvent.exe" = C:\Documents and Settings\Jennifer\Desktop\tbzip\TicketBuyEvent.exe:*:Enabled:
"J:\tbzip\TicketBuy.exe" = J:\tbzip\TicketBuy.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\TicketBuy4444\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\TicketBuy4444\TicketBuy.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\TicketBuy4444\TicketBuyEvent.exe" = C:\Documents and Settings\Jennifer\Desktop\TicketBuy4444\TicketBuyEvent.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\TICKET BUY\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\TICKET BUY\TicketBuy.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\TICKET BUY\TicketBuyEvent.exe" = C:\Documents and Settings\Jennifer\Desktop\TICKET BUY\TicketBuyEvent.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\Old ticketbuy\TicketBuy4444\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\Old ticketbuy\TicketBuy4444\TicketBuy.exe:*:Enabled: – ( )
"C:\Documents and Settings\Jennifer\temp\TeamViewer\Version4\TeamViewer.exe" = C:\Documents and Settings\Jennifer\temp\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application
"C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TicketBuy.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TicketBuyEvent.exe" = C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TicketBuyEvent.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TBuy 9-15\TicketBuyEvent.exe" = C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TBuy 9-15\TicketBuyEvent.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TBuy 9-15\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\TicketBuynew619\TicketBuy\TBuy 9-15\TicketBuy.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\Extra new ticketbuy\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\Extra new ticketbuy\TicketBuy.exe:*:Enabled:
"C:\Documents and Settings\Jennifer\Desktop\Extra new ticketbuy\TicketBuyEvent.exe" = C:\Documents and Settings\Jennifer\Desktop\Extra new ticketbuy\TicketBuyEvent.exe:*:Enabled:
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Documents and Settings\Jennifer\Desktop\may 26 ticketbuy\TicketBuy.exe" = C:\Documents and Settings\Jennifer\Desktop\may 26 ticketbuy\TicketBuy.exe:*:Enabled: – ( )
"C:\Documents and Settings\Jennifer\Desktop\may 26 ticketbuy\TicketBuyEvent.exe" = C:\Documents and Settings\Jennifer\Desktop\may 26 ticketbuy\TicketBuyEvent.exe:*:Enabled: – ( )
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{03A7C57A-B2C8-409b-92E5-524A0DFD0DD3}" = Status
"{087A66B8-1F0F-4a8d-A649-0CFE276AA7C0}" = WebReg
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{1ADB7BF5-F8EB-4F76-98FD-65A7FFBEAECE}" = Whitesmoke Translator
"{1E0AD97C-678A-48C6-A7C3-CCC87F2DA9D8}" = PS_BSIZE_04_B8500_Software_Min
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 14
"{2A329FB6-389D-4396-A974-29656D6864AE}" = MarketResearch
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2C0CD17D-0B06-4700-83FA-7344B868B0A2}" = Opera 9.63
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4A7AE408-7846-4D13-81F7-D4447A994DBA}" = Calendar
"{4D304678-738E-42a0-931A-2B022F49DEB8}" = TrayApp
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5783F2D7-5001-0409-0002-0060B0CE6BBA}" = AutoCAD 2007 - English
"{5783F2D7-7001-0409-0002-0060B0CE6BBA}" = AutoCAD 2009 - English
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67790AD5-777F-4652-9556-AED6ADC03D55}" = B8500
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6EED4269-588D-45b8-A80C-26A9CA62EE4E}" = HPSSupply
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{71310D9B-7555-44FE-914C-A1B55CB7BC5D}" = Scrapbook
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections [removed]
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{98B672F2-857C-4CC9-A25D-6B218077F4F6}" = Yahoo! Autosync
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C09DFEC-1F55-4E6D-BDEF-0D2F6CA06D21}" = addcustompaper
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{ACA85783-8EEA-4f0a-B2A3-A8173F30209F}" = C4200_doccd
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B09BCBF6-87EE-4403-A336-3A9510856535}" = HP Photosmart All-In-One Software 9.0
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B7F98125-4955-41E3-8A71-4CE11CE9C198}" = KODAK Gallery Upload Software
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BFDE4176-5DFE-4db9-AA00-8F30CB001BDA}" = c4200_Help
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C39E671D-0528-4c5e-A034-8470C5BC393A}" = C4200
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C867F57B-39C1-4341-A164-F569839BCCBF}" = Cards
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}" = Safari
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D8B7A682-20DA-4797-8415-B1FB14D4D32B}" = PS_AIO_Software
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E3C9FB9B-5D79-469e-8E81-9A5ACE0BB517}" = HP Photosmart B8500 Driver Software 12.0 Rel .4
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F769B78E-FF0E-4db5-95E2-9F4C8D6352FE}" = DeviceDiscovery
"{F855C3AE-992D-4B84-A09D-07103CDCDAC2}" = Compact Wireless-G USB Adapter
"{FD011F34-749C-47E0-BA48-6009412C4789}" = ArcSoft Print Creations
"{FD7F242B-9AA0-40c3-941E-3A9821D19C09}" = PS_AIO_ProductContext
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AIM_6" = AIM 6
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"ATT-R9" = AT&T; U-verse Setup
"AutoCAD 2009 - English" = AutoCAD 2009 - English
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"Avira AntiVir Desktop" = Avira AntiVir Premium
"AXP" = Online Assistant
"Browser Defender_is1" = Browser Defender 2.0.6.15
"Carbonite Backup" = Carbonite
"Create A Mall" = Create A Mall
"Defender of the Crown: Heroes Live Forever" = Defender of the Crown: Heroes Live Forever
"EsetOnlineScanner" = ESET Online Scanner
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 12.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 12.0
"HPOCR" = HP OCR Software 9.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Jigsaw Puzzle Player" = Jigsaw Puzzle Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Netscape Navigator ([removed])" = Netscape Navigator ([removed])
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PDF Splitter and Merger 4.0" = PDF Splitter and Merger 4.0
"Risk®" = Risk®
"SearchAssist" = SearchAssist
"Shop for HP Supplies" = Shop for HP Supplies
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Spyware Doctor" = Spyware Doctor 7.0
"TeamViewer 4" = TeamViewer 4
"UnityWebPlayer" = Unity Web Player
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.2

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post







Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    SRV - [2011/01/19 10:48:40 | 000,053,248 | —- | M] () [Auto | Stopped] – C:\WINDOWS\system32\6to4v32.dll – (6to4)
    IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://flyingincognitosleep.com/cgi-bin/h.pl
    IE - HKU\S-1-5-21-2975155819-199
    IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
    IE - HKU\S-1-5-21-2975155819-1990629535-245175267-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
    FF - prefs.js..browser.startup.homepage: "http://flyingincognitosleep.com/cgi-bin/h.pl"
    FF - user.js..browser.startup.homepage: "http://flyingincognitosleep.com/cgi-bin/h.pl"
    O2 - BHO: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
    O3 - HKLM\..\Toolbar: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
    O4 - HKU\S-1-5-21-2975155819-1990629535-245175267-1006..\Run: [{E3004CF3-65FE-B391-A4F3-F679A94B72C5}] C:\Documents and Settings\Jennifer\Application Data\Irba\rakib.exe ()
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk = C:\Program Files\Whitesmoke Translator\WSTrayDictMode.exe ()
    O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\efsoyb.exe ()
    O33 - MountPoints2\{54b6bb08-3dd1-11df-b8c2-001d0992444b}\Shell - "" = AutoRun
    O33 - MountPoints2\{54b6bb08-3dd1-11df-b8c2-001d0992444b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{54b6bb08-3dd1-11df-b8c2-001d0992444b}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
    O33 - MountPoints2\{d6bcafaa-626b-11de-b847-0016b654bb60}\Shell - "" = AutoRun
    O33 - MountPoints2\{d6bcafaa-626b-11de-b847-0016b654bb60}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{d6bcafaa-626b-11de-b847-0016b654bb60}\Shell\AutoRun\command - "" = J:\StarterOfficeGuardian.exe
    [2011/01/19 20:14:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Jennifer\Application Data\whitesmoketoolbar
    [2011/01/19 06:51:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WhiteSmoke Translator
    [2011/01/19 06:50:59 | 000,000,000 | —D | C] – C:\Program Files\whitesmoketoolbar
    [2011/01/19 10:48:40 | 000,053,248 | —- | M] () – C:\WINDOWS\System32\6to4v32.dll
    [2011/01/19 06:51:29 | 000,001,356 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Buy Whitesmoke Translator.lnk
    [2011/01/19 06:51:28 | 000,001,725 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
    [2011/01/19 06:51:02 | 000,001,453 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Launch WhiteSmoke Translator.lnk
    
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )








Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)










  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Thank you so much for your prompt reply. I am running into issues with executing the first command of "Run OTL.exe." The OTL program locks up immediately and goes into "not responding" mode. Thanks again for all of your assistance.
I completed the task of downloading and running the killer program first. It found a malicious object and i cured it. However, the OTL program still locks up the entire computer when attempting to run. Thanks again for all of your assistance. It is greatly appreciated.
Post the TDSSKiler log, A copy of the log will be saved automatically to the root of the drive (typically C:\),then continue with the malwarebytes instructions in my earlier post.
thanks again. 2011/01/22 10:30:51.0578 TDSS rootkit removing tool 2.4.14.0 Jan 18 2011 09:33:51 2011/01/22 10:30:51.0578 ================================================================================ 2011/01/22 10:30:51.0578 SystemInfo: 2011/01/22 10:30:51.0578 2011/01/22 10:30:51.0578 OS Version: 5.1.2600 ServicePack: 3.0 2011/01/22 10:30:51.0578 Product type: Workstation 2011/01/22 10:30:51.0578 ComputerName: JENS-OFFICE 2011/01/22 10:30:51.0578 UserName: Jennifer 2011/01/22 10:30:51.0578 Windows directory: C:\WINDOWS 2011/01/22 10:30:51.0578 System windows directory: C:\WINDOWS 2011/01/22 10:30:51.0578 Processor architecture: Intel x86 2011/01/22 10:30:51.0578 Number of processors: 2 2011/01/22 10:30:51.0578 Page size: 0x1000 2011/01/22 10:30:51.0578 Boot type: Normal boot 2011/01/22 10:30:51.0578 ================================================================================ 2011/01/22 10:30:51.0843 Initialize success 2011/01/22 10:30:54.0890 ================================================================================ 2011/01/22 10:30:54.0890 Scan started 2011/01/22 10:30:54.0890 Mode: Manual; 2011/01/22 10:30:54.0890 ================================================================================ 2011/01/22 10:30:55.0812 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 2011/01/22 10:30:55.0875 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/01/22 10:30:55.0937 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/01/22 10:30:56.0000 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 2011/01/22 10:30:56.0078 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/01/22 10:30:56.0140 AegisP (2f7f3e8da380325866e566f5d5ec23d5) C:\WINDOWS\system32\DRIVERS\AegisP.sys 2011/01/22 10:30:56.0187 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2011/01/22 10:30:56.0250 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 2011/01/22 10:30:56.0296 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 2011/01/22 10:30:56.0328 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 2011/01/22 10:30:56.0359 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 2011/01/22 10:30:56.0406 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 2011/01/22 10:30:56.0468 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 2011/01/22 10:30:56.0531 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 2011/01/22 10:30:56.0609 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 2011/01/22 10:30:56.0671 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 2011/01/22 10:30:56.0734 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 2011/01/22 10:30:56.0765 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 2011/01/22 10:30:56.0781 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 2011/01/22 10:30:56.0828 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/01/22 10:30:56.0875 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/01/22 10:30:56.0937 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/01/22 10:30:57.0015 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/01/22 10:30:57.0109 avgio (6a646c46b9415e13095aa9b352040a7a) C:\Program Files\Avira\AntiVir Desktop\avgio.sys 2011/01/22 10:30:57.0156 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys 2011/01/22 10:30:57.0203 avipbb (da39805e2bad99d37fce9477dd94e7f2) C:\WINDOWS\system32\DRIVERS\avipbb.sys 2011/01/22 10:30:57.0234 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/01/22 10:30:57.0281 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 2011/01/22 10:30:57.0312 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/01/22 10:30:57.0390 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 2011/01/22 10:30:57.0421 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/01/22 10:30:57.0468 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/01/22 10:30:57.0500 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/01/22 10:30:57.0562 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 2011/01/22 10:30:57.0640 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 2011/01/22 10:30:57.0671 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 2011/01/22 10:30:57.0687 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 2011/01/22 10:30:57.0734 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/01/22 10:30:57.0781 DLABMFSM (0659e6e0a95564f958d9df7313f7701e) C:\WINDOWS\system32\DLA\DLABMFSM.SYS 2011/01/22 10:30:57.0781 DLABOIOM (8691c78908f0bd66170669db268369f2) C:\WINDOWS\system32\DLA\DLABOIOM.SYS 2011/01/22 10:30:57.0812 DLACDBHM (76167b5eb2dffc729edc36386876b40b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 2011/01/22 10:30:57.0828 DLADResM (5615744a1056933b90e6ac54feb86f35) C:\WINDOWS\system32\DLA\DLADResM.SYS 2011/01/22 10:30:57.0843 DLAIFS_M (1aeca2afa5005ce4a550cf8eb55a8c88) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 2011/01/22 10:30:57.0859 DLAOPIOM (840e7f6abb885c72b9ffddb022ef5b6d) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 2011/01/22 10:30:57.0890 DLAPoolM (0294d18731ac05da80132ce88f8a876b) C:\WINDOWS\system32\DLA\DLAPoolM.SYS 2011/01/22 10:30:57.0890 DLARTL_M (91886fed52a3f9966207bce46cfd794f) C:\WINDOWS\system32\Drivers\DLARTL_M.SYS 2011/01/22 10:30:57.0906 DLAUDFAM (cca4e121d599d7d1706a30f603731e59) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 2011/01/22 10:30:57.0937 DLAUDF_M (7dab85c33135df24419951da4e7d38e5) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 2011/01/22 10:30:57.0984 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/01/22 10:30:58.0078 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/01/22 10:30:58.0171 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/01/22 10:30:58.0218 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/01/22 10:30:58.0265 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 2011/01/22 10:30:58.0312 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/01/22 10:30:58.0359 DRVMCDB (c00440385cf9f3d142917c63f989e244) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 2011/01/22 10:30:58.0421 DRVNDDM (6e6ab29d3c06e64ce81feacda85394b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 2011/01/22 10:30:58.0484 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2011/01/22 10:30:58.0515 e1express (34aaa3b298a852b3663e6e0d94d12945) C:\WINDOWS\system32\DRIVERS\e1e5132.sys 2011/01/22 10:30:58.0578 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/01/22 10:30:58.0640 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/01/22 10:30:58.0703 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/01/22 10:30:58.0734 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/01/22 10:30:58.0796 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/01/22 10:30:58.0843 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/01/22 10:30:58.0906 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/01/22 10:30:58.0953 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 2011/01/22 10:30:58.0984 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/01/22 10:30:59.0031 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/01/22 10:30:59.0062 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/01/22 10:30:59.0125 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 2011/01/22 10:30:59.0171 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2011/01/22 10:30:59.0203 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2011/01/22 10:30:59.0234 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2011/01/22 10:30:59.0281 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/01/22 10:30:59.0328 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 2011/01/22 10:30:59.0375 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 2011/01/22 10:30:59.0406 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/01/22 10:30:59.0546 ialm (28423512370705aeda6a652fedb25468) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 2011/01/22 10:30:59.0812 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\WINDOWS\system32\drivers\iaStor.sys 2011/01/22 10:30:59.0875 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/01/22 10:30:59.0953 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 2011/01/22 10:31:00.0093 IntcAzAudAddService (17bbbabb21f86b650b2626045a9d016c) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2011/01/22 10:31:00.0156 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/01/22 10:31:00.0187 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/01/22 10:31:00.0234 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/01/22 10:31:00.0265 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/01/22 10:31:00.0281 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/01/22 10:31:00.0312 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/01/22 10:31:00.0343 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/01/22 10:31:00.0375 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/01/22 10:31:00.0421 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/01/22 10:31:00.0453 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/01/22 10:31:00.0468 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/01/22 10:31:00.0515 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/01/22 10:31:00.0562 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/01/22 10:31:00.0687 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/01/22 10:31:00.0765 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/01/22 10:31:00.0796 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/01/22 10:31:00.0843 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/01/22 10:31:00.0890 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/01/22 10:31:00.0937 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 2011/01/22 10:31:01.0015 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS 2011/01/22 10:31:01.0031 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS 2011/01/22 10:31:01.0093 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/01/22 10:31:01.0140 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/01/22 10:31:01.0218 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/01/22 10:31:01.0250 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/01/22 10:31:01.0296 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/01/22 10:31:01.0343 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/01/22 10:31:01.0375 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/01/22 10:31:01.0390 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/01/22 10:31:01.0437 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/01/22 10:31:01.0468 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/01/22 10:31:01.0500 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/01/22 10:31:01.0515 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/01/22 10:31:01.0562 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/01/22 10:31:01.0609 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/01/22 10:31:01.0625 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/01/22 10:31:01.0671 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/01/22 10:31:01.0734 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/01/22 10:31:01.0781 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/01/22 10:31:01.0859 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/01/22 10:31:01.0984 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/01/22 10:31:02.0046 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/01/22 10:31:02.0109 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/01/22 10:31:02.0156 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/01/22 10:31:02.0234 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/01/22 10:31:02.0281 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/01/22 10:31:02.0328 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/01/22 10:31:02.0375 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/01/22 10:31:02.0437 PCTCore (807ff1dd6e1bdf8e7d2062fca0daecaf) C:\WINDOWS\system32\drivers\PCTCore.sys 2011/01/22 10:31:02.0468 pctgntdi (d15669bd3e1cf18f00b46a7949ea541f) C:\WINDOWS\system32\drivers\pctgntdi.sys 2011/01/22 10:31:02.0515 pctplsg (30c931fcb8df713bcd2fb7ce763a0b47) C:\WINDOWS\system32\drivers\pctplsg.sys 2011/01/22 10:31:02.0703 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 2011/01/22 10:31:02.0765 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 2011/01/22 10:31:02.0843 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/01/22 10:31:02.0859 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/01/22 10:31:02.0875 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/01/22 10:31:02.0937 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/01/22 10:31:02.0984 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 2011/01/22 10:31:03.0062 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 2011/01/22 10:31:03.0109 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 2011/01/22 10:31:03.0171 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 2011/01/22 10:31:03.0265 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 2011/01/22 10:31:03.0296 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/01/22 10:31:03.0343 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/01/22 10:31:03.0359 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/01/22 10:31:03.0375 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/01/22 10:31:03.0406 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/01/22 10:31:03.0421 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/01/22 10:31:03.0453 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/01/22 10:31:03.0484 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/01/22 10:31:03.0531 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/01/22 10:31:03.0593 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 2011/01/22 10:31:03.0625 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 2011/01/22 10:31:03.0687 RT73 (cb20f16afdba63707fb971e0922edec1) C:\WINDOWS\system32\DRIVERS\rt73.sys 2011/01/22 10:31:03.0781 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/01/22 10:31:03.0796 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/01/22 10:31:03.0921 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/01/22 10:31:03.0984 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/01/22 10:31:04.0015 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/01/22 10:31:04.0046 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/01/22 10:31:04.0093 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 2011/01/22 10:31:04.0140 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 2011/01/22 10:31:04.0203 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 2011/01/22 10:31:04.0250 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/01/22 10:31:04.0265 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/01/22 10:31:04.0296 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/01/22 10:31:04.0390 ssmdrv (654dfea96bc82b4acda4f37e5e4a3bbf) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 2011/01/22 10:31:04.0437 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/01/22 10:31:04.0468 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/01/22 10:31:04.0515 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 2011/01/22 10:31:04.0578 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 2011/01/22 10:31:04.0640 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 2011/01/22 10:31:04.0703 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 2011/01/22 10:31:04.0765 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/01/22 10:31:04.0859 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/01/22 10:31:04.0937 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/01/22 10:31:04.0953 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/01/22 10:31:04.0984 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/01/22 10:31:05.0031 TfFsMon (d2a1cd31200a6c9d3dfad022503e4836) C:\WINDOWS\system32\drivers\TfFsMon.sys 2011/01/22 10:31:05.0062 TfNetMon (3e3a544d10b0ac1c4c133048f84390ac) C:\WINDOWS\system32\drivers\TfNetMon.sys 2011/01/22 10:31:05.0078 TfSysMon (706be7328a35c39dbe449e10c1ac6a38) C:\WINDOWS\system32\drivers\TfSysMon.sys 2011/01/22 10:31:05.0125 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 2011/01/22 10:31:05.0187 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/01/22 10:31:05.0203 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 2011/01/22 10:31:05.0265 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/01/22 10:31:05.0312 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys 2011/01/22 10:31:05.0328 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/01/22 10:31:05.0359 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/01/22 10:31:05.0390 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/01/22 10:31:05.0406 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/01/22 10:31:05.0421 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/01/22 10:31:05.0437 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/01/22 10:31:05.0468 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/01/22 10:31:05.0500 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/01/22 10:31:05.0546 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 2011/01/22 10:31:05.0593 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 2011/01/22 10:31:05.0640 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/01/22 10:31:05.0781 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/01/22 10:31:06.0000 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/01/22 10:31:06.0250 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/01/22 10:31:06.0375 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 2011/01/22 10:31:06.0390 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/01/22 10:31:06.0421 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/01/22 10:31:06.0453 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/01/22 10:31:06.0453 ================================================================================ 2011/01/22 10:31:06.0453 Scan finished 2011/01/22 10:31:06.0453 ================================================================================ 2011/01/22 10:31:06.0468 Detected object count: 1 2011/01/22 10:32:33.0328 \HardDisk0 - will be cured after reboot 2011/01/22 10:32:33.0328 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure 2011/01/22 10:32:38.0796 Deinitialize success
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5584 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/23/2011 10:08:24 PM mbam-log-2011-01-23 (22-08-24).txt Scan type: Quick scan Objects scanned: 174117 Time elapsed: 13 minute(s), 17 second(s) Memory Processes Infected: 2 Memory Modules Infected: 0 Registry Keys Infected: 23 Registry Values Infected: 4 Registry Data Items Infected: 0 Folders Infected: 95 Files Infected: 745 Memory Processes Infected: c:\program files\whitesmoke translator\whitesmokedictregistration.exe (PUP.WhiteSmoke) -> 2424 -> Unloaded process successfully. c:\program files\whitesmoke translator\wstraydictmode.exe (PUP.WhiteSmoke) -> 2312 -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{52794457-af6c-4c50-9def-f2e24f4c8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (Spyware.Zbot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\WhiteSmokeTranslator (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\WhiteSmokeTranslator (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{49269ABB-3D8A-4153-93BC-2A695B066F82} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{CD6A6945-EB68-4F46-A4D2-184082A0491F} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{F33928A1-8849-48DE-BECB-829D7727AAF2} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\ComVistaElevator.LocalMachineWriter.1 (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\ComVistaElevator.LocalMachineWriter (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{064E314E-2382-46F2-A93A-239C7115579A} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{54DE313F-2261-4B8E-A699-9AE1D69BC7C9} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3D8A3085-A097-4312-B6A4-49FF1A4A460B} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\WCaptureX.WResult.1 (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\WCaptureX.WResult (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{C7E06D1D-4099-43D4-8C22-718E39713773} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{68D76969-99CA-4057-9C66-9D0C6F497528} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{BB283CBF-EB78-4438-BC3A-7563ED7FEDBF} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\WMonitorX.WMonitorX.1 (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\WMonitorX.WMonitorX (PUP.WhiteSmoke) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{E3004CF3-65FE-B391-A4F3-F679A94B72C5} (Spyware.Passwords.XGen) -> Value: {E3004CF3-65FE-B391-A4F3-F679A94B72C5} -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Value: {52794457-AF6C-4C50-9DEF-F2E24F4C8889} -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{52794457-af6c-4c50-9def-f2e24f4c8889} (PUP.WhiteSmoke) -> Value: {52794457-af6c-4c50-9def-f2e24f4c8889} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer (PUM.Bad.Proxy) -> Value: ProxyServer -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\program files\whitesmoketoolbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\modules (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\newtab (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\newtab\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\dynamicelements (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\rss (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\search (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\weather (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dtxwizard (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dtxwizard\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dtxwizard\skin\icon_library (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dtxwizard\skin\icon_library\Basics (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\options (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\searchbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\components (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\iepngfix (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\popup (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\style (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\captionbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\style (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background\attic (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\captionbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\style (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\style (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\whitesmoketoolbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\all users\start menu\Programs\whitesmoke translator (PUP.WhiteSmoke) -> Quarantined and deleted successfully. Files Infected: c:\documents and settings\Jennifer\application data\Irba\rakib.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\whitesmoketoolbarx.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\default user\start menu\Programs\Startup\efsoyb.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\WINDOWS\temp\385.tmp (PUP.BHO) -> Quarantined and deleted successfully. c:\WINDOWS\temp\cpyd\setup.exe (Spyware.Zbot) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\local settings\temporary internet files\Content.IE5\E4LSFPUJ\load[1].php (Rootkit.TDSS.XGen) -> Quarantined and deleted successfully. c:\documents and settings\localservice\local settings\temporary internet files\Content.IE5\4088KEBN\load[1].php (Rootkit.Dropper) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\YD1VIVFJ\load[1].php (Rootkit.TDSS.XGen) -> Quarantined and deleted successfully. c:\documents and settings\all users\Desktop\buy whitesmoke translator.lnk (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\all users\Desktop\launch whitesmoke translator.lnk (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\all users\start menu\Programs\Startup\launch whitesmoke translator.lnk (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\temp\explorer.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\local settings\temp\pdfupd.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\manifest.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\toolbar.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\uninstall.exe (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\whitesmoketoolbar.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\neterror.xhtml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\preferences.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\toolbar.htm (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\toolbar.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\vmncode.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\vmnrsswin.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\about.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\dtxpanel.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\dtxpanelwin.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\dtxprefwin.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\dtxwin.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\emailnotifierproviders.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\external.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\neterror.xhtml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\rsspreview.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\rsswin.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\rsswin.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\vmncode.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\lib\wmpstreamer.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\modules\datastore.jsm (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\newtab\newtab.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\newtab\images\btn_search.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\newtab\images\bullet.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\newtab\images\field_bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\newtab\images\powered_by_yahoo.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\css\twitter.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\btn-login-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\btn-login.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\btn-submit.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\loginbg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\refresh-over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\refresh.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-off-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-off-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-on-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-on-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\twitter-logo48.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\twitter_top.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\js\jquery.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\js\scripts.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\index.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollt.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\arrow-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\arrows_grey-left.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\arrows_grey-right.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\btn-search-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\powered-by-youtube.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollb-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollb-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollb.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollt-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollt-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-off-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-off-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-on-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-on-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-over-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-over-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-red-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-red-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-red-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-white-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-white-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-white-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\vid-bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\youtube.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\js\jquery-1.3.2.min.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\js\jquery.autocomplete.min.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\dynamicelements\vmntoolbar.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\rss\rss.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\search\engines.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\search\search.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\data\weather\icons.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\634017460871087500_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\about.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\babylon_logo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\bing_16x16.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\bing_searchicon_20x22_spaced_hover_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\bing_searchicon_20x22_spaced_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\blank_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\bluelite.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\bluesky.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\btn-search-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\btn-settings.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\btn-widgets-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\btn-widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\btn_settings.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\ca.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\checkmytext_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\checkmytext_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dictionary.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dictionary_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\divider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\downloadcom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dtxlogo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\email.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\email_on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\eteacher_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\facebook.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\feed_icon2_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\feed_icon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\france_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\games.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\gamesicon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\games_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred0.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred0_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred1.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred1_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred2.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred2_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred3.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred3_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred4.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred4_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphred5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\graphredna.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\grey.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\ico-shield.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\images.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\italy_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lichen.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\logo-about.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\logo-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\logo-separator.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\logo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\mail.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\menuseparatorback.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\modify-save.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\modify.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\modifyhot.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\music.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\namespacetoolbar.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\networkicons_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\btn-settings-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dictionary_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-found.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\shopping.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\vmn.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\news.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\orange.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\pixsy.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\protect-id.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\relatedlinks.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-collapse.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-delete.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-expand.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-feed.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-folder-remove.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-folder-rename.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-folder.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-reload.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss-subscribe.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rssback.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rsstopback.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\rss_feed_icon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\search-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\settings.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\siteinfo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\skin-bluelite.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\skin-bluesky.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\skin-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\skin-lichen.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\skin-orange.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\skin-yellow.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\skin.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\spain_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\technorati.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\toolbarsplitter.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\translate.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\translate_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\translate_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\truste_about.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\tvicons_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\tvicon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\tv_icon3_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\usa_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\vmn.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\web.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\whtsmke_logo_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\whtsmke_logo_png2_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\whtsmke_logo_png3_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\whtsmke_logo_png4_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\whtsmke_logo_png5_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\whtsmke_logo_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\wikipedia.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\yahoosearch.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\yellow.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\youtube.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\zoom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\dtxwizard\skin\icon_library\Basics\folder.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\add.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\aol.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\arrow-dn.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\arrow-right-disabled.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\arrow-right.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\arrow-up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btn-divider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btn-end.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btn-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btn-mdl_ff.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btn-start.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btnover-divider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btnover-end.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btnover-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btnover-mdl_ff.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\blank.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btn-widgets-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btn-widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btnback-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btnback-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btnleft-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btnleft-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btnright-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btnright-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\btn_slider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\button-splitter-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\button-splitter-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\checkmark.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\chevron.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\collapse.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\comcast.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\dtx.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\edit-back-hot.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\edit-back.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\expand.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\found.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\gmail.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\highlight.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\highlight_blue.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\highlight_cyan.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\highlight_lime.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\highlight_yellow.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\hotmail.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\ico-check.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\imap.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\lastsearch-thumb-back.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\loadingmid.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\lock.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\logo-separator.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\mailcom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menuitem-splitter.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menuitemback-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menuitemback-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menuitemleft-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menuitemleft-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menuitemright-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menuitemright-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menu_bg-basic.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menu_separator_bar.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\bg-btnover-start.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\highlight_magenta.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\menu_separator_white.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\modify.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\move.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\movetarget.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\pop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\reload.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\remove.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\rename.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\resize-box.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\rss.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\rsschannelback.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\RSSLogo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\rsstabdivider.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\scroll-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\scroll-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\search-go.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\text-ellipsis.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\toolbarsplitter.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\transparent_1px.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\yahoo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\footer.htm (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\gamecategory.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\gameData.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\gameList.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\games.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\gametype.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\inithtml.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\popupgames.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\popuphtml.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\popuprss.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\popupwidgets.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\scroll.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\css\panels.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\css\popupabout.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\css\popupgames.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\css\popupRSS.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\css\popupwidgets.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-off-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-off-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-on-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-on-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\ttlbar-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\ttlbar-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\ttlbar-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\default\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\gamethumb-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scroll-topwin.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-dn.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-sml-drop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-sml.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\arrowr-bluew5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\bg-aboutbox.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\bg-btnover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\bg-pnl520x390.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-back.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-drag.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-moredetails.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-next-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-next.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-previous-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-previous.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\bullet-orange.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\gamethumb2-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-calendar.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-download.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-joystick24.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-news24.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-play.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-tags.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-Add.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-download.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-info.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-play.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-shop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\menul-bgon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\menul-bgover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\panel-botm-noscroll.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scroll-bg-206.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scroll-bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\star_x_grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\star_x_orange.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\truste_about.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\view-detailed-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\view-detailed-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\view-thumb-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\view-thumb-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\widgets-square-16px.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\widgets-square-24px.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\panels\images\widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\managerpanel.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\volumeslider.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\css\manager.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\css\slider.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-off.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\bg-pnl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\collapsed_button.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\expanded_button.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-playstation-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-playstation-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-playstation.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-radio.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\music-note.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-pause-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-pause.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-play-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-play.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-buffer.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-busy.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-on.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-warning.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options-design-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options-design.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-0.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-1.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-2.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-3.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-mute.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\scrollbar-handle.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\scrollbar-track.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\slider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\slideron.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\radio\images\track.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_07.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_02.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_03.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_04.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_06.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_08.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_09.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_10.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_11.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_12.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_13.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_14.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_15.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_16.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_18.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_19.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_20.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\border_21.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\close-hot.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\close-normal.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\loadingmid.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\proxy.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\template.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\template.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\templateff.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\uwa\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\cond999.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\icons.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\na-s.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\na-t.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\na.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\weather.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\popupweather.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\popupweather.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\add.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\box-check.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\options\options-main.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\options\options-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\options\options-weather.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\options\options-widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\searchbar\searchbar-background-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\searchbar\searchbar-background-middle.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\chrome\skin\searchbar\searchbar-background-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoketoolbar\components\windowmediator.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\buy.ico (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\comvistaelevator.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\dictionary48x48.ico (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\license_agreement_translator.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\osmax.ocx (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\secman.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\settings.ini (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\TCCons.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\WCapture.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\wcapturex.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\WCustom.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\whitesmokedictregistration.exe (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\WHook.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\wmonitorx.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\wsdicthookdll.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\WSLogger.exe (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\wstraydictmode.exe (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\iepngfix\blank.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\iepngfix\checkerboard.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\iepngfix\helix.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\iepngfix\iepngfix.htc (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\iepngfix\iepngfix.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\iepngfix\opacity.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\js\common.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\js\pngfix.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\js\prototype.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\common\js\xmlhttp.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\index.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\spacer.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\ajax-loader.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\bottom_bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\bottom_left_corner.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\corner_bottom_left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\corner_bottom_right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\corner_top_left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\corner_top_right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\down_arrow.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\empty.jpg (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\input_bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\left_input.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\loading_dictionary.swf (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\resize.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\right_input.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\background\search_strip_bg3.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\idioms_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\dictionary_disabled.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\dictionary_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\dictionary_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\dictionary_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\down_arrow.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\go_disabled.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\go_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\go_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\go_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\idioms_disabled.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\idioms_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\idioms_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\thesaurus_disabled.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\thesaurus_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\thesaurus_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\thesaurus_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\translate_normal.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\translate_pressed.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\translate_rollover.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\translation_disabled.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\translation_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\translation_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\Buttons\translation_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_min_down.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_close_down.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_close_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_close_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_max_down.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_max_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_max_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_min_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_bar_min_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_dictionary_off.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_dictionary_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_dictionary_roll_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_strip.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_strip_right_corner.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_strip_right_corner.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_translation_off.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_translation_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\caption_translation_roll_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\captionbar\logo.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\popup\screen_bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\popup\screen_bg_bottom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\popup\screen_bg_top.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\popup\screen_captionbar_press.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\img\popup\screen_captionbar_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js\common.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js\contextmenu.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js\dictinterface.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js\jquery.combobox.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js\jquery.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js\prototype.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\js\xmlhttp.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\style\combobox.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\style\contextmenu.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientdic\style\dictionary.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\index.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\body_bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\congra.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\continue_button_click.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\continue_button_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\continue_button_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\intro.jpg (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\welcome.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\captionbar\caption_bar_close_down.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\captionbar\caption_bar_close_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\captionbar\caption_bar_close_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\captionbar\caption_strip.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\img\captionbar\logo.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\js\reginterface.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientregistration\style\registration.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\index.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\welcome_all.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\welcome_expired.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\buy_button.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\caption_bar_close_down.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\caption_bar_close_over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\caption_bar_close_up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\close_button.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\close_button_down.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\expired_bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background\translator-welcome-final.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background\translator-welcome-final.jpg (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background\translator-welcome-final.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background\use_ws_bgnew.jpg (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background\use_ws_bgnew.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\background\attic\use_ws_bgnew.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\captionbar\arrow_white.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\captionbar\caption_strip.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\captionbar\left_bot_chunk.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\captionbar\right_bot_chunk.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\img\captionbar\white_x_button.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\js\iframeinterface.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\content\style\welcome.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\js\welcomeinterface.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files\whitesmoke translator\html\english\dictclientwelcome\style\welcomescreen.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\dtx.ini (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\guid.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\preferences.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\stat.log (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\stats.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\uninstallie.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\uninstallstatie.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\Jennifer\application data\whitesmoketoolbar\version.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\whitesmoketoolbar\dtx.ini (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\whitesmoketoolbar\exeArgs.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\whitesmoketoolbar\guid.dat (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\whitesmoketoolbar\setupCfg.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\all users\start menu\Programs\whitesmoke translator\registration.lnk (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\all users\start menu\Programs\whitesmoke translator\uninstall.lnk (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\documents and settings\all users\start menu\Programs\whitesmoke translator\whitesmoke translator.lnk (PUP.WhiteSmoke) -> Quarantined and deleted successfully.
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-01-24.01 - Jennifer 01/24/2011 23:13:31.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3061.2324 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jennifer\Application Data\.#
c:\documents and settings\Jennifer\Local Settings\Temporary Internet Files\AAmAy.jpg
c:\documents and settings\Jennifer\Local Settings\Temporary Internet Files\ao15aP6BK.jpg
c:\documents and settings\Jennifer\Local Settings\Temporary Internet Files\bMo740LMo.jpg
c:\documents and settings\Jennifer\Local Settings\Temporary Internet Files\cookies.sqlite
c:\documents and settings\Jennifer\Local Settings\Temporary Internet Files\K1l35Xm.jpg
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\AutoRun.inf

.
((((((((((((((((((((((((( Files Created from 2010-12-25 to 2011-01-25 )))))))))))))))))))))))))))))))
.

2011-01-22 04:49 . 2011-01-22 04:49 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2011-01-22 04:49 . 2011-01-22 04:49 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-01-22 04:07 . 2011-01-22 04:07 ——– d—–w- C:\_OTL
2011-01-19 15:17 . 2011-01-19 15:17 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Unity
2011-01-19 13:40 . 2011-01-19 13:40 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-01-19 13:40 . 2011-01-19 13:40 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2011-01-19 12:50 . 2011-01-19 12:50 ——– d—–w- c:\windows\system32\%APPDATA%
2011-01-19 12:47 . 2011-01-19 12:48 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-01-19 04:51 . 2011-01-19 04:51 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-12-26 19:55 . 2010-09-28 21:44 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-12-26 19:55 . 2010-09-28 21:44 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-12-26 19:55 . 2010-12-26 19:55 ——– d—–w- c:\program files\Bonjour
2010-12-26 19:55 . 2010-12-26 19:57 ——– d—–w- c:\program files\Common Files\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 00:09 . 2010-03-04 14:10 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 00:08 . 2010-03-04 14:10 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 10:44 . 2009-06-02 13:33 135096 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-29 23:38 . 2010-11-29 23:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38 . 2010-11-29 23:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-11-22 11:42 . 2009-06-02 13:33 61960 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-18 18:12 . 2010-03-17 01:29 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2010-03-17 01:29 249856 —-a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-08-10 16:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-10 16:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-10 16:51 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-10 16:51 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2010-03-17 01:29 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2010-03-17 01:29 290048 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-12-03 21:52 574096 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-12-03 21:52 574096 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-12-03 21:52 574096 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-11 218032]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-12-03 670864]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-05-27 1287120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\Jennifer\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-5-9 7168]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Online Assistant.lnk - c:\program files\American Express Online Assistant\OnlineAssistant.exe [2008-11-3 1185680]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Online Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Online Assistant.lnk
backup=c:\windows\pss\Online Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Yahoo! Autosync.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Yahoo! Autosync.lnk
backup=c:\windows\pss\Yahoo! Autosync.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-05-19 05:23 49968 —-a-w- c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2007-06-14 00:41 69632 —-a-w- c:\windows\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 23:16 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2007-09-17 15:56 124200 ——w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 23:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 13:00 1116920 —-a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-06-14 00:41 16132608 —-a-w- c:\windows\RTHDCPL.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Documents and Settings\\Jennifer\\Desktop\\Old ticketbuy\\TicketBuy4444\\TicketBuy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"=
"c:\\Documents and Settings\\Jennifer\\Desktop\\may 26 ticketbuy\\TicketBuy.exe"=
"c:\\Documents and Settings\\Jennifer\\Desktop\\may 26 ticketbuy\\TicketBuyEvent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/1/2010 10:35 PM 218592]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [5/13/2010 8:39 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [5/13/2010 8:39 PM 59664]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [3/1/2010 10:35 PM 233136]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [6/2/2009 7:33 AM 339624]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/2/2009 7:33 AM 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [6/2/2009 7:33 AM 403624]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [3/1/2010 10:38 PM 112592]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/1/2010 10:35 PM 366840]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/6/2009 6:22 PM 24652]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [3/1/2010 10:35 PM 63360]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [5/13/2010 8:39 PM 33552]
S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service –> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]

— Other Services/Drivers In Memory —

*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 10:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2011-01-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:34]
.
.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = ;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://flyingincognitosleep.com/cgi-bin/h.pl
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {C73D32D1-835F-43B6-8151-8C5365059C66} - c:\documents and settings\Jennifer\Local Settings\Application Data\{C73D32D1-835F-43B6-8151-8C5365059C66}
FF - Ext: XULRunner: {CE1701E9-00FA-4AB3-88AC-0E424249F7A4} - c:\documents and settings\Jennifer\Local Settings\Application Data\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4}
FF - Ext: XULRunner: {214F2009-B770-4270-9860-89CD8A50478F} - c:\documents and settings\Jennifer\Local Settings\Application Data\{214F2009-B770-4270-9860-89CD8A50478F}
FF - Ext: XULRunner: {EA4C5146-8C4C-449A-9C25-4C435C87694A} - c:\documents and settings\Jennifer\Local Settings\Application Data\{EA4C5146-8C4C-449A-9C25-4C435C87694A}
FF - Ext: XULRunner: {AF45588C-2174-415C-8493-40DAC4AB1C62} - c:\documents and settings\Jennifer\Local Settings\Application Data\{AF45588C-2174-415C-8493-40DAC4AB1C62}
FF - Ext: XULRunner: {5CDC00D3-983D-42BB-A673-966E5B0E2306} - c:\documents and settings\Jennifer\Local Settings\Application Data\{5CDC00D3-983D-42BB-A673-966E5B0E2306}
FF - Ext: XULRunner: {87CA3053-8530-4233-A6C9-8D18285FB1E7} - c:\documents and settings\Jennifer\Local Settings\Application Data\{87CA3053-8530-4233-A6C9-8D18285FB1E7}
FF - Ext: XULRunner: {C3F91810-FD9C-47BA-BF56-523B99848792} - c:\documents and settings\Jennifer\Local Settings\Application Data\{C3F91810-FD9C-47BA-BF56-523B99848792}
FF - Ext: XULRunner: {86AE899F-3B6E-42D0-B054-301B77859398} - c:\documents and settings\Jennifer\Local Settings\Application Data\{86AE899F-3B6E-42D0-B054-301B77859398}
FF - Ext: XULRunner: {24AF10CD-D80F-4A93-B763-2B7CD1E15410} - c:\documents and settings\Jennifer\Local Settings\Application Data\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}
FF - Ext: XULRunner: {EC6A3E63-0817-49DA-95A6-A23140F0FC7F} - c:\documents and settings\Jennifer\Local Settings\Application Data\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F}
FF - Ext: XULRunner: {538C6ACE-FB87-474C-A103-46FB5832D8BD} - c:\documents and settings\Jennifer\Local Settings\Application Data\{538C6ACE-FB87-474C-A103-46FB5832D8BD}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: browser.startup.homepage - hxxp://flyingincognitosleep.com/cgi-bin/h.pl
FF - user.js: browser.startup.page - 1
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)
MSConfigStartUp-21316518 - c:\docume~1\ALLUSE~1\APPLIC~1\21316518\21316518.exe
MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-24 23:18
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\GTGina.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(796)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\program files\Avira\AntiVir Desktop\avsda.dll
.
Completion time: 2011-01-24 23:20:21
ComboFix-quarantined-files.txt 2011-01-25 05:20

Pre-Run: 190,970,462,208 bytes free
Post-Run: 199,707,262,976 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - E857E459E6EDC47BCDC42A8BBFFF547A
AV: AntiVir Desktop *Disabled/Updated* {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

You appear to have 2 antivirus running,you should remove Spyware doctor




COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Firefox::
    FF - ProfilePath - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\
    FF - prefs.js: browser.startup.homepage - hxxp://flyingincognitosleep.com/cgi-bin/h.pl
    FF - user.js: browser.startup.homepage - hxxp://flyingincognitosleep.com/cgi-bin/h.pl
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.








Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
ComboFix 11-01-25.01 - Jennifer 01/25/2011 18:28:32.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3061.2501 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jennifer\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
AV: Spyware Doctor with AntiVirus *Disabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.

((((((((((((((((((((((((( Files Created from 2010-12-26 to 2011-01-26 )))))))))))))))))))))))))))))))
.

2011-01-22 04:49 . 2011-01-22 04:49 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2011-01-22 04:49 . 2011-01-22 04:49 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-01-22 04:07 . 2011-01-22 04:07 ——– d—–w- C:\_OTL
2011-01-19 15:17 . 2011-01-19 15:17 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Unity
2011-01-19 13:40 . 2011-01-19 13:40 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-01-19 13:40 . 2011-01-19 13:40 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2011-01-19 12:50 . 2011-01-19 12:50 ——– d—–w- c:\windows\system32\%APPDATA%
2011-01-19 12:47 . 2011-01-19 12:48 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-01-19 04:51 . 2011-01-19 04:51 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 00:09 . 2010-03-04 14:10 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 00:08 . 2010-03-04 14:10 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 10:44 . 2009-06-02 13:33 135096 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-29 23:38 . 2010-11-29 23:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38 . 2010-11-29 23:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-11-22 11:42 . 2009-06-02 13:33 61960 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-18 18:12 . 2010-03-17 01:29 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2010-03-17 01:29 249856 —-a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-08-10 16:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-10 16:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-10 16:51 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-10 16:51 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2010-03-17 01:29 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2010-03-17 01:29 290048 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((( SnapShot@2011-01-25_05.18.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-26 00:18 . 2011-01-26 00:18 16384 c:\windows\temp\Perflib_Perfdata_2fc.dat
+ 2011-01-26 00:18 . 2011-01-26 00:18 16384 c:\windows\temp\Perflib_Perfdata_204.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-12-03 21:52 574096 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-12-03 21:52 574096 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-12-03 21:52 574096 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-11 218032]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-12-03 670864]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\Jennifer\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-5-9 7168]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Online Assistant.lnk - c:\program files\American Express Online Assistant\OnlineAssistant.exe [2008-11-3 1185680]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Online Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Online Assistant.lnk
backup=c:\windows\pss\Online Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Yahoo! Autosync.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Yahoo! Autosync.lnk
backup=c:\windows\pss\Yahoo! Autosync.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-05-19 05:23 49968 —-a-w- c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2007-06-14 00:41 69632 —-a-w- c:\windows\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 23:16 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2007-09-17 15:56 124200 ——w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 23:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 13:00 1116920 —-a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-06-14 00:41 16132608 —-a-w- c:\windows\RTHDCPL.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Documents and Settings\\Jennifer\\Desktop\\Old ticketbuy\\TicketBuy4444\\TicketBuy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"=
"c:\\Documents and Settings\\Jennifer\\Desktop\\may 26 ticketbuy\\TicketBuy.exe"=
"c:\\Documents and Settings\\Jennifer\\Desktop\\may 26 ticketbuy\\TicketBuyEvent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/1/2010 10:35 PM 218592]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [5/13/2010 8:39 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [5/13/2010 8:39 PM 59664]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [3/1/2010 10:35 PM 233136]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [6/2/2009 7:33 AM 339624]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/2/2009 7:33 AM 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [6/2/2009 7:33 AM 403624]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [3/1/2010 10:38 PM 112592]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/6/2009 6:22 PM 24652]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [3/1/2010 10:35 PM 63360]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/1/2010 10:35 PM 366840]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [5/13/2010 8:39 PM 33552]
S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service –> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]

— Other Services/Drivers In Memory —

*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 10:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2011-01-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:34]
.
.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = ;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {C73D32D1-835F-43B6-8151-8C5365059C66} - c:\documents and settings\Jennifer\Local Settings\Application Data\{C73D32D1-835F-43B6-8151-8C5365059C66}
FF - Ext: XULRunner: {CE1701E9-00FA-4AB3-88AC-0E424249F7A4} - c:\documents and settings\Jennifer\Local Settings\Application Data\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4}
FF - Ext: XULRunner: {214F2009-B770-4270-9860-89CD8A50478F} - c:\documents and settings\Jennifer\Local Settings\Application Data\{214F2009-B770-4270-9860-89CD8A50478F}
FF - Ext: XULRunner: {EA4C5146-8C4C-449A-9C25-4C435C87694A} - c:\documents and settings\Jennifer\Local Settings\Application Data\{EA4C5146-8C4C-449A-9C25-4C435C87694A}
FF - Ext: XULRunner: {AF45588C-2174-415C-8493-40DAC4AB1C62} - c:\documents and settings\Jennifer\Local Settings\Application Data\{AF45588C-2174-415C-8493-40DAC4AB1C62}
FF - Ext: XULRunner: {5CDC00D3-983D-42BB-A673-966E5B0E2306} - c:\documents and settings\Jennifer\Local Settings\Application Data\{5CDC00D3-983D-42BB-A673-966E5B0E2306}
FF - Ext: XULRunner: {87CA3053-8530-4233-A6C9-8D18285FB1E7} - c:\documents and settings\Jennifer\Local Settings\Application Data\{87CA3053-8530-4233-A6C9-8D18285FB1E7}
FF - Ext: XULRunner: {C3F91810-FD9C-47BA-BF56-523B99848792} - c:\documents and settings\Jennifer\Local Settings\Application Data\{C3F91810-FD9C-47BA-BF56-523B99848792}
FF - Ext: XULRunner: {86AE899F-3B6E-42D0-B054-301B77859398} - c:\documents and settings\Jennifer\Local Settings\Application Data\{86AE899F-3B6E-42D0-B054-301B77859398}
FF - Ext: XULRunner: {24AF10CD-D80F-4A93-B763-2B7CD1E15410} - c:\documents and settings\Jennifer\Local Settings\Application Data\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}
FF - Ext: XULRunner: {EC6A3E63-0817-49DA-95A6-A23140F0FC7F} - c:\documents and settings\Jennifer\Local Settings\Application Data\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F}
FF - Ext: XULRunner: {538C6ACE-FB87-474C-A103-46FB5832D8BD} - c:\documents and settings\Jennifer\Local Settings\Application Data\{538C6ACE-FB87-474C-A103-46FB5832D8BD}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: browser.startup.page - 1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-25 18:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\windows\system32\GTGina.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(800)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\program files\Avira\AntiVir Desktop\avsda.dll

- - - - - - - > 'explorer.exe'(4068)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-01-25 18:33:47
ComboFix-quarantined-files.txt 2011-01-26 00:33
ComboFix2.txt 2011-01-25 05:20

Pre-Run: 199,751,852,032 bytes free
Post-Run: 199,725,522,944 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - E178FDA24E4F9BD8CCE443221565DAB1
eset results C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\36\19707c64-60938f7a a variant of Win32/Kryptik.JZG trojan cleaned by deleting - quarantined
AV: AntiVir Desktop *Disabled/Updated* {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

You appear to have 2 antivirus running,you should remove Spyware doctor as having both running does more harm than good.



Please post a new OTL log
I just uninstalled spyware doctor.

OTL logfile created on: 1/25/2011 9:54:25 PM - Run 2
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Jennifer\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.77 Gb Total Space | 186.17 Gb Free Space | 79.98% Space Free | Partition Type: NTFS

Computer Name: JENS-OFFICE | User Name: Jennifer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/19 21:36:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
PRC - [2010/12/08 05:19:45 | 000,267,944 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/11/02 05:02:04 | 000,403,624 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2010/11/02 05:02:04 | 000,339,624 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
PRC - [2010/11/02 05:02:04 | 000,281,768 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/11/02 05:02:04 | 000,135,336 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010/10/27 19:17:52 | 000,207,424 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/08/25 10:27:44 | 000,309,824 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/03/24 05:04:16 | 000,076,968 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/12/03 15:52:32 | 001,980,560 | R— | M] (Carbonite, Inc. (www.carbonite.com)) – C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
PRC - [2009/12/03 15:52:32 | 000,670,864 | R— | M] (Carbonite, Inc.) – C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2009/02/23 07:05:34 | 000,111,856 | —- | M] (Yahoo! Inc) – C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/11/03 18:57:20 | 001,185,680 | —- | M] (American Express) – C:\Program Files\American Express Online Assistant\OnlineAssistant.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/19 11:16:56 | 008,253,440 | —- | M] (Netscape) – C:\Program Files\Netscape\Navigator 9\navigator.exe
PRC - [2007/05/25 09:38:46 | 000,112,176 | —- | M] (SingleClick Systems) – C:\Program Files\Dell Network Assistant\hnm_svc.exe
PRC - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/09/11 03:40:32 | 000,218,032 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2005/11/22 11:44:44 | 005,245,952 | —- | M] (Linksys) – C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
PRC - [2005/07/04 15:46:04 | 000,053,307 | —- | M] (GEMTEKS) – C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe


========== Modules (SafeList) ==========

MOD - [2011/01/19 21:36:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Running] – – (WUSB54GCSVC)
SRV - File not found [Auto | Stopped] – – (RoxLiveShare9)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2010/12/08 05:19:45 | 000,267,944 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2010/11/02 05:02:04 | 000,403,624 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE – (AntiVirWebService)
SRV - [2010/11/02 05:02:04 | 000,339,624 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe – (AntiVirMailService)
SRV - [2010/11/02 05:02:04 | 000,135,336 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2010/10/16 00:40:40 | 000,037,664 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2009/12/03 15:52:32 | 001,980,560 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe – (CarboniteService)
SRV - [2008/12/07 15:09:38 | 000,085,096 | —- | M] (Autodesk) [On_Demand | Stopped] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2007/05/25 09:38:46 | 000,112,176 | —- | M] (SingleClick Systems) [Auto | Running] – C:\Program Files\Dell Network Assistant\hnm_svc.exe – (hnmsvc)
SRV - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)


========== Driver Services (SafeList) ==========

DRV - [2010/12/20 04:44:38 | 000,135,096 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2010/11/22 05:42:16 | 000,061,960 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2010/05/10 12:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 12:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/06/09 02:29:50 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2009/06/02 07:25:00 | 000,011,608 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Program Files\Avira\AntiVir Desktop\avgio.sys – (avgio)
DRV - [2009/02/19 13:13:54 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2009/02/19 13:13:38 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2008/04/13 12:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 12:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/13 10:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/06/26 12:06:20 | 000,254,872 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\e1e5132.sys – (e1express) Intel®
DRV - [2007/06/13 18:41:44 | 004,403,712 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/06/13 17:25:14 | 000,304,920 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2007/06/13 17:21:16 | 005,760,096 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2006/08/18 11:18:08 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/08/18 11:17:46 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/08/18 11:17:44 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/08/18 11:17:44 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/08/18 11:17:42 | 000,026,008 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/08/18 11:17:40 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/08/18 11:17:38 | 000,104,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/08/18 11:17:38 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/08/11 09:05:58 | 000,051,768 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\DRVNDDM.SYS – (DRVNDDM)
DRV - [2006/08/11 08:35:18 | 000,012,920 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/08/11 08:35:16 | 000,028,184 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2006/07/21 09:21:26 | 000,099,176 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB)
DRV - [2005/11/03 19:39:02 | 000,245,504 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt73.sys – (RT73)
DRV - [2004/08/03 20:29:56 | 001,897,408 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2001/08/17 12:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 12:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 12:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 12:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 12:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 11:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 11:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 11:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 11:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 11:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 11:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 11:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 11:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 11:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 11:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080510
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080510

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D4 74 CE B9 7D BB CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;="
FF - prefs.js..browser.search.selectedEngine: "AIM Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {C73D32D1-835F-43B6-8151-8C5365059C66}:1.9.1
FF - prefs.js..extensions.enabledItems: {CE1701E9-00FA-4AB3-88AC-0E424249F7A4}:1.9.1
FF - prefs.js..extensions.enabledItems: {214F2009-B770-4270-9860-89CD8A50478F}:1.9.1
FF - prefs.js..extensions.enabledItems: {EA4C5146-8C4C-449A-9C25-4C435C87694A}:1.9.1
FF - prefs.js..extensions.enabledItems: {AF45588C-2174-415C-8493-40DAC4AB1C62}:1.9.1
FF - prefs.js..extensions.enabledItems: {5CDC00D3-983D-42BB-A673-966E5B0E2306}:1.9.1
FF - prefs.js..extensions.enabledItems: {87CA3053-8530-4233-A6C9-8D18285FB1E7}:1.9.1
FF - prefs.js..extensions.enabledItems: {C3F91810-FD9C-47BA-BF56-523B99848792}:1.9.1
FF - prefs.js..extensions.enabledItems: {86AE899F-3B6E-42D0-B054-301B77859398}:1.9.1
FF - prefs.js..extensions.enabledItems: {24AF10CD-D80F-4A93-B763-2B7CD1E15410}:1.9.1
FF - prefs.js..extensions.enabledItems: {EC6A3E63-0817-49DA-95A6-A23140F0FC7F}:1.9.1
FF - prefs.js..extensions.enabledItems: {538C6ACE-FB87-474C-A103-46FB5832D8BD}:1.9.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{C73D32D1-835F-43B6-8151-8C5365059C66}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{C73D32D1-835F-43B6-8151-8C5365059C66} [2009/12/26 15:27:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4} [2009/12/26 16:45:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{214F2009-B770-4270-9860-89CD8A50478F}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{214F2009-B770-4270-9860-89CD8A50478F} [2010/01/16 08:46:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{EA4C5146-8C4C-449A-9C25-4C435C87694A}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{EA4C5146-8C4C-449A-9C25-4C435C87694A}\ [2010/01/22 06:04:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{AF45588C-2174-415C-8493-40DAC4AB1C62}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{AF45588C-2174-415C-8493-40DAC4AB1C62} [2010/01/23 08:40:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{5CDC00D3-983D-42BB-A673-966E5B0E2306}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{5CDC00D3-983D-42BB-A673-966E5B0E2306}\ [2010/01/30 08:24:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{87CA3053-8530-4233-A6C9-8D18285FB1E7}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{87CA3053-8530-4233-A6C9-8D18285FB1E7}\ [2010/02/05 08:30:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{C3F91810-FD9C-47BA-BF56-523B99848792}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{C3F91810-FD9C-47BA-BF56-523B99848792}\ [2010/02/10 07:04:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{86AE899F-3B6E-42D0-B054-301B77859398}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{86AE899F-3B6E-42D0-B054-301B77859398} [2010/02/15 15:30:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}\ [2010/02/21 09:44:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F} [2010/02/24 07:39:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{538C6ACE-FB87-474C-A103-46FB5832D8BD}: C:\Documents and Settings\Jennifer\Local Settings\Application Data\{538C6ACE-FB87-474C-A103-46FB5832D8BD}\ [2010/02/27 08:27:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/05/10 12:32:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/04 08:43:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/26 13:57:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Components: C:\Program Files\Netscape\Navigator 9\components [2010/12/26 13:57:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Plugins: C:\Program Files\Netscape\Navigator 9\plugins [2010/12/26 13:57:02 | 000,000,000 | —D | M]

[2008/06/17 18:02:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Extensions
[2011/01/19 07:30:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions
[2009/09/02 07:29:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/19 13:56:28 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/07/22 18:57:34 | 000,000,000 | —D | M] (Power Twitter) – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\extensions\{b2509cd4-17cd-45ed-8146-a82af038f493}
[2009/01/06 18:22:48 | 000,001,739 | —- | M] () – C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\mngtyueh.default\searchplugins\aim-search.xml
[2011/01/19 07:30:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/11/25 09:40:13 | 000,000,000 | —D | M] (American Express Online Assistant) – C:\Program Files\Mozilla Firefox\extensions\{6bae2634-6076-40a2-be93-600b67061f6c}
[2010/01/16 08:46:42 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{214F2009-B770-4270-9860-89CD8A50478F}
[2010/02/21 09:44:33 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{24AF10CD-D80F-4A93-B763-2B7CD1E15410}
[2010/02/27 08:27:13 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{538C6ACE-FB87-474C-A103-46FB5832D8BD}
[2010/01/30 08:24:20 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{5CDC00D3-983D-42BB-A673-966E5B0E2306}
[2010/02/15 15:30:43 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{86AE899F-3B6E-42D0-B054-301B77859398}
[2010/02/05 08:30:41 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{87CA3053-8530-4233-A6C9-8D18285FB1E7}
[2010/01/23 08:40:32 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{AF45588C-2174-415C-8493-40DAC4AB1C62}
[2010/02/10 07:04:46 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{C3F91810-FD9C-47BA-BF56-523B99848792}
[2009/12/26 15:27:03 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{C73D32D1-835F-43B6-8151-8C5365059C66}
[2009/12/26 16:45:42 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{CE1701E9-00FA-4AB3-88AC-0E424249F7A4}
[2010/01/22 06:04:55 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{EA4C5146-8C4C-449A-9C25-4C435C87694A}
[2010/02/24 07:39:59 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\JENNIFER\LOCAL SETTINGS\APPLICATION DATA\{EC6A3E63-0817-49DA-95A6-A23140F0FC7F}
[2008/12/12 23:43:17 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2011/01/19 06:50:25 | 000,001,919 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing-zugo.xml

O1 HOSTS File: ([2011/01/24 23:18:18 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Online Assistant) - {F997ACBD-1292-4c74-B96B-83BA5665E260} - C:\Program Files\American Express Online Assistant\ietoolbar.dll (American Express)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Online Assistant) - {D79C4ACF-F903-4854-95CA-CDE413AC7E18} - C:\Program Files\American Express Online Assistant\ietoolbar.dll (American Express)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Online Assistant) - {D79C4ACF-F903-4854-95CA-CDE413AC7E18} - C:\Program Files\American Express Online Assistant\ietoolbar.dll (American Express)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk = C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Online Assistant.lnk = C:\Program Files\American Express Online Assistant\OnlineAssistant.exe (American Express)
O4 - Startup: C:\Documents and Settings\Jennifer\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKLM\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://www.shockwave.com/content/chainz2/sis/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (GTGina.dll) - C:\WINDOWS\System32\GTGina.dll (Gemtek)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jennifer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jennifer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 11:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/01/25 19:20:24 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/01/25 18:41:43 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/24 23:11:02 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/01/24 23:05:30 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/01/24 23:05:30 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/01/24 23:05:30 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/01/24 23:05:30 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/01/24 22:57:11 | 000,000,000 | —D | C] – C:\Qoobox
[2011/01/22 10:30:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Jennifer\Desktop\tdsskiller
[2011/01/21 22:49:35 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
[2011/01/21 22:49:35 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2011/01/21 22:07:22 | 000,000,000 | —D | C] – C:\_OTL
[2011/01/19 21:36:42 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
[2011/01/19 09:17:34 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Unity
[2011/01/19 07:40:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/01/19 07:40:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Apple Computer
[2011/01/19 06:51:25 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2011/01/19 06:50:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\%APPDATA%
[2011/01/19 06:47:57 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/01/18 23:10:05 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/01/18 22:52:43 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/01/18 22:51:04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/01/18 22:51:03 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/25 21:53:28 | 000,000,854 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Online Assistant.lnk
[2011/01/25 21:53:19 | 000,002,333 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk
[2011/01/25 21:52:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/25 21:52:49 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2011/01/25 18:41:35 | 002,672,312 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\esetsmartinstaller_enu.exe
[2011/01/25 18:24:27 | 004,160,433 | R— | M] () – C:\Documents and Settings\Jennifer\Desktop\ComboFix.exe
[2011/01/24 23:18:18 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/01/24 23:11:11 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/01/24 07:29:30 | 000,154,624 | —- | M] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/23 21:21:19 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/22 10:29:55 | 001,236,025 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\tdsskiller.zip
[2011/01/21 23:30:22 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/19 21:49:05 | 000,624,128 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\dds.scr
[2011/01/19 21:36:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jennifer\Desktop\OTL.exe
[2011/01/18 10:31:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/16 19:05:16 | 000,026,624 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs 2010 week 2.xls
[2011/01/15 16:08:10 | 001,215,575 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02857.JPG
[2011/01/15 16:08:02 | 001,253,441 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02856.JPG
[2011/01/15 16:06:58 | 001,302,227 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02855.JPG
[2011/01/15 16:06:46 | 001,305,501 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02854.JPG
[2011/01/15 16:06:24 | 000,385,706 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.MPG
[2011/01/15 16:06:24 | 000,004,820 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.THM
[2011/01/15 15:58:48 | 001,250,047 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02852.JPG
[2011/01/15 15:58:40 | 001,295,990 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02851.JPG
[2011/01/15 15:58:34 | 001,271,654 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02850.JPG
[2011/01/15 15:58:24 | 001,331,685 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02849.JPG
[2011/01/15 15:58:20 | 001,295,900 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02848.JPG
[2011/01/15 15:58:12 | 001,273,346 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02847.JPG
[2011/01/15 15:57:54 | 001,177,578 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02846.JPG
[2011/01/15 15:57:52 | 001,179,039 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02845.JPG
[2011/01/15 15:57:46 | 001,286,640 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02844.JPG
[2011/01/15 15:57:36 | 001,217,236 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02843.JPG
[2011/01/15 15:57:30 | 001,295,288 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02842.JPG
[2011/01/15 15:57:18 | 001,279,824 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02841.JPG
[2011/01/15 15:57:14 | 001,270,977 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02840.JPG
[2011/01/15 15:57:10 | 001,258,607 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02839.JPG
[2011/01/15 15:57:00 | 001,298,489 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02838.JPG
[2011/01/15 15:56:52 | 001,271,700 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02837.JPG
[2011/01/15 15:56:46 | 001,201,755 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02836.JPG
[2011/01/15 15:56:40 | 001,291,402 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02835.JPG
[2011/01/15 15:56:28 | 001,244,135 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02834.JPG
[2011/01/15 15:56:18 | 001,292,795 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02833.JPG
[2011/01/15 15:56:12 | 001,300,180 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02832.JPG
[2011/01/15 15:56:04 | 001,223,818 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02831.JPG
[2011/01/15 15:55:56 | 001,278,536 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02830.JPG
[2011/01/15 13:42:36 | 001,188,762 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02829.JPG
[2011/01/15 13:42:34 | 001,178,407 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02828.JPG
[2011/01/15 13:42:30 | 001,317,772 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02827.JPG
[2011/01/15 13:42:24 | 001,260,728 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02826.JPG
[2011/01/15 13:42:14 | 001,189,786 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02825.JPG
[2011/01/15 13:42:06 | 001,227,793 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02824.JPG
[2011/01/15 13:42:04 | 001,248,037 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02823.JPG
[2011/01/15 13:41:26 | 001,207,968 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02822.JPG
[2011/01/15 13:41:20 | 001,219,691 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02821.JPG
[2011/01/15 13:41:16 | 001,186,309 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02820.JPG
[2011/01/15 13:40:40 | 001,261,162 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02819.JPG
[2011/01/15 13:40:30 | 001,165,114 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02818.JPG
[2011/01/15 13:40:18 | 001,316,342 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02817.JPG
[2011/01/15 13:40:14 | 001,262,093 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02816.JPG
[2011/01/15 13:40:08 | 001,185,058 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02815.JPG
[2011/01/15 13:39:54 | 001,210,183 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02814.JPG
[2011/01/15 13:39:50 | 001,230,519 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02813.JPG
[2011/01/15 13:39:40 | 001,303,196 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02812.JPG
[2011/01/15 13:39:22 | 001,290,235 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02811.JPG
[2011/01/15 13:39:04 | 001,200,639 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02810.JPG
[2011/01/15 13:39:00 | 001,241,495 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02809.JPG
[2011/01/15 13:38:56 | 001,255,950 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02808.JPG
[2011/01/15 13:38:46 | 000,646,697 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.MPG
[2011/01/15 13:38:46 | 000,007,464 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.THM
[2011/01/15 13:05:38 | 001,232,889 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02806.JPG
[2011/01/15 13:05:26 | 001,265,191 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02805.JPG
[2011/01/15 13:05:18 | 001,232,785 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02804.JPG
[2011/01/15 13:04:00 | 001,301,496 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02803.JPG
[2011/01/15 13:03:58 | 001,267,995 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02802.JPG
[2011/01/15 13:03:52 | 001,326,501 | —- | M] () – C:\Documents and Settings\Jennifer\My Documents\DSC02801.JPG
[2011/01/10 07:47:57 | 000,024,576 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs.xls
[2011/01/04 08:30:59 | 000,037,376 | —- | M] () – C:\Documents and Settings\Jennifer\Desktop\Jaymes christmas List.doc
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/25 18:41:32 | 002,672,312 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\esetsmartinstaller_enu.exe
[2011/01/24 23:05:30 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/01/24 23:05:30 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/01/24 23:05:30 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/01/24 23:05:30 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/01/24 23:05:30 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/01/24 22:56:44 | 004,160,433 | R— | C] () – C:\Documents and Settings\Jennifer\Desktop\ComboFix.exe
[2011/01/22 10:30:03 | 001,236,025 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\tdsskiller.zip
[2011/01/19 21:42:16 | 000,624,128 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\dds.scr
[2011/01/18 22:51:22 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/16 19:04:46 | 000,026,624 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs 2010 week 2.xls
[2011/01/15 17:14:26 | 001,331,685 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02849.JPG
[2011/01/15 17:14:26 | 001,305,501 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02854.JPG
[2011/01/15 17:14:26 | 001,302,227 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02855.JPG
[2011/01/15 17:14:26 | 001,295,990 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02851.JPG
[2011/01/15 17:14:26 | 001,271,654 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02850.JPG
[2011/01/15 17:14:26 | 001,253,441 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02856.JPG
[2011/01/15 17:14:26 | 001,250,047 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02852.JPG
[2011/01/15 17:14:26 | 001,215,575 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02857.JPG
[2011/01/15 17:14:26 | 000,646,697 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.MPG
[2011/01/15 17:14:26 | 000,385,706 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.MPG
[2011/01/15 17:14:26 | 000,007,464 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02807.THM
[2011/01/15 17:14:26 | 000,004,820 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\MOV02853.THM
[2011/01/15 17:14:25 | 001,300,180 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02832.JPG
[2011/01/15 17:14:25 | 001,298,489 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02838.JPG
[2011/01/15 17:14:25 | 001,295,900 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02848.JPG
[2011/01/15 17:14:25 | 001,295,288 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02842.JPG
[2011/01/15 17:14:25 | 001,292,795 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02833.JPG
[2011/01/15 17:14:25 | 001,291,402 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02835.JPG
[2011/01/15 17:14:25 | 001,286,640 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02844.JPG
[2011/01/15 17:14:25 | 001,279,824 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02841.JPG
[2011/01/15 17:14:25 | 001,278,536 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02830.JPG
[2011/01/15 17:14:25 | 001,273,346 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02847.JPG
[2011/01/15 17:14:25 | 001,271,700 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02837.JPG
[2011/01/15 17:14:25 | 001,270,977 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02840.JPG
[2011/01/15 17:14:25 | 001,258,607 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02839.JPG
[2011/01/15 17:14:25 | 001,244,135 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02834.JPG
[2011/01/15 17:14:25 | 001,223,818 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02831.JPG
[2011/01/15 17:14:25 | 001,217,236 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02843.JPG
[2011/01/15 17:14:25 | 001,201,755 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02836.JPG
[2011/01/15 17:14:25 | 001,188,762 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02829.JPG
[2011/01/15 17:14:25 | 001,179,039 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02845.JPG
[2011/01/15 17:14:25 | 001,178,407 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02828.JPG
[2011/01/15 17:14:25 | 001,177,578 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02846.JPG
[2011/01/15 17:14:24 | 001,317,772 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02827.JPG
[2011/01/15 17:14:24 | 001,260,728 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02826.JPG
[2011/01/15 17:14:24 | 001,248,037 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02823.JPG
[2011/01/15 17:14:24 | 001,227,793 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02824.JPG
[2011/01/15 17:14:24 | 001,207,968 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02822.JPG
[2011/01/15 17:14:24 | 001,189,786 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02825.JPG
[2011/01/15 17:14:23 | 001,316,342 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02817.JPG
[2011/01/15 17:14:23 | 001,261,162 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02819.JPG
[2011/01/15 17:14:23 | 001,219,691 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02821.JPG
[2011/01/15 17:14:23 | 001,186,309 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02820.JPG
[2011/01/15 17:14:23 | 001,165,114 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02818.JPG
[2011/01/15 17:14:22 | 001,303,196 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02812.JPG
[2011/01/15 17:14:22 | 001,290,235 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02811.JPG
[2011/01/15 17:14:22 | 001,262,093 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02816.JPG
[2011/01/15 17:14:22 | 001,230,519 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02813.JPG
[2011/01/15 17:14:22 | 001,210,183 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02814.JPG
[2011/01/15 17:14:22 | 001,185,058 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02815.JPG
[2011/01/15 17:14:21 | 001,265,191 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02805.JPG
[2011/01/15 17:14:21 | 001,255,950 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02808.JPG
[2011/01/15 17:14:21 | 001,241,495 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02809.JPG
[2011/01/15 17:14:21 | 001,232,889 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02806.JPG
[2011/01/15 17:14:21 | 001,232,785 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02804.JPG
[2011/01/15 17:14:21 | 001,200,639 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02810.JPG
[2011/01/15 17:14:20 | 001,326,501 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02801.JPG
[2011/01/15 17:14:20 | 001,301,496 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02803.JPG
[2011/01/15 17:14:20 | 001,267,995 | —- | C] () – C:\Documents and Settings\Jennifer\My Documents\DSC02802.JPG
[2011/01/10 07:47:57 | 000,024,576 | —- | C] () – C:\Documents and Settings\Jennifer\Desktop\Copy of playoffs.xls
[2010/03/01 22:38:12 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll.old
[2010/03/01 22:25:09 | 000,016,924 | -HS- | C] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\GyBl5ci
[2009/04/19 12:32:35 | 000,000,022 | —- | C] () – C:\WINDOWS\iexplore.ini
[2009/02/24 08:21:40 | 000,000,131 | —- | C] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\fusioncache.dat
[2009/01/17 18:43:38 | 000,002,582 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/05/26 08:01:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/05/20 17:59:21 | 000,154,624 | —- | C] () – C:\Documents and Settings\Jennifer\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/14 21:23:43 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2008/05/14 21:23:29 | 000,001,361 | —- | C] () – C:\WINDOWS\System32\WLAN.INI
[2008/05/09 19:28:11 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/05/09 19:25:28 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/05/09 19:23:58 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/05/09 19:23:58 | 000,000,118 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/05/09 19:04:57 | 000,876,544 | —- | C] () – C:\WINDOWS\System32\TEACico2.dll
[2008/05/09 19:04:42 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/05/09 19:03:39 | 000,001,124 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/08/06 13:17:40 | 000,019,456 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/08/06 12:07:30 | 000,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/08/02 18:11:28 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2007/08/02 18:11:14 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2007/07/27 15:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 15:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2006/11/07 02:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/16 21:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 21:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/12/05 20:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 13:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 11:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 11:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 10:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 292 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7715B65F
@Alternate Data Stream - 162 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6D6C4572
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F38450C8
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B211CA64

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI