This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu virus help

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. If anybody could help me with this I would grately appreciate it.

I have attached everything that the sticky said to attach.



OTL logfile created on: 4/12/2011 12:05:17 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\David\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 69.00% Memory free
11.00 Gb Paging File | 9.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 917.66 Gb Total Space | 781.87 Gb Free Space | 85.20% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: DAVID-PC | User Name: David | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\David\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe ()
PRC - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\David\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (McODS) – C:\Program Files\mcafee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (McAWFwk) – c:\Program Files\mcafee\msc\McAWFwk.exe (McAfee, Inc.)
SRV:64bit: - (MSK80Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McOobeSv) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
SRV - (RoxWatch12) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (NOBU) – C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe (Dell, Inc.)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (LVUVC64) QuickCam for Notebooks Deluxe(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (lvpopf64) – C:\Windows\SysNative\drivers\lvpopf64.sys (Logitech Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/03/18 19:33:16 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\mcafee\msk\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20110318182145.dll (McAfee, Inc.)
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\mcafee\msk\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20110318182145.dll (McAfee, Inc.)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - Startup: C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WIC55D~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WIC55D~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WIC55D~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WIC55D~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/04/11 23:56:24 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Roxio Burn
[2011/04/11 23:55:24 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Sammsoft
[2011/04/11 22:02:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/04/11 22:00:55 | 000,069,376 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/04/11 22:00:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2011/04/11 21:54:23 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Sunbelt Software
[2011/04/11 21:53:54 | 000,000,000 | -H-D | C] – C:\ProgramData\{6A395471-4AA3-4072-AE1B-9B69A97AD164}
[2011/04/11 21:53:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/04/11 21:53:50 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2011/04/11 21:53:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2011/04/11 13:35:26 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Malwarebytes
[2011/04/11 13:34:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/04/11 13:34:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/11 13:34:59 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/04/11 13:34:56 | 000,024,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/04/11 13:34:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/04/11 13:28:04 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Macrovision
[2011/04/11 03:00:59 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/04/10 22:43:23 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Microsoft Help
[2011/04/10 22:43:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/04/10 20:48:45 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\PokerStars
[2011/04/10 18:25:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerStars
[2011/04/07 00:44:10 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Apple Computer
[2011/04/07 00:44:10 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Apple Computer
[2011/04/07 00:43:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/04/07 00:43:41 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/04/07 00:43:41 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/04/07 00:41:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/04/07 00:41:18 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/04/07 00:41:07 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Apple
[2011/04/07 00:41:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/04/07 00:40:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/04/07 00:40:42 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/04/07 00:40:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/04/07 00:40:28 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/04/07 00:40:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/04/06 23:39:12 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid
[2011/04/06 23:39:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\ilivid
[2011/04/06 23:38:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows ilivid Toolbar
[2011/04/06 23:38:46 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\PackageAware
[2011/04/04 13:19:42 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\TechSmith
[2011/04/04 12:33:38 | 000,000,000 | —D | C] – C:\Users\David\Documents\Camtasia Studio
[2011/04/04 12:33:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camtasia Studio 7
[2011/04/04 12:33:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/04/04 12:33:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\TechSmith Shared
[2011/04/04 12:33:13 | 000,000,000 | —D | C] – C:\ProgramData\TechSmith
[2011/04/04 12:33:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\TechSmith
[2011/03/31 21:50:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
[2011/03/29 12:08:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\logishrd
[2011/03/28 12:06:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
[2011/03/28 12:02:38 | 000,000,000 | —D | C] – C:\ProgramData\VirtualizedApplications
[2011/03/28 09:49:41 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\SoftGrid Client
[2011/03/28 09:49:40 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\SoftGrid Client
[2011/03/28 09:49:01 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/03/28 09:49:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Application Virtualization Client
[2011/03/28 09:49:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/03/28 09:48:52 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\TP
[2011/03/27 10:39:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/03/27 09:00:28 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\PCDr
[2011/03/27 09:00:01 | 000,000,000 | —D | C] – C:\ProgramData\PCDr
[2011/03/27 07:59:15 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\skypePM
[2011/03/27 07:58:49 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Skype
[2011/03/27 07:58:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/03/27 07:58:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/03/27 07:43:03 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2011/03/27 07:43:03 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2011/03/27 07:22:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2011/03/27 07:22:05 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2011/03/27 07:22:05 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2011/03/27 07:22:05 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2011/03/27 07:22:05 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2011/03/27 07:22:05 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2011/03/27 07:22:05 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2011/03/27 07:22:05 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2011/03/27 07:22:05 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2011/03/27 07:19:41 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/03/27 07:19:40 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/03/27 07:19:40 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/03/27 07:19:40 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/03/27 07:19:40 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/03/27 07:19:40 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/03/27 07:19:39 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/03/27 07:19:39 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/03/27 07:19:39 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/03/27 07:19:39 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/03/27 07:19:39 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/03/27 07:19:39 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/03/27 07:19:34 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/03/27 07:19:34 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/03/27 07:19:34 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/03/27 07:19:34 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/03/27 07:19:34 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/03/27 07:19:34 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/03/27 07:19:34 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/03/27 07:19:34 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/03/27 07:19:27 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/03/27 07:19:27 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/03/27 07:19:26 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/03/27 07:19:26 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/03/27 07:19:26 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/03/27 07:19:26 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/03/27 07:19:26 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/03/27 07:19:26 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/03/27 07:19:20 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/03/27 07:19:19 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/03/27 07:19:19 | 000,475,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/03/27 07:19:19 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/03/27 07:19:18 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/03/27 07:19:16 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/03/27 07:19:16 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/03/27 07:19:12 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/03/27 07:19:12 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/03/27 07:19:12 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/03/27 07:19:10 | 005,477,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/03/27 07:19:10 | 003,911,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/03/27 07:19:09 | 003,966,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/03/27 07:19:09 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/03/27 07:19:07 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/03/27 07:19:07 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/03/27 07:19:07 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/03/27 07:19:07 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/03/27 07:19:05 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/03/27 07:19:05 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/03/27 07:19:05 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/03/27 07:19:05 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/03/26 23:08:52 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/03/26 23:08:26 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Google
[2011/03/26 23:07:31 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Deployment
[2011/03/26 23:07:31 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Apps
[2011/03/26 23:06:49 | 000,000,000 | —D | C] – C:\Users\David\My Backup Files
[2011/03/26 21:04:35 | 000,000,000 | -HSD | C] – C:\System Recovery
[2011/03/26 21:03:43 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Macromedia
[2011/03/26 21:03:24 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Adobe
[2011/03/26 21:03:01 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Dell
[2011/03/26 21:02:59 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Stardock_Corporation
[2011/03/26 21:02:54 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Roxio
[2011/03/26 21:02:53 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\ATI
[2011/03/26 21:02:53 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\ATI
[2011/03/26 21:02:41 | 000,000,000 | R–D | C] – C:\Users\David\Searches
[2011/03/26 21:02:41 | 000,000,000 | R–D | C] – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/03/26 21:02:41 | 000,000,000 | -H-D | C] – C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/03/26 21:02:31 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Identities
[2011/03/26 21:02:29 | 000,000,000 | R–D | C] – C:\Users\David\Contacts
[2011/03/26 21:02:28 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\VirtualStore
[2011/03/26 21:02:18 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\SoftThinks
[2011/03/26 20:57:45 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Dell Edoc Viewer
[2011/03/26 20:57:37 | 000,000,000 | –SD | C] – C:\Users\David\AppData\Roaming\Microsoft
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Videos
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Saved Games
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Desktop\Play Games
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Pictures
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Music
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Links
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Favorites
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Downloads
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\My Documents
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\Desktop
[2011/03/26 20:57:37 | 000,000,000 | R–D | C] – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\AppData\Local\Temporary Internet Files
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Templates
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Start Menu
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\SendTo
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Recent
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\PrintHood
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\NetHood
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Documents\My Videos
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Documents\My Pictures
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Documents\My Music
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\My Documents
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Local Settings
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\AppData\Local\History
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Cookies
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\Application Data
[2011/03/26 20:57:37 | 000,000,000 | -HSD | C] – C:\Users\David\AppData\Local\Application Data
[2011/03/26 20:57:37 | 000,000,000 | -H-D | C] – C:\Users\David\AppData
[2011/03/26 20:57:37 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Temp
[2011/03/26 20:57:37 | 000,000,000 | —D | C] – C:\Users\David\AppData\Local\Microsoft
[2011/03/26 20:57:37 | 000,000,000 | —D | C] – C:\Users\David\AppData\Roaming\Media Center Programs
[2011/03/18 21:43:27 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2011/03/18 21:43:27 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2011/03/18 21:43:27 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2011/03/18 21:43:27 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2011/03/18 21:43:27 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2011/03/18 21:43:27 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2011/03/18 21:43:27 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2011/03/18 21:43:27 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2011/03/18 21:43:27 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2011/03/18 21:43:27 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2011/03/18 21:43:25 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/03/18 21:43:25 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/03/18 21:43:23 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/03/18 21:43:22 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/03/18 21:43:22 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011/03/18 21:43:22 | 001,024,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmpmde.dll
[2011/03/18 21:43:22 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40.dll
[2011/03/18 21:43:22 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40u.dll
[2011/03/18 21:43:22 | 000,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmpmde.dll
[2011/03/18 21:43:22 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2011/03/18 21:43:22 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/03/18 21:43:21 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskschd.dll
[2011/03/18 21:43:21 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmicmiplugin.dll
[2011/03/18 21:43:21 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskschd.dll
[2011/03/18 21:43:21 | 000,473,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskcomp.dll
[2011/03/18 21:43:21 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2011/03/18 21:43:21 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc.dll
[2011/03/18 21:43:21 | 000,422,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_isv.dll
[2011/03/18 21:43:21 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2011/03/18 21:43:21 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2011/03/18 21:43:21 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_isv.exe
[2011/03/18 21:43:21 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate.exe
[2011/03/18 21:43:21 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2011/03/18 21:43:21 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2011/03/18 21:43:21 | 000,306,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp.exe
[2011/03/18 21:43:21 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskcomp.dll
[2011/03/18 21:43:21 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2011/03/18 21:43:21 | 000,285,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\schtasks.exe
[2011/03/18 21:43:21 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2011/03/18 21:43:21 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2011/03/18 21:43:21 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schtasks.exe
[2011/03/18 21:43:21 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2011/03/18 21:43:21 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2011/03/18 21:43:21 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp_isv.dll
[2011/03/18 21:43:21 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp.dll
[2011/03/18 21:43:21 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2011/03/18 21:43:21 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2011/03/18 21:43:21 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2011/03/18 21:43:21 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2011/03/18 21:43:21 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2011/03/18 21:43:20 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2011/03/18 21:43:20 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2011/03/18 21:43:20 | 000,112,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2011/03/18 21:43:20 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2011/03/18 21:43:19 | 014,627,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2011/03/18 21:43:19 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2011/03/18 21:43:19 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2011/03/18 21:43:19 | 011,406,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2011/03/18 21:43:18 | 000,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\comctl32.dll
[2011/03/18 21:43:18 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2011/03/18 21:43:18 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wintrust.dll
[2011/03/18 21:43:18 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2011/03/18 21:43:18 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2011/03/18 21:43:17 | 001,446,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2011/03/18 21:43:16 | 004,068,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/03/18 21:43:16 | 003,181,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/03/18 21:43:16 | 001,888,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2011/03/18 21:43:16 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/03/18 21:43:16 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/03/18 21:43:16 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2011/03/18 21:43:16 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/03/18 21:43:16 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/03/18 21:43:16 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/03/18 21:43:16 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/03/18 21:43:16 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/03/18 21:43:16 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/03/18 21:43:16 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/03/18 21:43:16 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/03/18 21:43:16 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/03/18 21:43:16 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/03/18 21:43:16 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/03/18 21:43:16 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/03/18 21:43:16 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/03/18 21:43:16 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/03/18 21:43:16 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/03/18 21:43:16 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sscore.dll
[2011/03/18 21:43:15 | 002,085,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ole32.dll
[2011/03/18 21:43:15 | 000,483,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\StructuredQuery.dll
[2011/03/18 21:43:14 | 000,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2011/03/18 21:43:14 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2011/03/18 21:43:12 | 001,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2011/03/18 21:43:12 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2011/03/18 21:43:11 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/03/18 21:43:11 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2011/03/18 21:43:11 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/03/18 21:43:11 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/03/18 21:43:11 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/03/18 21:43:09 | 000,687,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2011/03/18 21:43:09 | 000,630,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\evr.dll
[2011/03/18 21:43:09 | 000,488,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\evr.dll
[2011/03/18 21:43:09 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/03/18 21:43:09 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2011/03/18 21:43:09 | 000,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2011/03/18 21:43:09 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\isoburn.exe
[2011/03/18 21:43:09 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\isoburn.exe
[2011/03/18 21:43:09 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2011/03/18 21:43:08 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2011/03/18 21:43:08 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AUDIOKSE.dll
[2011/03/18 21:43:08 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\AUDIOKSE.dll
[2011/03/18 21:43:08 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfds.dll
[2011/03/18 21:43:08 | 000,374,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\AudioEng.dll
[2011/03/18 21:43:08 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2011/03/18 21:43:08 | 000,292,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfds.dll
[2011/03/18 21:43:08 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\AudioSes.dll
[2011/03/18 21:43:07 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/03/18 21:43:07 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/03/18 21:43:07 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidclass.sys
[2011/03/18 21:35:50 | 000,000,000 | —D | C] – C:\Apps
[2011/03/18 21:30:41 | 000,000,000 | —D | C] – C:\Program Files\Dell Games Folder
[2011/03/18 21:21:29 | 000,320,040 | —- | C] (Broadcom Corporation) – C:\Windows\SysNative\drivers\k57nd60a.sys
[2011/03/18 21:21:26 | 001,680,416 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2011/03/18 21:21:26 | 000,611,872 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2011/03/18 21:21:26 | 000,513,536 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2011/03/18 21:21:26 | 000,211,376 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2011/03/18 21:21:26 | 000,193,536 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2011/03/18 21:21:26 | 000,150,528 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2011/03/18 21:21:25 | 000,332,320 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2011/03/18 21:21:24 | 001,638,432 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2011/03/18 21:21:24 | 001,201,184 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2011/03/18 21:21:24 | 000,437,280 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2011/03/18 21:21:24 | 000,363,008 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2011/03/18 21:21:24 | 000,304,640 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2011/03/18 21:21:24 | 000,304,640 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2011/03/18 21:21:24 | 000,198,656 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2011/03/18 21:21:24 | 000,149,536 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2011/03/18 21:21:24 | 000,095,744 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2011/03/18 21:21:24 | 000,073,216 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2011/03/18 21:21:24 | 000,066,592 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInst64.dll
[2011/03/18 21:21:23 | 000,370,176 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBTHX64.dll
[2011/03/18 21:21:23 | 000,277,504 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\MBTHX32.dll
[2011/03/18 21:21:23 | 000,072,192 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBWrp64.dll
[2011/03/18 21:21:22 | 000,601,088 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBAPO64.dll
[2011/03/18 21:21:22 | 000,524,288 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\MBAPO32.dll
[2011/03/18 21:21:22 | 000,321,536 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2011/03/18 21:21:22 | 000,320,512 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2011/03/18 21:21:21 | 000,166,400 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAC64.dll
[2011/03/18 21:21:21 | 000,108,032 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAR64.dll
[2011/03/18 21:21:17 | 000,016,440 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysNative\drivers\AtiPcie.sys
[2011/03/18 21:21:12 | 003,370,496 | —- | C] (ATI Technologies Inc. ) – C:\Windows\SysWow64\atiumdag.dll
[2011/03/18 21:21:12 | 002,799,616 | —- | C] (ATI Technologies Inc. ) – C:\Windows\SysWow64\atiumdva.dll
[2011/03/18 21:21:12 | 002,449,408 | —- | C] (ATI Technologies Inc. ) – C:\Windows\SysNative\atiumd6a.dll
[2011/03/18 21:21:12 | 000,274,432 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\Oemdspif.dll
[2011/03/18 21:21:12 | 000,121,872 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\drivers\AtiHdmi.sys
[2011/03/18 21:21:11 | 012,657,152 | —- | C] (ATI Technologies Inc.) – C:\Windows\SysWow64\atioglxx.dll
[2011/03/18 21:21:11 | 004,386,816 | —- | C] (ATI Technologies Inc. ) – C:\Windows\SysNative\atiumd64.dll
[2011/03/18 21:21:11 | 000,421,888 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\atipdl64.dll
[2011/03/18 21:21:11 | 000,356,352 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\atipdlxx.dll
[2011/03/18 21:21:11 | 000,120,320 | —- | C] (AMD) – C:\Windows\SysNative\atitmm64.dll
[2011/03/18 21:21:09 | 016,270,848 | —- | C] (ATI Technologies Inc.) – C:\Windows\SysNative\atio6axx.dll
[2011/03/18 21:21:09 | 006,096,896 | —- | C] (ATI Technologies Inc.) – C:\Windows\SysNative\drivers\atikmdag.sys
[2011/03/18 21:21:09 | 003,263,488 | —- | C] (ATI Technologies Inc. ) – C:\Windows\SysNative\atidxx64.dll
[2011/03/18 21:21:09 | 000,429,056 | —- | C] (AMD) – C:\Windows\SysNative\atieclxx.exe
[2011/03/18 21:21:09 | 000,202,752 | —- | C] (AMD) – C:\Windows\SysNative\atiesrxx.exe
[2011/03/18 21:21:09 | 000,059,392 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\atiedu64.dll
[2011/03/18 21:21:09 | 000,052,224 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\SysNative\atimpc64.dll
[2011/03/18 21:21:09 | 000,052,224 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\SysNative\amdpcom64.dll
[2011/03/18 21:21:09 | 000,051,712 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\SysWow64\atimpc32.dll
[2011/03/18 21:21:09 | 000,051,712 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\SysWow64\amdpcom32.dll
[2011/03/18 21:21:09 | 000,012,288 | —- | C] (AMD) – C:\Windows\SysNative\atimuixx.dll
[2011/03/18 21:21:08 | 004,353,024 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysNative\aticaldd64.dll
[2011/03/18 21:21:08 | 002,752,000 | —- | C] (ATI Technologies Inc. ) – C:\Windows\SysWow64\atidxx32.dll
[2011/03/18 21:21:08 | 000,446,464 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\SysNative\ATIDEMGX.dll
[2011/03/18 21:21:08 | 000,053,248 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysWow64\aticalrt.dll
[2011/03/18 21:21:08 | 000,048,640 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysNative\aticalrt64.dll
[2011/03/18 21:21:07 | 003,305,472 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysWow64\aticaldd.dll
[2011/03/18 21:21:07 | 000,280,064 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\SysNative\atiadlxx.dll
[2011/03/18 21:21:07 | 000,196,608 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\SysWow64\atiadlxy.dll
[2011/03/18 21:21:07 | 000,118,784 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\SysNative\atibtmon.exe
[2011/03/18 21:21:07 | 000,053,248 | —- | C] (ATI Technologies Inc.) – C:\Windows\SysNative\drivers\ati2erec.dll
[2011/03/18 21:21:07 | 000,053,248 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysWow64\aticalcl.dll
[2011/03/18 21:21:07 | 000,043,520 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\ati2edxx.dll
[2011/03/18 21:21:07 | 000,041,984 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\SysNative\aticalcl64.dll
[2011/03/18 21:17:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\oem
[2011/03/18 21:17:13 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/03/18 21:17:13 | 000,000,000 | —D | C] – C:\Drivers
[2011/03/18 21:10:43 | 000,000,000 | —D | C] – C:\dell
[2011/03/18 20:54:43 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2011/03/18 20:54:42 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2011/03/18 20:53:14 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2011/03/18 20:52:45 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2011/03/18 19:43:12 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2011/03/18 19:33:30 | 000,000,000 | -H-D | C] – C:\ProgramData\{04A07C23-5821-4F25-BF46-1188636AE238}
[2011/03/18 19:33:28 | 000,000,000 | —D | C] – C:\Program Files\Dell
[2011/03/18 19:32:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2011/03/18 19:32:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Jagex
[2011/03/18 19:32:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\TrustedID
[2011/03/18 19:29:57 | 000,000,000 | —D | C] – C:\ProgramData\Uninstall
[2011/03/18 19:28:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\SureThing Shared
[2011/03/18 19:27:54 | 000,000,000 | —D | C] – C:\ProgramData\PhotoShow Shared Assets
[2011/03/18 19:27:51 | 000,000,000 | —D | C] – C:\Program Files\Roxio
[2011/03/18 19:27:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter
[2011/03/18 19:26:24 | 000,000,000 | —D | C] – C:\ProgramData\Sonic
[2011/03/18 19:25:46 | 000,055,856 | —- | C] (Sonic Solutions) – C:\Windows\SysNative\drivers\PxHlpa64.sys
[2011/03/18 19:25:46 | 000,010,224 | —- | C] (Sonic Solutions) – C:\Windows\SysNative\drivers\cdralw2k.sys
[2011/03/18 19:25:46 | 000,010,224 | —- | C] (Sonic Solutions) – C:\Windows\SysNative\drivers\cdr4_xp.sys
[2011/03/18 19:25:32 | 000,000,000 | —D | C] – C:\ProgramData\Roxio
[2011/03/18 19:25:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PX Storage Engine
[2011/03/18 19:24:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Sonic Shared
[2011/03/18 19:24:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Roxio
[2011/03/18 19:24:48 | 000,000,000 | —D | C] – C:\ProgramData\Macrovision
[2011/03/18 19:24:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Roxio Shared
[2011/03/18 19:24:13 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2011/03/18 19:24:13 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2011/03/18 19:24:13 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2011/03/18 19:24:13 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2011/03/18 19:24:13 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2011/03/18 19:24:13 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2011/03/18 19:24:12 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2011/03/18 19:24:12 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2011/03/18 19:24:06 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2011/03/18 19:24:06 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2011/03/18 19:24:06 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2011/03/18 19:24:06 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2011/03/18 19:24:06 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2011/03/18 19:24:06 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2011/03/18 19:24:06 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2011/03/18 19:24:06 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2011/03/18 19:24:06 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2011/03/18 19:24:06 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2011/03/18 19:24:06 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2011/03/18 19:24:06 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2011/03/18 19:24:05 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2011/03/18 19:24:05 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2011/03/18 19:24:05 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2011/03/18 19:24:05 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2011/03/18 19:24:05 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2011/03/18 19:24:05 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2011/03/18 19:24:05 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2011/03/18 19:24:05 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2011/03/18 19:24:05 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2011/03/18 19:24:05 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2011/03/18 19:24:05 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2011/03/18 19:24:05 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2011/03/18 19:24:05 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2011/03/18 19:24:05 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2011/03/18 19:24:05 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2011/03/18 19:24:05 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2011/03/18 19:24:04 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2011/03/18 19:24:04 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2011/03/18 19:24:04 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2011/03/18 19:24:04 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2011/03/18 19:24:04 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2011/03/18 19:24:04 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2011/03/18 19:24:03 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2011/03/18 19:24:03 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2011/03/18 19:24:03 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2011/03/18 19:24:03 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2011/03/18 19:24:03 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2011/03/18 19:24:03 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2011/03/18 19:24:03 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2011/03/18 19:24:03 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2011/03/18 19:24:03 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2011/03/18 19:24:03 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2011/03/18 19:24:03 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2011/03/18 19:24:03 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2011/03/18 19:23:58 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2011/03/18 19:23:58 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2011/03/18 19:23:57 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2011/03/18 19:23:57 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2011/03/18 19:23:55 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2011/03/18 19:23:55 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2011/03/18 19:23:55 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2011/03/18 19:23:55 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2011/03/18 19:23:55 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2011/03/18 19:23:55 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2011/03/18 19:23:55 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2011/03/18 19:23:55 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2011/03/18 19:23:55 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2011/03/18 19:23:55 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2011/03/18 19:23:54 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2011/03/18 19:23:54 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2011/03/18 19:23:54 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2011/03/18 19:23:54 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2011/03/18 19:23:54 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2011/03/18 19:23:54 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2011/03/18 19:23:54 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2011/03/18 19:23:54 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2011/03/18 19:21:44 | 000,009,984 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2011/03/18 19:21:11 | 000,149,032 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2011/03/18 19:20:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\mcafee.com
[2011/03/18 19:20:58 | 000,000,000 | —D | C] – C:\Program Files\mcafee.com
[2011/03/18 19:20:58 | 000,000,000 | —D | C] – C:\Program Files\mcafee
[2011/03/18 19:20:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\mcafee
[2011/03/18 19:20:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee
[2011/03/18 19:20:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\mcafee
[2011/03/18 19:20:55 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2011/03/18 19:20:50 | 000,000,000 | —D | C] – C:\Program Files\Dell Support Center
[2011/03/18 19:20:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell DataSafe Online
[2011/03/18 19:20:31 | 000,000,000 | —D | C] – C:\ProgramData\Dell
[2011/03/18 19:20:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dell
[2011/03/18 19:19:29 | 000,000,000 | —D | C] – C:\Windows\en
[2011/03/18 19:18:53 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/03/18 19:18:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2011/03/18 19:17:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2011/03/18 19:17:10 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/03/18 19:16:48 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/03/18 19:16:35 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2011/03/18 19:16:35 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2011/03/18 19:16:34 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2011/03/18 19:16:34 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2011/03/18 19:15:50 | 004,398,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_32.dll
[2011/03/18 19:15:50 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_32.dll
[2011/03/18 19:15:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/03/18 19:14:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2011/03/18 19:14:29 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbonRes.dll
[2011/03/18 19:14:29 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbonRes.dll
[2011/03/18 19:14:24 | 002,983,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbon.dll
[2011/03/18 19:14:23 | 003,860,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbon.dll
[2011/03/18 19:12:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2011/03/18 19:12:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2011/03/18 19:11:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\eBay
[2011/03/18 19:11:02 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2011/03/18 19:10:28 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/03/18 19:09:31 | 000,000,000 | —D | C] – C:\Temp
[2011/03/18 19:09:30 | 000,151,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WimFltr.sys
[2011/03/18 19:09:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Dell DataSafe Local Backup
[2011/03/18 19:09:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell DataSafe
[2011/03/18 19:05:47 | 000,000,000 | —D | C] – C:\ProgramData\WildTangent
[2011/03/18 19:05:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\WildTangent
[2011/03/18 19:05:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
[2011/03/18 19:04:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Citrix
[2011/03/18 19:03:30 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2011/03/18 19:03:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/03/18 19:03:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2011/03/18 19:03:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011/03/18 19:01:48 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2011/03/18 19:01:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\ATI Technologies
[2011/03/18 19:01:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2011/03/18 19:01:28 | 000,521,448 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysNative\deployJava1.dll
[2011/03/18 19:01:28 | 000,189,728 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaws.exe
[2011/03/18 19:01:28 | 000,171,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaw.exe
[2011/03/18 19:01:28 | 000,171,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysNative\java.exe
[2011/03/18 19:01:25 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/03/18 19:01:22 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2011/03/18 19:01:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/03/18 19:01:01 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2011/03/18 19:01:01 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/03/18 19:01:01 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/03/18 19:01:01 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/03/18 19:00:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2011/03/18 19:00:27 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2011/03/18 19:00:24 | 000,000,000 | —D | C] – C:\Program Files\Dell Inc
[2011/03/18 19:00:20 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2011/03/18 18:58:32 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/11 23:20:17 | 000,000,506 | -H– | M] () – C:\aaw7boot.cmd
[2011/04/11 23:13:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001UA.job
[2011/04/11 23:13:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001Core.job
[2011/04/11 22:10:07 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/11 22:10:07 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/11 22:07:10 | 000,727,246 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/04/11 22:07:10 | 000,624,384 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/04/11 22:07:10 | 000,106,502 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/04/11 22:01:47 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/11 22:01:47 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2011/04/11 22:01:42 | 334,737,407 | -HS- | M] () – C:\hiberfil.sys
[2011/04/11 21:53:52 | 000,001,168 | —- | M] () – C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/04/11 21:53:52 | 000,001,144 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/04/11 21:12:24 | 000,000,422 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/04/11 13:36:53 | 000,743,066 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/11 13:34:59 | 000,001,111 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/07 00:41:25 | 000,001,847 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/06 23:39:12 | 000,000,981 | —- | M] () – C:\Users\David\Desktop\iLivid Download Manager.lnk
[2011/04/04 12:57:21 | 000,004,608 | —- | M] () – C:\Users\David\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/04 12:33:23 | 000,001,170 | —- | M] () – C:\Users\Public\Desktop\Camtasia Studio 7.lnk
[2011/04/01 03:22:02 | 000,069,376 | —- | M] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/04/01 03:22:01 | 000,016,432 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2011/03/27 07:59:19 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2011/03/27 07:44:14 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/03/27 07:44:12 | 000,319,000 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/03/26 23:08:54 | 000,002,316 | —- | M] () – C:\Users\David\Desktop\Google Chrome.lnk
[2011/03/26 21:56:02 | 000,039,219 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/03/26 21:56:02 | 000,039,219 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/03/26 21:03:16 | 000,001,439 | —- | M] () – C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/26 21:03:00 | 000,001,940 | —- | M] () – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2011/03/18 21:45:26 | 000,030,405 | RH– | M] () – C:\dell.sdr
[2011/03/18 21:43:27 | 001,572,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2011/03/18 21:43:27 | 001,328,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2011/03/18 21:43:27 | 000,243,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2011/03/18 21:43:27 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2011/03/18 21:43:27 | 000,084,480 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2011/03/18 21:43:27 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2011/03/18 21:43:27 | 000,014,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2011/03/18 21:43:27 | 000,007,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2011/03/18 21:43:27 | 000,005,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2011/03/18 21:43:27 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2011/03/18 21:43:25 | 000,247,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/03/18 21:43:25 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/03/18 21:43:23 | 000,861,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/03/18 21:43:22 | 002,870,272 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/03/18 21:43:22 | 002,614,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011/03/18 21:43:22 | 001,024,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wmpmde.dll
[2011/03/18 21:43:22 | 000,954,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40.dll
[2011/03/18 21:43:22 | 000,954,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40u.dll
[2011/03/18 21:43:22 | 000,738,816 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wmpmde.dll
[2011/03/18 21:43:22 | 000,389,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2011/03/18 21:43:22 | 000,027,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/03/18 21:43:21 | 001,169,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\taskschd.dll
[2011/03/18 21:43:21 | 000,524,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wmicmiplugin.dll
[2011/03/18 21:43:21 | 000,496,128 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\taskschd.dll
[2011/03/18 21:43:21 | 000,473,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\taskcomp.dll
[2011/03/18 21:43:21 | 000,464,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2011/03/18 21:43:21 | 000,424,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\secproc.dll
[2011/03/18 21:43:21 | 000,422,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\secproc_isv.dll
[2011/03/18 21:43:21 | 000,369,152 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2011/03/18 21:43:21 | 000,365,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2011/03/18 21:43:21 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_isv.exe
[2011/03/18 21:43:21 | 000,356,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate.exe
[2011/03/18 21:43:21 | 000,324,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2011/03/18 21:43:21 | 000,320,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2011/03/18 21:43:21 | 000,306,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp.exe
[2011/03/18 21:43:21 | 000,305,152 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\taskcomp.dll
[2011/03/18 21:43:21 | 000,305,152 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2011/03/18 21:43:21 | 000,285,696 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\schtasks.exe
[2011/03/18 21:43:21 | 000,280,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2011/03/18 21:43:21 | 000,277,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2011/03/18 21:43:21 | 000,179,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\schtasks.exe
[2011/03/18 21:43:21 | 000,139,264 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2011/03/18 21:43:21 | 000,132,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2011/03/18 21:43:21 | 000,121,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp_isv.dll
[2011/03/18 21:43:21 | 000,121,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp.dll
[2011/03/18 21:43:21 | 000,100,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2011/03/18 21:43:21 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2011/03/18 21:43:21 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2011/03/18 21:43:21 | 000,082,944 | —- | M] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2011/03/18 21:43:21 | 000,070,656 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2011/03/18 21:43:20 | 000,395,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2011/03/18 21:43:20 | 000,314,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2011/03/18 21:43:20 | 000,112,000 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2011/03/18 21:43:20 | 000,046,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2011/03/18 21:43:19 | 014,627,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2011/03/18 21:43:19 | 012,625,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2011/03/18 21:43:19 | 012,625,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2011/03/18 21:43:19 | 011,406,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2011/03/18 21:43:18 | 000,633,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\comctl32.dll
[2011/03/18 21:43:18 | 000,220,672 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2011/03/18 21:43:18 | 000,172,032 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wintrust.dll
[2011/03/18 21:43:18 | 000,052,224 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2011/03/18 21:43:18 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2011/03/18 21:43:17 | 001,446,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2011/03/18 21:43:16 | 004,068,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/03/18 21:43:16 | 003,181,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/03/18 21:43:16 | 001,888,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2011/03/18 21:43:16 | 001,863,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/03/18 21:43:16 | 001,837,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/03/18 21:43:16 | 001,619,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2011/03/18 21:43:16 | 001,540,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/03/18 21:43:16 | 001,495,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/03/18 21:43:16 | 001,170,944 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/03/18 21:43:16 | 001,074,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/03/18 21:43:16 | 000,902,656 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/03/18 21:43:16 | 000,739,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/03/18 21:43:16 | 000,320,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/03/18 21:43:16 | 000,257,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/03/18 21:43:16 | 000,229,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/03/18 21:43:16 | 000,218,624 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/03/18 21:43:16 | 000,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/03/18 21:43:16 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/03/18 21:43:16 | 000,196,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/03/18 21:43:16 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/03/18 21:43:16 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/03/18 21:43:16 | 000,009,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\sscore.dll
[2011/03/18 21:43:15 | 002,085,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ole32.dll
[2011/03/18 21:43:15 | 000,483,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\StructuredQuery.dll
[2011/03/18 21:43:14 | 000,148,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2011/03/18 21:43:14 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2011/03/18 21:43:12 | 001,975,296 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2011/03/18 21:43:12 | 001,320,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2011/03/18 21:43:11 | 000,613,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/03/18 21:43:11 | 000,552,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2011/03/18 21:43:11 | 000,465,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/03/18 21:43:11 | 000,288,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/03/18 21:43:11 | 000,204,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/03/18 21:43:09 | 000,687,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2011/03/18 21:43:09 | 000,630,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\evr.dll
[2011/03/18 21:43:09 | 000,488,448 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\evr.dll
[2011/03/18 21:43:09 | 000,324,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/03/18 21:43:09 | 000,228,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2011/03/18 21:43:09 | 000,183,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2011/03/18 21:43:09 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\isoburn.exe
[2011/03/18 21:43:09 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\isoburn.exe
[2011/03/18 21:43:09 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2011/03/18 21:43:08 | 000,514,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2011/03/18 21:43:08 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\AUDIOKSE.dll
[2011/03/18 21:43:08 | 000,442,880 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\AUDIOKSE.dll
[2011/03/18 21:43:08 | 000,376,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mfds.dll
[2011/03/18 21:43:08 | 000,374,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\AudioEng.dll
[2011/03/18 21:43:08 | 000,366,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2011/03/18 21:43:08 | 000,292,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mfds.dll
[2011/03/18 21:43:08 | 000,195,584 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\AudioSes.dll
[2011/03/18 21:43:07 | 000,720,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/03/18 21:43:07 | 000,573,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/03/18 21:43:07 | 000,076,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidclass.sys
[2011/03/18 21:20:51 | 000,004,232 | —- | M] () – C:\Windows\SysWow64\drivers\1028_Dell_INS_570.mrk
[2011/03/18 21:20:51 | 000,004,232 | —- | M] () – C:\Windows\SysNative\drivers\1028_Dell_INS_570.mrk
[2011/03/18 20:54:39 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2011/03/18 20:54:18 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/03/18 19:32:32 | 000,000,204 | —- | M] () – C:\Users\Public\Desktop\My Identity Protection.url
[2011/03/18 19:11:29 | 000,001,997 | —- | M] () – C:\Users\Public\Desktop\eBay.lnk
[2011/03/18 19:01:26 | 000,521,448 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\deployJava1.dll
[2011/03/18 19:01:26 | 000,189,728 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaws.exe
[2011/03/18 19:01:26 | 000,171,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\javaw.exe
[2011/03/18 19:01:26 | 000,171,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysNative\java.exe
[2011/03/18 19:00:58 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2011/03/18 19:00:58 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/03/18 19:00:58 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/03/18 19:00:58 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/11 23:20:18 | 000,016,432 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2011/04/11 23:20:17 | 000,000,506 | -H– | C] () – C:\aaw7boot.cmd
[2011/04/11 21:53:52 | 000,001,168 | —- | C] () – C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/04/11 21:53:52 | 000,001,144 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/04/11 13:34:59 | 000,001,111 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/07 00:41:25 | 000,001,847 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/07 00:41:06 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/04/06 23:39:12 | 000,000,981 | —- | C] () – C:\Users\David\Desktop\iLivid Download Manager.lnk
[2011/04/04 12:57:21 | 000,004,608 | —- | C] () – C:\Users\David\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/04 12:33:23 | 000,001,170 | —- | C] () – C:\Users\Public\Desktop\Camtasia Studio 7.lnk
[2011/03/29 12:08:15 | 000,000,000 | —- | C] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2011/03/28 09:49:12 | 000,743,066 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/27 07:59:19 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/03/26 23:08:54 | 000,002,316 | —- | C] () – C:\Users\David\Desktop\Google Chrome.lnk
[2011/03/26 23:08:31 | 000,000,908 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001UA.job
[2011/03/26 23:08:31 | 000,000,856 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001Core.job
[2011/03/26 21:03:16 | 000,001,439 | —- | C] () – C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/26 21:03:00 | 000,001,940 | —- | C] () – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2011/03/26 21:02:47 | 000,001,371 | —- | C] () – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/03/26 21:02:42 | 000,001,445 | —- | C] () – C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/03/26 21:00:45 | 000,000,422 | —- | C] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/03/26 21:00:44 | 000,000,564 | —- | C] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/03/26 20:58:10 | 000,001,935 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Help Documentation.lnk
[2011/03/26 20:57:37 | 000,000,290 | —- | C] () – C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/03/26 20:57:37 | 000,000,272 | —- | C] () – C:\Users\David\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/03/18 21:45:26 | 000,030,405 | RH– | C] () – C:\dell.sdr
[2011/03/18 21:21:12 | 000,241,920 | —- | C] () – C:\Windows\SysWow64\atiumdva.cap
[2011/03/18 21:21:12 | 000,241,920 | —- | C] () – C:\Windows\SysNative\atiumd6a.cap
[2011/03/18 21:21:11 | 000,018,440 | —- | C] () – C:\Windows\atiogl.xml
[2011/03/18 21:21:10 | 000,332,288 | —- | C] () – C:\Windows\SysNative\ATIODE.exe
[2011/03/18 21:21:10 | 000,051,200 | —- | C] () – C:\Windows\SysNative\ATIODCLI.exe
[2011/03/18 21:21:09 | 000,197,655 | —- | C] () – C:\Windows\SysNative\atiicdxx.dat
[2011/03/18 21:20:51 | 000,004,232 | —- | C] () – C:\Windows\SysWow64\drivers\1028_Dell_INS_570.mrk
[2011/03/18 21:20:51 | 000,004,232 | —- | C] () – C:\Windows\SysNative\drivers\1028_Dell_INS_570.mrk
[2011/03/18 20:55:46 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/03/18 20:55:42 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/03/18 20:54:39 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/03/18 20:54:18 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/03/18 20:52:45 | 334,737,407 | -HS- | C] () – C:\hiberfil.sys
[2011/03/18 19:33:16 | 000,001,382 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Default Manager.lnk
[2011/03/18 19:32:32 | 000,000,204 | —- | C] () – C:\Users\Public\Desktop\My Identity Protection.url
[2011/03/18 19:18:48 | 000,001,307 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/03/18 19:18:38 | 000,001,376 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/03/18 19:18:15 | 000,001,460 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/03/18 19:18:04 | 000,002,488 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/03/18 19:12:32 | 000,002,435 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2011/03/18 19:11:29 | 000,001,997 | —- | C] () – C:\Users\Public\Desktop\eBay.lnk
[2011/03/18 19:03:31 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/03/27 09:00:28 | 000,000,000 | —D | M] – C:\Users\David\AppData\Roaming\PCDr
[2011/04/11 23:56:44 | 000,000,000 | —D | M] – C:\Users\David\AppData\Roaming\Sammsoft
[2011/04/11 13:30:03 | 000,000,000 | —D | M] – C:\Users\David\AppData\Roaming\SoftGrid Client
[2011/03/28 09:49:49 | 000,000,000 | —D | M] – C:\Users\David\AppData\Roaming\TP
[2011/03/27 07:44:14 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2009/07/14 01:08:49 | 000,003,870 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/04/11 21:12:24 | 000,000,422 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/11 23:20:17 | 000,000,506 | -H– | M] () – C:\aaw7boot.cmd
[2011/03/18 21:45:26 | 000,030,405 | RH– | M] () – C:\dell.sdr
[2011/04/11 22:01:42 | 334,737,407 | -HS- | M] () – C:\hiberfil.sys
[2011/04/11 22:01:44 | 1877,975,039 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 03:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/26 21:03:16 | 000,000,221 | -HS- | M] () – C:\Users\David\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


OTL Extras logfile created on: 4/12/2011 12:05:17 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\David\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 69.00% Memory free
11.00 Gb Paging File | 9.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 917.66 Gb Total Space | 781.87 Gb Free Space | 85.20% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: DAVID-PC | User Name: David | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416023FF}" = Java™ 6 Update 23 (64-bit)
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E06357A3-5F44-B1AE-F4BA-9DAC26A209C9}" = ccc-utility64
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D29B7E9-CDFF-807D-1D4E-FFB77D809836}" = CCC Help Italian
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{144D9816-818D-C36E-33A0-889A19C5EDA6}" = CCC Help Portuguese
"{18BED011-2EEF-1148-E90C-D6556565B2EC}" = CCC Help Polish
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20C2435C-5B06-2E12-5087-116D8EF658B8}" = CCC Help Korean
"{26791563-0BDF-1FBE-CC21-994A09559CCE}" = Catalyst Control Center Graphics Previews Common
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3A25676C-038C-504A-FA32-F971B36BF7EE}" = Catalyst Control Center Graphics Previews Vista
"{3B8FF075-F41B-89DD-41F7-B90A6A01B8F8}" = Catalyst Control Center Graphics Full New
"{44453D07-5BDB-45F8-E3DF-20A7F76407D0}" = CCC Help Czech
"{466E1C7A-AEAF-2F55-26E2-A727B761AAB0}" = CCC Help Dutch
"{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}" = Camtasia Studio 7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{50ED6ABB-078C-8B17-1181-DC6DDB4E52DC}" = Catalyst Control Center InstallProxy
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.2
"{56E55229-CBE7-211E-0CD1-AB3712AF177A}" = CCC Help Danish
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5CE2D957-59C2-4489-481E-2E38EAE59762}" = CCC Help Spanish
"{5DEB2BA0-0E1F-D5CB-A0C4-F738590BE973}" = Catalyst Control Center Core Implementation
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{6675371D-22CD-F426-DC4C-9DDF594D0BBE}" = CCC Help Chinese Traditional
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6839108F-BC82-30BC-776F-D635EDA2B3D4}" = CCC Help Russian
"{6B1ADEE1-1595-82C4-6FB9-97B65F68E9EE}" = CCC Help Swedish
"{6B206787-2964-D9D8-A1F6-7D98B6BCD7F9}" = CCC Help Hungarian
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{73EFFD76-009E-A554-AA1F-106DBE475525}" = CCC Help French
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{775FCAEB-C804-02B9-135F-D9A189A1CCDC}" = CCC Help English
"{77D41B26-31DE-4EBA-F974-26D67B728FDB}" = CCC Help Turkish
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{833FE2B0-DCD7-8995-6374-F69F1A84055F}" = CCC Help German
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D0BED50-BD2B-5EBA-7F04-5513F1B9EC74}" = CCC Help Thai
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{98C7AEBC-350A-52D6-6886-76FB98C6A503}" = Catalyst Control Center Graphics Full Existing
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A69D7B32-2BE9-42BF-B576-69B5E0FF7394}" = Catalyst Control Center - Branding
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8B88634-7F90-402F-B66A-86429755F6A5}" = eBay
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA31EA7B-7917-4000-949B-38E91F848A25}" = Internet Explorer
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{BE6F906F-9F86-5CED-E122-8C6A162295B8}" = Skins
"{C16A92EF-017B-4839-9C75-FBADB5A1FA27}" = TrustedID
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF67ED0C-F85D-4791-AED3-3FE882EDB45D}" = Dell Marketplace Webslice IE8
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1E89604-DFBE-2DF8-BE82-A0076107AA32}" = CCC Help Finnish
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50D9AC2-EB3C-3161-FF97-4E800D106D0E}" = CCC Help Norwegian
"{E65DADC9-D6B1-6706-41DE-FA19149869E5}" = Catalyst Control Center Graphics Light
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EBF60699-3D2E-6677-D504-5B4846171C8E}" = ccc-core-static
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4044E58-9707-2918-1DA9-D3E400F0B699}" = CCC Help Japanese
"{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement
"{F70ACEA1-05C5-6D98-9C0C-F3AD818E1E33}" = CCC Help Chinese Standard
"{F835D378-5073-8C86-70EF-9A3B739F9897}" = CCC Help Greek
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FFD3A1EB-F550-3309-7AFE-17E4BB778423}" = Catalyst Control Center Localization All
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Dell Dock" = Dell Dock
"GoToAssist" = GoToAssist 8.0.0.514
"iLivid Download Manager" = iLivid Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MSC" = McAfee SecurityCenter
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Searchqu 406 MediaBar" = Windows ilivid Toolbar
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/27/2011 9:00:27 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (584) Asapi: (09:00:27:8070)(584) libMatrix.profiler.ProfilerSnapshots
- Error – 439 getDirectoryContents(C:\ProgramData\PCDr/hardware) failed

Error - 3/27/2011 9:00:27 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (584) Asapi: (09:00:27:9050)(584) libMatrix.profiler.ProfilerSnapshots
- Error – 348 getDirectoryContents(C:\ProgramData\PCDr/software) failed

Error - 3/27/2011 9:00:27 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (584) Asapi: (09:00:27:9060)(584) libMatrix.profiler.ProfilerSnapshots
- Error – 439 getDirectoryContents(C:\ProgramData\PCDr/software) failed

Error - 3/27/2011 9:00:27 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (584) Asapi: (09:00:27:9770)(584) libMatrix.profiler.ProfilerSnapshots
- Error – 348 getDirectoryContents(C:\ProgramData\PCDr/smartdata) failed

Error - 3/27/2011 9:00:27 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (584) Asapi: (09:00:27:9780)(584) libMatrix.profiler.ProfilerSnapshots
- Error – 439 getDirectoryContents(C:\ProgramData\PCDr/smartdata) failed

Error - 3/27/2011 9:00:27 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (584) Asapi: (09:00:27:9860)(584) libMatrix.profiler.ProfilerSnapshots
- Error – 348 getDirectoryContents(C:\ProgramData\PCDr/performance) failed

Error - 3/27/2011 9:00:27 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (584) Asapi: (09:00:27:9870)(584) libMatrix.profiler.ProfilerSnapshots
- Error – 439 getDirectoryContents(C:\ProgramData\PCDr/performance) failed

Error - 3/27/2011 9:36:26 AM | Computer Name = David-PC | Source = MsiInstaller | ID = 1013
Description =

Error - 3/28/2011 9:01:51 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (4724) Asapi: (09:01:51:1080)(4724) libAsapi.DynamicLoadedPlugin -
Error – 64 Unable to load library 'S3LogPusher.dll'

Error - 3/28/2011 9:01:51 AM | Computer Name = David-PC | Source = PC-Doctor | ID = 1
Description = (4724) Asapi: (09:01:51:1230)(4724) Asapi.State - Error – 123 Plugin
S3LogPusher.dll failed to load.

[ Dell Events ]
Error - 3/26/2011 11:06:46 PM | Computer Name = David-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/26/2011 11:06:46 PM | Computer Name = David-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/26/2011 11:17:46 PM | Computer Name = David-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/26/2011 11:17:46 PM | Computer Name = David-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/27/2011 8:07:48 AM | Computer Name = David-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/27/2011 8:07:49 AM | Computer Name = David-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 4/7/2011 12:44:29 AM | Computer Name = David-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

[ System Events ]
Error - 4/4/2011 8:11:24 PM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/4/2011 8:19:01 PM | Computer Name = David-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:17:07 PM on ?4/?4/?2011 was unexpected.

Error - 4/4/2011 8:23:25 PM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/5/2011 12:47:17 AM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/6/2011 1:09:53 AM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/6/2011 10:22:15 AM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/6/2011 10:34:10 AM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/6/2011 10:46:08 AM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/6/2011 10:58:11 AM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =

Error - 4/6/2011 1:10:15 PM | Computer Name = David-PC | Source = bowser | ID = 8003
Description =


< End of report >

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:10:42 AM, on 4/12/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\datamngrUI.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\Downloads\HiJackThis (1).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110318182145.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WIC55D~1\Datamngr\IEBHO.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIC55D~1\ToolBar\searchqudtx.dll (file missing)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~2\WIC55D~1\Datamngr\datamngr.dll C:\PROGRA~2\WIC55D~1\Datamngr\IEBHO.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - c:\PROGRA~1\mcafee\msc\mcawfwk.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Dell DataSafe Online (NOBU) - Dell, Inc. - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12326 bytes

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 0:11:28.99 on Tue 04/12/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.5887.3704 [GMT -4:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\mfevtps.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\SearchIndexer.exe
c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Windows ilivid Toolbar\Datamngr\datamngrUI.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\Downloads\OTL.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\mcafee\VirusScan\mcods.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\notepad.exe
C:\Windows\notepad.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\Downloads\HiJackThis (1).exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\David\Downloads\dds (2).scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110318182145.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: UrlHelper Class: {a40dc6c5-79d0-4ca8-a185-8ff989af1115} - C:\PROGRA~2\WIC55D~1\Datamngr\IEBHO.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIC55D~1\ToolBar\searchqudtx.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
uRun: [Google Update] "C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: []
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
StartupFolder: C:\Users\David\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\PROGRA~2\WIC55D~1\Datamngr\datamngr.dll C:\PROGRA~2\WIC55D~1\Datamngr\IEBHO.dll
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110318182145.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: UrlHelper Class: {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WIC55D~1\Datamngr\x64\IEBHO.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
AppInit_DLLs-X64: C:\PROGRA~2\WIC55D~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WIC55D~1\Datamngr\x64\IEBHO.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2011-4-11 69376]
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2010-10-13 529128]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2010-10-13 283360]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-3-18 55856]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\System32\drivers\mfenlfk.sys [2010-10-13 75032]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-3-18 202752]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-4-1 1405384]
R2 McMPFSvc;McAfee Personal Firewall Service;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2010-3-10 355440]
R2 McNaiAnn;McAfee VirusScan Announcer;"C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2010-3-10 355440]
R2 McProxy;McAfee Proxy Service;"C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2010-3-10 355440]
R2 McShield;McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2011-3-18 200056]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2011-3-18 245352]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\System32\mfevtps.exe [2011-3-18 149032]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-3-18 705856]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2010-10-13 62800]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-3-18 320040]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-4-1 17152]
R3 lvpopf64;Logitech POP Suppression Filter;C:\Windows\System32\drivers\lvpopf64.sys [2009-10-7 271640]
R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2009-10-7 327704]
R3 LVUVC64;QuickCam for Notebooks Deluxe(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2009-10-7 6379288]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2010-10-13 190136]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2010-10-13 441328]
R3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\drivers\mferkdet.sys [2010-10-13 94864]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-4-24 721768]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-4-24 269672]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-4-24 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-4-24 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 McAWFwk;McAfee Activation Service;C:\PROGRA~1\mcafee\msc\mcawfwk.exe [2011-3-18 220528]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\Dell Support Center\pcdsrvc_x64.pkms [2010-7-30 25072]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-27 1255736]
S4 McOobeSv;McAfee OOBE Service;"C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2010-3-10 355440]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-04-12 03:56:24 ——– d—–w- C:\Users\David\AppData\Roaming\Roxio Burn
2011-04-12 03:55:24 ——– d—–w- C:\Users\David\AppData\Roaming\Sammsoft
2011-04-12 03:20:18 16432 —-a-w- C:\Windows\System32\lsdelete.exe
2011-04-12 03:20:17 506 —ha-w- C:\aaw7boot.cmd
2011-04-12 02:00:55 69376 —-a-w- C:\Windows\System32\drivers\Lbd.sys
2011-04-12 01:54:23 ——– d—–w- C:\Users\David\AppData\Local\Sunbelt Software
2011-04-12 01:53:54 ——– dc-h–w- C:\PROGRA~3\{6A395471-4AA3-4072-AE1B-9B69A97AD164}
2011-04-12 01:53:50 ——– d—–w- C:\Program Files (x86)\Lavasoft
2011-04-11 17:35:26 ——– d—–w- C:\Users\David\AppData\Roaming\Malwarebytes
2011-04-11 17:34:59 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-11 17:34:59 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-04-11 17:34:56 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-04-11 17:34:56 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-04-11 17:28:04 ——– d—–w- C:\Users\David\AppData\Roaming\Macrovision
2011-04-11 02:43:23 ——– d—–w- C:\Users\David\AppData\Local\Microsoft Help
2011-04-11 00:48:45 ——– d—–w- C:\Users\David\AppData\Local\PokerStars
2011-04-10 22:25:30 ——– d—–w- C:\Program Files (x86)\PokerStars
2011-04-07 04:44:10 ——– d—–w- C:\Users\David\AppData\Local\Apple Computer
2011-04-07 04:43:41 ——– d—–w- C:\Program Files\iPod
2011-04-07 04:43:41 ——– d—–w- C:\Program Files (x86)\iTunes
2011-04-07 04:43:41 ——– d—–w- C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-04-07 04:41:33 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-04-07 04:41:33 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-04-07 04:41:33 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-04-07 04:41:33 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-04-07 04:41:33 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-04-07 04:41:32 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-04-07 04:41:32 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-04-07 04:41:07 ——– d—–w- C:\Users\David\AppData\Local\Apple
2011-04-07 04:40:42 ——– d—–w- C:\Program Files\Bonjour
2011-04-07 04:40:42 ——– d—–w- C:\Program Files (x86)\Bonjour
2011-04-07 03:39:03 ——– d—–w- C:\Program Files (x86)\ilivid
2011-04-07 03:38:50 ——– d—–w- C:\Program Files (x86)\Windows ilivid Toolbar
2011-04-07 03:38:46 ——– d—–w- C:\Users\David\AppData\Local\PackageAware
2011-04-04 17:19:42 ——– d—–w- C:\Users\David\AppData\Local\TechSmith
2011-04-04 16:33:13 ——– d—–w- C:\Program Files (x86)\Common Files\TechSmith Shared
2011-03-28 16:02:38 ——– d—–w- C:\PROGRA~3\VirtualizedApplications
2011-03-28 13:49:41 ——– d—–w- C:\Users\David\AppData\Local\SoftGrid Client
2011-03-28 13:49:40 ——– d—–w- C:\Users\David\AppData\Roaming\SoftGrid Client
2011-03-28 13:49:01 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2011-03-28 13:48:52 ——– d—–w- C:\Users\David\AppData\Roaming\TP
2011-03-27 13:00:28 ——– d—–w- C:\Users\David\AppData\Roaming\PCDr
2011-03-27 13:00:01 ——– d—–w- C:\PROGRA~3\PCDr
2011-03-27 11:43:03 ——– d—–w- C:\Windows\SysWow64\Wat
2011-03-27 11:43:03 ——– d—–w- C:\Windows\System32\Wat
2011-03-27 11:23:31 367104 —-a-w- C:\Windows\System32\wcncsvc.dll
2011-03-27 11:23:31 276992 —-a-w- C:\Windows\SysWow64\wcncsvc.dll
2011-03-27 11:22:36 ——– d—–w- C:\Program Files (x86)\MSXML 4.0
2011-03-27 11:22:05 99176 —-a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2011-03-27 11:22:05 49472 —-a-w- C:\Windows\SysWow64\netfxperf.dll
2011-03-27 11:22:05 48960 —-a-w- C:\Windows\System32\netfxperf.dll
2011-03-27 11:22:05 444752 —-a-w- C:\Windows\System32\mscoree.dll
2011-03-27 11:22:05 320352 —-a-w- C:\Windows\System32\PresentationHost.exe
2011-03-27 11:22:05 297808 —-a-w- C:\Windows\SysWow64\mscoree.dll
2011-03-27 11:22:05 295264 —-a-w- C:\Windows\SysWow64\PresentationHost.exe
2011-03-27 11:22:05 1942856 —-a-w- C:\Windows\System32\dfshim.dll
2011-03-27 11:22:05 1130824 —-a-w- C:\Windows\SysWow64\dfshim.dll
2011-03-27 11:22:05 109912 —-a-w- C:\Windows\System32\PresentationHostProxy.dll
2011-03-27 03:08:26 ——– d—–w- C:\Users\David\AppData\Local\Google
2011-03-27 03:07:31 ——– d—–w- C:\Users\David\AppData\Local\Deployment
2011-03-27 03:07:31 ——– d—–w- C:\Users\David\AppData\Local\Apps
2011-03-27 03:06:49 ——– d—–w- C:\Users\David\My Backup Files
2011-03-27 01:04:35 ——– d-sh–w- C:\System Recovery
2011-03-27 01:03:01 ——– d—–w- C:\Users\David\AppData\Roaming\Dell
2011-03-27 01:02:59 ——– d—–w- C:\Users\David\AppData\Local\Stardock_Corporation
2011-03-27 01:02:53 ——– d—–w- C:\Users\David\AppData\Local\ATI
2011-03-27 01:02:28 ——– d—–w- C:\Users\David\AppData\Local\VirtualStore
2011-03-27 01:02:18 ——– d—–w- C:\Users\David\AppData\Local\SoftThinks
2011-03-19 01:43:28 286720 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-03-19 01:35:50 ——– d—–w- C:\Apps
2011-03-19 01:30:41 ——– d—–w- C:\Program Files\Dell Games Folder
2011-03-19 01:17:17 ——– d—–w- C:\Windows\System32\oem
2011-03-19 01:17:13 ——– d—–w- C:\Windows\Panther
2011-03-19 01:17:13 ——– d—–w- C:\Drivers
2011-03-19 01:10:43 ——– d—–w- C:\dell
2011-03-19 00:54:43 ——– d—–w- C:\Program Files\Realtek
2011-03-19 00:54:42 ——– d—–w- C:\Windows\SysWow64\RTCOM
2011-03-19 00:54:39 0 —-a-w- C:\Windows\ativpsrm.bin
2011-03-18 23:33:30 ——– dc-h–w- C:\PROGRA~3\{04A07C23-5821-4F25-BF46-1188636AE238}
2011-03-18 23:33:28 ——– d—–w- C:\Program Files\Dell
2011-03-18 23:32:55 ——– d—–w- C:\Program Files (x86)\Microsoft
2011-03-18 23:32:33 ——– d—–w- C:\Program Files (x86)\Jagex
2011-03-18 23:32:32 ——– d—–w- C:\Program Files (x86)\TrustedID
2011-03-18 23:29:57 ——– d—–w- C:\PROGRA~3\Uninstall
2011-03-18 23:28:06 ——– d—–w- C:\Program Files (x86)\Common Files\SureThing Shared
2011-03-18 23:27:54 ——– d—–w- C:\PROGRA~3\PhotoShow Shared Assets
2011-03-18 23:27:51 ——– d—–w- C:\Program Files\Roxio
2011-03-18 23:25:46 55856 ——w- C:\Windows\System32\drivers\PxHlpa64.sys
2011-03-18 23:25:46 10224 ——w- C:\Windows\System32\drivers\cdralw2k.sys
2011-03-18 23:25:46 10224 ——w- C:\Windows\System32\drivers\cdr4_xp.sys
2011-03-18 23:25:22 ——– d—–w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-03-18 23:21:44 9984 —-a-w- C:\Windows\System32\drivers\mfeclnk.sys
2011-03-18 23:21:11 149032 —-a-w- C:\Windows\System32\mfevtps.exe
2011-03-18 23:20:59 ——– d—–w- C:\Program Files (x86)\mcafee.com
2011-03-18 23:20:58 ——– d—–w- C:\Program Files\mcafee.com
2011-03-18 23:20:58 ——– d—–w- C:\Program Files\mcafee
2011-03-18 23:20:58 ——– d—–w- C:\Program Files\Common Files\mcafee
2011-03-18 23:20:58 ——– d—–w- C:\Program Files (x86)\McAfee
2011-03-18 23:20:58 ——– d—–w- C:\Program Files (x86)\Common Files\mcafee
2011-03-18 23:20:50 ——– d—–w- C:\Program Files\Dell Support Center
2011-03-18 23:20:31 ——– d—–w- C:\Program Files (x86)\Dell
2011-03-18 23:19:29 ——– d—–w- C:\Windows\en
2011-03-18 23:18:35 ——– d—–w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-03-18 23:17:10 ——– d—–w- C:\Windows\PCHEALTH
2011-03-18 23:16:35 69464 —-a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-03-18 23:16:35 515416 —-a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-03-18 23:16:34 523088 —-a-w- C:\Windows\System32\d3dx10_42.dll
2011-03-18 23:16:34 453456 —-a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-03-18 23:15:50 4398360 —-a-w- C:\Windows\System32\d3dx9_32.dll
2011-03-18 23:15:50 3426072 —-a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-03-18 23:14:29 1164800 —-a-w- C:\Windows\SysWow64\UIRibbonRes.dll
2011-03-18 23:14:29 1164800 —-a-w- C:\Windows\System32\UIRibbonRes.dll
2011-03-18 23:14:24 2983424 —-a-w- C:\Windows\SysWow64\UIRibbon.dll
2011-03-18 23:14:23 3860992 —-a-w- C:\Windows\System32\UIRibbon.dll
2011-03-18 23:12:59 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\5b037d81cbe5c205\DSETUP.dll
2011-03-18 23:12:59 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\5b037d81cbe5c205\DXSETUP.exe
2011-03-18 23:12:59 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\5b037d81cbe5c205\dsetup32.dll
2011-03-18 23:12:59 15712 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\611d0431cbe5c206\MeshBetaRemover.exe
2011-03-18 23:12:58 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\561aa6f1cbe5c204\DSETUP.dll
2011-03-18 23:12:58 6260088 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\52165471cbe5c203\Silverlight.4.0.exe
2011-03-18 23:12:58 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\561aa6f1cbe5c204\DXSETUP.exe
2011-03-18 23:12:58 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\561aa6f1cbe5c204\dsetup32.dll
2011-03-18 23:12:53 ——– d—–w- C:\Program Files (x86)\Common Files\Windows Live
2011-03-18 23:12:46 ——– d–h–w- C:\Windows\msdownld.tmp
2011-03-18 23:09:31 ——– d—–w- C:\Temp
2011-03-18 23:09:30 151656 —-a-w- C:\Windows\System32\drivers\WimFltr.sys
2011-03-18 23:09:16 ——– d—–w- C:\Program Files (x86)\Dell DataSafe Local Backup
2011-03-18 23:08:53 733184 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
2011-03-18 23:08:53 69715 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
2011-03-18 23:08:53 5632 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
2011-03-18 23:08:53 303236 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
2011-03-18 23:08:53 266240 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
2011-03-18 23:08:53 180356 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
2011-03-18 23:08:53 172032 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
2011-03-18 23:05:47 ——– d—–w- C:\Program Files (x86)\WildTangent
2011-03-18 23:05:47 ——– d—–w- C:\PROGRA~3\WildTangent
2011-03-18 23:04:14 ——– d—–w- C:\Program Files (x86)\Citrix
2011-03-18 23:00:24 ——– d—–w- C:\Program Files\Dell Inc
2011-03-18 23:00:20 ——– d-sh–w- C:\Windows\Installer
.
==================== Find3M ====================
.
2011-03-18 23:01:26 521448 —-a-w- C:\Windows\System32\deployJava1.dll
2011-03-18 23:00:58 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2011-01-26 06:53:10 982912 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2011-01-26 06:53:10 265088 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys
2011-01-26 06:31:20 144384 —-a-w- C:\Windows\System32\cdd.dll
.
============= FINISH: 0:11:53.10 ===============
Posted Image

Looks like you're running 2 anti-virus programs.

Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.

Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove either:
Lavasoft Ad-Watch Live! Anti-Virus
McAfee Anti-Virus and Anti-Spyware





DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


I've been seeing some Java infections lately.

Go here and follow the instructions to clear your Java Cache
http://www.java.com/en/download/help/plugin_cache.xml


Next:
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.


  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Hey mate, much thanks for responding. I did everything you said to do, but when I open the internet searchqu still comes up as the default browser. Here is the result of my scan. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6357 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4/13/2011 9:41:21 PM mbam-log-2011-04-13 (21-41-21).txt Scan type: Quick scan Objects scanned: 165007 Time elapsed: 1 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\David\downloads\whitesmokeinstaller_9128.exe (PUP.WhiteSmoke) -> Quarantined and deleted successfully.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Here is the log from combofix. My computer is running fine, but searchqu still comes up as the default webpage. ComboFix 11-04-13.06 - David 04/14/2011 11:00:47.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.5887.4617 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2011-03-14 to 2011-04-14 ))))))))))))))))))))))))))))))) . . 2011-04-14 15:05 . 2011-04-14 15:05 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-04-14 01:57 . 2011-03-03 03:58 3133440 —-a-w- c:\windows\system32\win32k.sys 2011-04-14 01:56 . 2011-02-12 06:14 267776 —-a-w- c:\windows\system32\FXSCOVER.exe 2011-04-14 01:56 . 2011-02-23 05:15 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-14 01:56 . 2011-02-23 05:15 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-14 01:56 . 2011-02-23 05:15 126464 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-04-14 01:56 . 2011-02-23 05:15 90624 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-04-13 03:50 . 2009-05-18 17:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-04-13 03:50 . 2008-04-17 16:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2011-04-07 04:43 . 2011-04-07 04:43 ——– d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-04-07 04:41 . 2011-04-07 04:41 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-04-07 04:41 . 2011-04-07 04:41 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-04-07 04:41 . 2011-04-07 04:41 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-04-07 04:41 . 2011-04-07 04:41 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-04-04 16:33 . 2011-04-04 16:33 ——– d—–w- c:\programdata\TechSmith 2011-04-04 16:33 . 2011-04-04 16:33 ——– d—–w- c:\program files (x86)\TechSmith 2011-04-04 16:33 . 2011-04-04 16:33 ——– d—–w- c:\program files (x86)\Common Files\TechSmith Shared 2011-03-29 16:08 . 2011-03-29 16:08 ——– d—–w- c:\program files\Common Files\logishrd 2011-03-28 16:02 . 2011-03-28 16:04 ——– d—–w- c:\programdata\VirtualizedApplications 2011-03-28 13:49 . 2011-04-11 17:36 ——– d—–w- c:\program files (x86)\Microsoft Application Virtualization Client 2011-03-27 13:00 . 2011-03-27 13:00 ——– d—–w- c:\programdata\PCDr 2011-03-27 11:58 . 2011-03-27 11:58 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-03-27 11:43 . 2011-03-27 11:43 ——– d—–w- c:\windows\SysWow64\Wat 2011-03-27 11:43 . 2011-03-27 11:43 ——– d—–w- c:\windows\system32\Wat 2011-03-27 11:23 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll 2011-03-27 11:23 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-03-27 11:22 . 2011-03-27 11:22 ——– d—–w- c:\program files (x86)\MSXML 4.0 2011-03-27 11:22 . 2009-11-25 16:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll 2011-03-27 11:22 . 2009-11-25 16:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll 2011-03-27 11:22 . 2009-11-25 16:47 48960 —-a-w- c:\windows\system32\netfxperf.dll 2011-03-27 11:22 . 2009-11-25 16:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll 2011-03-27 11:22 . 2009-11-25 16:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe 2011-03-27 11:22 . 2009-11-25 16:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll 2011-03-27 11:22 . 2009-11-25 16:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2011-03-27 11:22 . 2009-11-25 16:47 444752 —-a-w- c:\windows\system32\mscoree.dll 2011-03-27 11:22 . 2009-11-25 16:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe 2011-03-27 11:22 . 2009-11-25 16:47 1942856 —-a-w- c:\windows\system32\dfshim.dll 2011-03-27 01:04 . 2011-03-27 03:06 ——– d-sh–w- C:\System Recovery 2011-03-27 01:02 . 2011-03-27 01:02 ——– d—–w- c:\users\Default\AppData\Local\SoftThinks 2011-03-27 00:57 . 2011-04-11 17:31 ——– d—–w- c:\users\David 2011-03-19 01:35 . 2011-03-18 23:32 ——– d—–w- C:\Apps 2011-03-19 01:30 . 2011-03-19 01:30 ——– d—–w- c:\program files\Dell Games Folder 2011-03-19 01:17 . 2011-03-27 11:42 ——– d—–w- c:\windows\system32\oem 2011-03-19 01:17 . 2011-03-27 01:53 ——– d—–w- c:\windows\Panther 2011-03-19 01:17 . 2011-03-19 01:21 ——– d—–w- C:\Drivers 2011-03-19 01:10 . 2011-03-27 11:42 ——– d—–w- C:\dell 2011-03-19 00:54 . 2011-03-19 00:54 ——– d—–w- c:\program files\Realtek 2011-03-19 00:54 . 2011-03-18 22:57 ——– d—–w- c:\windows\SysWow64\RTCOM 2011-03-19 00:54 . 2011-03-19 00:54 0 —-a-w- c:\windows\ativpsrm.bin 2011-03-18 23:43 . 2011-03-18 23:43 ——– d—–w- c:\programdata\ATI 2011-03-18 23:33 . 2011-03-18 23:33 ——– dc-h–w- c:\programdata\{04A07C23-5821-4F25-BF46-1188636AE238} 2011-03-18 23:33 . 2011-03-18 23:33 ——– d—–w- c:\program files\Dell 2011-03-18 23:32 . 2011-04-11 17:29 ——– d—–w- c:\program files (x86)\Microsoft 2011-03-18 23:32 . 2011-03-18 23:32 ——– d—–w- c:\program files (x86)\Jagex 2011-03-18 23:32 . 2011-03-18 23:32 ——– d—–w- c:\program files (x86)\TrustedID 2011-03-18 23:29 . 2011-03-18 23:29 ——– d—–w- c:\programdata\Uninstall 2011-03-18 23:28 . 2011-03-18 23:28 ——– d—–w- c:\program files (x86)\Common Files\SureThing Shared 2011-03-18 23:27 . 2011-03-18 23:27 ——– d—–w- c:\programdata\PhotoShow Shared Assets 2011-03-18 23:27 . 2011-03-18 23:27 ——– d—–w- c:\program files\Roxio 2011-03-18 23:26 . 2011-04-14 01:53 ——– d—–w- c:\programdata\Sonic 2011-03-18 23:25 . 2010-03-19 08:00 55856 ——w- c:\windows\system32\drivers\PxHlpa64.sys 2011-03-18 23:25 . 2009-10-20 08:00 10224 ——w- c:\windows\system32\drivers\cdralw2k.sys 2011-03-18 23:25 . 2009-10-20 08:00 10224 ——w- c:\windows\system32\drivers\cdr4_xp.sys 2011-03-18 23:25 . 2011-03-18 23:43 ——– d—–w- c:\programdata\Roxio 2011-03-18 23:25 . 2011-03-18 23:28 ——– d—–w- c:\program files (x86)\Common Files\PX Storage Engine 2011-03-18 23:21 . 2010-10-14 03:28 9984 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2011-03-18 23:21 . 2010-10-14 03:28 149032 —-a-w- c:\windows\system32\mfevtps.exe 2011-03-18 23:20 . 2011-03-18 23:20 ——– d—–w- c:\program files (x86)\mcafee.com 2011-03-18 23:20 . 2011-04-12 02:01 ——– d—–w- c:\program files (x86)\McAfee 2011-03-18 23:20 . 2011-03-18 23:22 ——– d—–w- c:\program files\mcafee 2011-03-18 23:20 . 2011-03-18 23:22 ——– d—–w- c:\program files (x86)\Common Files\mcafee 2011-03-18 23:20 . 2011-03-18 23:20 ——– d—–w- c:\program files\Common Files\mcafee 2011-03-18 23:20 . 2011-03-27 06:58 ——– d—–w- c:\programdata\McAfee 2011-03-18 23:20 . 2011-03-18 23:20 ——– d—–w- c:\program files\Dell Support Center 2011-03-18 23:20 . 2011-03-18 23:38 ——– d—–w- c:\program files (x86)\Dell 2011-03-18 23:20 . 2011-03-18 23:33 ——– d—–w- c:\programdata\Dell 2011-03-18 23:19 . 2011-03-18 23:19 ——– d—–w- c:\windows\en 2011-03-18 23:18 . 2011-03-18 23:18 ——– d—–w- c:\program files (x86)\Microsoft SQL Server Compact Edition 2011-03-18 23:17 . 2011-03-18 23:19 ——– d—–w- c:\program files (x86)\Windows Live 2011-03-18 23:17 . 2011-03-18 23:17 ——– d—–w- c:\windows\PCHEALTH 2011-03-18 23:16 . 2011-03-18 23:17 ——– d—–w- c:\program files\Windows Live 2011-03-18 23:16 . 2009-09-04 22:44 69464 —-a-w- c:\windows\SysWow64\XAPOFX1_3.dll 2011-03-18 23:16 . 2009-09-04 22:44 515416 —-a-w- c:\windows\SysWow64\XAudio2_5.dll 2011-03-18 23:16 . 2009-09-04 22:29 453456 —-a-w- c:\windows\SysWow64\d3dx10_42.dll 2011-03-18 23:16 . 2009-09-04 22:29 523088 —-a-w- c:\windows\system32\d3dx10_42.dll 2011-03-18 23:15 . 2006-11-29 18:06 4398360 —-a-w- c:\windows\system32\d3dx9_32.dll 2011-03-18 23:15 . 2006-11-29 18:06 3426072 —-a-w- c:\windows\SysWow64\d3dx9_32.dll 2011-03-18 23:14 . 2011-04-14 01:43 ——– d—–w- c:\program files (x86)\Microsoft Silverlight 2011-03-18 23:14 . 2010-08-11 05:13 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll 2011-03-18 23:14 . 2010-08-11 04:35 1164800 —-a-w- c:\windows\SysWow64\UIRibbonRes.dll 2011-03-18 23:14 . 2010-08-11 04:44 2983424 —-a-w- c:\windows\SysWow64\UIRibbon.dll 2011-03-18 23:14 . 2010-08-11 05:19 3860992 —-a-w- c:\windows\system32\UIRibbon.dll 2011-03-18 23:12 . 2011-03-18 23:12 ——– d—–w- c:\program files (x86)\Common Files\Windows Live 2011-03-18 23:12 . 2011-03-18 23:12 ——– d–h–w- c:\windows\msdownld.tmp 2011-03-18 23:10 . 2011-03-27 11:58 ——– d—–w- c:\programdata\Skype 2011-03-18 23:09 . 2011-03-18 23:10 ——– d—–w- C:\Temp 2011-03-18 23:09 . 2006-11-01 17:51 151656 —-a-w- c:\windows\system32\drivers\WimFltr.sys 2011-03-18 23:09 . 2011-04-14 02:21 ——– d—–w- c:\program files (x86)\Dell DataSafe Local Backup 2011-03-18 23:05 . 2011-03-18 23:08 ——– d—–w- c:\programdata\WildTangent 2011-03-18 23:05 . 2011-03-18 23:05 ——– d—–w- c:\program files (x86)\WildTangent 2011-03-18 23:04 . 2011-03-18 23:04 ——– d—–w- c:\program files (x86)\Citrix 2011-03-18 23:03 . 2011-03-18 23:03 ——– d—–w- c:\program files (x86)\Common Files\Adobe 2011-03-18 23:00 . 2011-03-18 23:00 ——– d—–w- c:\program files (x86)\Java 2011-03-18 23:00 . 2011-03-18 23:00 ——– d—–w- c:\windows\SysWow64\Macromed 2011-03-18 23:00 . 2011-03-18 23:00 ——– d—–w- c:\program files\Dell Inc 2011-03-18 23:00 . 2011-04-14 02:05 ——– d-sh–w- c:\windows\Installer . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-27 23:53 . 2010-06-24 16:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-03-19 01:43 . 2011-03-19 01:43 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-03-19 01:43 . 2011-03-19 01:43 347648 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2011-03-19 01:43 . 2011-03-19 01:43 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-03-27 136176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-15 98304] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1484856] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] "Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-03-30 560128] "Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2011-01-13 165184] . c:\users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\WIC55D~1\Datamngr\datamngr.dll c:\progra~2\WIC55D~1\Datamngr\IEBHO.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-30 220528] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-14 245352] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x] S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] S3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys [x] S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x] S3 LVUVC64;QuickCam for Notebooks Deluxe(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2010-07-30 25072] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768] . . — Other Services/Drivers In Memory — . *Deregistered* - mfeavfk01 . Contents of the 'Scheduled Tasks' folder . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001Core.job - c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-27 03:08] . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001UA.job - c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-27 03:08] . 2011-03-27 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2010-08-05 23:47] . 2011-04-14 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\pcdrcui.exe [2010-08-05 23:47] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}] 2011-03-24 12:30 1058712 —-a-w- c:\progra~2\WIC55D~1\Datamngr\x64\IEBHO.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-11-10 8321568] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\progra~2\WIC55D~1\Datamngr\x64\datamngr.dll c:\progra~2\WIC55D~1\Datamngr\x64\IEBHO.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-10 - (no file) Toolbar-Locked - (no file) Toolbar-10 - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0] "ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-04-14 11:07:27 ComboFix-quarantined-files.txt 2011-04-14 15:07 . Pre-Run: 939,101,069,312 bytes free Post-Run: 939,024,691,200 bytes free . - - End Of File - - 0CAABF43759C8F109EC28890C4227005
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

DDS::
C:\PROGRA~2\WIC55D~1\ToolBar\searchqudtx.dll

Folder::
C:\PROGRA~2\WIC55D~1

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Here is the combo fix test. My computer is running alright, but the searchqu still comes up as default search engine.

ComboFix 11-04-15.01 - David 04/15/2011 21:41:21.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.5887.4406 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\David\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\progra~2\WIC55D~1
c:\progra~2\WIC55D~1\Datamngr\datamngr.dll
c:\progra~2\WIC55D~1\Datamngr\datamngrUI.exe
c:\progra~2\WIC55D~1\Datamngr\IEBHO.dll
c:\progra~2\WIC55D~1\Datamngr\x64\datamngr.dll
c:\progra~2\WIC55D~1\Datamngr\x64\datamngrUI.exe
c:\progra~2\WIC55D~1\Datamngr\x64\IEBHO.dll
c:\progra~2\WIC55D~1\ToolBar\as_guid.dat
c:\progra~2\WIC55D~1\ToolBar\chrome\content\bandoocode.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\data\search\engines.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\data\search\search.xsl
c:\progra~2\WIC55D~1\ToolBar\chrome\content\imeshcode.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\about.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\bandoocode.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\dtxpanel.xul
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\dtxpanelwin.xul
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\dtxprefwin.xul
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\dtxtransparentwin.xul
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\dtxwin.xul
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\emailnotifierproviders.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\external.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\imeshcode.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\neterror.xhtml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\nsDragAndDrop.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\vmncode.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\lib\wmpstreamer.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\modules\datastore.jsm
c:\progra~2\WIC55D~1\ToolBar\chrome\content\neterror.xhtml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\partner.coupons.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\preferences.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\radiobeta.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\template.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\toolbar.htm
c:\progra~2\WIC55D~1\ToolBar\chrome\content\toolbar.xul
c:\progra~2\WIC55D~1\ToolBar\chrome\content\vmncode.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\vmnrsswin.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\alert_coupon.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next-off.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous-off.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-coupon-blue.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-save.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-getcoupon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-next-blue.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-previous-blue.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\coupon-activated.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\couponTooltip.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\css\ie7style.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-coupon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-dollar.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrow-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-left.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-right.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\bg_top.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-back.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-getcoupon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\coupon-activated.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\delete.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\loader.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\sprite.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-arrow-hover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-arrow.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-l_BAK.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-r_BAK.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-on-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-on-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-over-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-over-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\vid-bg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\index.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\jquery.contextMenu.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\jquery.contextMenu.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery-1.4.2.min.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery.event.wheel.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery.scrollTo-min.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\JSON.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\listnav.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\main.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\page_white_copy.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\panel.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\partner.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\placeholder-logo.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\bg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\default.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\transparent.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-right-resize.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\main.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts\defscript.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\tb_icon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\widget.jsw
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\widget.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\widget_version.txt
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrow-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-left.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-right.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\back.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\btn-search-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\btn-search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\delete.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-arrow-hover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-arrow.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-off-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-off-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-on-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-on-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-over-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-over-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\throbber.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\vid-bg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\youtube.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\index.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\function.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\jquery-1.4.2.min.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\JSON.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\bg-facebook.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\blank.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\default.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\transparent.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-right-resize.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\main.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts\defscript.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts\jquery-1.4.2.min.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\tb_icon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget.jsw
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget_version.txt
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\tb_icon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget_version
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\css\twitter.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\btn-login-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\btn-login.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\btn-submit.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\loginbg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\refresh-over.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\refresh.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-off-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-off-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-on-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-on-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\throbber.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\twitter-logo48.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\twitter_top.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\js\jquery.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\js\scripts.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\bg.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\btn-wide-close-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\btn-wide-close.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\default.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\transparent.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-right-resize.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\main.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\scripts\defscript.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\tb_icon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\widget.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\widget.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\widget_version.txt
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\css\autocomplete.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrow-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-left.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-right.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\bg.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\powered-by-youtube.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-off-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-off-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-on-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-on-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\throbber.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\vid-bg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\youtube.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\index.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\autocomplete.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\jquery-1.4.3.min.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\paginator.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\youtube.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\bg.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\default.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-off-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-off-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-on-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-on-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\transparent.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-right-resize.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\main.html
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts\defscript.js
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\tb_icon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\widget.jsw
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\widget.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\widget_version.txt
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\babylon_logo.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\bandoo.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\bluelite.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\bluesky.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\btn-search-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\btn-search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\btn-settings-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\btn-settings.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\btn-widgets-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\btn-widgets.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\btn_settings.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\ca.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\dictionary.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\divider.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\downloadcom.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\dtxlogo.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\ebay.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\email.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\email_on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\facebook.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\games.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred0.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred0_5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred1.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred1_5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred2.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred2_5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred3.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred3_5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred4.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred4_5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphred5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\graphredna.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\grey.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\ico-shield.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\icon_radio_png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\icon_seperator_png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\images.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\imesh.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\add.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\aol.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\arrow-dn.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\arrow-right-disabled.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\arrow-right.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\arrow-up.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btn-divider.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btn-end.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btn-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btn-mdl_ff.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btn-start.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btnover-divider.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btnover-end.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btnover-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btnover-mdl_ff.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\bg-btnover-start.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\blank.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btn-widgets-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btn-widgets.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btn_slider.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btnback-down-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btnback-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btnleft-down-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btnleft-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btnright-down-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\btnright-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\button-splitter-down-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\button-splitter-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\checkmark.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\chevron.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\collapse.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\comcast.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\dtx.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\edit-back-hot.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\edit-back.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\expand.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\found.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\gmail.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\highlight.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\highlight_blue.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\highlight_cyan.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\highlight_lime.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\highlight_magenta.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\highlight_yellow.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\hotmail.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\ico-check.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\imap.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\lastsearch-thumb-back.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\loadingMid.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\lock.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\logo-separator.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\mailcom.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menu_bg-basic.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menu_separator_bar.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menu_separator_white.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menuitem-splitter.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menuitemback-down-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menuitemback-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menuitemleft-down-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menuitemleft-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menuitemright-down-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\menuitemright-vista.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\modify.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\move.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\movetarget.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\css\panels.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\css\popupAbout.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\css\popupGames.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\css\popupRSS.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\css\popupWidgets.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\css\dialog.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\bg.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\btn-search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\btn-wide-close-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\btn-wide-close.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\default.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\tab-off-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\tab-off-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\tab-on-l.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\tab-on-r.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\transparent.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-right-resize.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\win-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\images\win-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\main.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\default\scripts\defscript.js
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\footer.htm
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\gamecategory.xsl
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\gameData.js
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\gameList.xsl
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\games.xsl
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\gametype.xsl
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\arrow-dn.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\arrow-sml-drop.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\arrow-sml.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\arrow-up.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\arrowr-bluew5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\bg-aboutbox.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\bg-btnover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\bg-pnl520x390.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-left-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-back.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-close-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-close-greyover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-drag.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-mdl-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-mdl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-moredetails.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-next-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-next.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-play-left-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-play-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-previous-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-previous.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-right-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-try-left-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\btn-try-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\bullet-orange.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\gamethumb-on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\gamethumb2-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\ico-calendar.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\ico-dollar.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\ico-download.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\ico-joystick24.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\ico-news24.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\ico-play.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\ico-tags.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\icon-Add.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\icon-download.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\icon-Info.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\icon-play.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\icon-shop.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\menul-bgon.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\menul-bgover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\panel-botm-noscroll.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scroll-bg-206.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scroll-bg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scroll-topwin.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollb-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollb-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollb-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollb.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollt-disable.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollt-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollt-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\scrollt.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\star_x_grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\star_x_orange.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\TRUSTe_about.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\view-detailed-on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\view-detailed-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\view-thumb-on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\view-thumb-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\widgets-square-16px.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\widgets-square-24px.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\images\widgets.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\initHTML.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\popupGames.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\popupHTML.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\popupRSS.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\popupWidgets.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\panels\scroll.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\pop.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\css\manager.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\css\slider.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\bg-pnl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\btn-close-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\btn-close-greyover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\collapsed_button.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\expanded_button.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\ico-playstation-down.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\ico-playstation-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\ico-playstation.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\ico-radio.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\music-note.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause-on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-play-on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-play.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-bg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-buffer.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-busy.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-off.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-on.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-warning.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-options-design-on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-options-design.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-options-on.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-options.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-0.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-1.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-2.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-3.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-mute.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\scrollbar-handle.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\scrollbar-track.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\slider.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\slideron.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\images\track.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\managerpanel.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radio\volumeslider.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radiobeta-buffering.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radiobeta-connecting.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radiobeta-playing.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radiobeta-stopped.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\radiobeta.ico
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\reload.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\remove.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\rename.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\resize-box.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\rss.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\rsschannelback.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\RSSLogo.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\rsstabdivider.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\scroll-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\scroll-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\search-go.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\text-ellipsis.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\throbber.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\toolbarsplitter.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\transparent_1px.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_02.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_03.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_04.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_06.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_07.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_08.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_09.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_10.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_11.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_12.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_13.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_14.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_15.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_16.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_18.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_19.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_20.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\border_21.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\btn-close-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\btn-close-greyover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\close-hot.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\close-normal.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\loadingMid.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\proxy.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\template.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\template.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\templateFF.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\uwa\throbber.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\icons\cond999.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\icons\icons.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\icons\na-s.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\icons\na-t.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\icons\na.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\add.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-check.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.html
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lib\yahoo.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\lichen.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\logo-about.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\logo-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\logo-separator.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\logo.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\mail.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\maps.bmp
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\menuseparatorback.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\modify-save.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\modify.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\modifyhot.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\music.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\news.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\options\options-main.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\options\options-search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\options\options-weather.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\options\options-weather.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\options\options-widgets.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\orange.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\pixsy.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\protect-id.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\radiobeta-buffering.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\radiobeta-connecting.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\radiobeta-playing.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\radiobeta-stopped.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\radiobeta.ico
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\relatedlinks.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-collapse.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-delete.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-expand.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-feed.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-folder-remove.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-folder-rename.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-folder.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-found.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-reload.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss-subscribe.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rss.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rssback.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\rsstopback.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\search-over.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\search.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\search_button_over_png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\search_button_png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\searchbar\searchbar-background-left.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\searchbar\searchbar-background-middle.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\searchbar\searchbar-background-right.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\settings.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\shopping.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\siteinfo.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\skin-bluelite.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\skin-bluesky.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\skin-grey.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\skin-lichen.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\skin-orange.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\skin-yellow.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\skin.xml
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\technorati.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\throbber.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\toolbarsplitter.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\translate.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\video.bmp
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\vmn.css
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\vmn.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\weather.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\web.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\widgets-square-16px.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\wikipedia.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\yahoosearch.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\yellow.gif
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\youtube.png
c:\progra~2\WIC55D~1\ToolBar\chrome\skin\zoom.png
c:\progra~2\WIC55D~1\ToolBar\components\windowmediator.js
c:\progra~2\WIC55D~1\ToolBar\manifest.xml
c:\progra~2\WIC55D~1\ToolBar\uninstall.exe
c:\progra~2\WIC55D~1\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-03-16 to 2011-04-16 )))))))))))))))))))))))))))))))
.
.
2011-04-14 01:57 . 2011-03-03 03:58 3133440 —-a-w- c:\windows\system32\win32k.sys
2011-04-14 01:56 . 2011-02-12 06:14 267776 —-a-w- c:\windows\system32\FXSCOVER.exe
2011-04-14 01:56 . 2011-02-23 05:15 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-14 01:56 . 2011-02-23 05:15 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-14 01:56 . 2011-02-23 05:15 126464 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-14 01:56 . 2011-02-23 05:15 90624 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-04-13 03:50 . 2009-05-18 17:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-04-13 03:50 . 2008-04-17 16:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll
2011-04-07 04:43 . 2011-04-07 04:43 ——– d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-04-07 04:41 . 2011-04-07 04:41 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-04-07 04:41 . 2011-04-07 04:41 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-04-07 04:41 . 2011-04-07 04:41 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-04-04 16:33 . 2011-04-04 16:33 ——– d—–w- c:\programdata\TechSmith
2011-04-04 16:33 . 2011-04-04 16:33 ——– d—–w- c:\program files (x86)\TechSmith
2011-04-04 16:33 . 2011-04-04 16:33 ——– d—–w- c:\program files (x86)\Common Files\TechSmith Shared
2011-03-29 16:08 . 2011-03-29 16:08 ——– d—–w- c:\program files\Common Files\logishrd
2011-03-28 16:02 . 2011-03-28 16:04 ——– d—–w- c:\programdata\VirtualizedApplications
2011-03-28 13:49 . 2011-04-11 17:36 ——– d—–w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-03-27 13:00 . 2011-03-27 13:00 ——– d—–w- c:\programdata\PCDr
2011-03-27 11:58 . 2011-03-27 11:58 ——– d—–w- c:\program files (x86)\Common Files\Skype
2011-03-27 11:43 . 2011-03-27 11:43 ——– d—–w- c:\windows\SysWow64\Wat
2011-03-27 11:43 . 2011-03-27 11:43 ——– d—–w- c:\windows\system32\Wat
2011-03-27 11:23 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll
2011-03-27 11:23 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll
2011-03-27 11:22 . 2011-03-27 11:22 ——– d—–w- c:\program files (x86)\MSXML 4.0
2011-03-27 11:22 . 2009-11-25 16:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-03-27 11:22 . 2009-11-25 16:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll
2011-03-27 11:22 . 2009-11-25 16:47 48960 —-a-w- c:\windows\system32\netfxperf.dll
2011-03-27 11:22 . 2009-11-25 16:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll
2011-03-27 11:22 . 2009-11-25 16:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe
2011-03-27 11:22 . 2009-11-25 16:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll
2011-03-27 11:22 . 2009-11-25 16:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2011-03-27 11:22 . 2009-11-25 16:47 444752 —-a-w- c:\windows\system32\mscoree.dll
2011-03-27 11:22 . 2009-11-25 16:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe
2011-03-27 11:22 . 2009-11-25 16:47 1942856 —-a-w- c:\windows\system32\dfshim.dll
2011-03-27 01:04 . 2011-03-27 03:06 ——– d-sh–w- C:\System Recovery
2011-03-27 01:02 . 2011-03-27 01:02 ——– d—–w- c:\users\Default\AppData\Local\SoftThinks
2011-03-27 00:57 . 2011-04-11 17:31 ——– d—–w- c:\users\David
2011-03-19 01:35 . 2011-03-18 23:32 ——– d—–w- C:\Apps
2011-03-19 01:30 . 2011-03-19 01:30 ——– d—–w- c:\program files\Dell Games Folder
2011-03-19 01:17 . 2011-03-27 11:42 ——– d—–w- c:\windows\system32\oem
2011-03-19 01:17 . 2011-03-27 01:53 ——– d—–w- c:\windows\Panther
2011-03-19 01:17 . 2011-03-19 01:21 ——– d—–w- C:\Drivers
2011-03-19 01:10 . 2011-03-27 11:42 ——– d—–w- C:\dell
2011-03-19 00:54 . 2011-03-19 00:54 ——– d—–w- c:\program files\Realtek
2011-03-19 00:54 . 2011-03-18 22:57 ——– d—–w- c:\windows\SysWow64\RTCOM
2011-03-19 00:54 . 2011-03-19 00:54 0 —-a-w- c:\windows\ativpsrm.bin
2011-03-18 23:43 . 2011-03-18 23:43 ——– d—–w- c:\programdata\ATI
2011-03-18 23:33 . 2011-03-18 23:33 ——– dc-h–w- c:\programdata\{04A07C23-5821-4F25-BF46-1188636AE238}
2011-03-18 23:33 . 2011-03-18 23:33 ——– d—–w- c:\program files\Dell
2011-03-18 23:32 . 2011-04-11 17:29 ——– d—–w- c:\program files (x86)\Microsoft
2011-03-18 23:32 . 2011-03-18 23:32 ——– d—–w- c:\program files (x86)\Jagex
2011-03-18 23:32 . 2011-03-18 23:32 ——– d—–w- c:\program files (x86)\TrustedID
2011-03-18 23:29 . 2011-03-18 23:29 ——– d—–w- c:\programdata\Uninstall
2011-03-18 23:28 . 2011-03-18 23:28 ——– d—–w- c:\program files (x86)\Common Files\SureThing Shared
2011-03-18 23:27 . 2011-03-18 23:27 ——– d—–w- c:\programdata\PhotoShow Shared Assets
2011-03-18 23:27 . 2011-03-18 23:27 ——– d—–w- c:\program files\Roxio
2011-03-18 23:26 . 2011-04-14 01:53 ——– d—–w- c:\programdata\Sonic
2011-03-18 23:25 . 2010-03-19 08:00 55856 ——w- c:\windows\system32\drivers\PxHlpa64.sys
2011-03-18 23:25 . 2009-10-20 08:00 10224 ——w- c:\windows\system32\drivers\cdralw2k.sys
2011-03-18 23:25 . 2009-10-20 08:00 10224 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2011-03-18 23:25 . 2011-03-18 23:43 ——– d—–w- c:\programdata\Roxio
2011-03-18 23:25 . 2011-03-18 23:28 ——– d—–w- c:\program files (x86)\Common Files\PX Storage Engine
2011-03-18 23:21 . 2010-10-14 03:28 9984 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-03-18 23:21 . 2010-10-14 03:28 149032 —-a-w- c:\windows\system32\mfevtps.exe
2011-03-18 23:20 . 2011-03-18 23:20 ——– d—–w- c:\program files (x86)\mcafee.com
2011-03-18 23:20 . 2011-04-12 02:01 ——– d—–w- c:\program files (x86)\McAfee
2011-03-18 23:20 . 2011-03-18 23:22 ——– d—–w- c:\program files\mcafee
2011-03-18 23:20 . 2011-03-18 23:22 ——– d—–w- c:\program files (x86)\Common Files\mcafee
2011-03-18 23:20 . 2011-03-18 23:20 ——– d—–w- c:\program files\Common Files\mcafee
2011-03-18 23:20 . 2011-03-27 06:58 ——– d—–w- c:\programdata\McAfee
2011-03-18 23:20 . 2011-03-18 23:20 ——– d—–w- c:\program files\Dell Support Center
2011-03-18 23:20 . 2011-03-18 23:38 ——– d—–w- c:\program files (x86)\Dell
2011-03-18 23:20 . 2011-03-18 23:33 ——– d—–w- c:\programdata\Dell
2011-03-18 23:19 . 2011-03-18 23:19 ——– d—–w- c:\windows\en
2011-03-18 23:18 . 2011-03-18 23:18 ——– d—–w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-03-18 23:17 . 2011-03-18 23:19 ——– d—–w- c:\program files (x86)\Windows Live
2011-03-18 23:17 . 2011-03-18 23:17 ——– d—–w- c:\windows\PCHEALTH
2011-03-18 23:16 . 2011-03-18 23:17 ——– d—–w- c:\program files\Windows Live
2011-03-18 23:16 . 2009-09-04 22:44 69464 —-a-w- c:\windows\SysWow64\XAPOFX1_3.dll
2011-03-18 23:16 . 2009-09-04 22:44 515416 —-a-w- c:\windows\SysWow64\XAudio2_5.dll
2011-03-18 23:16 . 2009-09-04 22:29 453456 —-a-w- c:\windows\SysWow64\d3dx10_42.dll
2011-03-18 23:16 . 2009-09-04 22:29 523088 —-a-w- c:\windows\system32\d3dx10_42.dll
2011-03-18 23:15 . 2006-11-29 18:06 4398360 —-a-w- c:\windows\system32\d3dx9_32.dll
2011-03-18 23:15 . 2006-11-29 18:06 3426072 —-a-w- c:\windows\SysWow64\d3dx9_32.dll
2011-03-18 23:14 . 2011-04-14 01:43 ——– d—–w- c:\program files (x86)\Microsoft Silverlight
2011-03-18 23:14 . 2010-08-11 05:13 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2011-03-18 23:14 . 2010-08-11 04:35 1164800 —-a-w- c:\windows\SysWow64\UIRibbonRes.dll
2011-03-18 23:14 . 2010-08-11 04:44 2983424 —-a-w- c:\windows\SysWow64\UIRibbon.dll
2011-03-18 23:14 . 2010-08-11 05:19 3860992 —-a-w- c:\windows\system32\UIRibbon.dll
2011-03-18 23:12 . 2011-03-18 23:12 ——– d—–w- c:\program files (x86)\Common Files\Windows Live
2011-03-18 23:12 . 2011-03-18 23:12 ——– d–h–w- c:\windows\msdownld.tmp
2011-03-18 23:10 . 2011-03-27 11:58 ——– d—–w- c:\programdata\Skype
2011-03-18 23:09 . 2011-03-18 23:10 ——– d—–w- C:\Temp
2011-03-18 23:09 . 2006-11-01 17:51 151656 —-a-w- c:\windows\system32\drivers\WimFltr.sys
2011-03-18 23:09 . 2011-04-16 01:52 ——– d—–w- c:\program files (x86)\Dell DataSafe Local Backup
2011-03-18 23:05 . 2011-03-18 23:08 ——– d—–w- c:\programdata\WildTangent
2011-03-18 23:05 . 2011-03-18 23:05 ——– d—–w- c:\program files (x86)\WildTangent
2011-03-18 23:04 . 2011-03-18 23:04 ——– d—–w- c:\program files (x86)\Citrix
2011-03-18 23:03 . 2011-03-18 23:03 ——– d—–w- c:\program files (x86)\Common Files\Adobe
2011-03-18 23:00 . 2011-03-18 23:00 ——– d—–w- c:\program files (x86)\Java
2011-03-18 23:00 . 2011-03-18 23:00 ——– d—–w- c:\windows\SysWow64\Macromed
2011-03-18 23:00 . 2011-03-18 23:00 ——– d—–w- c:\program files\Dell Inc
2011-03-18 23:00 . 2011-04-14 02:05 ——– d-sh–w- c:\windows\Installer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-27 23:53 . 2010-06-24 16:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-19 01:43 . 2011-03-19 01:43 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2011-03-19 01:43 . 2011-03-19 01:43 347648 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2011-03-19 01:43 . 2011-03-19 01:43 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-04-14_15.05.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-16 01:48 . 2011-04-16 01:48 13318 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-04-14 02:17 . 2011-04-14 02:17 13318 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 04:54 . 2011-04-16 01:49 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-04-14 02:18 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-04-16 01:49 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-04-14 02:18 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-04-16 01:49 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-04-14 02:18 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-03-27 01:54 . 2011-04-14 14:29 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-27 01:54 . 2011-04-16 01:51 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-27 01:54 . 2011-04-16 01:51 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-03-27 01:54 . 2011-04-14 14:29 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-04-16 01:51 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-04-14 14:29 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-03-27 11:16 . 2011-04-14 02:20 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-27 11:16 . 2011-04-16 01:52 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-27 11:16 . 2011-04-16 01:52 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-03-27 11:16 . 2011-04-14 02:20 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-03-27 11:16 . 2011-04-16 01:52 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-03-27 11:16 . 2011-04-14 02:20 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-03-27 07:09 . 2011-04-14 14:32 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-27 07:09 . 2011-04-16 01:52 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-03-27 07:09 . 2011-04-14 14:32 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-03-27 07:09 . 2011-04-16 01:52 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-04-14 02:18 . 2011-04-14 02:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-04-16 01:49 . 2011-04-16 01:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-04-16 01:49 . 2011-04-16 01:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-04-14 02:18 . 2011-04-14 02:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-27 11:16 . 2011-04-16 00:29 242074 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
- 2009-07-14 05:12 . 2011-04-14 14:29 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2011-04-16 01:51 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2011-03-27 11:24 . 2011-04-14 01:42 368968 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-03-27 11:24 . 2011-04-16 01:48 368968 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2011-04-16 01:48 265712 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-04-14 02:17 265712 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-03-27 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-15 98304]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1484856]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-03-30 560128]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2011-01-13 165184]
.
c:\users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-30 220528]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2010-07-30 25072]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-14 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;QuickCam for Notebooks Deluxe(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
NETSVCS REQUIRES REPAIRS - current entries shown
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001Core.job
- c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-27 03:08]
.
2011-04-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-723521283-2411224418-3229263381-1001UA.job
- c:\users\David\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-27 03:08]
.
2011-03-27 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-08-05 23:47]
.
2011-04-15 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-08-05 23:47]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-11-10 8321568]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
AddRemove-Searchqu 406 MediaBar - c:\program files (x86)\Windows ilivid Toolbar\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
c:\program files (x86)\Dell DataSafe Local Backup\Toaster.exe
c:\program files (x86)\Common Files\Java\Java Update\jusched.exe
.
**************************************************************************
.
Completion time: 2011-04-15 21:54:59 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-16 01:54
ComboFix2.txt 2011-04-14 15:07
.
Pre-Run: 938,025,377,792 bytes free
Post-Run: 937,959,825,408 bytes free
.
- - End Of File - - EFA85811A0B8D53D08FB930720F1F7A9

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI