This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

High CPU usage, Ping.exe, browsers redirect, [Closed]

109 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm not sure what this computer pick up and brought back home while out on the internets but its doing some strange things. I get high CPU with this ping.exe. Try to end task on it but comes back. I also get browser redirect when using google, bing, yahoo search engines. I have also notice that a lot of my shortcuts are missing from desktop and start menu. Also sometimes when I'm surfing the computer would shut down. My AVG virus protection would display a window that says that I need to restart to update but when I restart that same message would appear.

thanks in advance for the help

here are the needed files:


.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by [removed] at 11:36:19.65 on Wed 11/30/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.304 [GMT -7:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\ping.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
mStart Page = hxxp://home.sweetim.com
mSearchAssistant = hxxp://google.inklineglobal.com
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: AutorunsDisabled - No File
BHO: MyWebSearch Search Assistant BHO: {00a6faf1-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL
BHO: {02098825-2d19-44e4-8646-ff9d9e7b7084} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {031d5a43-7734-4ff1-a427-52bcb87ccb98} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: mwsBar BHO: {07b18ea1-a523-4961-b6bb-170de4475cca} - c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL
BHO: {08b59703-89a1-4115-a6b2-1f3e1bbb4af2} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {0ac4bc75-2fa3-4de6-846a-bbed024f8d2d} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {0c51f24c-2e89-44c7-a435-7e3e03db771c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {0d775d40-3ed7-4080-92b4-b9533cb5fad7} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: IEPlugin Class: {11222041-111b-46e3-bd29-efb2449479b1} - c:\progra~1\arcsoft\mediac~1\intern~1\ARCURL~1.DLL
BHO: {11646753-4b5a-4a9b-9790-d0758bd33d2b} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - c:\program files\pricegong\2.5.0\PriceGongIE.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {1914f979-cc37-450b-8cf8-67bf56999654} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {19151316-cfc8-4051-834e-4ecb1a56100a} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {1e057dd2-ddb1-48dc-9bd5-45eaac26c05f} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: PlaySushi: {21608b66-026f-4dcb-9244-0daca328dced} - c:\program files\playsushi\PSText.dll
BHO: {2279bc6a-e2f2-43a2-b43b-c41392dfe284} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {27c5fe0a-7b74-4772-93e7-d8cab42de27c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {27cd137d-d81b-4ecd-9304-4d70da7fcc6b} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.4.35.10\bh\BabylonToolbar.dll
BHO: {2f176343-cc24-4354-96bd-6199b670ae54} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: {3386df80-6478-45f4-aa62-74e2f1becb7f} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {37944d43-089b-4a38-b908-c98ac52d3b47} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {3c5a3df9-1beb-4054-af20-78f5eed217b6} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: {3fb2eee7-f373-4e15-8c09-be4b7cc92392} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {4a58fd21-5a5d-492e-939b-9053e0076148} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {5e592931-d93a-454d-81e2-200502edf31d} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {5edb91e2-6e75-4561-b118-d42f32971cfd} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {609626b2-760d-46ce-89bf-0e55f55cdc90} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: PlayBryte BHO: {61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd} - mscoree.dll
BHO: {62361208-526b-40e1-b5c8-c24f442573e1} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {62d5a1d5-be5f-4256-bea0-48fd48fb84d9} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {63524016-219e-4c56-8b73-9cbf49ac7500} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {6378f079-fe8b-47f2-b4d4-509d6b540bb7} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - c:\program files\facemoods.com\facemoods\1.4.17.10\bh\facemoods.dll
BHO: {67cae67f-7416-4b44-ad86-c9788bbfa66c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {68a7a69e-930f-4956-aa5b-2002f0489e51} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {68b2d89e-fbb3-4f73-8732-653bd8eabc7a} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {6b2c36d8-bb94-4807-a201-66ed7d3a940c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {6b6ee3c0-89c6-4e38-ae8c-f5417d4a2463} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {6d3215da-74fd-45fa-94a9-3c607ec10a4b} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - c:\program files\startnow toolbar\Toolbar32.dll
BHO: {6e7c2f01-2cf0-4f71-ac9a-7ddb517418ee} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {7436f9bf-cf0e-4fa3-8def-85f15cec85fb} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: AdventureQuest Worlds Toolbar BHO: {745a6d3b-4db0-4246-b596-9189787d4ed5} - c:\program files\adventurequest worlds toolbar\Toolbar.dll
BHO: {806eeb53-7b9e-43c3-a6fb-4ebd351cc847} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {858910ec-5ab0-42fe-b37b-eadc5ca731e1} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {85b8cbc4-6ad3-435d-b316-1478a35f6391} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {86411dbc-6415-4932-b2c8-7029bc2f811c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {8670df61-36dc-4e1e-b2d0-44bdda39ad3f} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {89d9460a-4c65-49a8-b41d-ad6581b25e31} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {90854496-e592-4ef0-ab2f-4bfe8c3068ff} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: IncrediMail MediaBar 4 Toolbar: {90eee664-34b1-422a-a782-779af65cdf6d} - c:\program files\incredimail_mediabar_4\prxtbInc0.dll
BHO: {91ddd3c1-ec0a-4876-a947-321469191148} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {92617435-4eec-4e22-9ae1-21b3496b5394} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {946a89b1-2015-4167-bc38-91f665862fd2} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\prxtbPage.dll
BHO: {96718b93-be07-491c-85bf-4a269fa62030} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {9b5b5c1e-ec26-4d3c-986b-c23d45e3cdc2} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {9cac9987-dcd7-4df2-8a3a-408c6dbcc036} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
BHO: {a01c5b37-b8db-4557-a7a3-e75f850c1e61} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {a07d269b-8e49-41c0-95d7-99698809735c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {a2163cfa-3f85-4f41-ba71-993459e5126a} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {a21f94f7-2554-4547-8b37-28a3d49d7cb1} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: {a50e22f0-3c9d-4d36-a937-d774ec512d3a} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {ab803a5d-3756-41e6-b71d-74d0bd4ca1b3} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {abdf46d3-ceb2-4d48-bde4-6d1d9661dcc5} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {aea03a35-e267-4d30-b87e-6ab54e411161} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {af31ec03-a7f8-4bb9-bc2f-bd1703241a6b} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {afa23b78-9aaf-4582-a41c-49609211e365} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {b3bf3315-d4d8-4f7b-8364-1a90a8c8afb4} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: DCA BHO: {b49699fc-1665-4414-a1cb-c4a2a4a13eec} - c:\program files\common files\freecause\dca\dca-bho.dll
BHO: {b5674017-b7f8-4766-9e2f-fb6dd7162583} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {b78d4e3d-d8a2-45f9-8568-42f126f9abfe} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {c9bc87e3-0422-4970-9bad-9a3bbd09d71d} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {d1de18ff-d429-4b0a-979a-70e72b21cea2} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {d1f15550-f38f-44c9-8c73-4b68afb22d5e} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: Softonic Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: {d51b8d91-8748-43a0-8f28-b7d75ba677e0} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {d5d5a3d5-affe-4352-be1f-9440f906fb5c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: WeCareReminder Class: {d824f0de-3d60-4f57-9eb1-66033ecd8abb} - c:\documents and settings\all users\application data\wecarereminder\IEHelperv2.5.0.dll
BHO: {d8368836-312e-449f-9414-16db5118a6d3} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {dd56063d-2d2a-45f9-900f-144bad628489} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {df22c401-957f-4daa-a178-3e11e50dbd44} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {e41f3bed-6b2a-4bc2-a7cb-b722250ad1f8} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {e4a08245-94ef-4e68-9825-5c26ee63b49d} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: kikin Plugin: {e601996f-e400-41ca-804b-cd6373a7eee2} - c:\program files\kikin\ie_kikin.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SweetIM Toolbar Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
BHO: {efdb866f-9ed2-4ff8-9aa9-f40c50d41db4} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {f07e8e93-8a2c-439f-8507-d56828803c3f} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: {f3a5588b-b98d-4ff9-84c6-7eb48c49172c} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: A Free Ride Games Bar Toolbar: {f92a9fe4-2850-4198-b9d5-279880e49b16} - c:\program files\a_free_ride_games_bar\prxtbA_Fr.dll
BHO: {fbdaeb32-438a-45a0-bbcb-83b28a01ead8} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\hypercam toolbar\tbcore3.dll
BHO: {fd6e9ad3-e10a-4ddb-8107-9de04ea2408e} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers\YontooIEClient.dll
BHO: {ff517d7c-1568-4a7b-9adf-de732990c6fb} - c:\documents and settings\the crew.deam\local settings\application data\ExplorerWin32.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll
TB: QT TabBar: {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll
TB: QT Tab Standard Buttons: {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - mscoree.dll
TB: My Web Search: {07b18ea9-a523-4961-b6bb-170de4475cca} - c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL
TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - c:\program files\facemoods.com\facemoods\1.4.17.10\facemoodsTlbr.dll
TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
TB: AdventureQuest Worlds Toolbar: {3385e2d6-567b-4fc6-8f0f-d7a8c6e6118c} - c:\program files\adventurequest worlds toolbar\Toolbar.dll
TB: HyperCam Toolbar: {338b4dfe-2e2c-4338-9e41-e176d497299e} - c:\program files\hypercam toolbar\tbcore3.dll
TB: {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No File
TB: Softonic Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: IncrediMail MediaBar 4 Toolbar: {90eee664-34b1-422a-a782-779af65cdf6d} - c:\program files\incredimail_mediabar_4\prxtbInc0.dll
TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\prxtbPage.dll
TB: A Free Ride Games Bar Toolbar: {f92a9fe4-2850-4198-b9d5-279880e49b16} - c:\program files\a_free_ride_games_bar\prxtbA_Fr.dll
TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - c:\program files\startnow toolbar\Toolbar32.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.4.35.10\BabylonToolbarTlbr.dll
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10x_Plugin.exe -update plugin
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [My Web Search Bar Search Scope Monitor] "c:\progra~1\mywebs~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [Exetender] "c:\program files\free ride games\GPlayer.exe" /runonstartup
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…mp;n=2011050817
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} - {7A3D6D17-9DD5-4C60-8076-D1784DABAF8C} - c:\program files\clickpotatolite\bin\10.0.728.0\ClickPotatoLiteSABHO.dll
LSP: mswsock.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/PCPitStop.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} - hxxps://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {62789780-B744-11D0-986B-00609731A21D} - hxxp://gis.pima.gov/mapguide/viewer/ver65/mgaxctrl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259477377359
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1259477481812
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15109/CTPID.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstop2.dll
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: AutorunsDisabled - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\gn7nuhve.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm593YYUS&ptb=yFNr5NpMFZ7vV0qkXYavEQ&ind=2011050817&ptnrS=ZUxdm593YYUS&si=&n=77de3341&psa=&st=kwd&searchfor=
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\microsoft\search enhancement pack\search helper\firefoxextension\searchhelperextension\components\SEPsearchhelperff.dll
FF - plugin: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\gn7nuhve.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\free ride games\npExentCtl.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_ClickPotatoLiteSA.dll
FF - plugin: c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-10-12 206256]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 297168]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [2009-12-11 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [2009-10-7 457312]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2010-2-18 551680]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-11-20 28552]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 248656]
S1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896]
S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-9-15 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-9-15 74480]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-8-18 7390560]
S2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-14 54752]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-10-11 133104]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-4-27 2218600]
S2 X4HSEx;X4HSEx;c:\program files\free ride games\X4HSEx.sys [2011-11-4 56424]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-5-12 1025352]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 134480]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 24144]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 27216]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-10-11 133104]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-11-21 50704]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [2007-5-1 132232]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-15 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2009-2-3 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2009-2-3 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-10-8 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys –> c:\windows\system32\drivers\VBoxNetFlt.sys [?]
S4 cpuz132;cpuz132; [x]
S4 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe [2011-5-8 34320]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-10-12 348824]
S4 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-10-12 1097096]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\deada275\application data\ocs\sm\SearchAnonymizerHelper.exe [2011-9-12 40960]
S4 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;c:\program files\startnow toolbar\ToolbarUpdaterService.exe [2011-7-27 267488]
.
=============== Created Last 30 ================
.
2011-11-27 01:39:14 293888 —-a-w- c:\windows\system32\0.6344036376832972.exe
2011-11-26 22:35:20 290816 —-a-w- c:\windows\system32\0.15040859031063447.exe
2011-11-22 12:19:10 ——– d-sh–w- C:\found.000
2011-11-22 04:58:30 822272 —-a-w- c:\docume~1\alluse~1\applic~1\B2E9.tmp
2011-11-22 00:24:29 436224 —-a-w- c:\windows\system32\0.949885126871846.exe
2011-11-22 00:24:29 2722816 —-a-w- c:\windows\system32\0.9150836843586603.exe
2011-11-21 20:36:31 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-11-21 20:36:30 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-11-21 20:36:30 100880 —-a-w- c:\windows\system32\Packet.dll
2011-11-19 23:45:15 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40:58 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40:24 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15:45 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47:59 ——– d—–w- c:\docume~1\alluse~1\applic~1\3B35B
2011-11-18 06:52:23 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39:15 ——– d—–w- c:\docume~1\alluse~1\applic~1\F3A9
2011-11-11 05:50:53 ——– d—–w- c:\program files\BabylonToolbar
2011-11-11 05:50:40 ——– d—–w- c:\docume~1\alluse~1\applic~1\Babylon
2011-11-06 01:14:38 ——– d—–w- c:\program files\FunnyGames
2011-11-05 04:48:29 ——– d—–w- c:\program files\A_Free_Ride_Games_Bar
2011-11-05 04:48:11 ——– d—–w- C:\Remote Programs
2011-11-05 04:47:54 ——– d—–w- c:\docume~1\alluse~1\applic~1\Free Ride Games
2011-11-05 04:47:46 53314 ——w- c:\windows\ExentInfo.exe
2011-11-05 04:47:44 ——– d—–w- c:\program files\Free Ride Games
2011-11-03 17:09:26 94720 —-a-w- c:\docume~1\alluse~1\applic~1\KeyboardBackupManager.dll
2011-11-01 02:10:04 ——– d—–w- c:\program files\Bohemia Interactive
.
==================== Find3M ====================
.
2011-10-25 08:07:23 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-09-23 22:02:58 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 11:37:45.84 ===============

Attachments:

Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

It looks as if you have the ZeroAccess Rootkit on your system. It is an extremely nasty piece of malware that may take quite some time to remove depending on how it has infected your system. During the cleaning (if you choose to do so) you may even lose your internet access.

If you would like to format and reinstall your Operating System please let me know and I can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-

If you choose to continue, please post the logs created by TDSSKiller and ComboFix. :)
Hi Jeff, thanks for your help. I've decided to go ahead and press forward on getting this issue fixed. I want reinstall to be the last resort. I ran the tdsskiller and when the system was rebooted, I went back into safe mode and it got hung up on loading drivers/files. I rebooted again and the file scan came on and after it finished it booted into windows(not safe mode) but the ps/2 mouse and keyboard doesn't work anymore. I'm now using a usb mouse and keyboard. Needed files: 05:44:14.0593 0516 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 05:44:16.0609 0516 ============================================================ 05:44:16.0609 0516 Current date / time: 2011/12/01 05:44:16.0609 05:44:16.0609 0516 SystemInfo: 05:44:16.0609 0516 05:44:16.0609 0516 OS Version: 5.1.2600 ServicePack: 3.0 05:44:16.0609 0516 Product type: Workstation 05:44:16.0609 0516 ComputerName: DEAM 05:44:16.0609 0516 UserName: Administrator 05:44:16.0609 0516 Windows directory: C:\WINDOWS 05:44:16.0609 0516 System windows directory: C:\WINDOWS 05:44:16.0609 0516 Processor architecture: Intel x86 05:44:16.0609 0516 Number of processors: 2 05:44:16.0609 0516 Page size: 0x1000 05:44:16.0609 0516 Boot type: Safe boot with network 05:44:16.0609 0516 ============================================================ 05:44:19.0109 0516 Initialize success 05:44:31.0687 1812 ============================================================ 05:44:31.0687 1812 Scan started 05:44:31.0687 1812 Mode: Manual; 05:44:31.0687 1812 ============================================================ 05:44:34.0390 1812 Abiosdsk - ok 05:44:34.0468 1812 abp480n5 - ok 05:44:34.0593 1812 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 05:44:34.0609 1812 ACPI - ok 05:44:34.0687 1812 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 05:44:34.0703 1812 ACPIEC - ok 05:44:34.0750 1812 adpu160m - ok 05:44:34.0953 1812 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 05:44:34.0953 1812 aec - ok 05:44:35.0062 1812 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 05:44:35.0078 1812 AFD - ok 05:44:35.0140 1812 Aha154x - ok 05:44:35.0171 1812 aic78u2 - ok 05:44:35.0234 1812 aic78xx - ok 05:44:35.0390 1812 AliIde - ok 05:44:35.0421 1812 amsint - ok 05:44:35.0531 1812 asc - ok 05:44:35.0640 1812 asc3350p - ok 05:44:35.0718 1812 asc3550 - ok 05:44:35.0890 1812 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 05:44:35.0890 1812 AsyncMac - ok 05:44:36.0031 1812 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 05:44:36.0031 1812 atapi - ok 05:44:36.0062 1812 Atdisk - ok 05:44:36.0125 1812 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 05:44:36.0125 1812 Atmarpc - ok 05:44:36.0234 1812 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 05:44:36.0234 1812 audstub - ok 05:44:36.0421 1812 AVGIDSDriver (2d18221aab3db2d408d6c55c0f23090a) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 05:44:36.0421 1812 AVGIDSDriver - ok 05:44:36.0484 1812 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 05:44:36.0484 1812 AVGIDSEH - ok 05:44:36.0625 1812 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 05:44:36.0625 1812 AVGIDSFilter - ok 05:44:36.0734 1812 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 05:44:36.0734 1812 AVGIDSShim - ok 05:44:36.0812 1812 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 05:44:36.0828 1812 Avgldx86 - ok 05:44:36.0859 1812 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 05:44:36.0859 1812 Avgmfx86 - ok 05:44:36.0906 1812 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 05:44:36.0906 1812 Avgrkx86 - ok 05:44:36.0984 1812 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 05:44:36.0984 1812 Avgtdix - ok 05:44:37.0125 1812 BANTExt (5d7be7b19e827125e016325334e58ff1) C:\WINDOWS\System32\Drivers\BANTExt.sys 05:44:37.0125 1812 BANTExt - ok 05:44:37.0187 1812 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 05:44:37.0203 1812 Beep - ok 05:44:37.0281 1812 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 05:44:37.0296 1812 Bridge - ok 05:44:37.0312 1812 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 05:44:37.0312 1812 BridgeMP - ok 05:44:37.0375 1812 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 05:44:37.0375 1812 cbidf2k - ok 05:44:37.0421 1812 cd20xrnt - ok 05:44:37.0468 1812 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 05:44:37.0484 1812 Cdaudio - ok 05:44:37.0515 1812 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 05:44:37.0515 1812 Cdfs - ok 05:44:37.0562 1812 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 05:44:37.0578 1812 Cdrom - ok 05:44:37.0593 1812 Changer - ok 05:44:37.0734 1812 CmdIde - ok 05:44:37.0890 1812 Cpqarray - ok 05:44:37.0953 1812 cpuz132 - ok 05:44:38.0109 1812 ctsfm2k (8db84de3aab34a8b4c2f644eff41cd76) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys 05:44:38.0125 1812 ctsfm2k - ok 05:44:38.0156 1812 dac2w2k - ok 05:44:38.0187 1812 dac960nt - ok 05:44:38.0328 1812 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 05:44:38.0328 1812 Disk - ok 05:44:38.0453 1812 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 05:44:38.0515 1812 dmboot - ok 05:44:38.0578 1812 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys 05:44:38.0578 1812 dmio - ok 05:44:38.0625 1812 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 05:44:38.0625 1812 dmload - ok 05:44:38.0734 1812 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 05:44:38.0750 1812 DMusic - ok 05:44:38.0828 1812 dpti2o - ok 05:44:38.0906 1812 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 05:44:38.0921 1812 drmkaud - ok 05:44:39.0156 1812 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 05:44:39.0156 1812 Fastfat - ok 05:44:39.0234 1812 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 05:44:39.0234 1812 Fdc - ok 05:44:39.0328 1812 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 05:44:39.0328 1812 Fips - ok 05:44:39.0390 1812 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 05:44:39.0390 1812 Flpydisk - ok 05:44:39.0531 1812 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 05:44:39.0531 1812 FltMgr - ok 05:44:39.0609 1812 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 05:44:39.0609 1812 fssfltr - ok 05:44:39.0687 1812 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 05:44:39.0687 1812 Fs_Rec - ok 05:44:39.0796 1812 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 05:44:39.0796 1812 Ftdisk - ok 05:44:39.0875 1812 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 05:44:39.0875 1812 GEARAspiWDM - ok 05:44:40.0031 1812 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 05:44:40.0031 1812 Gpc - ok 05:44:40.0125 1812 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 05:44:40.0140 1812 HDAudBus - ok 05:44:40.0234 1812 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 05:44:40.0234 1812 hidusb - ok 05:44:40.0281 1812 hpn - ok 05:44:40.0390 1812 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 05:44:40.0406 1812 HPZid412 - ok 05:44:40.0468 1812 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 05:44:40.0468 1812 HPZipr12 - ok 05:44:40.0546 1812 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 05:44:40.0546 1812 HPZius12 - ok 05:44:40.0671 1812 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 05:44:40.0687 1812 HTTP - ok 05:44:40.0734 1812 i2omgmt - ok 05:44:40.0843 1812 i2omp - ok 05:44:40.0984 1812 i8042prt (b0ad251c92ce81039dc88b291a1d33e6) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 05:44:41.0000 1812 i8042prt ( Rootkit.Win32.ZAccess.k ) - infected 05:44:41.0000 1812 i8042prt - detected Rootkit.Win32.ZAccess.k (0) 05:44:41.0078 1812 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 05:44:41.0078 1812 Imapi - ok 05:44:41.0156 1812 ini910u - ok 05:44:41.0203 1812 IntelIde - ok 05:44:41.0296 1812 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 05:44:41.0296 1812 intelppm - ok 05:44:41.0343 1812 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 05:44:41.0343 1812 Ip6Fw - ok 05:44:41.0390 1812 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 05:44:41.0390 1812 IpFilterDriver - ok 05:44:41.0421 1812 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 05:44:41.0421 1812 IpInIp - ok 05:44:41.0484 1812 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 05:44:41.0484 1812 IpNat - ok 05:44:41.0515 1812 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 05:44:41.0515 1812 IPSec - ok 05:44:41.0578 1812 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 05:44:41.0578 1812 IRENUM - ok 05:44:41.0656 1812 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 05:44:41.0656 1812 isapnp - ok 05:44:41.0734 1812 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 05:44:41.0734 1812 Kbdclass - ok 05:44:41.0828 1812 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 05:44:41.0828 1812 kbdhid - ok 05:44:41.0890 1812 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 05:44:41.0906 1812 kmixer - ok 05:44:41.0953 1812 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 05:44:41.0953 1812 KSecDD - ok 05:44:42.0109 1812 lbrtfdc - ok 05:44:42.0718 1812 libusb0 (03e12dbfacf1aeb86c553b0db488fb81) C:\WINDOWS\system32\drivers\libusb0.sys 05:44:42.0718 1812 libusb0 - ok 05:44:42.0828 1812 MCSTRM - ok 05:44:42.0937 1812 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 05:44:42.0937 1812 mnmdd - ok 05:44:43.0031 1812 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 05:44:43.0046 1812 Modem - ok 05:44:43.0109 1812 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 05:44:43.0109 1812 Mouclass - ok 05:44:43.0171 1812 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 05:44:43.0171 1812 mouhid - ok 05:44:43.0265 1812 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 05:44:43.0265 1812 MountMgr - ok 05:44:43.0343 1812 mraid35x - ok 05:44:43.0437 1812 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 05:44:43.0437 1812 MRxDAV - ok 05:44:43.0484 1812 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 05:44:43.0500 1812 MRxSmb - ok 05:44:43.0562 1812 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 05:44:43.0562 1812 Msfs - ok 05:44:43.0656 1812 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 05:44:43.0656 1812 MSKSSRV - ok 05:44:43.0703 1812 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 05:44:43.0703 1812 MSPCLOCK - ok 05:44:43.0734 1812 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 05:44:43.0734 1812 MSPQM - ok 05:44:43.0812 1812 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 05:44:43.0812 1812 mssmbios - ok 05:44:43.0843 1812 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 05:44:43.0843 1812 Mup - ok 05:44:44.0000 1812 N3AB (0bb59b42cf3431d55a0bfbb5d7f77ee5) C:\WINDOWS\system32\DRIVERS\N3AB.sys 05:44:44.0000 1812 N3AB - ok 05:44:44.0265 1812 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 05:44:44.0265 1812 NDIS - ok 05:44:44.0390 1812 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 05:44:44.0390 1812 NdisTapi - ok 05:44:44.0453 1812 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 05:44:44.0468 1812 Ndisuio - ok 05:44:44.0531 1812 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 05:44:44.0531 1812 NdisWan - ok 05:44:44.0609 1812 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 05:44:44.0609 1812 NDProxy - ok 05:44:44.0640 1812 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 05:44:44.0640 1812 NetBIOS - ok 05:44:44.0750 1812 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 05:44:44.0750 1812 NetBT - ok 05:44:45.0109 1812 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys 05:44:45.0109 1812 NPF - ok 05:44:45.0171 1812 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 05:44:45.0171 1812 Npfs - ok 05:44:45.0312 1812 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 05:44:45.0328 1812 Ntfs - ok 05:44:45.0468 1812 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 05:44:45.0468 1812 Null - ok 05:44:45.0937 1812 nv (f1de35c89d98a883d1b4030dc9896855) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 05:44:46.0328 1812 nv - ok 05:44:46.0406 1812 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 05:44:46.0406 1812 NwlnkFlt - ok 05:44:46.0453 1812 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 05:44:46.0468 1812 NwlnkFwd - ok 05:44:46.0546 1812 ossrv (103a9b117a7d9903111955cdafe65ac6) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys 05:44:46.0546 1812 ossrv - ok 05:44:46.0671 1812 P17 (df886ffed69aead0cf608b89b18c3f6f) C:\WINDOWS\system32\drivers\P17.sys 05:44:46.0703 1812 P17 - ok 05:44:46.0765 1812 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 05:44:46.0765 1812 Parport - ok 05:44:46.0828 1812 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 05:44:46.0828 1812 PartMgr - ok 05:44:46.0921 1812 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 05:44:46.0921 1812 ParVdm - ok 05:44:46.0968 1812 pavboot (3adb8bd6154a3ef87496e8fce9c22493) C:\WINDOWS\system32\drivers\pavboot.sys 05:44:46.0968 1812 pavboot - ok 05:44:47.0062 1812 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 05:44:47.0078 1812 PCI - ok 05:44:47.0109 1812 PCIDump - ok 05:44:47.0171 1812 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 05:44:47.0171 1812 PCIIde - ok 05:44:47.0234 1812 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 05:44:47.0250 1812 Pcmcia - ok 05:44:47.0328 1812 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys 05:44:47.0328 1812 pcouffin - ok 05:44:47.0375 1812 PCTCore (d302a59e6d1842a201930928a5bad68b) C:\WINDOWS\system32\drivers\PCTCore.sys 05:44:47.0390 1812 PCTCore - ok 05:44:47.0453 1812 PDCOMP - ok 05:44:47.0546 1812 PDFRAME - ok 05:44:47.0578 1812 PDRELI - ok 05:44:47.0625 1812 PDRFRAME - ok 05:44:47.0656 1812 perc2 - ok 05:44:47.0703 1812 perc2hib - ok 05:44:47.0953 1812 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 05:44:47.0953 1812 PptpMiniport - ok 05:44:48.0046 1812 prodrv06 (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys 05:44:48.0046 1812 prodrv06 - ok 05:44:48.0093 1812 prohlp02 (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys 05:44:48.0093 1812 prohlp02 - ok 05:44:48.0203 1812 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys 05:44:48.0203 1812 prosync1 - ok 05:44:48.0250 1812 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 05:44:48.0250 1812 PSched - ok 05:44:48.0312 1812 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 05:44:48.0312 1812 Ptilink - ok 05:44:48.0406 1812 ql1080 - ok 05:44:48.0453 1812 Ql10wnt - ok 05:44:48.0531 1812 ql12160 - ok 05:44:48.0609 1812 ql1240 - ok 05:44:48.0671 1812 ql1280 - ok 05:44:48.0828 1812 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 05:44:48.0828 1812 RasAcd - ok 05:44:48.0921 1812 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 05:44:48.0921 1812 Rasl2tp - ok 05:44:48.0984 1812 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 05:44:48.0984 1812 RasPppoe - ok 05:44:49.0046 1812 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 05:44:49.0046 1812 Raspti - ok 05:44:49.0156 1812 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 05:44:49.0156 1812 Rdbss - ok 05:44:49.0218 1812 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 05:44:49.0218 1812 RDPCDD - ok 05:44:49.0296 1812 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 05:44:49.0296 1812 rdpdr - ok 05:44:49.0375 1812 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 05:44:49.0375 1812 RDPWD - ok 05:44:49.0453 1812 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 05:44:49.0453 1812 redbook - ok 05:44:49.0656 1812 rt2870 (b10c0cea067240b6741cc7862f63d2fd) C:\WINDOWS\system32\DRIVERS\rt2870.sys 05:44:49.0671 1812 rt2870 - ok 05:44:49.0703 1812 RTL8023xp (cf84b1f0e8b14d4120aaf9cf35cbb265) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 05:44:49.0703 1812 RTL8023xp - ok 05:44:49.0828 1812 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 05:44:49.0828 1812 rtl8139 - ok 05:44:49.0890 1812 SaiH075C (de7a2fc379671998865122a08fd9db52) C:\WINDOWS\system32\DRIVERS\SaiH075C.sys 05:44:49.0890 1812 SaiH075C - ok 05:44:50.0046 1812 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 05:44:50.0046 1812 SASDIFSV - ok 05:44:50.0093 1812 SASENUM (a22f08c98ac2f44587bf3a1fb52bf8cd) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS 05:44:50.0093 1812 SASENUM - ok 05:44:50.0156 1812 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 05:44:50.0156 1812 SASKUTIL - ok 05:44:50.0296 1812 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) C:\WINDOWS\system32\DRIVERS\secdrv.sys 05:44:50.0296 1812 Secdrv - ok 05:44:50.0437 1812 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 05:44:50.0437 1812 serenum - ok 05:44:50.0468 1812 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 05:44:50.0484 1812 Serial - ok 05:44:50.0578 1812 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys 05:44:50.0578 1812 sfhlp01 - ok 05:44:50.0625 1812 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 05:44:50.0625 1812 Sfloppy - ok 05:44:50.0734 1812 silabenm (c16173316918a1360dc22947c4ff6352) C:\WINDOWS\system32\DRIVERS\silabenm.sys 05:44:50.0750 1812 silabenm - ok 05:44:50.0781 1812 silabser (093c31ec727ecbcbe38992fc69657594) C:\WINDOWS\system32\DRIVERS\silabser.sys 05:44:50.0781 1812 silabser - ok 05:44:50.0828 1812 Simbad - ok 05:44:50.0937 1812 Sparrow - ok 05:44:51.0015 1812 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 05:44:51.0015 1812 splitter - ok 05:44:51.0093 1812 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 05:44:51.0109 1812 sr - ok 05:44:51.0218 1812 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 05:44:51.0234 1812 Srv - ok 05:44:51.0359 1812 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 05:44:51.0359 1812 swenum - ok 05:44:51.0406 1812 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 05:44:51.0406 1812 swmidi - ok 05:44:51.0515 1812 symc810 - ok 05:44:51.0546 1812 symc8xx - ok 05:44:51.0593 1812 sym_hi - ok 05:44:51.0640 1812 sym_u3 - ok 05:44:51.0734 1812 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 05:44:51.0734 1812 sysaudio - ok 05:44:51.0843 1812 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 05:44:51.0875 1812 Tcpip - ok 05:44:51.0921 1812 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 05:44:51.0937 1812 TDPIPE - ok 05:44:52.0031 1812 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 05:44:52.0046 1812 TDTCP - ok 05:44:52.0093 1812 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 05:44:52.0109 1812 TermDD - ok 05:44:52.0187 1812 TosIde - ok 05:44:52.0281 1812 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 05:44:52.0281 1812 Udfs - ok 05:44:52.0406 1812 ultra - ok 05:44:52.0453 1812 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 05:44:52.0468 1812 Update - ok 05:44:52.0593 1812 USBAAPL - ok 05:44:52.0718 1812 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 05:44:52.0718 1812 usbaudio - ok 05:44:52.0781 1812 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 05:44:52.0781 1812 usbccgp - ok 05:44:52.0828 1812 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 05:44:52.0843 1812 usbehci - ok 05:44:52.0875 1812 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 05:44:52.0875 1812 usbhub - ok 05:44:52.0968 1812 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 05:44:52.0968 1812 usbohci - ok 05:44:53.0031 1812 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 05:44:53.0031 1812 usbprint - ok 05:44:53.0062 1812 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 05:44:53.0062 1812 usbscan - ok 05:44:53.0171 1812 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 05:44:53.0171 1812 USBSTOR - ok 05:44:53.0218 1812 VBoxNetAdp (4529f598bf8c8dbeda96be6ae5991c4a) C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys 05:44:53.0234 1812 VBoxNetAdp - ok 05:44:53.0250 1812 VBoxNetFlt - ok 05:44:53.0375 1812 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 05:44:53.0375 1812 VgaSave - ok 05:44:53.0437 1812 ViaIde - ok 05:44:53.0484 1812 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 05:44:53.0484 1812 VolSnap - ok 05:44:53.0656 1812 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 05:44:53.0656 1812 Wanarp - ok 05:44:53.0781 1812 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 05:44:53.0796 1812 Wdf01000 - ok 05:44:53.0812 1812 WDICA - ok 05:44:53.0875 1812 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 05:44:53.0875 1812 wdmaud - ok 05:44:54.0078 1812 WmBEnum (84a90f13eebf4380345ef9474d30f10e) C:\WINDOWS\system32\drivers\WmBEnum.sys 05:44:54.0078 1812 WmBEnum - ok 05:44:54.0156 1812 WmFilter (eb0034ac02a44dc784a3174d2b81e764) C:\WINDOWS\system32\drivers\WmFilter.sys 05:44:54.0156 1812 WmFilter - ok 05:44:54.0187 1812 WmHidLo (31d2906d59f127654964be334b615720) C:\WINDOWS\system32\drivers\WmHidLo.sys 05:44:54.0187 1812 WmHidLo - ok 05:44:54.0312 1812 WmVirHid (72c4f5a748c74d8d4016ccfa7367210f) C:\WINDOWS\system32\drivers\WmVirHid.sys 05:44:54.0312 1812 WmVirHid - ok 05:44:54.0359 1812 WmXlCore (eacdcced934a185e61ce0684f71c2dec) C:\WINDOWS\system32\drivers\WmXlCore.sys 05:44:54.0359 1812 WmXlCore - ok 05:44:54.0421 1812 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 05:44:54.0484 1812 WpdUsb - ok 05:44:54.0546 1812 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 05:44:54.0562 1812 WS2IFSL - ok 05:44:54.0687 1812 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 05:44:54.0687 1812 WudfPf - ok 05:44:54.0718 1812 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 05:44:54.0734 1812 WudfRd - ok 05:44:54.0890 1812 X4HSEx (332da0c7126c830aef0cad85cc5286a2) C:\Program Files\Free Ride Games\X4HSEx.Sys 05:44:54.0890 1812 X4HSEx - ok 05:44:55.0140 1812 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 05:44:55.0312 1812 \Device\Harddisk0\DR0 - ok 05:44:55.0343 1812 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR2 05:44:56.0343 1812 \Device\Harddisk1\DR2 - ok 05:44:56.0359 1812 Boot (0x1200) (f926653c38f5e7cf6a08e058c59b7ae9) \Device\Harddisk0\DR0\Partition0 05:44:56.0359 1812 \Device\Harddisk0\DR0\Partition0 - ok 05:44:56.0406 1812 Boot (0x1200) (0863b260de3e0fca9388664a2fbd6c57) \Device\Harddisk1\DR2\Partition0 05:44:56.0406 1812 \Device\Harddisk1\DR2\Partition0 - ok 05:44:56.0421 1812 ============================================================ 05:44:56.0421 1812 Scan finished 05:44:56.0421 1812 ============================================================ 05:44:56.0484 1912 Detected object count: 1 05:44:56.0484 1912 Actual detected object count: 1 05:46:19.0687 1912 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\i8042prt.sys) error 1813 05:46:25.0546 1912 Backup copy found, using it.. 05:46:25.0562 1912 C:\WINDOWS\system32\DRIVERS\i8042prt.sys - will be cured on reboot 05:46:29.0421 1912 i8042prt ( Rootkit.Win32.ZAccess.k ) - User select action: Cure 05:47:21.0359 0524 Deinitialize success

Attachments:

Hi Wicked Kitt_E,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DDS::
     mStart Page = hxxp://home.sweetim.com
     uInternet Settings,ProxyOverride = ;*.local
     uInternet Settings,ProxyServer = http=127.0.0.1:5643
     IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
     BHO: MyWebSearch Search Assistant BHO: {00a6faf1-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL
     BHO: mwsBar BHO: {07b18ea1-a523-4961-b6bb-170de4475cca} - c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL
     BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - c:\program files\pricegong\2.5.0\PriceGongIE.dll
     BHO: PlaySushi: {21608b66-026f-4dcb-9244-0daca328dced} - c:\program files\playsushi\PSText.dll
     BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.4.35.10\bh\BabylonToolbar.dll
     BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
     BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
     BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - c:\program files\startnow toolbar\Toolbar32.dll
     BHO: AdventureQuest Worlds Toolbar BHO: {745a6d3b-4db0-4246-b596-9189787d4ed5} - c:\program files\adventurequest worlds toolbar\Toolbar.dll
     BHO: IncrediMail MediaBar 4 Toolbar: {90eee664-34b1-422a-a782-779af65cdf6d} - c:\program files\incredimail_mediabar_4\prxtbInc0.dll
     BHO: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\prxtbPage.dll
     BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
     BHO: Softonic Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
     BHO: SweetIM Toolbar Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
     BHO: A Free Ride Games Bar Toolbar: {f92a9fe4-2850-4198-b9d5-279880e49b16} - c:\program files\a_free_ride_games_bar\prxtbA_Fr.dll
     TB: My Web Search: {07b18ea9-a523-4961-b6bb-170de4475cca} - c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL
     TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - c:\program files\facemoods.com\facemoods\1.4.17.10\facemoodsTlbr.dll
     TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll
     TB: AdventureQuest Worlds Toolbar: {3385e2d6-567b-4fc6-8f0f-d7a8c6e6118c} - c:\program files\adventurequest worlds toolbar\Toolbar.dll
     TB: Softonic Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
     TB: IncrediMail MediaBar 4 Toolbar: {90eee664-34b1-422a-a782-779af65cdf6d} - c:\program files\incredimail_mediabar_4\prxtbInc0.dll
     TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
     TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
     TB: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\prxtbPage.dll
     TB: A Free Ride Games Bar Toolbar: {f92a9fe4-2850-4198-b9d5-279880e49b16} - c:\program files\a_free_ride_games_bar\prxtbA_Fr.dll
     TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - c:\program files\startnow toolbar\Toolbar32.dll
     TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.4.35.10\BabylonToolbarTlbr.dll
     mRun: [My Web Search Bar Search Scope Monitor] "c:\progra~1\mywebs~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
     IE: &Search - http://edits.mywebsearch.com/toolbaredits/…mp;n=2011050817
     
     Firefox::
     FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\gn7nuhve.default\
     FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm593YYUS&ptb=yFNr5NpMFZ7vV0qkXYavEQ&ind=2011050817&ptnrS=ZUxdm593YYUS&si=&n=77de3341&psa=&st=kwd&searchfor=
     FF - plugin: c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL
     
     File::
     c:\windows\system32\ConduitEngine.tmp
     c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
     c:\program files\AdventureQuest Worlds Toolbar\Toolbar.dll
      c:\program files\Ask.com\GenericAskToolbar.dll
      c:\program files\IncrediMail_MediaBar_4\prxtbInc0.dll
      c:\program files\ConduitEngine\prxConduitEngine.dll
      c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
      c:\program files\PageRage\prxtbPage.dll
      c:\program files\A_Free_Ride_Games_Bar\prxtbA_Fr.dll
     c:\windows\system32\drivers\05507009.sys
     c:\windows\system32\drivers\i8042prt.sys
     
     Folder::
     c:\documents and settings\Deano-Casino\Application Data\BabylonToolbar
     c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar
     c:\program files\BabylonToolbar
     c:\documents and settings\All Users\Application Data\Babylon
     c:\program files\A_Free_Ride_Games_Bar
     c:\documents and settings\All Users\Application Data\Free Ride Games
     c:\program files\Free Ride Games
     
     Registry::
     [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
     "{EEE6C35D-6118-11DC-9C72-001320C79847}"=-
     [-HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
     [-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
     [-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
     [-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
     [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
     "{3385E2D6-567B-4FC6-8F0F-D7A8C6E6118C}"=-
     "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
     "{90eee664-34b1-422a-a782-779af65cdf6d}"=-
     "{30F9B915-B755-4826-820B-08FBA6BD249D}"=-
     "{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
     "{9565115d-c7d6-46d3-bd63-b67b481a4368}"=-
     "{f92a9fe4-2850-4198-b9d5-279880e49b16}"=-
     [-HKEY_CLASSES_ROOT\clsid\{3385e2d6-567b-4fc6-8f0f-d7a8c6e6118c}]
     [-HKEY_CLASSES_ROOT\FCTB000059925.IEToolbar.1]
     [-HKEY_CLASSES_ROOT\TypeLib\{C14DB733-609C-4DAA-9CC5-8ED0CA2FE093}]
     [-HKEY_CLASSES_ROOT\FCTB000059925.IEToolbar]
     [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
     [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
     [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
     [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
     [-HKEY_CLASSES_ROOT\clsid\{90eee664-34b1-422a-a782-779af65cdf6d}]
     [-HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
     [-HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
     [-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
     [-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
     [-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
     [-HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
     [-HKEY_CLASSES_ROOT\clsid\{f92a9fe4-2850-4198-b9d5-279880e49b16}]
     [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
     "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
     "{3385E2D6-567B-4FC6-8F0F-D7A8C6E6118C}"=-
     "{90EEE664-34B1-422A-A782-779AF65CDF6D}"=-
     "{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
     "{9565115D-C7D6-46D3-BD63-B67B481A4368}"=-
     "{F92A9FE4-2850-4198-B9D5-279880E49B16}"=-
     [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
     [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
     [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
     [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
     [-HKEY_CLASSES_ROOT\clsid\{3385e2d6-567b-4fc6-8f0f-d7a8c6e6118c}]
     [-HKEY_CLASSES_ROOT\FCTB000059925.IEToolbar.1]
     [-HKEY_CLASSES_ROOT\TypeLib\{C14DB733-609C-4DAA-9CC5-8ED0CA2FE093}]
     [-HKEY_CLASSES_ROOT\FCTB000059925.IEToolbar]
     [-HKEY_CLASSES_ROOT\clsid\{90eee664-34b1-422a-a782-779af65cdf6d}]
     [-HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
     [-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
     [-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
     [-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
     [-HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
     [-HKEY_CLASSES_ROOT\clsid\{f92a9fe4-2850-4198-b9d5-279880e49b16}]
     [-HKLM\~\startupfolder\C:^Documents and Settings^The Crew.DEAM^Start Menu^Programs^Startup^Launch WhiteSmoke.lnk]
     [-HKLM\~\startupfolder\C:^Documents and Settings^The Crew.DEAM^Start Menu^Programs^Startup^Zentom System Guard.lnk]
     [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
     [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
     "MyWebSearchService"=-
     
     Driver::
     97179484
     i8042prt
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Here is the file that you requested:

ComboFix 11-12-01.03 - Deano-Casino 12/01/2011 21:15:04.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.185 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\program files\A_Free_Ride_Games_Bar\prxtbA_Fr.dll"
"c:\program files\AdventureQuest Worlds Toolbar\Toolbar.dll"
"c:\program files\Ask.com\GenericAskToolbar.dll"
"c:\program files\ConduitEngine\prxConduitEngine.dll"
"c:\program files\IncrediMail_MediaBar_4\prxtbInc0.dll"
"c:\program files\PageRage\prxtbPage.dll"
"c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll"
"c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll"
"c:\windows\system32\ConduitEngine.tmp"
"c:\windows\system32\drivers\05507009.sys"
"c:\windows\system32\drivers\i8042prt.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Babylon
c:\documents and settings\All Users\Application Data\Free Ride Games
c:\documents and settings\All Users\Application Data\Free Ride Games\data1.cab
c:\documents and settings\All Users\Application Data\Free Ride Games\data1.hdr
c:\documents and settings\All Users\Application Data\Free Ride Games\data2.cab
c:\documents and settings\All Users\Application Data\Free Ride Games\ExentCtl.ocx
c:\documents and settings\All Users\Application Data\Free Ride Games\exs.dll
c:\documents and settings\All Users\Application Data\Free Ride Games\FRGN.ico
c:\documents and settings\All Users\Application Data\Free Ride Games\ikernel.ex_
c:\documents and settings\All Users\Application Data\Free Ride Games\layout.bin
c:\documents and settings\All Users\Application Data\Free Ride Games\Setup.exe
c:\documents and settings\All Users\Application Data\Free Ride Games\Setup.ini
c:\documents and settings\All Users\Application Data\Free Ride Games\setup.inx
c:\documents and settings\All Users\Application Data\Free Ride Games\setup.iss
c:\documents and settings\All Users\Application Data\Free Ride Games\setup.log
c:\documents and settings\Deano-Casino\Application Data\BabylonToolbar
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633505278667031250_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633505279274062500_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633505280436718750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633505280910468750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633512195508425000_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633513173263837500_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633548316810068750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633692396709800000_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633692398362925000_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633692398554800000_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633692410316850000_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633692911412006250_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633807547520418750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633812016392337500_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633812021264681250_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633813749187493750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633813749293743750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633860353313606250_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633921623893106250_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633940691023706250_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633940749801987500_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633940749924956250_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633940750261987500_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633940750377143750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633940750491518750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_633940750612143750_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634006360000625000_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634018491814843750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634018492235937500_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634028170114523750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369197391593750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369197613312500_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369197820656250_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369198824250000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369199593000000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369200847843750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369202462018750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369204696706250_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369206142643750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369207191550000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369208167800000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369211018893750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369211935143750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369213702331250_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369215049237500_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369216785800000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369217671268750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369219614393750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369222840643750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369224648925000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369226026850000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369227239506250_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369228110443750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369229078256250_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369233899818750_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369234911225000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369235851225000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369237345600000_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369238656481250_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634369239550856250_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_634428733460245053_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467706420398372_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467707540326692_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467709871925507_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467711008044197_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467737734663870_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467739937336340_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467742214992158_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467743057251062_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467743716817404_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467749551953574_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467750409515800_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467751125373366_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467751586475056_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467753091571912_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467753528336730_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467754279273768_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467755186437508_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467756016480230_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467756795559554_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467757588669746_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467758988091656_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467759515079411_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467760277989566_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634467760984458021_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468390879392763_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468391550053281_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468392501212851_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468393156989985_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468393975234295_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468396724470721_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468397534511591_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468398285585353_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468400625528719_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468401409133027_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468401999770941_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468402691652977_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468405709639954_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468406271643956_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468406977374180_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468407668113594_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468408435652832_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468409118247402_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468409922584928_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468410577043652_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634468411217546762_16PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634557396889312501_24PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_images_634557687537112501_24PX_
png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_80_132_CT1320680_Images_Buttons2_xml-16-Gadgets-634031267804680000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_Bsilkset_house_go_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.p
ng
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.
png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png
.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.pn
g
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_pn
g.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.pn
g
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPub
lisher_png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png
.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png
.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png
.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png
.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_bankimages_iconsGallery_24_4873958610687078792_p
ng.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_bankimages_iconsGallery_24_4936694050736281480_p
ng.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_bankimages_iconsGallery_24_5127008798017327137_p
ng.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_bankimages_iconsGallery_24_5282727194955988626_p
ng.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_bankimages_iconsGallery_24_5603729215823178696_p
ng.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_calc
_jpg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_calo
ries_jpg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_conv
erter_jpg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_ip_j
pg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_note
s_jpg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_todo
_jpg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_tv_j
pg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_PreDefinedComponents_GadgetsMenu_wiki
_jpg_gif_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_chevron_menu_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_chevron_play_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_chevron_stop_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_display_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_Equalizer_GIF.GIF
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_Error_GIF.GIF
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_idel_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_Loading_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_maxi_dn_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_maxi_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_maxi_over_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_minimize_dn_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_minimize_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_minimize_over_gif.gi
f
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_pause_dn_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_pause_dn_mini_gif.gi
f
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_pause_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_pause_mini_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_pause_over_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_pause_over_mini_gif.
gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_play_dn_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_play_dn_mini_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_play_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_play_mini_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_play_over_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_play_over_mini_gif.g
if
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_slider_bg_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_slider_dn_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_slider_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_slider_over_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_stop_dn_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_stop_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_stop_over_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_vol_dn_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_vol_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_BankImages_RadioSkins_Tapuz_vol_over_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_ClientImages_radio_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_about_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_clear_history_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_contact_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_help_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_home_page_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_options_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_privacy_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_refresh_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_shrink_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_main_menu_upgrade_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_SearchEngines_images_search_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_SearchEngines_news_icon_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_searchengines_softonic_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_SearchEngines_tfd_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_images_SearchEngines_video_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_4bd_58786575-7deb-474a-9b29-5b95e08a44bd_Appearance_634045350172025004_png.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633856984376962500_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633856984876650000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633856985375243750_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633856986143525000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633856986997900000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633933748873500000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935574711218750_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935576227156250_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935577047625000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935581035437500_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935583214656250_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935584531375000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935586029343750_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935587183875000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935591890125000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935593154968750_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935594921843750_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935596098250000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935598941687500_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935606579968750_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633935607113250000_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___storage_conduit_com_MarketPlace_58_bd_58786575-7deb-474a-9b29-5b95e08a44bd_Images_633937212165118750_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\CacheIcons\http___weather_conduit_com_images_weather_Default_partly_cloudy_gif.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\AddedAppDialog\app-added.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\AddedAppDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\DefualtImages\icon.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\DetectedAppDialog\app-2go.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\DetectedAppDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\DialogsAPI.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\EngineFirstTimeDialog\EngineFirstTimeDialog.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\EngineFirstTimeDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\EngineFirstTimeDialog\right-click.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\excanvas.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\generalDialogStyle.css
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\NewSearchProtectorDialog\images\ok-button.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\NewSearchProtectorDialog\images\separation-line.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\NewSearchProtectorDialog\images\warning.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\NewSearchProtectorDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\NewSearchProtectorDialog\SearchProtector.css
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\NewSearchProtectorDialog\SearchProtector.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\PIE.htc
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\RoundedCorners.css
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\RoundedCornersIE9.css
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\bubble.css
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\bubble.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\images\information.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\images\x-default-LTR.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\images\x-default-RTL.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-LTR.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-RTL.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorBubbleDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorDialog\Images\info.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorDialog\Images\ok-on.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorDialog\Images\ok.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorDialog\SearchProtector.css
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\SearchProtectorDialog\SearchProtector.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\settings.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\app-store-icon.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\arrow.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\divider.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\emailNotifier.gif
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\facebook.png
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\radio.GIF
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\Thumbs.db
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\truste_welcome.GIF
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\images\weather.GIF
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.css
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarUntrustedAppsApprovalDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\ToolbarUntrustedAppsApprovalDialog\ToolbarUntrustedAppsApprovalDialog.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\UntrustedAddedAppDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\UntrustedAddedAppDialog\UT-app-dialog-added.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\UntrustedAppApprovalDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\UntrustedAppApprovalDialog\UT-app-dialog-needs-your-approval.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\UntrustedAppPendingDialog\main.html
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\UntrustedAppPendingDialog\UT-app-dialog-is-waiting.js
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Dialogs\version.txt
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\EmailNotifier\AccountTypes.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\EmailNotifier\aol.com.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\EmailNotifier\comcast.net.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\EmailNotifier\google.com.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\EmailNotifier\hotmail.com.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\EmailNotifier\yahoo.com.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=GottenApps&locale;=en.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=OtherApps&locale;=en.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=SharedApps&locale;=en.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=Toolbar&locale;=en.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\RadioPlayer\IP_Stations_Media_List.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\RadioPlayer\Predefined_Media_List.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Repository\conduit_CT1320680_CT1320680\AppsMetaData\data.bck.txt
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Repository\conduit_CT1320680_CT1320680\AppsMetaData\data.txt
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Repository\conduit_CT1320680_CT1320680\DynamicDialogs\data.txt
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Repository\conduit_CT1320680_CT1320680\ToolbarLogin\data.txt
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\Repository\conduit_CT1320680_CT1320680\ToolbarSettings\data.txt
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\SearchInNewTab\SearchInNewTabContent.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\tbA_Fr.dll
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\ThirdPartyComponents.xml
c:\documents and settings\Deano-Casino\Local Settings\Application Data\A_Free_Ride_Games_Bar\toolbar.cfg
c:\documents and settings\The Crew\Application Data\facemoods.com
c:\documents and settings\The Crew\Application Data\inst.exe
c:\documents and settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}
c:\documents and settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest
c:\documents and settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar
c:\documents and settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\defaults\preferences\xulcache.js
c:\documents and settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\install.rdf
c:\documents and settings\The Crew\Application Data\Toolbar4
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\07342a6755dee760339186a222929be2
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\1a9351a4bb94258aae1a132d1df6bbd6
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\27c746d432b7a753a0af8d7c033b46fe
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\2b4ad282984708f7b89800e17a257476
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\2cc60d08b36af576b11419505050cc6e
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\36edbd9cd1d972f7b815c3c429d9e778
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\392a700638f235a296b69d16949f5de4
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\44567846e0387d6a62062ab4dbf9ae96
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\476e581759e584c2c282de2998241067
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\52b66d6979ef2abcea9a736d1b4dbc82
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\757a20d7a75ae93435ac64a6095eab39
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\89c35566d3dfdce78572ff8c2a627ad2
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9840cd5f73490a37d4f3e47107ced675
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9d810aab3f7bcbacb07c241f8d726714
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\a2c186b67472c6e600e20a266c490399
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\a95eb0e6de33d7634932d4e6a0a8fcb1
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\ab175bcff5c73a195b31011921537077
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\acfc834035dccfb94e7f9067f5d48a83
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\b19a226e37d70388c09e79d59e928706
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\b60520640d82e970595e95ad6eed09a5
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\ba2b10a34ec5487830bcffd24e6ce6a6
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\bdcf0ed363b85538f740c9b718bf611c
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c0b9e89d52d9e1ff85c2db9f694af77d
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c3a959e6bb881e61278a5411610b65c8
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c594d37e13c887da6ddc9975fa9aae82
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\cc68743a659d204f1d8ed9e6ccf8ce9a
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\e13b2994352b9b3027a914debb087454
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\e6f9cd396acf3782de6615e7be7146d0
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\faeabe2383655e57bfe411d09932eca8
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\fc57bf3aee1b4ac0db547af3a4f4a1b1
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\3b963f6a344a956fcc0827519e6da290
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\458fd8e1e5cf59131216d5a9596dae20
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\59ce19cd4ac0c01d536c5755dc0838a6
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\6d9ede87120096fcf2f4d17f38be5819
c:\documents and settings\The Crew\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\e9310c650964ac7676cb41dcda03762e
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\background.html
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\cached_http_request.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\extension_info.json
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\icons\icon128.png
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\icons\icon19.png
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\icons\icon32.png
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\icons\icon48.png
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\includes\content.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\includes\content_kango.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\includes\content_messaging.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\includes\content_userscript.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango-ui\button.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango-ui\ui.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\browser.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\console.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\event_listener.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\initialize.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\io.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\jsonstorage.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\kango.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\lang.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\messaging.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\userscript_engine.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\kango\xhr.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\main.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\manifest.json
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\minibar\actions.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\minibar\cachedxhr.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\minibar\config.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\minibar\macros.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\minibar\minibar.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\popup.html
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\popup.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\tab.html
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome\tab.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\chrome_installer.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\common.js
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\install.json
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\minibar.crx
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\sqlite3.exe
c:\documents and settings\The Crew\Local Settings\Application Data\Minibar\Uninstall.exe
c:\program files\A_Free_Ride_Games_Bar
c:\program files\A_Free_Ride_Games_Bar\A_Free_Ride_Games_BarToolbarHelper.exe
c:\program files\A_Free_Ride_Games_Bar\GottenAppsContextMenu.xml
c:\program files\A_Free_Ride_Games_Bar\OtherAppsContextMenu.xml
c:\program files\A_Free_Ride_Games_Bar\prxtbA_Fr.dll
c:\program files\A_Free_Ride_Games_Bar\SharedAppsContextMenu.xml
c:\program files\A_Free_Ride_Games_Bar\tbA_Fr.dll
c:\program files\A_Free_Ride_Games_Bar\toolbar.cfg
c:\program files\A_Free_Ride_Games_Bar\ToolbarContextMenu.xml
c:\program files\A_Free_Ride_Games_Bar\uninstall.exe
c:\program files\BabylonToolbar
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarEng.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarsrv.exe
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\uninstall.exe
c:\program files\Free Ride Games
c:\program files\Free Ride Games\AppLoader2KEx.dll
c:\program files\Free Ride Games\AX32.dll
c:\program files\Free Ride Games\ClientSettings.ini
c:\program files\Free Ride Games\cmhelper.exe
c:\program files\Free Ride Games\DoDlg.exe
c:\program files\Free Ride Games\ExentComponents.ini
c:\program files\Free Ride Games\exs.dll
c:\program files\Free Ride Games\exs.ini
c:\program files\Free Ride Games\Free_Ride_Games.exe
c:\program files\Free Ride Games\FRGN.ico
c:\program files\Free Ride Games\GameInst.dll
c:\program files\Free Ride Games\GameLauncher.exe
c:\program files\Free Ride Games\GPlayer.exe
c:\program files\Free Ride Games\GPlrLanc.exe
c:\program files\Free Ride Games\IGL\2000119\ComponentMgrConfig.xml
c:\program files\Free Ride Games\IGL\2000119\connect_bottom.gif
c:\program files\Free Ride Games\IGL\2000119\connect_bottom.html
c:\program files\Free Ride Games\IGL\2000119\connect_left.gif
c:\program files\Free Ride Games\IGL\2000119\connect_left.html
c:\program files\Free Ride Games\IGL\2000119\connect_right.gif
c:\program files\Free Ride Games\IGL\2000119\connect_right.html
c:\program files\Free Ride Games\IGL\2000119\connect_top.gif
c:\program files\Free Ride Games\IGL\2000119\connect_top.html
c:\program files\Free Ride Games\IGL\2000119\default_bottom.gif
c:\program files\Free Ride Games\IGL\2000119\default_bottom.html
c:\program files\Free Ride Games\IGL\2000119\default_left.gif
c:\program files\Free Ride Games\IGL\2000119\default_left.html
c:\program files\Free Ride Games\IGL\2000119\default_right.gif
c:\program files\Free Ride Games\IGL\2000119\default_right.html
c:\program files\Free Ride Games\IGL\2000119\default_top.gif
c:\program files\Free Ride Games\IGL\2000119\default_top.html
c:\program files\Free Ride Games\IGL\2000119\GFComponent.dll
c:\program files\Free Ride Games\IGL\2000119\IGH1.dll
c:\program files\Free Ride Games\IGL\2000119\IGH2.dll
c:\program files\Free Ride Games\IGL\2000119\IGH3.dll
c:\program files\Free Ride Games\IGL\2000119\IGL.dll
c:\program files\Free Ride Games\IGL\2000119\IGL.ini
c:\program files\Free Ride Games\IGL\2000119\temp_bottom.dds
c:\program files\Free Ride Games\IGL\2000119\temp_left.dds
c:\program files\Free Ride Games\IGL\2000119\temp_right.dds
c:\program files\Free Ride Games\IGL\2000119\temp_top.dds
c:\program files\Free Ride Games\IGL\7001402\ComponentMgrConfig.xml
c:\program files\Free Ride Games\IGL\7001402\connect_bottom.gif
c:\program files\Free Ride Games\IGL\7001402\connect_bottom.html
c:\program files\Free Ride Games\IGL\7001402\connect_left.gif
c:\program files\Free Ride Games\IGL\7001402\connect_left.html
c:\program files\Free Ride Games\IGL\7001402\connect_right.gif
c:\program files\Free Ride Games\IGL\7001402\connect_right.html
c:\program files\Free Ride Games\IGL\7001402\connect_top.gif
c:\program files\Free Ride Games\IGL\7001402\connect_top.html
c:\program files\Free Ride Games\IGL\7001402\default_bottom.gif
c:\program files\Free Ride Games\IGL\7001402\default_bottom.html
c:\program files\Free Ride Games\IGL\7001402\default_left.gif
c:\program files\Free Ride Games\IGL\7001402\default_left.html
c:\program files\Free Ride Games\IGL\7001402\default_right.gif
c:\program files\Free Ride Games\IGL\7001402\default_right.html
c:\program files\Free Ride Games\IGL\7001402\default_top.gif
c:\program files\Free Ride Games\IGL\7001402\default_top.html
c:\program files\Free Ride Games\IGL\7001402\GFComponent.dll
c:\program files\Free Ride Games\IGL\7001402\IGH1.dll
c:\program files\Free Ride Games\IGL\7001402\IGH2.dll
c:\program files\Free Ride Games\IGL\7001402\IGH3.dll
c:\program files\Free Ride Games\IGL\7001402\IGL.dll
c:\program files\Free Ride Games\IGL\7001402\IGL.ini
c:\program files\Free Ride Games\IGL\7001402\ISH1.dll
c:\program files\Free Ride Games\IGL\7001402\resources\css\dialogwindow.css
c:\program files\Free Ride Games\IGL\7001402\resources\error.html
c:\program files\Free Ride Games\IGL\7001402\resources\img\connecting.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\devider.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\DialogWindow\cancelButton_over.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\DialogWindow\cancelButton_up.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\DialogWindow\retryButton_over.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\DialogWindow\retryButton_up.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\errorIcon.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\headerBackground.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\headerBackgroundUnfocused.gif
c:\program files\Free Ride Games\IGL\7001402\resources\img\toolTipBackground.gif
c:\program files\Free Ride Games\IGL\7001402\resources\js\network_disconnection.js
c:\program files\Free Ride Games\IGL\7001402\resources\js\pageurlinfo.js
c:\program files\Free Ride Games\IGL\7001402\resources\js\util.js
c:\program files\Free Ride Games\IGL\7001402\resources\js\window_content_resize.js
c:\program files\Free Ride Games\IGL\7001402\resources\loading.html
c:\program files\Free Ride Games\IGL\7001402\resources\networkDisconnection.html
c:\program files\Free Ride Games\IGL\7001402\temp_bottom.dds
c:\program files\Free Ride Games\IGL\7001402\temp_left.dds
c:\program files\Free Ride Games\IGL\7001402\temp_right.dds
c:\program files\Free Ride Games\IGL\7001402\temp_top.dds
c:\program files\Free Ride Games\IGL\8000200\ComponentMgrConfig.xml
c:\program files\Free Ride Games\IGL\8000200\connect_bottom.gif
c:\program files\Free Ride Games\IGL\8000200\connect_bottom.html
c:\program files\Free Ride Games\IGL\8000200\connect_left.gif
c:\program files\Free Ride Games\IGL\8000200\connect_left.html
c:\program files\Free Ride Games\IGL\8000200\connect_right.gif
c:\program files\Free Ride Games\IGL\8000200\connect_right.html
c:\program files\Free Ride Games\IGL\8000200\connect_top.gif
c:\program files\Free Ride Games\IGL\8000200\connect_top.html
c:\program files\Free Ride Games\IGL\8000200\default_bottom.gif
c:\program files\Free Ride Games\IGL\8000200\default_bottom.html
c:\program files\Free Ride Games\IGL\8000200\default_left.gif
c:\program files\Free Ride Games\IGL\8000200\default_left.html
c:\program files\Free Ride Games\IGL\8000200\default_right.gif
c:\program files\Free Ride Games\IGL\8000200\default_right.html
c:\program files\Free Ride Games\IGL\8000200\default_top.gif
c:\program files\Free Ride Games\IGL\8000200\default_top.html
c:\program files\Free Ride Games\IGL\8000200\GFComponent.dll
c:\program files\Free Ride Games\IGL\8000200\IGH1.dll
c:\program files\Free Ride Games\IGL\8000200\IGH2.dll
c:\program files\Free Ride Games\IGL\8000200\IGH3.dll
c:\program files\Free Ride Games\IGL\8000200\IGL.dll
c:\program files\Free Ride Games\IGL\8000200\IGL.ini
c:\program files\Free Ride Games\IGL\8000200\ISH1.dll
c:\program files\Free Ride Games\IGL\8000200\resources\css\dialogwindow.css
c:\program files\Free Ride Games\IGL\8000200\resources\error.html
c:\program files\Free Ride Games\IGL\8000200\resources\img\connecting.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\devider.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\DialogWindow\cancelButton_over.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\DialogWindow\cancelButton_up.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\DialogWindow\retryButton_over.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\DialogWindow\retryButton_up.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\errorIcon.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\headerBackground.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\headerBackgroundUnfocused.gif
c:\program files\Free Ride Games\IGL\8000200\resources\img\Thumbs.db
c:\program files\Free Ride Games\IGL\8000200\resources\img\toolTipBackground.gif
c:\program files\Free Ride Games\IGL\8000200\resources\js\network_disconnection.js
c:\program files\Free Ride Games\IGL\8000200\resources\js\pageurlinfo.js
c:\program files\Free Ride Games\IGL\8000200\resources\js\util.js
c:\program files\Free Ride Games\IGL\8000200\resources\js\window_content_resize.js
c:\program files\Free Ride Games\IGL\8000200\resources\loading.html
c:\program files\Free Ride Games\IGL\8000200\resources\networkDisconnection.html
c:\program files\Free Ride Games\IGL\8000200\temp_bottom.dds
c:\program files\Free Ride Games\IGL\8000200\temp_left.dds
c:\program files\Free Ride Games\IGL\8000200\temp_right.dds
c:\program files\Free Ride Games\IGL\8000200\temp_top.dds
c:\program files\Free Ride Games\Info\1.clg
c:\program files\Free Ride Games\Info\10.clg
c:\program files\Free Ride Games\Info\11.clg
c:\program files\Free Ride Games\Info\12.clg
c:\program files\Free Ride Games\Info\13.clg
c:\program files\Free Ride Games\Info\14.clg
c:\program files\Free Ride Games\Info\15.clg
c:\program files\Free Ride Games\Info\16.clg
c:\program files\Free Ride Games\Info\2.clg
c:\program files\Free Ride Games\Info\3.clg
c:\program files\Free Ride Games\Info\4.clg
c:\program files\Free Ride Games\Info\5.clg
c:\program files\Free Ride Games\Info\6.clg
c:\program files\Free Ride Games\Info\7.clg
c:\program files\Free Ride Games\Info\8.clg
c:\program files\Free Ride Games\Info\9.clg
c:\program files\Free Ride Games\Info\AIGsXML_143.xml
c:\program files\Free Ride Games\Info\co_DEADA275.dat
c:\program files\Free Ride Games\Info\co_MommyDearest.dat
c:\program files\Free Ride Games\Info\Direction[1].rgmxold
c:\program files\Free Ride Games\Info\Direction[2].rgmxold
c:\program files\Free Ride Games\Info\Direction[3].rgmxold
c:\program files\Free Ride Games\Info\ExentRssDB_143.xml
c:\program files\Free Ride Games\Info\NM_CP_143.xml
c:\program files\Free Ride Games\Info\Rptusg.xml
c:\program files\Free Ride Games\Info\sXp.dat
c:\program files\Free Ride Games\license.txt
c:\program files\Free Ride Games\myGames.ico
c:\program files\Free Ride Games\npExentCtl.dll
c:\program files\Free Ride Games\ProviderComponents.ini
c:\program files\Free Ride Games\Report.exe
c:\program files\Free Ride Games\report.ini
c:\program files\Free Ride Games\Skins\000005\dat\GPlrLanc.dat
c:\program files\Free Ride Games\Skins\000005\GameInfoDefault\GameImage_DefaultGameImage.gif
c:\program files\Free Ride Games\Skins\000005\GameInfoDefault\md.dat
c:\program files\Free Ride Games\Skins\000005\GameInfoDefault\SplashScreenGameImage_DefaultSplashScreenGameImage.jpg
c:\program files\Free Ride Games\Skins\000005\GameInfoDefault\Thumbs.db
c:\program files\Free Ride Games\Skins\000005\html\Connecting.html
c:\program files\Free Ride Games\Skins\000005\html\OffLineErrUI.html
c:\program files\Free Ride Games\Skins\000005\html\OffLineWebUI.html
c:\program files\Free Ride Games\Skins\000005\html\OffLineWebUIFailure.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\ap_application.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\ap_controller.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\ap_defines.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\ap_model.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\ap_playerSession.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_ace.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_authentication_request.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_base64.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_cookies.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_defines.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_directions_request.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_download_list.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_download_list_action.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_error.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_errorTools.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_frplus_service.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_game.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_game_action.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_game_list.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_get_directions_engine.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_href_request.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_json.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_keep_connection.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_my_games.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_partner.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_provider_cache.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_st_icon.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_string_loader.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_tabs.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_tracking.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_ui.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\cls_utils.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\classes\gmt\cls_gmt_authentication.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\debug.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\gplayer\gplayer_api.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\gplayer\gplayer_api_defines.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\gplayer\gplayer_api_notification.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Exent\logic.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\adGame.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\adGameHigh.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\autoCompleteSearch.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\dialogBox.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\dl_in.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\errorPage.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\errorPagePopUp.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\frame.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\login.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\mg_in.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\og_in.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\skinUI.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\splash.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\css\yesnoDialogBox.css
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\defaultMostPopularGames.json
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\dl.htm
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\buy_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\cancel_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\cancel_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\cancel_2.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\chk_0_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\chk_0_0.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\chk_0_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\chk_1_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\chk_1_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\close_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\close_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\close_2.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\helpcenter_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\helpcenter_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\helpcenter_2.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\hideinfo_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\hideinfo_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\hideinfo_2.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\moreinfo_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\moreinfo_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\moreinfo_2.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\ok_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\ok_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\ok_2.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\submit_0.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\submit_1.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\btn\submit_2.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialog_shade.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\attantionIcon.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\bgBottom.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\bgLeft.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\bgRight.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\bgTop.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\bottomLeft.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\bottomRight.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\flashPlayerIcon.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\loader_2a.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\loader_2a.swf
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\logoDialogBox.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\retryBut.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\topLeft.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\dialogBox\topRight.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\eror.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\GATracker.swf
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\icon_error.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\layout0.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\layout1.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\layout2.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_off_0_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_off_1_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_off_2_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_off_3_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_on_0_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_on_1_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_on_2_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\banner_on_3_buttons.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\login_splash.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\login_splash_high.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\masks\playerMask.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\MostPopular.swf
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\MyGames.swf
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\myGames_Banner_160x600.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\pb.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\close_disabled.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\close_down.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\close_over.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\close_up.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\invite_header_pixel.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\launching.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\loading.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\play_bg.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\preRoll\play_norm.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\channelsDropDown.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\dottedDevider.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\dropDownList.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\dropdownTopBottom.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\gametaniumLogo.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\loadingImage.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\loadingProgressBar.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\logo.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\mainBg.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\MinCloseButton.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\searchBg.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\searchButton.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\SubscriptionGametaniumTab.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\SubscriptionMyGamesTab.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\SubscriptionOnlineGamesTab.png
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\skinUI\tabsBg.jpg
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\img\spacer.gif
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\AC_RunActiveContent.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\client_externals.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\dl_in.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\dropDownList.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\errorPage.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\errorPagePopUp.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\errorPageTools.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\flash_detect.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\flashEventDelegator.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\flashObjectsFactory.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\frame.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\jquery.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\key_blocker.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\login.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\mg_in.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\og_in.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\player_movment.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\postRoll.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\postRoll.js.with timer
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\preRoll.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\signIn.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\skin_events\PreRollAdMgrListener.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\skin_events\PreRollAdMgrProducer.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\skin_events\SkinComMgr.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\skin_events\SkinComMgrListener.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\skin_events\SkinComMgrProducer.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\skin_events\specialAdsEvent.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\splash.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\switchStateMachine.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\trackManager.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\yesnoDialogBox.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\YUI\animation-min.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\YUI\autocomplete-min.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\YUI\autocompleteSearch.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\YUI\datasource-min.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\js\YUI\yahoo-dom-event.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\mg.htm
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pids.xml
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_ad_game_splash.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_download_list.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_end_game_ad_splash.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_end_game_splash_screen.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_error.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_error_pop_up.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_errorTools.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_gametanium.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_general.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_get_directions_game_splash_screen.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_intro.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_load_game_splash_screen.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_my games.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_online_games.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_skin.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\pl\pl_updating_game_splash_screen.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_ConfirmDeleteGame.htm
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_defines.js
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_DownLoadListPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_EndGameAdPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_ErrorPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_ErrorPagePopUp.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_ErrorTools.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_FatalErrorPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_GameEndSplashScreenPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_GametaniumPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_GetDirectionsGameSplashScreenPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_Intro.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_LoadGameAdPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_LoadGameAdPageHigh.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_LoadGameSplashScreenPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_MyGamesPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_OnlineGamesPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_Skin.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_TrialGameEndSplashScreenPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_UnAcceptableProviderId.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_UpdatingGameSplashScreenPage.html
c:\program files\Free Ride Games\Skins\000005\html\Skin\Provider\prvd_ViewMapping.js
c:\program files\Free Ride Games\Skins\000005\icon\ChangeCD.ico
c:\program files\Free Ride Games\Skins\000005\icon\Exit.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoBase.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoBase_HR.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoDownload.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoDownload_HR.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoMultiplay.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoMultiplay_HR.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoRun.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoRun_HR.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoScheduling.ico
c:\program files\Free Ride Games\Skins\000005\icon\FRGLogoScheduling_HR.ico
c:\program files\Free Ride Games\Skins\000005\icon\GPlayer.ico
c:\program files\Free Ride Games\Skins\000005\icon\GPlrLanc.ico
c:\program files\Free Ride Games\Skins\000005\icon\Help.ico
c:\program files\Free Ride Games\Skins\000005\icon\IAF.ico
c:\program files\Free Ride Games\Skins\000005\icon\MyDownloads.ico
c:\program files\Free Ride Games\Skins\000005\icon\MyGames.ico
c:\program files\Free Ride Games\Skins\000005\icon\OnlineGames.ico
c:\program files\Free Ride Games\Skins\000005\icon\Service.ico
c:\program files\Free Ride Games\Skins\000005\icon\Settings.ico
c:\program files\Free Ride Games\Skins\000005\icon\TrayBallon.ico
c:\program files\Free Ride Games\Skins\000005\Langs\0409\EXEtenderOptionsHelp.htm
c:\program files\Free Ride Games\Skins\000005\Langs\0409\Strings.xml
c:\program files\Free Ride Games\Skins\000005\mask\error.rgn
c:\program files\Free Ride Games\Skins\000005\mask\login.rgn
c:\program files\Free Ride Games\Skins\000005\mask\login_splash.rgn
c:\program files\Free Ride Games\Skins\000005\mask\login_splash_high.rgn
c:\program files\Free Ride Games\Skins\000005\mask\playerMask.rgn
c:\program files\Free Ride Games\Skins\000005\mask\updating_splash.rgn
c:\program files\Free Ride Games\Skins\000005\NIBmps\NetInd1.bmp
c:\program files\Free Ride Games\Skins\000005\NIBmps\NetInd2.bmp
c:\program files\Free Ride Games\Skins\000005\NIBmps\NetInd3.bmp
c:\program files\Free Ride Games\Skins\000005\NIBmps\NetInd4.bmp
c:\program files\Free Ride Games\Skins\000005\NIBmps\NetInd5.bmp
c:\program files\Free Ride Games\Skins\000005\NIBmps\NetInd6.bmp
c:\program files\Free Ride Games\Skins\000005\NIBmps\Thumbs.db
c:\program files\Free Ride Games\Skins\000005\Popups\1\background.jpg
c:\program files\Free Ride Games\Skins\000005\Popups\1\cancelbuttondown.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\cancelbuttonnorm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\cancelbuttonoff.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\cancelbuttonover.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\CheckBoxChecked.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\CheckBoxNormal.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\closebuttondown.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\closebuttonnorm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\closebuttonoff.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\closebuttonover.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\nobuttondown.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\nobuttonnorm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\nobuttonoff.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\nobuttonover.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton1down.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton1norm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton1off.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton1over.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton2down.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton2norm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton2off.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\pinbutton2over.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\skipbuttondown.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\skipbuttonnorm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\skipbuttonoff.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\skipbuttonover.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\updatebuttondown.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\updatebuttonnorm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\updatebuttonoff.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\updatebuttonover.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\yesbuttondown.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\yesbuttonnorm.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\yesbuttonoff.bmp
c:\program files\Free Ride Games\Skins\000005\Popups\1\yesbuttonover.bmp
c:\program files\Free Ride Games\Skins\000005\Settings.xml
c:\program files\Free Ride Games\Skins\000005\SkinCfg.xml
c:\program files\Free Ride Games\Skins\000005\sound\PopupMessage.wav
c:\program files\Free Ride Games\Uninstall.exe
c:\program files\Free Ride Games\X4Ex.sys
c:\program files\Free Ride Games\X4HSEx.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_97179484
——-\Legacy_X4HSEx
——-\Legacy_X4HSEx
——-\Service_X4HSEx
——-\Service_X4HSEx
.
.
((((((((((((((((((((((((( Files Created from 2011-11-02 to 2011-12-02 )))))))))))))))))))))))))))))))
.
.
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47 . 2011-11-18 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\3B35B
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39 . 2011-11-16 15:39 ——– d—–w- c:\documents and settings\All Users\Application Data\F3A9
2011-11-12 14:51 . 2011-11-12 14:52 ——– d—–w- c:\documents and settings\Deano-Casino\Local Settings\Application Data\PageRage
2011-11-08 00:18 . 2011-11-08 00:18 ——– d—–w- c:\documents and settings\Deano-Casino\.autodesk
2011-11-06 01:14 . 2011-11-06 01:14 ——– d—–w- c:\program files\FunnyGames
2011-11-05 04:48 . 2011-11-09 20:06 ——– d—–w- C:\Remote Programs
2011-11-05 04:47 . 2011-06-22 16:44 53314 ——w- c:\windows\ExentInfo.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-01_23.54.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-02 04:44 . 2011-12-02 04:44 16384 c:\windows\Temp\Perflib_Perfdata_400.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-09-01 16:16 2532680 —-a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
2011-05-18 02:40 395240 —-a-w- c:\program files\Ask.com\Updater\Updater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Updater Service for StartNow Toolbar"=2 (0x2)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Documents and Settings\\The Crew\\My Documents\\Downloads\\FlvPlayerSetup.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57601:TCP"= 57601:TCP:Pando Media Booster
"57601:UDP"= 57601:UDP:Pando Media Booster
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 1:19 PM 297168]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/12/2011 9:59 AM 1025352]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [8/18/2011 1:33 AM 7390560]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134480]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24144]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 27216]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-02 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-02 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-02 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-02 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-11-12 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-10-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-11-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-02 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-05-18 02:40]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-02 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
FF - prefs.js: browser.search.selectedEngine - My Web Search
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm593YYUS&ptb;=yFNr5NpMFZ7vV0qkXYavEQ&ind;=2011050817&ptnrS;=ZUxdm593YYUS&si;=&n;=77de3341&psa;=&st;=kwd&searchfor;=
.
- - - - ORPHANS REMOVED - - - -
.
HKU-Default-Run-Exetender - c:\program files\Free Ride Games\GPlayer.exe
AddRemove-A_Free_Ride_Games_Bar Toolbar - c:\progra~1\A_FREE~1\UNINST~1.EXE
AddRemove-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\uninstall.exe
AddRemove-{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7} - c:\program files\Free Ride Games\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-01 21:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="system32\drivers\tskE.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1764)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG10\avgchsvx.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\AVG\AVG10\avgnsx.exe
c:\program files\AVG\AVG10\avgemcx.exe
c:\windows\system32\Rundll32.exe
c:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
c:\progra~1\AVG\AVG10\avgrsx.exe
c:\program files\AVG\AVG10\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2011-12-01 21:51:20 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-02 04:51
ComboFix2.txt 2011-12-02 00:03
.
Pre-Run: 42,887,798,784 bytes free
Post-Run: 45,553,930,240 bytes free
.
- - End Of File - - E9D9A6084F08078D9277110AE7B9EE22
Hi Wicked Kitt_E,

While I am looking over your ComboFix log please do the following:

Run TDSSKiller once again and save the log that is created.
————–

GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

In your next reply please post the logs created by TDSSKiller and GMER. :)
Hi Jeff. I ran the tsskiller and below is the results. I ran the gmer and left it to run for awhile and when I came back there was a blue screen that has "A process or thread crucial to system operations has unexpectedly exit or been terminated. Stop Ox000000F4. Should I run gmer again. 09:33:04.0984 0620 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 09:33:06.0984 0620 ============================================================ 09:33:06.0984 0620 Current date / time: 2011/12/03 09:33:06.0984 09:33:06.0984 0620 SystemInfo: 09:33:06.0984 0620 09:33:06.0984 0620 OS Version: 5.1.2600 ServicePack: 3.0 09:33:06.0984 0620 Product type: Workstation 09:33:06.0984 0620 ComputerName: DEAM 09:33:06.0984 0620 UserName: Deano-Casino 09:33:06.0984 0620 Windows directory: C:\WINDOWS 09:33:06.0984 0620 System windows directory: C:\WINDOWS 09:33:06.0984 0620 Processor architecture: Intel x86 09:33:06.0984 0620 Number of processors: 2 09:33:06.0984 0620 Page size: 0x1000 09:33:06.0984 0620 Boot type: Normal boot 09:33:06.0984 0620 ============================================================ 09:33:24.0296 0620 Initialize success 09:33:45.0109 2952 ============================================================ 09:33:45.0109 2952 Scan started 09:33:45.0109 2952 Mode: Manual; 09:33:45.0109 2952 ============================================================ 09:34:10.0265 2952 Abiosdsk - ok 09:34:10.0875 2952 abp480n5 - ok 09:34:11.0984 2952 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 09:34:12.0093 2952 ACPI - ok 09:34:13.0015 2952 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 09:34:13.0093 2952 ACPIEC - ok 09:34:13.0843 2952 adpu160m - ok 09:34:14.0796 2952 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 09:34:14.0906 2952 aec - ok 09:34:15.0625 2952 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 09:34:15.0734 2952 AFD - ok 09:34:16.0234 2952 Aha154x - ok 09:34:16.0734 2952 aic78u2 - ok 09:34:17.0156 2952 aic78xx - ok 09:34:17.0625 2952 AliIde - ok 09:34:18.0125 2952 amsint - ok 09:34:18.0640 2952 asc - ok 09:34:19.0140 2952 asc3350p - ok 09:34:19.0703 2952 asc3550 - ok 09:34:20.0468 2952 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 09:34:20.0531 2952 AsyncMac - ok 09:34:21.0203 2952 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 09:34:21.0203 2952 atapi - ok 09:34:21.0687 2952 Atdisk - ok 09:34:22.0421 2952 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 09:34:22.0484 2952 Atmarpc - ok 09:34:23.0500 2952 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 09:34:23.0546 2952 audstub - ok 09:34:24.0875 2952 AVGIDSDriver (2d18221aab3db2d408d6c55c0f23090a) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 09:34:25.0046 2952 AVGIDSDriver - ok 09:34:25.0812 2952 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 09:34:25.0859 2952 AVGIDSEH - ok 09:34:26.0593 2952 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 09:34:26.0687 2952 AVGIDSFilter - ok 09:34:27.0390 2952 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 09:34:27.0406 2952 AVGIDSShim - ok 09:34:28.0265 2952 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 09:34:28.0453 2952 Avgldx86 - ok 09:34:29.0281 2952 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 09:34:29.0296 2952 Avgmfx86 - ok 09:34:30.0062 2952 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 09:34:30.0109 2952 Avgrkx86 - ok 09:34:31.0015 2952 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 09:34:31.0265 2952 Avgtdix - ok 09:34:32.0046 2952 BANTExt (5d7be7b19e827125e016325334e58ff1) C:\WINDOWS\System32\Drivers\BANTExt.sys 09:34:32.0109 2952 BANTExt - ok 09:34:32.0828 2952 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 09:34:32.0875 2952 Beep - ok 09:34:33.0625 2952 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 09:34:33.0671 2952 Bridge - ok 09:34:33.0734 2952 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 09:34:33.0734 2952 BridgeMP - ok 09:34:33.0750 2952 catchme - ok 09:34:34.0437 2952 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 09:34:34.0531 2952 cbidf2k - ok 09:34:35.0015 2952 cd20xrnt - ok 09:34:35.0750 2952 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 09:34:35.0750 2952 Cdaudio - ok 09:34:36.0484 2952 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 09:34:36.0546 2952 Cdfs - ok 09:34:37.0265 2952 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 09:34:37.0312 2952 Cdrom - ok 09:34:37.0875 2952 Changer - ok 09:34:38.0375 2952 CmdIde - ok 09:34:38.0906 2952 Cpqarray - ok 09:34:39.0453 2952 cpuz132 - ok 09:34:40.0218 2952 ctsfm2k (8db84de3aab34a8b4c2f644eff41cd76) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys 09:34:40.0359 2952 ctsfm2k - ok 09:34:40.0812 2952 dac2w2k - ok 09:34:41.0375 2952 dac960nt - ok 09:34:42.0140 2952 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 09:34:42.0187 2952 Disk - ok 09:34:43.0218 2952 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 09:34:44.0015 2952 dmboot - ok 09:34:45.0656 2952 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys 09:34:45.0765 2952 dmio - ok 09:34:46.0765 2952 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 09:34:46.0828 2952 dmload - ok 09:34:48.0156 2952 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 09:34:48.0156 2952 DMusic - ok 09:34:48.0812 2952 dpti2o - ok 09:34:49.0625 2952 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 09:34:49.0656 2952 drmkaud - ok 09:34:50.0859 2952 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 09:34:51.0015 2952 Fastfat - ok 09:34:52.0625 2952 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 09:34:52.0656 2952 Fdc - ok 09:34:53.0406 2952 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 09:34:53.0421 2952 Fips - ok 09:34:54.0187 2952 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 09:34:54.0250 2952 Flpydisk - ok 09:34:54.0859 2952 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 09:34:54.0890 2952 FltMgr - ok 09:34:55.0546 2952 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 09:34:55.0562 2952 fssfltr - ok 09:34:56.0218 2952 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 09:34:56.0234 2952 Fs_Rec - ok 09:34:56.0937 2952 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 09:34:56.0984 2952 Ftdisk - ok 09:34:57.0609 2952 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 09:34:57.0703 2952 GEARAspiWDM - ok 09:34:58.0250 2952 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 09:34:58.0265 2952 Gpc - ok 09:34:59.0046 2952 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 09:34:59.0218 2952 HDAudBus - ok 09:34:59.0750 2952 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 09:34:59.0781 2952 hidusb - ok 09:35:00.0203 2952 hpn - ok 09:35:00.0875 2952 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 09:35:00.0906 2952 HPZid412 - ok 09:35:01.0687 2952 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 09:35:01.0734 2952 HPZipr12 - ok 09:35:02.0453 2952 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 09:35:02.0515 2952 HPZius12 - ok 09:35:03.0250 2952 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 09:35:03.0406 2952 HTTP - ok 09:35:03.0906 2952 i2omgmt - ok 09:35:04.0531 2952 i2omp - ok 09:35:05.0234 2952 i8042prt - ok 09:35:06.0000 2952 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 09:35:06.0015 2952 Imapi - ok 09:35:06.0531 2952 ini910u - ok 09:35:07.0109 2952 IntelIde - ok 09:35:07.0875 2952 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 09:35:08.0046 2952 intelppm - ok 09:35:08.0703 2952 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 09:35:08.0750 2952 Ip6Fw - ok 09:35:09.0609 2952 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 09:35:09.0687 2952 IpFilterDriver - ok 09:35:10.0390 2952 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 09:35:10.0437 2952 IpInIp - ok 09:35:11.0187 2952 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 09:35:11.0328 2952 IpNat - ok 09:35:11.0968 2952 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 09:35:12.0046 2952 IPSec - ok 09:35:12.0609 2952 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 09:35:12.0671 2952 IRENUM - ok 09:35:13.0203 2952 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 09:35:13.0234 2952 isapnp - ok 09:35:13.0953 2952 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 09:35:13.0984 2952 Kbdclass - ok 09:35:14.0609 2952 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 09:35:14.0671 2952 kbdhid - ok 09:35:15.0281 2952 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 09:35:15.0375 2952 kmixer - ok 09:35:16.0031 2952 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 09:35:16.0109 2952 KSecDD - ok 09:35:16.0671 2952 lbrtfdc - ok 09:35:17.0687 2952 libusb0 (03e12dbfacf1aeb86c553b0db488fb81) C:\WINDOWS\system32\drivers\libusb0.sys 09:35:17.0718 2952 libusb0 - ok 09:35:18.0656 2952 MCSTRM - ok 09:35:19.0390 2952 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 09:35:19.0437 2952 mnmdd - ok 09:35:20.0187 2952 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 09:35:20.0265 2952 Modem - ok 09:35:21.0046 2952 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 09:35:21.0078 2952 Mouclass - ok 09:35:21.0734 2952 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 09:35:21.0781 2952 mouhid - ok 09:35:22.0500 2952 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 09:35:22.0531 2952 MountMgr - ok 09:35:23.0125 2952 mraid35x - ok 09:35:23.0953 2952 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 09:35:24.0093 2952 MRxDAV - ok 09:35:25.0031 2952 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 09:35:25.0390 2952 MRxSmb - ok 09:35:26.0296 2952 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 09:35:26.0312 2952 Msfs - ok 09:35:26.0953 2952 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 09:35:27.0093 2952 MSKSSRV - ok 09:35:27.0859 2952 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 09:35:27.0937 2952 MSPCLOCK - ok 09:35:28.0859 2952 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 09:35:28.0953 2952 MSPQM - ok 09:35:29.0640 2952 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 09:35:29.0656 2952 mssmbios - ok 09:35:30.0578 2952 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 09:35:30.0671 2952 Mup - ok 09:35:31.0921 2952 N3AB (0bb59b42cf3431d55a0bfbb5d7f77ee5) C:\WINDOWS\system32\DRIVERS\N3AB.sys 09:35:32.0593 2952 N3AB - ok 09:35:33.0281 2952 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 09:35:33.0375 2952 NDIS - ok 09:35:34.0046 2952 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 09:35:34.0062 2952 NdisTapi - ok 09:35:34.0718 2952 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 09:35:34.0750 2952 Ndisuio - ok 09:35:35.0578 2952 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 09:35:35.0671 2952 NdisWan - ok 09:35:36.0359 2952 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 09:35:36.0406 2952 NDProxy - ok 09:35:37.0093 2952 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 09:35:37.0109 2952 NetBIOS - ok 09:35:37.0734 2952 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 09:35:37.0937 2952 NetBT - ok 09:35:38.0859 2952 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 09:35:38.0875 2952 Npfs - ok 09:35:40.0031 2952 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 09:35:40.0609 2952 Ntfs - ok 09:35:41.0515 2952 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 09:35:41.0562 2952 Null - ok 09:35:49.0046 2952 nv (f1de35c89d98a883d1b4030dc9896855) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 09:35:59.0734 2952 nv - ok 09:36:00.0578 2952 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 09:36:00.0609 2952 NwlnkFlt - ok 09:36:01.0359 2952 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 09:36:01.0421 2952 NwlnkFwd - ok 09:36:02.0046 2952 ossrv (103a9b117a7d9903111955cdafe65ac6) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys 09:36:02.0093 2952 ossrv - ok 09:36:02.0656 2952 P17 (df886ffed69aead0cf608b89b18c3f6f) C:\WINDOWS\system32\drivers\P17.sys 09:36:03.0406 2952 P17 - ok 09:36:03.0890 2952 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 09:36:03.0953 2952 Parport - ok 09:36:04.0390 2952 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 09:36:04.0421 2952 PartMgr - ok 09:36:04.0921 2952 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 09:36:04.0937 2952 ParVdm - ok 09:36:05.0390 2952 pavboot (3adb8bd6154a3ef87496e8fce9c22493) C:\WINDOWS\system32\drivers\pavboot.sys 09:36:05.0406 2952 pavboot - ok 09:36:06.0453 2952 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 09:36:06.0546 2952 PCI - ok 09:36:06.0953 2952 PCIDump - ok 09:36:07.0187 2952 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 09:36:07.0234 2952 PCIIde - ok 09:36:07.0656 2952 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 09:36:07.0843 2952 Pcmcia - ok 09:36:08.0328 2952 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys 09:36:08.0375 2952 pcouffin - ok 09:36:08.0859 2952 PCTCore (d302a59e6d1842a201930928a5bad68b) C:\WINDOWS\system32\drivers\PCTCore.sys 09:36:08.0890 2952 PCTCore - ok 09:36:09.0406 2952 PDCOMP - ok 09:36:09.0578 2952 PDFRAME - ok 09:36:09.0734 2952 PDRELI - ok 09:36:09.0984 2952 PDRFRAME - ok 09:36:10.0281 2952 perc2 - ok 09:36:10.0468 2952 perc2hib - ok 09:36:10.0968 2952 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 09:36:10.0968 2952 PptpMiniport - ok 09:36:11.0500 2952 prodrv06 (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys 09:36:11.0531 2952 prodrv06 - ok 09:36:12.0046 2952 prohlp02 (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys 09:36:12.0109 2952 prohlp02 - ok 09:36:12.0625 2952 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys 09:36:12.0640 2952 prosync1 - ok 09:36:13.0140 2952 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 09:36:13.0234 2952 PSched - ok 09:36:14.0015 2952 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 09:36:14.0093 2952 Ptilink - ok 09:36:14.0656 2952 ql1080 - ok 09:36:15.0203 2952 Ql10wnt - ok 09:36:15.0546 2952 ql12160 - ok 09:36:15.0890 2952 ql1240 - ok 09:36:16.0093 2952 ql1280 - ok 09:36:16.0484 2952 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 09:36:16.0515 2952 RasAcd - ok 09:36:17.0078 2952 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 09:36:17.0078 2952 Rasl2tp - ok 09:36:17.0484 2952 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 09:36:17.0500 2952 RasPppoe - ok 09:36:17.0812 2952 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 09:36:17.0890 2952 Raspti - ok 09:36:18.0359 2952 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 09:36:18.0437 2952 Rdbss - ok 09:36:18.0937 2952 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 09:36:18.0953 2952 RDPCDD - ok 09:36:19.0484 2952 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 09:36:19.0593 2952 rdpdr - ok 09:36:20.0171 2952 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 09:36:20.0250 2952 RDPWD - ok 09:36:20.0828 2952 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 09:36:20.0875 2952 redbook - ok 09:36:21.0515 2952 rt2870 (b10c0cea067240b6741cc7862f63d2fd) C:\WINDOWS\system32\DRIVERS\rt2870.sys 09:36:21.0734 2952 rt2870 - ok 09:36:22.0234 2952 RTL8023xp (cf84b1f0e8b14d4120aaf9cf35cbb265) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 09:36:22.0296 2952 RTL8023xp - ok 09:36:22.0890 2952 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 09:36:22.0968 2952 rtl8139 - ok 09:36:23.0515 2952 SaiH075C (de7a2fc379671998865122a08fd9db52) C:\WINDOWS\system32\DRIVERS\SaiH075C.sys 09:36:23.0609 2952 SaiH075C - ok 09:36:23.0906 2952 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 09:36:23.0906 2952 SASDIFSV - ok 09:36:24.0187 2952 SASENUM (a22f08c98ac2f44587bf3a1fb52bf8cd) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS 09:36:24.0234 2952 SASENUM - ok 09:36:24.0531 2952 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 09:36:24.0546 2952 SASKUTIL - ok 09:36:25.0312 2952 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) C:\WINDOWS\system32\DRIVERS\secdrv.sys 09:36:25.0500 2952 Secdrv - ok 09:36:26.0062 2952 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 09:36:26.0078 2952 serenum - ok 09:36:26.0515 2952 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 09:36:26.0531 2952 Serial - ok 09:36:26.0984 2952 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys 09:36:27.0000 2952 sfhlp01 - ok 09:36:27.0328 2952 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 09:36:27.0343 2952 Sfloppy - ok 09:36:27.0765 2952 silabenm (c16173316918a1360dc22947c4ff6352) C:\WINDOWS\system32\DRIVERS\silabenm.sys 09:36:27.0781 2952 silabenm - ok 09:36:28.0109 2952 silabser (093c31ec727ecbcbe38992fc69657594) C:\WINDOWS\system32\DRIVERS\silabser.sys 09:36:28.0140 2952 silabser - ok 09:36:28.0437 2952 Simbad - ok 09:36:28.0562 2952 Sparrow - ok 09:36:28.0843 2952 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 09:36:28.0843 2952 splitter - ok 09:36:29.0312 2952 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 09:36:29.0343 2952 sr - ok 09:36:29.0843 2952 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 09:36:29.0984 2952 Srv - ok 09:36:30.0406 2952 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 09:36:30.0453 2952 swenum - ok 09:36:30.0875 2952 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 09:36:30.0890 2952 swmidi - ok 09:36:31.0078 2952 symc810 - ok 09:36:31.0531 2952 symc8xx - ok 09:36:31.0687 2952 sym_hi - ok 09:36:31.0984 2952 sym_u3 - ok 09:36:32.0421 2952 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 09:36:32.0437 2952 sysaudio - ok 09:36:33.0031 2952 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 09:36:33.0187 2952 Tcpip - ok 09:36:33.0640 2952 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 09:36:33.0687 2952 TDPIPE - ok 09:36:34.0140 2952 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 09:36:34.0156 2952 TDTCP - ok 09:36:34.0593 2952 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 09:36:34.0609 2952 TermDD - ok 09:36:34.0968 2952 TosIde - ok 09:36:35.0468 2952 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 09:36:35.0578 2952 Udfs - ok 09:36:36.0046 2952 ultra - ok 09:36:36.0562 2952 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 09:36:36.0812 2952 Update - ok 09:36:37.0156 2952 USBAAPL - ok 09:36:37.0671 2952 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 09:36:37.0671 2952 usbaudio - ok 09:36:38.0062 2952 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 09:36:38.0078 2952 usbccgp - ok 09:36:38.0625 2952 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 09:36:38.0671 2952 usbehci - ok 09:36:39.0203 2952 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 09:36:39.0203 2952 usbhub - ok 09:36:39.0718 2952 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 09:36:39.0765 2952 usbohci - ok 09:36:40.0375 2952 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 09:36:40.0390 2952 usbprint - ok 09:36:40.0781 2952 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 09:36:40.0828 2952 usbscan - ok 09:36:41.0281 2952 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 09:36:41.0312 2952 USBSTOR - ok 09:36:41.0593 2952 VBoxNetAdp (4529f598bf8c8dbeda96be6ae5991c4a) C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys 09:36:41.0593 2952 VBoxNetAdp - ok 09:36:41.0796 2952 VBoxNetFlt - ok 09:36:42.0453 2952 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 09:36:42.0453 2952 VgaSave - ok 09:36:42.0781 2952 ViaIde - ok 09:36:43.0062 2952 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 09:36:43.0078 2952 VolSnap - ok 09:36:43.0421 2952 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 09:36:43.0437 2952 Wanarp - ok 09:36:43.0875 2952 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 09:36:44.0218 2952 Wdf01000 - ok 09:36:44.0406 2952 WDICA - ok 09:36:44.0671 2952 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 09:36:44.0750 2952 wdmaud - ok 09:36:45.0218 2952 WmBEnum (84a90f13eebf4380345ef9474d30f10e) C:\WINDOWS\system32\drivers\WmBEnum.sys 09:36:45.0218 2952 WmBEnum - ok 09:36:45.0640 2952 WmFilter (eb0034ac02a44dc784a3174d2b81e764) C:\WINDOWS\system32\drivers\WmFilter.sys 09:36:45.0656 2952 WmFilter - ok 09:36:45.0875 2952 WmHidLo (31d2906d59f127654964be334b615720) C:\WINDOWS\system32\drivers\WmHidLo.sys 09:36:45.0968 2952 WmHidLo - ok 09:36:46.0156 2952 WmVirHid (72c4f5a748c74d8d4016ccfa7367210f) C:\WINDOWS\system32\drivers\WmVirHid.sys 09:36:46.0171 2952 WmVirHid - ok 09:36:46.0437 2952 WmXlCore (eacdcced934a185e61ce0684f71c2dec) C:\WINDOWS\system32\drivers\WmXlCore.sys 09:36:46.0453 2952 WmXlCore - ok 09:36:46.0531 2952 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 09:36:46.0640 2952 WpdUsb - ok 09:36:47.0046 2952 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 09:36:47.0062 2952 WS2IFSL - ok 09:36:47.0343 2952 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 09:36:47.0375 2952 WudfPf - ok 09:36:47.0875 2952 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 09:36:47.0937 2952 WudfRd - ok 09:36:48.0046 2952 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 09:36:52.0875 2952 \Device\Harddisk0\DR0 - ok 09:36:52.0937 2952 Boot (0x1200) (f926653c38f5e7cf6a08e058c59b7ae9) \Device\Harddisk0\DR0\Partition0 09:36:52.0968 2952 \Device\Harddisk0\DR0\Partition0 - ok 09:36:52.0968 2952 ============================================================ 09:36:52.0968 2952 Scan finished 09:36:52.0968 2952 ============================================================ 09:36:53.0000 4024 Detected object count: 0 09:36:53.0000 4024 Actual detected object count: 0 09:38:18.0187 0776 Deinitialize success
Hi Wicked Kitt_E,

No don't worry about running GMER.
———-

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    i8042prt.sys
    
    :reg
    HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
———–

In your next reply please post the logs created by CKScanner and SystemLook. :)
Hi Jeff, Here are the two requested files: CKScanner - Additional Security Risks - These are not necessarily bad c:\android-sdk-windows\docs\reference\java\security\spec\rsakeygenparameterspec.html c:\android-sdk-windows\docs\reference\javax\crypto\keygenerator.html c:\android-sdk-windows\docs\reference\javax\crypto\keygeneratorspi.html c:\program files\steam\steamapps\azcrew\counter-strike source\cstrike\materials\sprites\trails\crackedbeam.vmt c:\program files\steam\steamapps\azcrew\counter-strike source\cstrike\materials\sprites\trails\crackedbeam.vtf c:\steam\steamapps\common\call of duty black ops\zone\common\mp_cracked.ff c:\steam\steamapps\common\call of duty black ops\zone\english\en_mp_cracked.ff scanner sequence 3.GL.11.KIAPVK —– EOF —– SystemLook 30.07.11 by jpshortstuff Log created at 22:24 on 03/12/2011 by Deano-Casino Administrator - Elevation successful ========== filefind ========== Searching for "i8042prt.sys" C:\WINDOWS\system32\drivers\i8042prt.sys –a—- 52480 bytes [12:00 14/04/2008] [12:48 01/12/2011] 4A0B06AA8943C1E332520F7440C0AA30 ========== reg ========== [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt] "Type"= 0x0000000001 (1) "Start"= 0x0000000001 (1) "Group"="Keyboard Port" "ErrorControl"= 0x0000000001 (1) "DisplayName"="i8042 Keyboard and PS/2 Mouse Port Driver" "ImagePath"="system32\drivers\tskE.tmp" "Tag"= 0x0000000004 (4) [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt\Parameters] "PollingIterations"= 0x0000002ee0 (12000) "PollingIterationsMaximum"= 0x0000002ee0 (12000) "ResendIterations"= 0x0000000003 (3) "LayerDriver JPN"="kbd101.dll" "LayerDriver KOR"="kbd101a.dll" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt\Enum] "0"="ACPI\PNP0F13\3&61aaa01&0" "Count"= 0x0000000002 (2) "NextInstance"= 0x0000000002 (2) "1"="ACPI\PNP0303\3&61aaa01&0" "INITSTARTFAILED"= 0x0000000001 (1)
Hi Wicked Kitt_E, CKScanner has detected illegal software on your system. Besides being illegal, it's the number one way of infecting your system as all cracked/keygen software is infected. This forum, as well as all the other malware removal forums, do not support the use of illegal software except for their removal. If I were to continue helping you with illegal software installed, it could be construed in the eyes of the law as aiding and abetting a crime. I have worked up a fix for their removal. If you do not agree to this then this thread will be closed and no further help will be offered. Please let me know if you wish to continue.
Which software is illegal? I looked at the CKScanner and is the file under steam, what is that type of file? If it doesn't suppose to be there, then it can be taken off. We can proceed.
:thumbup:

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click VirusTotal

copy and paste the following into the upload a file box (one at a time if more than one file is listed)

C:\WINDOWS\system32\drivers\i8042prt.sys

scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.
———-
I'm not sure what info you needed for that virustotal but I give you both File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis: MD5: 4a0b06aa8943c1e332520f7440c0aa30 Date first seen: 2009-02-26 19:01:04 (UTC) Date last seen: 2011-12-02 17:46:43 (UTC) Detection ratio: 1/42 1 VT Community user(s) with a total of 19214 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: DA98A4B800100080CD5600D07A196E00FE352846.sys Submission date: 2011-12-02 17:46:43 (UTC) Current status: finished Result: 1 /42 (2.4%) Antivirus Version Last Update Result AhnLab-V3 2011.12.01.02 2011.12.01 - AntiVir 7.11.18.204 2011.12.02 - Antiy-AVL 2.0.3.7 2011.12.02 - Avast 6.0.1289.0 2011.12.02 - AVG 10.0.0.1190 2011.12.02 - BitDefender 7.2 2011.12.02 - ByteHero 1.0.0.1 2011.11.29 - CAT-QuickHeal 12.00 2011.12.02 - ClamAV 0.97.3.0 2011.12.02 - Commtouch 5.3.2.6 2011.12.02 - Comodo 10815 2011.12.02 - DrWeb 5.0.2.03300 2011.12.02 - Emsisoft 5.1.0.11 2011.12.02 - eSafe 7.0.17.0 2011.12.01 - eTrust-Vet 37.0.9599 2011.12.02 - F-Prot 4.6.5.141 2011.11.29 - F-Secure 9.0.16440.0 2011.12.02 - Fortinet 4.3.388.0 2011.12.02 - GData 22 2011.12.02 - Ikarus T3.1.1.109.0 2011.12.02 - Jiangmin 13.0.900 2011.12.02 - K7AntiVirus 9.119.5586 2011.12.02 - Kaspersky 9.0.0.837 2011.12.02 - McAfee 5.400.0.1158 2011.12.02 - McAfee-GW-Edition 2010.1D 2011.12.02 Microsoft 1.7903 2011.12.02 - NOD32 6668 2011.12.01 - Norman 6.07.13 2011.12.02 - nProtect 2011-12-02.01 2011.12.02 - Panda 10.0.3.5 2011.12.02 - PCTools 8.0.0.5 2011.12.02 - Prevx 3.0 2011.12.02 - Rising 23.86.04.02 2011.12.02 - Sophos 4.71.0 2011.12.02 - SUPERAntiSpyware 4.40.0.1006 2011.12.02 - Symantec 20111.2.0.82 2011.12.02 - TheHacker 6.7.0.1.352 2011.12.01 - TrendMicro 9.500.0.1008 2011.12.02 - VBA32 3.12.16.4 2011.12.01 - VIPRE 11192 2011.12.02 - ViRobot 2011.12.2.4805 2011.12.02 - VirusBuster 14.1.96.0 2011.12.02 - Additional information MD5 : 4a0b06aa8943c1e332520f7440c0aa30 SHA1 : 684d74767873a042de4ba26a7d322f1e7ca9d6f7 SHA256: db2452390ccfe67e0c5feb4fd42ca24abe2ddd40d0b22dd5f5b8f70416863918 VT Community User: angel1973 Reputation: 19214 credits Comment date: 2011-11-08 09:46:03 (UTC)
Great Job Wicked Kitt_E,

I wanted to be sure that the file is now safe. :)

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    File::
    c:\windows\system32\ConduitEngine.tmp
    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
    FF - prefs.js: browser.search.selectedEngine - My Web Search
    FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm593YYUS&ptb=yFNr5NpMFZ7vV0qkXYavEQ&ind=2011050817&ptnrS=ZUxdm593YYUS&si=&n=77de3341&psa=&st=kwd&searchfor=
    
    Folder::
    c:\program files\Ask.com
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "57601:TCP"=-
    "57601:UDP"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Here is the CFScript.txt into ComboFix.exe log.txt file:

ComboFix 11-12-04.04 - Deano-Casino 12/04/2011 18:52:36.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.136 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\system32\ConduitEngine.tmp"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Deano-Casino\Application Data\Toolbar4
c:\program files\Ask.com
c:\program files\Ask.com\assets\oobe\b.png
c:\program files\Ask.com\assets\oobe\bl.png
c:\program files\Ask.com\assets\oobe\br.png
c:\program files\Ask.com\assets\oobe\l.png
c:\program files\Ask.com\assets\oobe\pointer.png
c:\program files\Ask.com\assets\oobe\r.png
c:\program files\Ask.com\assets\oobe\t.png
c:\program files\Ask.com\assets\oobe\tl.png
c:\program files\Ask.com\assets\oobe\tr.png
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_18b.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\precache.exe
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\Updater\config.xml
c:\program files\Ask.com\Updater\Updater.exe
c:\program files\Ask.com\UpdateTask.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-05 to 2011-12-05 )))))))))))))))))))))))))))))))
.
.
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47 . 2011-11-18 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\3B35B
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39 . 2011-11-16 15:39 ——– d—–w- c:\documents and settings\All Users\Application Data\F3A9
2011-11-12 14:51 . 2011-11-12 14:52 ——– d—–w- c:\documents and settings\Deano-Casino\Local Settings\Application Data\PageRage
2011-11-08 00:18 . 2011-11-08 00:18 ——– d—–w- c:\documents and settings\Deano-Casino\.autodesk
2011-11-06 01:14 . 2011-11-06 01:14 ——– d—–w- c:\program files\FunnyGames
2011-11-05 04:48 . 2011-11-09 20:06 ——– d—–w- C:\Remote Programs
2011-11-05 04:47 . 2011-06-22 16:44 53314 ——w- c:\windows\ExentInfo.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-01_23.54.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-05 00:07 . 2011-12-05 00:07 16384 c:\windows\Temp\Perflib_Perfdata_44c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-09-01 16:16 2532680 —-a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Updater Service for StartNow Toolbar"=2 (0x2)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Documents and Settings\\The Crew\\My Documents\\Downloads\\FlvPlayerSetup.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 1:19 PM 297168]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/12/2011 9:59 AM 1025352]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [8/18/2011 1:33 AM 7390560]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134480]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24144]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 27216]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-05 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-05 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-05 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-11-12 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-10-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-05 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 19:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="system32\drivers\tskE.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
Completion time: 2011-12-04 19:19:05
ComboFix-quarantined-files.txt 2011-12-05 02:19
ComboFix2.txt 2011-12-02 04:51
ComboFix3.txt 2011-12-02 00:03
.
Pre-Run: 45,462,695,936 bytes free
Post-Run: 45,451,259,904 bytes free
.
- - End Of File - - B84122C46C766B86D1C8BDD6A05E9447

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI