This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojans/Worms/Antivirus2009 popup problems

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi:
This forum has helped me keep my PC running smooth for some time, but have a new problem now. It seems to start when I click on a Google search result link in IE, then a pop-up comes up saying I have some serious threats (Trojans,Worms etc.) and immediate attention is needed. It (Windows Security) says I can remove them after downloading Antivirus2009 or something, but that just leads me to a never ending cycle of clicking boxes. I removed a few things with Spybot but the pop up still comes up.
Thanks in advance and here's me Hijack This log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:01 PM, on 2/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O1 - Hosts: HP79BEAB HP0017A479BEAB
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKCU\..\Run: [ApacheAirAssault_Setup.exe] C:\DOWNLO~1\APACHE~1.EXE /r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/24/install/gtdownls.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
O23 - Service: WPS Scanner Service (WPSScannerSvc) - Skyhook Wireless - C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe

–
End of file - 11647 bytes
Hi BobDylan,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi Tomk - thanks for the help.
I've done the ATF cleaner and the Malwarebyte Anti-Malware removed 38 threats.
The PC runs smooth but I still get the Antivirus 2009 popup when I click on a few, but not all, Google search result links - actually, just in playing around with Google, it's really only the initial search result that started this that does it - not sure what to make of that.
Here are the Malwarebyte log and then the new HJT log.
Thanks so much again!

Malwarebytes' Anti-Malware 1.33
Database version: 1654
Windows 5.1.2600 Service Pack 2

2/3/2009 12:20:42 AM
mbam-log-2009-02-03 (00-20-42).txt

Scan type: Quick Scan
Objects scanned: 69609
Time elapsed: 14 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 35
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Adware.AskSBAR) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{f0d4b230-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23a-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23c-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b15fd82e-85bc-430d-90cb-65db1b030510} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cpbrkpie.coupon6ctrl.1 (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a85a5e6a-de2c-4f4e-99dc-f469df5a0eec} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp.1 (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\optimizer.adssite2 (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\optimizer.adssite2.1 (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{48dc6ffb-64d7-42e8-949d-8ef2641eb73a} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9c8a568e-4201-478a-8536-526cf371d2e2} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{b4094603-dda9-4caf-9b13-0ad1034c9c53} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9c8a568e-4201-478a-8536-526cf371d2e2} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f31b3634-12aa-41ca-b021-0685c3b3e4ca} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{36a91cec-6c71-4758-b492-397bfc8e96a2} (Adware.Rightonadz) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{343ce214-9998-4b21-a151-ffe970167297} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adssite (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\adssite (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\HID_Layer (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Adware.AskSBAR) -> Delete on reboot.
C:\WINDOWS\CouponPrinter.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\adssite-remove.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.



HIJACK THIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:41:05 AM, on 2/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O1 - Hosts: HP79BEAB HP0017A479BEAB
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKCU\..\Run: [ApacheAirAssault_Setup.exe] C:\DOWNLO~1\APACHE~1.EXE /r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/24/install/gtdownls.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
O23 - Service: WPS Scanner Service (WPSScannerSvc) - Skyhook Wireless - C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe

–
End of file - 11283 bytes
BobDylan,

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 12…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u12-windows-i586-p.exe to install the newest version.

Then let's dig a little deeper.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Tomk:
I've taken care of the Java thing and successfully ran ComboFix, and re-enabled all the antivirus/spyware. Still no obvious problems with the PC, other than that one Google search which still comes up with this pop-up:

"Warning!!! Your computer contains various signs of viruses and malware programs presences.
Your system requires immediate antiviruses check! Antivirus 2009 will perform a quick and free scanning of your PC for viruses and malicious programs" (Then I have to use the Task Manager to get out of those screens.)

Another odd thing that happened today was we got a call saying someone may have gotten my credit card number from Paypal, so we had to cancel that - and this all seemed to happen after I was doing something involving Paypal and that one link from Google which is giving me problems (A Youth League Management website for my daughter's softball)- so I'm thinking it's all related. Not sure if all this background info is helpful for you, but thought I'd throw it in there.

So here's the lengthy ComboFix log and a new HJT log
Thanks again for your time!


COMBOFIX Log

ComboFix 09-02-02.04 - Peter 2009-02-03 13:46:31.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.638.196 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\calculator.exe
c:\documents and settings\Peter\Application Data\Adssite Advanced Toolbar
c:\documents and settings\Peter\Application Data\Adssite Advanced Toolbar\advertbuttons.xml
c:\documents and settings\Peter\Application Data\Adssite Advanced Toolbar\selected.xml
c:\documents and settings\Peter\Desktop\Games.url
c:\documents and settings\peter\favorites\Download programs.url
c:\documents and settings\peter\favorites\Games.url
c:\documents and settings\peter\favorites\Translator.url
c:\documents and settings\peter\favorites\Videos.url
c:\documents and settings\Peter\Start Menu\Programs\Download programs.url
c:\documents and settings\Peter\Start Menu\Programs\Games.url
c:\documents and settings\Peter\Start Menu\Programs\Translator.url
c:\documents and settings\Peter\Start Menu\Programs\Videos.url
c:\program files\Adssite Advanced Toolbar
c:\program files\Adssite Advanced Toolbar\buttons.xml
c:\program files\Adssite Advanced Toolbar\search.xml
c:\program files\Adssite Advanced Toolbar\uninstall.exe
c:\program files\Adssite Games Collection
c:\program files\Adssite Games Collection\BattlesOfHelicopters.exe
c:\program files\Adssite Games Collection\BobAndBill.exe
c:\program files\Adssite Games Collection\CrazyBlocks.exe
c:\program files\Adssite Games Collection\Lines.exe
c:\program files\Adssite Games Collection\uninstall.exe
c:\program files\Adssite Games Collection\VideoPool.exe
C:\setup.exe
C:\test.txt
c:\windows\bundles
c:\windows\bundles\1stpublisher.exe
c:\windows\bundles\2504041019.exe
c:\windows\bundles\58kd52fg.exe
c:\windows\bundles\activeshopper.exe
c:\windows\bundles\adl_dh.exe
c:\windows\bundles\adl_hl.exe
c:\windows\bundles\adl_ibis_AS2.exe
c:\windows\bundles\adl_mteststub.exe
c:\windows\bundles\adl_zeno.exe
c:\windows\bundles\AdSmartMedia_bundle.exe
c:\windows\bundles\adv0ltc0m.exe
c:\windows\bundles\ast_5_adsav.exe
c:\windows\bundles\b2s-162813.exe
c:\windows\bundles\Beryllium.exe
c:\windows\bundles\Beryllium1.exe
c:\windows\bundles\bs5-goodyr1.exe
c:\windows\bundles\bs5-vwqouc.exe
c:\windows\bundles\CSv12P108.exe
c:\windows\bundles\CSV7P070.exe
c:\windows\bundles\cxt_big.exe
c:\windows\bundles\cxt_wmg.exe
c:\windows\bundles\cxtpls_loader.exe
c:\windows\bundles\d_ic.exe
c:\windows\bundles\d_otbp.exe
c:\windows\bundles\dealhelper.exe
c:\windows\bundles\Decade.exe
c:\windows\bundles\dh_vl.exe
c:\windows\bundles\e2g51.exe
c:\windows\bundles\EDow_vl.exe
c:\windows\bundles\ei51.exe
c:\windows\bundles\ez_advolt.exe
c:\windows\bundles\ezStubseedcorn.exe
c:\windows\bundles\gogotoolsSILAWO8pi.exe
c:\windows\bundles\HelperInstaller.exe
c:\windows\bundles\HLInstaller.exe
c:\windows\bundles\icmedia2_56.exe
c:\windows\bundles\ICMMedia_1cmm3d1a.exe
c:\windows\bundles\iehost.exe
c:\windows\bundles\installcasino.exe
c:\windows\bundles\james_dh.exe
c:\windows\bundles\KnNe1.exe
c:\windows\bundles\mfs.exe
c:\windows\bundles\mfsetup.exe
c:\windows\bundles\mstub-pal_nmw_a352_r15800.exe
c:\windows\bundles\new_vcm.exe
c:\windows\bundles\newmb.exe
c:\windows\bundles\NzI0MDo4OjEy.exe
c:\windows\bundles\optimizejames.exe
c:\windows\bundles\OTY2MTo4OjEy.exe
c:\windows\bundles\package8033_MARKETING5.exe
c:\windows\bundles\pounder.exe
c:\windows\bundles\rop_marketing_1_168.exe
c:\windows\bundles\ropbundle.exe
c:\windows\bundles\runsearch.exe
c:\windows\bundles\s4Sept.exe
c:\windows\bundles\sahagent-dectest1001.exe
c:\windows\bundles\sahagent-onlinetrafficbroker1001.exe
c:\windows\bundles\sahagent-seedcorn1002.exe
c:\windows\bundles\saie1101.exe
c:\windows\bundles\search_toolbar.exe
c:\windows\bundles\seedcorn.exe
c:\windows\bundles\setup_Incredifind_TrafficSpec.exe
c:\windows\bundles\setup_silent_26221.exe
c:\windows\bundles\Setup1171.exe
c:\windows\bundles\setupactiv2.exe
c:\windows\bundles\SetupCasino.exe
c:\windows\bundles\shopinst.exe
c:\windows\bundles\snackman.exe
c:\windows\bundles\ssee.exe
c:\windows\bundles\SSK_B5.EXE
c:\windows\bundles\SSK_I.exe
c:\windows\bundles\stlb2_seed.exe
c:\windows\bundles\thin-8-1-x-x.exe
c:\windows\bundles\thinadvolt.exe
c:\windows\bundles\tinko_vcm.exe
c:\windows\bundles\trade.exe
c:\windows\bundles\TVM_B5_Bundle_8.EXE
c:\windows\bundles\txdesuf.exe
c:\windows\bundles\ucmoreiex.exe
c:\windows\bundles\ventura1.exe
c:\windows\bundles\videoinst.exe
c:\windows\bundles\vl_ezstub.exe
c:\windows\bundles\vrinstall_icmedia.exe
c:\windows\bundles\WebRebates_Auto_InstallSilent.exe
c:\windows\bundles\winversion.exe
c:\windows\bundles\wrapperouter.exe
c:\windows\system32\Cache
c:\windows\system32\Cache\uninstall.exe
c:\windows\system32\config.dat
c:\windows\system32\dbxDgrevCheck.dll
c:\windows\system32\gzmrot-uninst.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ZESOFT


((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.

2009-02-03 12:29 . 2009-02-03 12:28 410,984 –a—— c:\windows\SYSTEM32\deploytk.dll
2009-02-03 12:29 . 2009-02-03 12:28 73,728 –a—— c:\windows\SYSTEM32\javacpl.cpl
2009-02-02 23:49 . 2009-02-02 23:49 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-02 23:49 . 2009-01-14 16:11 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-02-02 23:49 . 2009-01-14 16:11 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-31 21:55 . 2009-01-31 21:56 73,640,195 –a—— C:\38447_ring_of_fire.wmv
2009-01-31 21:48 . 2009-01-31 21:49 50,863,157 –a—— C:\38447_Second_Hand_News.wmv
2009-01-31 21:39 . 2009-01-31 21:41 84,056,771 –a—— C:\38447_Sweet_Caroline.wmv
2009-01-27 12:10 . 2009-01-27 12:10 d——– c:\documents and settings\Alex\Application Data\DisplayTune
2009-01-20 08:15 . 2009-02-01 22:33 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-20 08:15 . 2009-01-20 08:15 1,409 –a—— c:\windows\QTFont.for
2009-01-12 18:40 . 2009-01-12 18:41 d——– c:\documents and settings\Peter\.frugoo_file_store_32
2009-01-05 13:27 . 2009-01-05 13:27 d——– c:\program files\Coupons

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 17:52 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 17:28 ——— d—–w c:\program files\Java
2009-02-03 07:37 ——— d—–w c:\program files\Full Tilt Poker
2009-02-03 04:52 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-01 18:41 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-27 19:04 ——— d—–w c:\documents and settings\Peter\Application Data\DisplayTune
2008-12-26 18:17 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-26 18:16 ——— d—–w c:\program files\Portrait Displays
2008-12-26 18:16 ——— d—–w c:\program files\Common Files\Portrait Displays
2008-12-21 19:37 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-12-21 19:37 ——— d—–w c:\program files\Adobe Media Player
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-09 00:37 ——— d—–w c:\documents and settings\Peter\Application Data\MSN6
2008-10-13 14:26 24 —-a-w c:\documents and settings\Peter\jagex_runescape_preferences.dat
2006-05-01 23:57 32 —-a-r c:\documents and settings\All Users\hash.dat
2006-01-04 04:08 212,849 —-a-w c:\program files\hijackthis.zip
2006-01-02 20:56 6,224,992 —-a-w c:\program files\TrojanHunter.exe
2005-12-19 01:18 15,271,071 —-a-w c:\program files\thesims2_update_cd.zip
2005-12-19 01:15 444,161 —-a-w c:\program files\TS2SysReqc.zip
2005-12-18 06:55 10,940,595 —-a-w c:\program files\GP5DEMO.exe
2005-12-15 15:50 10,537,576 —-a-w c:\program files\zlsSetup_61_737_000_en.exe
2005-12-11 20:51 5,037,072 —-a-w c:\program files\spybotsd14.exe
2005-12-10 16:08 561,810 —-a-w c:\program files\country_cottage.zip
2005-12-09 20:57 12,820,430 —-a-w c:\program files\atgset.zip
2005-12-09 20:52 66,218 —-a-w c:\program files\k860slava_lamp_4.zip
2005-12-08 23:29 49,011 —-a-w c:\program files\k8sprwall6.zip
2005-12-08 23:27 2,989,597 —-a-w c:\program files\sprset.zip
2005-12-08 04:54 703 —-a-w c:\program files\DelTypedURL.inf
2005-03-29 04:36 276,408 —-a-w c:\program files\CleanUp312.exe
2005-03-27 08:05 76,551 —-a-w c:\program files\bholist.txt
2005-03-26 04:51 42,171 —-a-w c:\program files\KillBox.zip
2005-03-20 18:09 320,000 —-a-w c:\program files\IE-SPYAD2.exe
2005-03-20 17:48 5,205,858 —-a-w c:\program files\ZoneAlarm.exe
2005-03-19 21:10 2,179,792 —-a-w c:\program files\CWShredder.exe
2005-01-29 12:44 168 —-a-w c:\program files\AdbeRdr70_enu_full_FEAD_error.log
2005-01-29 08:28 20,798,256 —-a-w c:\program files\AdbeRdr70_enu_full.exe
2005-01-29 05:13 2,606,037 —-a-w c:\program files\692509.pdf
2005-01-28 23:47 12,404 —-a-w c:\program files\WildChild.ttf
2004-01-02 07:39 814 —-a-w c:\documents and settings\Peter\CDQUEUE.DAT
2008-02-01 04:30 131,584 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 19:50 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 19:50 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 19:50 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-01-18 10:06 278,528 —-a-w c:\program files\mozilla firefox\components\nsBrowserCmp.dll
2009-01-04 19:50 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 19:50 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-08-27 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-08-27 20:58 66912 –a—— c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-07 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-10-29 86016]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 292152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-15 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-28 1261336]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-06-29 278528]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless USB Utility.lnk - c:\program files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe [2005-10-28 1404928]
SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2005-10-17 421888]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=c:\windows\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Peter^Start Menu^Programs^Startup^Greetings Workshop Reminders.lnk]
path=c:\documents and settings\Peter\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk
backup=c:\windows\pss\Greetings Workshop Reminders.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\AIM\\aim.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2008-05-27 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-04 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-05-27 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2008-05-27 76040]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\Peter\LOCALS~1\Temp\cdiskdun.sys –> c:\docume~1\Peter\LOCALS~1\Temp\cdiskdun.sys [?]
S3 epstw2k;SCM Parallel Port SCSI Driver;c:\windows\SYSTEM32\DRIVERS\epstw2k.sys [2003-12-29 114944]
S3 scsiscan;SCSI Scanner Driver;c:\windows\SYSTEM32\DRIVERS\scsiscan.sys [2003-12-29 10880]
S3 SMC2862W;SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter Driver;c:\windows\SYSTEM32\DRIVERS\2862WICB.sys [2007-09-30 357632]
S3 USB Wireless USB Adapter®;USB Wireless USB Adapter® Service for Wireless USB Adapter;c:\windows\SYSTEM32\DRIVERS\vnetusbr.sys [2005-02-22 100736]
S4 bvvldjfyxpvvgd;bvvldjfyxpvvgd; [x]
S4 fdgxmlaaejlee;fdgxmlaaejlee; [x]
S4 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-07-16 29744]
S4 luiqfhomyuoiflj;luiqfhomyuoiflj; [x]
S4 mteowffwpug;mteowffwpug; [x]
S4 vytptojndhrw;vytptojndhrw; [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder

2009-02-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ApacheAirAssault_Setup.exe - c:\downlo~1\APACHE~1.EXE
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
HKLM-Run-PRISMSVR.EXE - c:\program files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g
MSConfigStartUp-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
Trusted Zone: adobe.com
Trusted Zone: comcast.net\www
Trusted Zone: frugooscape.net
Trusted Zone: partypoker.com\www
DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - hxxp://www.digitalwebbooks.com/reader/dbplugin.cab
FF - ProfilePath - c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\hom35zvs.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\progra~1\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\progra~1\Mozilla Firefox\components\nsBrowserCmp.dll
FF - component: c:\progra~1\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 13:54:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1511319073-2591443367-2869321682-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1212)
c:\windows\System32\BCMLogon.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SYSTEM32\DRIVERS\KodakCCS.exe
c:\windows\SYSTEM32\HPZipm12.exe
c:\windows\SYSTEM32\ScsiAccess.EXE
c:\windows\SYSTEM32\TCPSVCS.EXE
c:\windows\SYSTEM32\snmp.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\wanmpsvc.exe
c:\windows\SYSTEM32\WLTRYSVC.EXE
c:\program files\Linksys Wireless-G PCI Adapter\WLService.exe
c:\program files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
c:\program files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\SYSTEM32\BCMWLTRY.EXE
c:\windows\SYSTEM32\wscntfy.exe
c:\program files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.exe
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
.
**************************************************************************
.
Completion time: 2009-02-03 14:03:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-03 19:02:52
ComboFix2.txt 2007-09-27 04:17:19

Pre-Run: 2,130,161,664 bytes free
Post-Run: 2,508,296,192 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

368 — E O F — 2009-02-03 17:58:41



HIJACKTHIS Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:21:09 PM, on 2/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/24/install/gtdownls.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
O23 - Service: WPS Scanner Service (WPSScannerSvc) - Skyhook Wireless - C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe

–
End of file - 10301 bytes
BobDylan,

There are signs of several infections on your machine. There are remnants of others. I'm guessing you've had some ongoing problems and have managed to get them mostly cleaned up by yourself? I don't specifically see the cause of the paypal incident. But that doesn't mean you didn't have a backdoor trojan that I'm not seeing now. Because of your experience, here is the warning I would have given you:

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    
    Folder::
    c:\program files\Full Tilt Poker
    
    dds::
    Trusted Zone: partypoker.com\www
    
    Driver::
    bvvldjfyxpvvgd
    fdgxmlaaejlee
    luiqfhomyuoiflj
    mteowffwpug
    vytptojndhrw
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • Rooter report
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Hi Tomk:
Thanks for your concern and advice about my PC's security. I did use another computer to change the passwords for my email, paypal, etc as I'd really like to try to avoid re-formatting the PC. I really don't have much financial stuff on this one except for the PayPal and hopefully with both the card and the password being changed, that will be enough.

Going back to that Antivirus 2009 virus thing - I Googled that and I guess it's a rogue virus that's going around. They had some fixes for it that I could try, but should I wait for your suggestions on taking care of it? One site said the Malwarebytes should have eradicated it, but I think it's still there after we did that.

I finally finished all the scans and fixes you asked for and here are the Rooter report, Combofix, Kasperskyreport and new HJT logs, in that order.

Thanks again!

ROOTER REPORT

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.53GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A03
USER : Peter ( Administrator )
BOOT : Normal boot

Antivirus : AVG Anti-Virus Free 8.0 (Activated)


A:\ (USB)
C:\ (Local Disk) - NTFS - Total:37 Go (Free:2 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

Tue 02/03/2009|17:19

———————-\\ Search..

No infections found !


COMBOFIX.TXT
ComboFix 09-02-02.04 - Peter 2009-02-03 17:42:09.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.638.214 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Peter\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Full Tilt Poker
c:\program files\Full Tilt Poker\application.prefs
c:\program files\Full Tilt Poker\Cache\13_omaha_03et.png
c:\program files\Full Tilt Poker\Cache\1Million-DCS.png
c:\program files\Full Tilt Poker\Cache\42D4EB830001.dc
c:\program files\Full Tilt Poker\Cache\5050_guarantee_DCS_03.png
c:\program files\Full Tilt Poker\Cache\50KHorse_DCS.png
c:\program files\Full Tilt Poker\Cache\6_ring_21et.png
c:\program files\Full Tilt Poker\Cache\750-DCS.png
c:\program files\Full Tilt Poker\Cache\allen-cunningham-team-full-tilt.png
c:\program files\Full Tilt Poker\Cache\aussie_millions_DCS.png
c:\program files\Full Tilt Poker\Cache\aussiemill_last_dcs.png
c:\program files\Full Tilt Poker\Cache\centerFrame_ftops_03.png
c:\program files\Full Tilt Poker\Cache\centerFrame_ftops_III_34.png
c:\program files\Full Tilt Poker\Cache\ChipReese_client_DCS.png
c:\program files\Full Tilt Poker\Cache\daily-double.png
c:\program files\Full Tilt Poker\Cache\dcs-holiday100k.png
c:\program files\Full Tilt Poker\Cache\Double_Deuce_DCS.png
c:\program files\Full Tilt Poker\Cache\en-0100-happy-hour-DCS.png
c:\program files\Full Tilt Poker\Cache\en-0600_HappyHourDCS.png
c:\program files\Full Tilt Poker\Cache\en-1400-happy-hour-DCS.png
c:\program files\Full Tilt Poker\Cache\en-1500_HappyHourDCS.png
c:\program files\Full Tilt Poker\Cache\en-150seats.png
c:\program files\Full Tilt Poker\Cache\en-1900_HappyHourDCS.png
c:\program files\Full Tilt Poker\Cache\en-2300_HappyHourDCS.png
c:\program files\Full Tilt Poker\Cache\en-25k-heads-up-plo-world-championship-on-now.png
c:\program files\Full Tilt Poker\Cache\en-25k-heads-up-plo-world-championship-saturday.png
c:\program files\Full Tilt Poker\Cache\en-25k_Heads_Up_Champion_DCS.png
c:\program files\Full Tilt Poker\Cache\en-3xmas-0100et.png
c:\program files\Full Tilt Poker\Cache\en-3xmas-2300et.png
c:\program files\Full Tilt Poker\Cache\en-3xmas-now-running.png
c:\program files\Full Tilt Poker\Cache\en-benyamine-dcs.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-event08.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-event09.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-event11.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-event13.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-event18.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-event21.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-event22.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-mainevent.png
c:\program files\Full Tilt Poker\Cache\en-ftops-ix-more.png
c:\program files\Full Tilt Poker\Cache\en-fTOPS-VIII-Event1.png
c:\program files\Full Tilt Poker\Cache\en-ftops-viii-more.png
c:\program files\Full Tilt Poker\Cache\en-ftops-xi-more.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event13.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event14.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event16.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event17.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event20.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event21.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event22.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event24.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event6.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event7.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event8.png
c:\program files\Full Tilt Poker\Cache\en-FTOPS_VIII_Event9.png
c:\program files\Full Tilt Poker\Cache\en-h3-all-games-2200.png
c:\program files\Full Tilt Poker\Cache\en-h3-on-now.png
c:\program files\Full Tilt Poker\Cache\en-HappyHourDCS.png
c:\program files\Full Tilt Poker\Cache\en-hollink-dcs.png
c:\program files\Full Tilt Poker\Cache\en-ironman-myb-dcs.png
c:\program files\Full Tilt Poker\Cache\en-jens-vortmann-dcs.png
c:\program files\Full Tilt Poker\Cache\en-Limit_HappyHourDCS.png
c:\program files\Full Tilt Poker\Cache\en-matrix.png
c:\program files\Full Tilt Poker\Cache\en-msop-dcs.png
c:\program files\Full Tilt Poker\Cache\en-Ring_HappyHourDCS.png
c:\program files\Full Tilt Poker\Cache\en-seidel-foxwoods.png
c:\program files\Full Tilt Poker\Cache\en-sit-GoMadnessIII.png
c:\program files\Full Tilt Poker\Cache\en-sng-madness-IV.png
c:\program files\Full Tilt Poker\Cache\en-superbowl-happy-pre-dcs.png
c:\program files\Full Tilt Poker\Cache\en-take2-pre-event-dcs.png
c:\program files\Full Tilt Poker\Cache\en-take2-pre-event-new-dcs.png
c:\program files\Full Tilt Poker\Cache\en-take2-running-dcs.png
c:\program files\Full Tilt Poker\Cache\en-triple-debate-running-dcs.png
c:\program files\Full Tilt Poker\Cache\en-triple-thanksgiving-dcs.png
c:\program files\Full Tilt Poker\Cache\en-triple-thanksgiving-running-dcs.png
c:\program files\Full Tilt Poker\Cache\en-wsop-08-pescatori-dcs.png
c:\program files\Full Tilt Poker\Cache\en-wsop-18-matusow.png
c:\program files\Full Tilt Poker\Cache\en-wsop-event1-medic-v2.png
c:\program files\Full Tilt Poker\Cache\en-wsop-tran-dcs.png
c:\program files\Full Tilt Poker\Cache\en-wsope-winner-08-dcs.png
c:\program files\Full Tilt Poker\Cache\european07_dcs_2.png
c:\program files\Full Tilt Poker\Cache\event-main-event.jpg
c:\program files\Full Tilt Poker\Cache\event13-14.jpg
c:\program files\Full Tilt Poker\Cache\ftops-VII.png
c:\program files\Full Tilt Poker\Cache\ftops-x.png
c:\program files\Full Tilt Poker\Cache\ftops_VI.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event11.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event12.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event14.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event16.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event17-18.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event20.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event5.png
c:\program files\Full Tilt Poker\Cache\FTOPS_VII_Event6-7.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event01.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event05.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event06.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event07.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event09a.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event13.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event14.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event15.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event17.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event19.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event20.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event21.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_Event22.png
c:\program files\Full Tilt Poker\Cache\FTOPS_X_MainEvent.png
c:\program files\Full Tilt Poker\Cache\FTOPSV_event1213.png
c:\program files\Full Tilt Poker\Cache\hlwin-dcs.png
c:\program files\Full Tilt Poker\Cache\Ironman-EOY-DCS.png
c:\program files\Full Tilt Poker\Cache\Ironman_Plus_DCS.png
c:\program files\Full Tilt Poker\Cache\Ivey_LAPC_DCS.png
c:\program files\Full Tilt Poker\Cache\my-promotions.png
c:\program files\Full Tilt Poker\Cache\NewYear_DCS.png
c:\program files\Full Tilt Poker\Cache\pad-center-00.png
c:\program files\Full Tilt Poker\Cache\pad-center-01.png
c:\program files\Full Tilt Poker\Cache\PPA-centerframe_04.png
c:\program files\Full Tilt Poker\Cache\ppa-freeroll-dcs.jpg
c:\program files\Full Tilt Poker\Cache\sit-and-go-MadnessV.png
c:\program files\Full Tilt Poker\Cache\Sit-GoMadness.png
c:\program files\Full Tilt Poker\Cache\Sit&GoMadness;_2.png
c:\program files\Full Tilt Poker\Cache\SundayBrawl_DCS.png
c:\program files\Full Tilt Poker\Cache\votenplay_running_DCS.png
c:\program files\Full Tilt Poker\Cache\votenplay_starts_DCS.png
c:\program files\Full Tilt Poker\Cache\we-are-here-to-stay.png
c:\program files\Full Tilt Poker\Cache\Xmas-centerframe_04.png
c:\program files\Full Tilt Poker\DylanBob.dat
c:\program files\Full Tilt Poker\Fonts\Univers-Bold.otf
c:\program files\Full Tilt Poker\Fonts\Univers-Condensed.otf
c:\program files\Full Tilt Poker\Fonts\Univers-CondensedBold.otf
c:\program files\Full Tilt Poker\Fonts\Univers-CondensedLight.otf
c:\program files\Full Tilt Poker\Fonts\Univers-Light.otf
c:\program files\Full Tilt Poker\FullTiltPoker.exe
c:\program files\Full Tilt Poker\Graphics\Cashier\Bonus_Account_Box.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Bonus_Account_Table_Box.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Bonus_HappyHour_Left.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Bonus_HappyHour_Right.png
c:\program files\Full Tilt Poker\Graphics\Cashier\BonusAccount_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\BonusAccount_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Cashier.jpg
c:\program files\Full Tilt Poker\Graphics\Cashier\CashierBlue_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\CashierBlue_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Convert_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Convert_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\DCS_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\DCS_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\DepositOptions\Deposit_Verify.jpg
c:\program files\Full Tilt Poker\Graphics\Cashier\Detach_Win_Icon.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Exit_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Exit_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\FTPstore_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\FTPstore_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\GiftCert_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\GiftCert_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\History_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\History_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\InfoEdit_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\InfoEdit_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\MakeDepositLg_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\MakeDepositLg_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\MakeDepositSm_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\MakeDepositSm_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Progress_Bar_Green.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Progress_Bar_White.png
c:\program files\Full Tilt Poker\Graphics\Cashier\ReloadPlayChips_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\ReloadPlayChips_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Store_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Store_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Transfer_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Transfer_On.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Withdraw_Off.png
c:\program files\Full Tilt Poker\Graphics\Cashier\Withdraw_On.png
c:\program files\Full Tilt Poker\Graphics\CSChat\FTG_Left.png
c:\program files\Full Tilt Poker\Graphics\CSChat\FTG_Mid.png
c:\program files\Full Tilt Poker\Graphics\CSChat\FTG_Right.png
c:\program files\Full Tilt Poker\Graphics\CSChat\FTP_Logo.png
c:\program files\Full Tilt Poker\Graphics\CSChat\HeadingLine.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Simplified\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Chinese Traditional\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Sit&Go;_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Sit&Go;_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Sit&Go;_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Danish\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Dutch\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Finnish\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\French\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\French\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\German\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\German\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Italian\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Norwegian\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Portuguese\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\MixedGames_dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\MixedGames_off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\MixedGames_on.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\ProChat_dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\ProChat_off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\ProChat_on.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\SitNGo_dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\SitNGo_off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\SitNGo_on.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\Special_dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\Special_off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\Special_on.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\Tournaments_dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\Tournaments_off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\Tournaments_on.png
c:\program files\Full Tilt Poker\Graphics\LNG\Russian\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Spanish\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\Special_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\LNG\Swedish\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\CheckBox_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\CheckBox_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\chip_100percent.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\chip_20percent.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\0.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\1.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\2.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\3.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\4.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\5.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\6.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\7.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\8.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\9.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Clock\Colon.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Default_Adv.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\HideFullTables.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Legend.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\LoaderChip.gif
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Lobby.jpg
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\LobbyCenter.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\LobbyMiddle.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\PleaseCheck.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\PPA_Deck.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\PPA_Logo.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\PromotionSlider.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Refer_Splash.jpg
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\Show.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\SiteFound.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Backgrounds\VerticalLine.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\ArrowDown.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\ArrowUp.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Cashier_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Cashier_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Edit_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Edit_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\FTR_Play_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\FTR_Play_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\FTR_Play_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\FTR_Real_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\FTR_Real_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\FTR_Real_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\PlayerNotesColours.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\ProChat\ChatSchedule_center.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\ProChat\ChatSchedule_left.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\ProChat\ChatSchedule_right.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\ProChat\JoinChat_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\ProChat\JoinChat_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\Players\Players_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\Players\Players_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\Players\WaitingList_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\Players\WaitingList_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\Players\WaitingList_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\Tables\Checkbox.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\Tables\Stakes.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\ViewTable_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\ViewTable_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\WaitList_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Ring\WaitList_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\2Handed.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\6Handed.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\AddOn.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Bounty.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\DeepStack.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\DoubleStack.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\GoToTourneyLobby_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\GotoTourneyLobby_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\HappyHour.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Legend.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Matrix.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Rebuy.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\RegisterNow_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\RegisterNow_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\ShootOut.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\SitNGo\FTR_Satellites_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\SitNGo\FTR_Satellites_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_FTOPS_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_FTOPS_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_Guarantees_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_Guarantees_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_LiveEvents_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_LiveEvents_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_PAD_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_PAD_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_Satellites_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_Satellites_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_Series_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Special\FTR_Series_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Cash_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Cash_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_FTOPS_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_FTOPS_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Private_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Private_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Satellites_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Satellites_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Series_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Tourn\FTR_Series_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Buttons\Tourn\Turbo.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Chinese Simplified.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Chinese Traditional.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Czech.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Danish.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Dutch.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\English.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Finnish.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\French.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\German.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Italian.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Japanese.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Korean.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Norwegian.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Polish.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Portuguese.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Russian.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Spanish.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Swedish.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Language\Turkish.bmp
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\HoldEm_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\HoldEm_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\HoldEm_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\MixedGames_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\MixedGames_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\MixedGames_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Omaha_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Omaha_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Omaha_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\OmahaHiLo_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\OmahaHiLo_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\OmahaHiLo_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\ProChat_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\ProChat_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\ProChat_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Razz_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Razz_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Razz_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\SitNGo_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\SitNGo_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\SitNGo_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Special_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Special_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Special_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Stud_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Stud_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Stud_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\StudHiLo_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\StudHiLo_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\StudHiLo_On.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Tournaments_Dis.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Tournaments_Off.png
c:\program files\Full Tilt Poker\Graphics\Lobby\Tabs\Tournaments_On.png
c:\program files\Full Tilt Poker\Graphics\NewAccount\Help_Off.png
c:\program files\Full Tilt Poker\Graphics\NewAccount\Help_On.png
c:\program files\Full Tilt Poker\Graphics\NewAccount\ProgressBar_Off.png
c:\program files\Full Tilt Poker\Graphics\NewAccount\ProgressBar_On.png
c:\program files\Full Tilt Poker\Graphics\NewAccount\PromoImage0.png
c:\program files\Full Tilt Poker\Graphics\NewAccount\Tick_Off.png
c:\program files\Full Tilt Poker\Graphics\NewAccount\Tick_On.png
c:\program files\Full Tilt Poker\Graphics\ProChat\Logo.png
c:\program files\Full Tilt Poker\Graphics\ProChat\PostedQA.png
c:\program files\Full Tilt Poker\Graphics\ProChat\Question.png
c:\program files\Full Tilt Poker\Graphics\ProChat\QuestionFrom.png
c:\program files\Full Tilt Poker\Graphics\ProChat\Questions.png
c:\program files\Full Tilt Poker\Graphics\ProChat\Response.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Left_Dis.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Left_Off.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Left_On.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Mid_Dis.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Mid_Off.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Mid_On.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Right_Dis.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Right_Off.png
c:\program files\Full Tilt Poker\Graphics\System\BigBTN_Right_On.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Left_Dis.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Left_Off.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Left_On.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Mid_Dis.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Mid_Off.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Mid_On.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Right_Dis.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Right_Off.png
c:\program files\Full Tilt Poker\Graphics\System\BTN_Right_On.png
c:\program files\Full Tilt Poker\Graphics\System\FTR_Left_Off.png
c:\program files\Full Tilt Poker\Graphics\System\FTR_Left_On.png
c:\program files\Full Tilt Poker\Graphics\System\FTR_Mid_Off.png
c:\program files\Full Tilt Poker\Graphics\System\FTR_Mid_On.png
c:\program files\Full Tilt Poker\Graphics\System\FTR_Right_Off.png
c:\program files\Full Tilt Poker\Graphics\System\FTR_Right_On.png
c:\program files\Full Tilt Poker\Graphics\System\HDR_Divider.png
c:\program files\Full Tilt Poker\Graphics\System\HDR_Off.png
c:\program files\Full Tilt Poker\Graphics\System\HDR_On.png
c:\program files\Full Tilt Poker\Graphics\System\HDR2_Divider.png
c:\program files\Full Tilt Poker\Graphics\System\HDR2_Off.png
c:\program files\Full Tilt Poker\Graphics\System\HDR2_On.png
c:\program files\Full Tilt Poker\Graphics\System\Pattern_Short.jpg
c:\program files\Full Tilt Poker\Graphics\System\Pattern_Tall.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\emptybox.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\hilite_1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\hilite_2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\0\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\0\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\0\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\0\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\1\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\1\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\1\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\1\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\10\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\10\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\10\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\10\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\11\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\11\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\11\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\11\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\12\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\12\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\12\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\12\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\13\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\13\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\13\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\13\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\14\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\14\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\14\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\14\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\15\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\15\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\15\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\15\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\16\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\16\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\16\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\16\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\17\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\17\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\17\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\17\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\18\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\18\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\18\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\18\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\19\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\19\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\19\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\19\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\2\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\2\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\2\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\2\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\20\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\20\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\20\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\20\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\21\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\21\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\21\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\21\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\22\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\22\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\22\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\22\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\3\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\3\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\3\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\3\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\4\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\4\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\4\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\4\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\5\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\5\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\5\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\5\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\6\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\6\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\6\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\6\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\7\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\7\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\7\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\7\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\8\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\8\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\8\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\8\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\9\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\9\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\9\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\9\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Private\private.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\0\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\0\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\0\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\0\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\1\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\1\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\1\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\1\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\10\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\10\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\10\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\10\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\100\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\100\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\100\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\100\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\101\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\101\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\101\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\101\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\102\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\102\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\102\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\102\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\103\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\103\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\103\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\103\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\104\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\104\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\104\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\104\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\105\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\105\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\105\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\105\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\106\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\106\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\106\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\106\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\107\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\107\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\107\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\107\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\108\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\108\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\108\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\108\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\109\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\109\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\109\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\109\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\11\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\11\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\11\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\11\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\110\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\110\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\110\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\110\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\111\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\111\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\111\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\111\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\112\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\112\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\112\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\112\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\113\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\113\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\113\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\113\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\114\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\114\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\114\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\114\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\115\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\115\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\115\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\115\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\116\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\116\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\116\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\116\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\117\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\117\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\117\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\117\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\118\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\118\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\118\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\118\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\12\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\12\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\12\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\12\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\13\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\13\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\13\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\13\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\14\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\14\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\14\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\14\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\15\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\15\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\15\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\15\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\16\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\16\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\16\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\16\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\17\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\17\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\17\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\17\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\18\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\18\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\18\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\18\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\19\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\19\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\19\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\19\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\2\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\2\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\2\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\2\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\20\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\20\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\20\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\20\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\21\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\21\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\21\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\21\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\22\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\22\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\22\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\22\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\23\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\23\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\23\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\23\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\24\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\24\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\24\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\24\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\25\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\25\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\25\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\25\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\26\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\26\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\26\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\26\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\27\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\27\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\27\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\27\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\28\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\28\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\28\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\28\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\29\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\29\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\29\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\29\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\3\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\3\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\3\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\3\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\30\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\30\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\30\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\30\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\31\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\31\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\31\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\31\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\32\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\32\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\32\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\32\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\33\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\33\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\33\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\33\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\34\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\34\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\34\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\34\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\35\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\35\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\35\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\35\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\36\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\36\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\36\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\36\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\37\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\37\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\37\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\37\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\38\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\38\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\38\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\38\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\39\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\39\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\39\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\39\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\4\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\4\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\4\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\4\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\40\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\40\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\40\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\40\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\41\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\41\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\41\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\41\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\42\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\42\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\42\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\42\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\43\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\43\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\43\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\43\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\44\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\44\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\44\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\44\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\45\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\45\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\45\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\45\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\46\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\46\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\46\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\46\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\47\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\47\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\47\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\47\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\48\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\48\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\48\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\48\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\49\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\49\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\49\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\49\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\5\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\5\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\5\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\5\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\50\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\50\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\50\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\50\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\51\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\51\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\51\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\51\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\52\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\52\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\52\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\52\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\53\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\53\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\53\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\53\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\54\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\54\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\54\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\54\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\55\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\55\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\55\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\55\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\56\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\56\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\56\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\56\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\57\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\57\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\57\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\57\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\58\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\58\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\58\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\58\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\59\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\59\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\59\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\59\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\6\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\6\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\6\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\6\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\60\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\60\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\60\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\60\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\61\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\61\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\61\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\61\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\62\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\62\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\62\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\62\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\63\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\63\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\63\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\63\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\64\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\64\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\64\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\64\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\65\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\65\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\65\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\65\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\66\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\66\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\66\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\66\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\67\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\67\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\67\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\67\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\68\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\68\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\68\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\68\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\69\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\69\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\69\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\69\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\7\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\7\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\7\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\7\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\70\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\70\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\70\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\70\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\71\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\71\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\71\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\71\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\72\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\72\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\72\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\72\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\73\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\73\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\73\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\73\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\74\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\74\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\74\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\74\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\75\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\75\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\75\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\75\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\76\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\76\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\76\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\76\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\77\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\77\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\77\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\77\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\78\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\78\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\78\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\78\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\79\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\79\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\79\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\79\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\8\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\8\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\8\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\8\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\80\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\80\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\80\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\80\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\81\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\81\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\81\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\81\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\82\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\82\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\82\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\82\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\83\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\83\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\83\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\83\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\84\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\84\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\84\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\84\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\85\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\85\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\85\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\85\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\86\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\86\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\86\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\86\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\87\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\87\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\87\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\87\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\88\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\88\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\88\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\88\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\89\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\89\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\89\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\89\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\9\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\9\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\9\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\9\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\90\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\90\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\90\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\90\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\91\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\91\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\91\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\91\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\92\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\92\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\92\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\92\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\93\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\93\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\93\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\93\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\94\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\94\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\94\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\94\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\95\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\95\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\95\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\95\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\96\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\96\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\96\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\96\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\97\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\97\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\97\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\97\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\98\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\98\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\98\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\98\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\99\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\99\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\99\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\99\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Pro\pro.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\0\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\0\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\0\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\0\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\1\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\1\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\1\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\1\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\10\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\10\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\10\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\10\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\11\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\11\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\11\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\11\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\12\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\12\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\12\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\12\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\13\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\13\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\13\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\13\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\14\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\14\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\14\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\14\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\15\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\15\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\15\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\15\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\16\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\16\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\16\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\16\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\17\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\17\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\17\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\17\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\18\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\18\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\18\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\18\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\19\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\19\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\19\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\19\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\2\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\2\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\2\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\2\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\20\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\20\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\20\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\20\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\21\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\21\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\21\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\21\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\22\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\22\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\22\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\22\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\23\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\23\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\23\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\23\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\24\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\24\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\24\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\24\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\25\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\25\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\25\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\25\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\26\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\26\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\26\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\26\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\27\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\27\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\27\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\27\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\28\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\28\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\28\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\28\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\29\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\29\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\29\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\29\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\3\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\3\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\3\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\3\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\30\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\30\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\30\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\30\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\31\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\31\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\31\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\31\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\32\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\32\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\32\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\32\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\33\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\33\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\33\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\33\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\34\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\34\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\34\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\34\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\35\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\35\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\35\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\35\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\36\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\36\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\36\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\36\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\37\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\37\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\37\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\37\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\38\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\38\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\38\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\38\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\39\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\39\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\39\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\39\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\4\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\4\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\4\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\4\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\40\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\40\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\40\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\40\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\41\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\41\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\41\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\41\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\42\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\42\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\42\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\42\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\43\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\43\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\43\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\43\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\44\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\44\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\44\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\44\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\45\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\45\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\45\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\45\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\46\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\46\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\46\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\46\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\47\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\47\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\47\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\47\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\48\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\48\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\48\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\48\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\49\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\49\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\49\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\49\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\5\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\5\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\5\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\5\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\50\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\50\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\50\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\50\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\51\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\51\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\51\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\51\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\52\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\52\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\52\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\52\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\53\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\53\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\53\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\53\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\54\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\54\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\54\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\54\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\55\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\55\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\55\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\55\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\56\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\56\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\56\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\56\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\57\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\57\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\57\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\57\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\58\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\58\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\58\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\58\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\59\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\59\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\59\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\59\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\6\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\6\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\6\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\6\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\60\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\60\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\60\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\60\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\61\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\61\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\61\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\61\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\62\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\62\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\62\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\62\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\63\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\63\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\63\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\63\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\64\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\64\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\64\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\64\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\65\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\65\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\65\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\65\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\66\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\66\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\66\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\66\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\67\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\67\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\67\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\67\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\68\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\68\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\68\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\68\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\69\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\69\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\69\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\69\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\7\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\7\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\7\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\7\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\70\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\70\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\70\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\70\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\71\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\71\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\71\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\71\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\72\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\72\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\72\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\72\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\8\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\8\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\8\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\8\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\9\0.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\9\1.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\9\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\9\3.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\Public\public.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\SeatRT_Empty.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\SeatRT_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Avatars\SeatRT_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Backgrounds.ini
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Beach Scene\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Beach Scene\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Beach Scene\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Beach Scene\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Beach Scene\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Beach Scene\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Final Table\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Final Table\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Final Table\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Final Table\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Final Table\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Final Table\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Jungle\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Jungle\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Jungle\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Jungle\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Jungle\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Jungle\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Midnight\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Midnight\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Midnight\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Midnight\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Midnight\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Midnight\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Outer Space\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Outer Space\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Outer Space\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Outer Space\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Outer Space\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Outer Space\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Plain\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Plain\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Plain\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Plain\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Plain\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Plain\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Ski Lodge\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Ski Lodge\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Ski Lodge\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Ski Lodge\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Ski Lodge\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Ski Lodge\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Vegas Skyline\10.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Vegas Skyline\2.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Vegas Skyline\6.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Vegas Skyline\8.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Vegas Skyline\9.png
c:\program files\Full Tilt Poker\Graphics\Table\Backgrounds\Vegas Skyline\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\BigButton_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\BigButton_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\CheckBox_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\CheckBox_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\GetChips_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\GetChips_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Info_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Info_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\LastHand_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\LastHand_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\LastHandTourney_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\LastHandTourney_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Layout_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Layout_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Lobby_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Lobby_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\OptionCheckbox_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\OptionCheckbox_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\OptionRadiobutton_Disabled.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\OptionRadiobutton_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\OptionRadiobutton_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Options_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Options_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\PlayMoney_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\PlayMoney_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\PlayMoneyRT_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\PlayMoneyRT_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Rebuy_Disabled.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Rebuy_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Rebuy_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\RebuyInfo_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\RebuyInfo_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\SingleClick_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\SingleClick_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\SingleClickRT_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\SingleClickRT_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\SmallButton_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\SmallButton_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Stand-Up_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Stand-Up_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Stats_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Buttons\Stats_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\Classic_Avatars_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\Classic_Avatars_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\Classic_NoAvatars_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\Classic_NoAvatars_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\RaceTrack_Avatars_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\RaceTrack_Avatars_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\RaceTrack_NoAvatars_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Choose\RaceTrack_NoAvatars_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\AdvanceActions.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\AvatarShadow.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\button_3.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\CapAmountBG.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Cards0.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Cards1.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Cards2.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Cards3.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Cards4.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Cards5.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Cards6.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\CardSmall.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ChatAttach_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ChatAttach_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ChatDetach_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ChatDetach_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ChipCover.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Chips0.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Chips1.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Chips2.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Chips3.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Chips4.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Chips5.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Chips6.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Diodes.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Divider.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\DividerRT.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Gripper.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_0.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_1.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_2.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_3.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_4.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_5.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_6.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\ironman_chip_def.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Muted.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\OptionMenu.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\OptionMenuRT.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\PPA.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\RankDiodes.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderBox.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderBoxBig.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderBoxSmall.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderCap_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderCap_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderCapBig_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderCapBig_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderCapSmall_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderCapSmall_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderHalfPot_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderHalfPot_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderHalfPotBig_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderHalfPotBig_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderHalfPotSmall_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderHalfPotSmall_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMax_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMax_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMaxBig_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMaxBig_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMaxSmall_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMaxSmall_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMin_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMin_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMinBig_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMinBig_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMinSmall_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderMinSmall_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderPot_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderPot_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderPotBig_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderPotBig_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderPotSmall_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderPotSmall_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderThumb.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderThumbBig.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\SliderThumbSmall.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Table.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TableRT.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TimeBank_Active.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TimeBank_Disconnect.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TimeBank_Inactive.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TimeBank_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TimeBank_On.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TimeBank_Reconnect.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\Timer.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\TimerRT.png
c:\program files\Full Tilt Poker\Graphics\Table\Elements\YouHaveBeenMoved.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Chat.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Dealer.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\FastForward_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\FastForward_On.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\FastRewind_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\FastRewind_On.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Forward_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Forward_On.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Header_Left.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Header_Right.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\ObserverChat.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Pod.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\PodHighlight_Green.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\PodHighlight_Red.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Rewind_Off.png
c:\program files\Full Tilt Poker\Graphics\Table\LastHand\Rewind_On.png
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Backgrounds.ini
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Blue Carpet\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\FinalTable\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Gold Carpet\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Green Carpet\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Marble\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Red Carpet\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Stainless\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Table\RaceTrack\Wood\Table.jpg
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\FTP_Logo.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\Left.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\LeftShort.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\Lobby2.jpg
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\Lobby3.jpg
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\Main.jpg
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\MatrixLeft.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\MatrixRight.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\MatrixSatellites.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\MatrixView.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\Middle.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\Right.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Backgrounds\Satellite.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\Cashier_Off.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\Cashier_On.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\MainLobby_Off.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\MainLobby_On.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\ObserveTable_Off.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\ObserveTable_On.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\OpenSatelliteLobby_Off.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\OpenSatelliteLobby_On.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\RegisterNow_Off.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\RegisterNow_On.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\TakeYourSeat_Off.png
c:\program files\Full Tilt Poker\Graphics\Tournament\Buttons\TakeYourSeat_On.png
c:\program files\Full Tilt Poker\Hippl642.dat
c:\program files\Full Tilt Poker\Hippl642.xml
c:\program files\Full Tilt Poker\Install.log
c:\program files\Full Tilt Poker\libeay32.dll
c:\program files\Full Tilt Poker\libexpat.dll
c:\program files\Full Tilt Poker\libjpeg.dll
c:\program files\Full Tilt Poker\libpng.dll
c:\program files\Full Tilt Poker\Microsoft.VC80.CRT.manifest
c:\program files\Full Tilt Poker\msvcr80.dll
c:\program files\Full Tilt Poker\preferences.orig
c:\program files\Full Tilt Poker\ssleay32.dll
c:\program files\Full Tilt Poker\StmOCX.dll
c:\program files\Full Tilt Poker\unicows.dll
c:\program files\Full Tilt Poker\updater.exe
c:\program files\Full Tilt Poker\Waves\Alert-5.wav
c:\program files\Full Tilt Poker\Waves\Bell-2.wav
c:\program files\Full Tilt Poker\Waves\Bell-4.wav
c:\program files\Full Tilt Poker\Waves\Bell-5.wav
c:\program files\Full Tilt Poker\Waves\Bell-6.wav
c:\program files\Full Tilt Poker\Waves\Bell-7.wav
c:\program files\Full Tilt Poker\Waves\Bet-4.wav
c:\program files\Full Tilt Poker\Waves\Buzzer-2.wav
c:\program files\Full Tilt Poker\Waves\Checkmark-4.wav
c:\program files\Full Tilt Poker\Waves\Connect.avi
c:\program files\Full Tilt Poker\Waves\Deal-4.wav
c:\program files\Full Tilt Poker\Waves\Fold-3.wav
c:\program files\Full Tilt Poker\Waves\Mountain-9.wav
c:\program files\Full Tilt Poker\Waves\Raise-2.wav
c:\program files\Full Tilt Poker\Waves\Shuffle-4.wav
c:\program files\Full Tilt Poker\Waves\Sweep-3.wav
c:\program files\Full Tilt Poker\Waves\Sweep-5.wav
c:\program files\Full Tilt Poker\zlib1-ft.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_BVVLDJFYXPVVGD
——-\Legacy_FDGXMLAAEJLEE
——-\Legacy_LUIQFHOMYUOIFLJ
——-\Legacy_MTEOWFFWPUG
——-\Legacy_VYTPTOJNDHRW
——-\Service_bvvldjfyxpvvgd
——-\Service_fdgxmlaaejlee
——-\Service_luiqfhomyuoiflj
——-\Service_mteowffwpug
——-\Service_vytptojndhrw


((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.

2009-02-03 17:19 . 2009-02-03 17:20 d——– C:\Rooter$
2009-02-03 12:29 . 2009-02-03 12:28 410,984 –a—— c:\windows\SYSTEM32\deploytk.dll
2009-02-03 12:29 . 2009-02-03 12:28 73,728 –a—— c:\windows\SYSTEM32\javacpl.cpl
2009-02-02 23:49 . 2009-02-02 23:49 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-02 23:49 . 2009-01-14 16:11 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-02-02 23:49 . 2009-01-14 16:11 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-31 21:55 . 2009-01-31 21:56 73,640,195 –a—— C:\38447_ring_of_fire.wmv
2009-01-31 21:48 . 2009-01-31 21:49 50,863,157 –a—— C:\38447_Second_Hand_News.wmv
2009-01-31 21:39 . 2009-01-31 21:41 84,056,771 –a—— C:\38447_Sweet_Caroline.wmv
2009-01-27 12:10 . 2009-01-27 12:10 d——– c:\documents and settings\Alex\Application Data\DisplayTune
2009-01-20 08:15 . 2009-02-01 22:33 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-20 08:15 . 2009-01-20 08:15 1,409 –a—— c:\windows\QTFont.for
2009-01-12 18:40 . 2009-01-12 18:41 d——– c:\documents and settings\Peter\.frugoo_file_store_32
2009-01-05 13:27 . 2009-01-05 13:27 d——– c:\program files\Coupons

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 19:39 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-03 17:52 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 17:28 ——— d—–w c:\program files\Java
2009-02-03 04:52 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-01 18:41 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-27 19:04 ——— d—–w c:\documents and settings\Peter\Application Data\DisplayTune
2008-12-26 18:17 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-26 18:16 ——— d—–w c:\program files\Portrait Displays
2008-12-26 18:16 ——— d—–w c:\program files\Common Files\Portrait Displays
2008-12-21 19:37 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-12-21 19:37 ——— d—–w c:\program files\Adobe Media Player
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-09 00:37 ——— d—–w c:\documents and settings\Peter\Application Data\MSN6
2008-10-13 14:26 24 —-a-w c:\documents and settings\Peter\jagex_runescape_preferences.dat
2006-05-01 23:57 32 —-a-r c:\documents and settings\All Users\hash.dat
2006-01-04 04:08 212,849 —-a-w c:\program files\hijackthis.zip
2006-01-02 20:56 6,224,992 —-a-w c:\program files\TrojanHunter.exe
2005-12-19 01:18 15,271,071 —-a-w c:\program files\thesims2_update_cd.zip
2005-12-19 01:15 444,161 —-a-w c:\program files\TS2SysReqc.zip
2005-12-18 06:55 10,940,595 —-a-w c:\program files\GP5DEMO.exe
2005-12-15 15:50 10,537,576 —-a-w c:\program files\zlsSetup_61_737_000_en.exe
2005-12-11 20:51 5,037,072 —-a-w c:\program files\spybotsd14.exe
2005-12-10 16:08 561,810 —-a-w c:\program files\country_cottage.zip
2005-12-09 20:57 12,820,430 —-a-w c:\program files\atgset.zip
2005-12-09 20:52 66,218 —-a-w c:\program files\k860slava_lamp_4.zip
2005-12-08 23:29 49,011 —-a-w c:\program files\k8sprwall6.zip
2005-12-08 23:27 2,989,597 —-a-w c:\program files\sprset.zip
2005-12-08 04:54 703 —-a-w c:\program files\DelTypedURL.inf
2005-03-29 04:36 276,408 —-a-w c:\program files\CleanUp312.exe
2005-03-27 08:05 76,551 —-a-w c:\program files\bholist.txt
2005-03-26 04:51 42,171 —-a-w c:\program files\KillBox.zip
2005-03-20 18:09 320,000 —-a-w c:\program files\IE-SPYAD2.exe
2005-03-20 17:48 5,205,858 —-a-w c:\program files\ZoneAlarm.exe
2005-03-19 21:10 2,179,792 —-a-w c:\program files\CWShredder.exe
2005-01-29 12:44 168 —-a-w c:\program files\AdbeRdr70_enu_full_FEAD_error.log
2005-01-29 08:28 20,798,256 —-a-w c:\program files\AdbeRdr70_enu_full.exe
2005-01-29 05:13 2,606,037 —-a-w c:\program files\692509.pdf
2005-01-28 23:47 12,404 —-a-w c:\program files\WildChild.ttf
2004-01-02 07:39 814 —-a-w c:\documents and settings\Peter\CDQUEUE.DAT
2008-02-01 04:30 131,584 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 19:50 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 19:50 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 19:50 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-01-18 10:06 278,528 —-a-w c:\program files\mozilla firefox\components\nsBrowserCmp.dll
2009-01-04 19:50 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 19:50 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot@2009-02-03_14.01.17.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-03 18:56:53 64,200 —-a-w c:\windows\SYSTEM32\PERFC009.DAT
+ 2009-02-03 23:00:24 64,200 —-a-w c:\windows\SYSTEM32\PERFC009.DAT
- 2009-02-03 18:56:53 407,670 —-a-w c:\windows\SYSTEM32\PERFH009.DAT
+ 2009-02-03 23:00:24 407,670 —-a-w c:\windows\SYSTEM32\PERFH009.DAT
+ 2009-02-03 22:56:12 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_3dc.dat
+ 2009-02-03 22:56:22 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_70c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-08-27 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-08-27 20:58 66912 –a—— c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-07 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-10-29 86016]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 292152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-15 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-28 1261336]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-06-29 278528]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless USB Utility.lnk - c:\program files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe [2005-10-28 1404928]
SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2005-10-17 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2008-07-04 09:31 10520 c:\windows\SYSTEM32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=c:\windows\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Peter^Start Menu^Programs^Startup^Greetings Workshop Reminders.lnk]
path=c:\documents and settings\Peter\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk
backup=c:\windows\pss\Greetings Workshop Reminders.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\AIM\\aim.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2008-05-27 97928]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2008-05-27 76040]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-04 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-05-27 231704]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\Peter\LOCALS~1\Temp\cdiskdun.sys –> c:\docume~1\Peter\LOCALS~1\Temp\cdiskdun.sys [?]
S3 epstw2k;SCM Parallel Port SCSI Driver;c:\windows\SYSTEM32\DRIVERS\epstw2k.sys [2003-12-29 114944]
S3 scsiscan;SCSI Scanner Driver;c:\windows\SYSTEM32\DRIVERS\scsiscan.sys [2003-12-29 10880]
S3 SMC2862W;SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter Driver;c:\windows\SYSTEM32\DRIVERS\2862WICB.sys [2007-09-30 357632]
S3 USB Wireless USB Adapter®;USB Wireless USB Adapter® Service for Wireless USB Adapter;c:\windows\SYSTEM32\DRIVERS\vnetusbr.sys [2005-02-22 100736]
S4 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-07-16 29744]

— Other Services/Drivers In Memory —

*NewlyCreated* - GTNDIS5

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder

2009-02-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
Trusted Zone: adobe.com
Trusted Zone: comcast.net\www
Trusted Zone: frugooscape.net
DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - hxxp://www.digitalwebbooks.com/reader/dbplugin.cab
FF - ProfilePath - c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\hom35zvs.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\progra~1\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\progra~1\Mozilla Firefox\components\nsBrowserCmp.dll
FF - component: c:\progra~1\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 17:58:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1511319073-2591443367-2869321682-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1208)
c:\windows\system32\avgrsstx.dll
c:\windows\System32\BCMLogon.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SYSTEM32\DRIVERS\KodakCCS.exe
c:\windows\SYSTEM32\HPZipm12.exe
c:\windows\SYSTEM32\ScsiAccess.EXE
c:\windows\SYSTEM32\TCPSVCS.EXE
c:\windows\SYSTEM32\snmp.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\wanmpsvc.exe
c:\windows\SYSTEM32\WLTRYSVC.EXE
c:\program files\Linksys Wireless-G PCI Adapter\WLService.exe
c:\program files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
c:\program files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\windows\SYSTEM32\BCMWLTRY.EXE
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
.
**************************************************************************
.
Completion time: 2009-02-03 18:07:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-03 23:06:49
ComboFix2.txt 2009-02-03 19:03:57
ComboFix3.txt 2007-09-27 04:17:19

Pre-Run: 2,389,508,096 bytes free
Post-Run: 2,435,170,304 bytes free

1994 — E O F — 2009-02-03 17:58:41


KASPERSKY REPORT
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, February 3, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, February 03, 2009 22:59:05
Records in database: 1741613
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 123353
Threat name: 4
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 02:48:57


File name / Threat name / Threats count
C:\Documents and Settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-4d02e9ca Infected: Exploit.Java.Gimsh.b 1
C:\Documents and Settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-60f54428 Infected: Exploit.Java.Gimsh.b 1
C:\Documents and Settings\Peter\Desktop\Shared\02 Track 2.wma Infected: Trojan-Downloader.WMA.Wimad.k 1
C:\Program Files\Mozilla Firefox\components\nsBrowserCmp.dll Infected: Trojan.Win32.Vapsup.lsp 1
C:\WINDOWS\SYSTEM32\ssm.exe Infected: Trojan-Downloader.Win32.Agent.gp 1

The selected area was scanned.

HIJACKTHIS log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:30:29 PM, on 2/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/24/install/gtdownls.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
O23 - Service: WPS Scanner Service (WPSScannerSvc) - Skyhook Wireless - C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe

–
End of file - 10395 bytes
BobDylan,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Documents and Settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-4d02e9ca
    C:\Documents and Settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-60f54428
    C:\Documents and Settings\Peter\Desktop\Shared\02 Track 2.wma
    C:\Program Files\Mozilla Firefox\components\nsBrowserCmp.dll
    C:\WINDOWS\SYSTEM32\ssm.exe
    
    Folder::
    
    Registry::
    
    Driver::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Somehow, I'm not seeing what is still showing as Antivirus 2009.

Please start malware bytes, update it, and then run another scan.
Tomk - here's the latest after the recent ComboFix. Malwarebytes came up clean it looks like. The PC's the same - still not sure where this Anitvirus2009 is hiding, otherwise seems to be running well. Do you still see other threats/infections in it?!
Thanks!

COMBOFIX

ComboFix 09-02-04.01 - Peter 2009-02-04 22:23:27.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.638.203 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Peter\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\documents and settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-4d02e9ca
c:\documents and settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-60f54428
c:\documents and settings\Peter\Desktop\Shared\02 Track 2.wma
c:\program files\Mozilla Firefox\components\nsBrowserCmp.dll
c:\windows\SYSTEM32\ssm.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-4d02e9ca
c:\documents and settings\Peter\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-60f54428
c:\documents and settings\Peter\Desktop\Shared\02 Track 2.wma
c:\program files\Mozilla Firefox\components\nsBrowserCmp.dll
c:\windows\SYSTEM32\ssm.exe

.
((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
.

2009-02-04 01:25 . 2009-02-04 01:27 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-04 01:25 . 2009-01-14 16:11 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-02-04 01:25 . 2009-01-14 16:11 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-02-04 00:31 . 2009-02-04 00:31 1,152 –a—— c:\windows\SYSTEM32\windrv.sys
2009-02-04 00:30 . 2009-02-04 00:30 d——– c:\program files\Common Files\Download Manager
2009-02-03 17:19 . 2009-02-03 17:20 d——– C:\Rooter$
2009-02-03 12:29 . 2009-02-03 12:28 410,984 –a—— c:\windows\SYSTEM32\deploytk.dll
2009-02-03 12:29 . 2009-02-03 12:28 73,728 –a—— c:\windows\SYSTEM32\javacpl.cpl
2009-02-02 23:49 . 2009-02-02 23:49 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-31 21:55 . 2009-01-31 21:56 73,640,195 –a—— C:\38447_ring_of_fire.wmv
2009-01-31 21:48 . 2009-01-31 21:49 50,863,157 –a—— C:\38447_Second_Hand_News.wmv
2009-01-31 21:39 . 2009-01-31 21:41 84,056,771 –a—— C:\38447_Sweet_Caroline.wmv
2009-01-27 12:10 . 2009-01-27 12:10 d——– c:\documents and settings\Alex\Application Data\DisplayTune
2009-01-20 08:15 . 2009-02-01 22:33 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-20 08:15 . 2009-01-20 08:15 1,409 –a—— c:\windows\QTFont.for
2009-01-12 18:40 . 2009-01-12 18:41 d——– c:\documents and settings\Peter\.frugoo_file_store_32
2009-01-05 13:27 . 2009-01-05 13:27 d——– c:\program files\Coupons

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 05:29 ——— d—–w c:\program files\Skyhook Wireless
2009-02-04 03:38 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-04 03:38 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-02-04 03:38 10,520 —-a-w c:\windows\SYSTEM32\avgrsstx.dll
2009-02-03 19:39 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-03 17:52 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 17:28 ——— d—–w c:\program files\Java
2009-02-01 18:41 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-27 19:04 ——— d—–w c:\documents and settings\Peter\Application Data\DisplayTune
2008-12-26 18:17 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-26 18:16 ——— d—–w c:\program files\Portrait Displays
2008-12-26 18:16 ——— d—–w c:\program files\Common Files\Portrait Displays
2008-12-21 19:37 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-12-21 19:37 ——— d—–w c:\program files\Adobe Media Player
2008-12-13 06:40 3,593,216 —-a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-11 11:57 333,184 —-a-w c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-12-09 00:37 ——— d—–w c:\documents and settings\Peter\Application Data\MSN6
2008-10-13 14:26 24 —-a-w c:\documents and settings\Peter\jagex_runescape_preferences.dat
2006-05-01 23:57 32 —-a-r c:\documents and settings\All Users\hash.dat
2006-01-04 04:08 212,849 —-a-w c:\program files\hijackthis.zip
2006-01-02 20:56 6,224,992 —-a-w c:\program files\TrojanHunter.exe
2005-12-19 01:18 15,271,071 —-a-w c:\program files\thesims2_update_cd.zip
2005-12-19 01:15 444,161 —-a-w c:\program files\TS2SysReqc.zip
2005-12-18 06:55 10,940,595 —-a-w c:\program files\GP5DEMO.exe
2005-12-15 15:50 10,537,576 —-a-w c:\program files\zlsSetup_61_737_000_en.exe
2005-12-11 20:51 5,037,072 —-a-w c:\program files\spybotsd14.exe
2005-12-10 16:08 561,810 —-a-w c:\program files\country_cottage.zip
2005-12-09 20:57 12,820,430 —-a-w c:\program files\atgset.zip
2005-12-09 20:52 66,218 —-a-w c:\program files\k860slava_lamp_4.zip
2005-12-08 23:29 49,011 —-a-w c:\program files\k8sprwall6.zip
2005-12-08 23:27 2,989,597 —-a-w c:\program files\sprset.zip
2005-12-08 04:54 703 —-a-w c:\program files\DelTypedURL.inf
2005-03-29 04:36 276,408 —-a-w c:\program files\CleanUp312.exe
2005-03-27 08:05 76,551 —-a-w c:\program files\bholist.txt
2005-03-26 04:51 42,171 —-a-w c:\program files\KillBox.zip
2005-03-20 18:09 320,000 —-a-w c:\program files\IE-SPYAD2.exe
2005-03-20 17:48 5,205,858 —-a-w c:\program files\ZoneAlarm.exe
2005-03-19 21:10 2,179,792 —-a-w c:\program files\CWShredder.exe
2005-01-29 12:44 168 —-a-w c:\program files\AdbeRdr70_enu_full_FEAD_error.log
2005-01-29 08:28 20,798,256 —-a-w c:\program files\AdbeRdr70_enu_full.exe
2005-01-29 05:13 2,606,037 —-a-w c:\program files\692509.pdf
2005-01-28 23:47 12,404 —-a-w c:\program files\WildChild.ttf
2004-01-02 07:39 814 —-a-w c:\documents and settings\Peter\CDQUEUE.DAT
2008-02-01 04:30 131,584 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 19:50 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 19:50 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 19:50 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-04 19:50 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 19:50 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot@2009-02-03_14.01.17.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-04 14:31:43 26,824 —-a-w c:\windows\SYSTEM32\DRIVERS\avgmfx86.sys
+ 2009-02-04 03:38:47 27,656 —-a-w c:\windows\SYSTEM32\DRIVERS\avgmfx86.sys
- 2009-02-03 18:56:53 64,200 —-a-w c:\windows\SYSTEM32\PERFC009.DAT
+ 2009-02-04 21:05:43 64,200 —-a-w c:\windows\SYSTEM32\PERFC009.DAT
- 2009-02-03 18:56:53 407,670 —-a-w c:\windows\SYSTEM32\PERFH009.DAT
+ 2009-02-04 21:05:43 407,670 —-a-w c:\windows\SYSTEM32\PERFH009.DAT
+ 2009-02-04 21:01:45 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_36c.dat
+ 2009-02-04 21:02:03 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_48c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-08-27 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-08-27 20:58 66912 –a—— c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-07 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-10-29 86016]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 292152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-15 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-03 1601304]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-06-29 278528]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 158208]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless USB Utility.lnk - c:\program files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe [2005-10-28 1404928]
SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2005-10-17 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-03 22:38 10520 c:\windows\SYSTEM32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=c:\windows\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Peter^Start Menu^Programs^Startup^Greetings Workshop Reminders.lnk]
path=c:\documents and settings\Peter\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk
backup=c:\windows\pss\Greetings Workshop Reminders.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\AIM\\aim.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2008-05-27 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2008-05-27 107272]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-04 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-05-27 298264]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\Peter\LOCALS~1\Temp\cdiskdun.sys –> c:\docume~1\Peter\LOCALS~1\Temp\cdiskdun.sys [?]
S3 epstw2k;SCM Parallel Port SCSI Driver;c:\windows\SYSTEM32\DRIVERS\epstw2k.sys [2003-12-29 114944]
S3 scsiscan;SCSI Scanner Driver;c:\windows\SYSTEM32\DRIVERS\scsiscan.sys [2003-12-29 10880]
S3 SMC2862W;SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter Driver;c:\windows\SYSTEM32\DRIVERS\2862WICB.sys [2007-09-30 357632]
S3 USB Wireless USB Adapter®;USB Wireless USB Adapter® Service for Wireless USB Adapter;c:\windows\SYSTEM32\DRIVERS\vnetusbr.sys [2005-02-22 100736]
S4 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-07-16 29744]

— Other Services/Drivers In Memory —

*NewlyCreated* - GTNDIS5

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder

2009-02-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SNM - c:\program files\SpyNoMore\SNM.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
Trusted Zone: adobe.com
Trusted Zone: comcast.net\www
Trusted Zone: frugooscape.net
DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - hxxp://www.digitalwebbooks.com/reader/dbplugin.cab
FF - ProfilePath - c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\hom35zvs.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\progra~1\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\progra~1\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 22:30:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1511319073-2591443367-2869321682-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1212)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-02-04 22:37:11
ComboFix-quarantined-files.txt 2009-02-05 03:35:53
ComboFix2.txt 2009-02-03 23:07:45
ComboFix3.txt 2009-02-03 19:03:57
ComboFix4.txt 2007-09-27 04:17:19

Pre-Run: 2,205,102,080 bytes free
Post-Run: 2,330,570,752 bytes free

242 — E O F — 2009-02-03 17:58:41





MALWAREBYTES

Malwarebytes' Anti-Malware 1.33
Database version: 1730
Windows 5.1.2600 Service Pack 2

2/4/2009 11:41:10 PM
mbam-log-2009-02-04 (23-41-10).txt

Scan type: Quick Scan
Objects scanned: 69902
Time elapsed: 7 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HIJACKTHIS

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:21 PM, on 2/4/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/24/install/gtdownls.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe

–
End of file - 10301 bytes
BobDylan,

I missed some adware.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    
    Folder::
    c:\program files\Coupons
    
    Registry::
    
    Driver::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

That's not causing your warning however.

askBar.dll (Ask Toolbar) process can be removed to free up resources without compromising system performance. This is a valid program but it is not required to start automatically as you can start it manually if you need it. http://vil.nai.com/vil/content/v_146646.htm

This software is not a virus or a Trojan. It is detected as a "potentially unwanted program" (PUP). PUPs are any piece of software that a reasonably security- or privacy-minded computer user may want to be informed of and, in some cases, remove. PUPs are often made by a legitimate corporate entity for some beneficial purpose, but they alter the security state of the computer on which they are installed, or the privacy posture of the user of the system, such that most users will want to be aware of them.

It is advised that you disable this program so that it does not take up necessary resources. To uninstall the Ask Toolbar.
  • Click Start > Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Ask Toolbar , click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.
  • Using Windows Explorer (Windows key+e), search for the Ask Toolbar folder. If the program folder is still there, select/highlight the Ask Toolbar folder. DELETE it. (File > Delete.) If Windows is not installed on the C drive, replace C:\ with the appropriate drive letter.
  • Close Windows Explorer.
There is a Video showing how to uninstall a program (Grinler) detailing how to add or remove program in Windows for those who find a visual aid appealing.Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
      O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Now please run your AVG scan and see if anything shows.
Hi Tomk:

I couldn't uninstall the Ask Toolbar using Add/Remove programs - it gave me an rundll error stating a specified module could not be found (C:\ PROGRAM~1\AskSBar\bar\ 1.bin\AskSBar.dll) I deleted the AskSBar folder from the Programs but it still shows up on the add/remove list in Control Panel - and I don't see any way to uninstall it with Firefox which is where it is - any other ideas?

And my old friend antispyware 2009 is still popping up - this is the address that comes up:

http://anti-spyware-2009.info/products/antispyware/

seems to be a tricky thing as he's not showing up on any scans!


And the AVG scan looks clean, and here's the latest HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:27:28 AM, on 2/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O4 - Global Startup: SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/24/install/gtdownls.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe

–
End of file - 10684 bytes
BobDylan,

That screen shot was very helpful. That is not warning you that you have Antivirus2009, that is your security programs warning you that the site you are trying to go to is known to infect visitors with Antivirus2009. It's telling you not to go there or there is a likelyhood that you will be infected. All you need to do, is not visit the contaminated site, and you won't see the warning.

Lets get rid of Ask Toolbar this way:

  • Start HijackThis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button.
  • A screen will appear with a list of the programs in the Add/Remove Software list in the control panel


Locate Ask Toolbar on the list then click on the Delete this entry button.

With that complete, Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Okay Tomk - I guess that's why I can't find any sign of that antispyware 2009 thing on my computer except for that one site. Just to be clear, it's okay to leave it as it is - and it won't propagate or cause any problems?
And would it help to do a system restore to a time before I noticed the problem? - or would that just mess up all of what you just helped me clean up?!
I think it's just associated with the link from Google to that website - could that be?, as I can reach the website from my Favorites from a link I had added a long time ago without any problems (if any of that makes sense!) - and it's a website I'll need to access frequently, as it's for my daughter's softball team.

And the Ask Toolbar is gone - that was an easy way to do it!

I'll look over your other routine suggestions when I have a chance and try to beef up my security, otherwise I guess I'm set - thanks so much again!
BobDylan, There is a little info on googles warning if you click on "why was this site blocked". Please don't do a restore. The warning is triggered from google's side. Not from your computer. Restore wouldn't change anything as far as the warning goes. It would restore everything we took off of your computer. :wacko: You are very welcome. Glad we could help Good Luck and Be Well. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI