Jump to content

skookum

Members
  • Posts

    10
  • Joined

  • Last visited

Reputation

0 Neutral
  1. All clear! Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5248 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 12/5/2010 8:34:14 AM mbam-log-2010-12-05 (08-34-14).txt Scan type: Quick scan Objects scanned: 164191 Time elapsed: 1 minute(s), 12 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
  2. This white smoke thing must be something new, MBAM wasn't catching it until I updated to 1.50.. My browser seems snappier now
  3. Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5248 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 12/5/2010 8:14:59 AM mbam-log-2010-12-05 (08-14-59).txt Scan type: Quick scan Objects scanned: 164160 Time elapsed: 1 minute(s), 17 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 63 Files Infected: 574 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{52794457-AF6C-4C50-9DEF-F2E24F4C8889} (PUP.WhiteSmoke) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\program files (x86)\whitesmoketoolbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\modules (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\newtab (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\newtab\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\dynamicelements (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\rss (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\search (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\weather (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dtxwizard (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dtxwizard\skin (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dtxwizard\skin\icon_library (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dtxwizard\skin\icon_library\Basics (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\scripts (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\options (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\searchbar (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\components (PUP.WhiteSmoke) -> Quarantined and deleted successfully. Files Infected: c:\program files (x86)\whitesmoketoolbar\manifest.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\toolbar.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\uninstall.exe (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\whitesmoketoolbar.dll (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\neterror.xhtml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\preferences.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\toolbar.htm (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\toolbar.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\vmncode.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\vmnrsswin.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\about.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\dtxpanel.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\dtxpanelwin.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\dtxprefwin.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\dtxwin.xul (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\emailnotifierproviders.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\external.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\neterror.xhtml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\rsspreview.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\rsswin.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\rsswin.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\vmncode.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\wmpstreamer.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\modules\datastore.jsm (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\newtab\newtab.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\newtab\images\btn_search.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\newtab\images\bullet.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\newtab\images\field_bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\newtab\images\powered_by_yahoo.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.facebook\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\css\twitter.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\btn-login-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\btn-login.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\btn-submit.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\loginbg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\refresh-over.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\refresh.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrollbottom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\scrolltop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-off-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-off-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-on-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\tab-on-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\twitter-logo48.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\images\twitter_top.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\js\jquery.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\js\scripts.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.twitter\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.webtv\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\index.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\tb_icon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\widget.jsw (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\widget.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\widget_version.txt (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\arrow-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\arrows_grey-left.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\arrows_grey-right.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\btn-search-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\powered-by-youtube.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollb-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollb-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollb.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollt-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollt-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\scrollt.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-off-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-off-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-on-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-on-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-over-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-over-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-red-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-red-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-red-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-white-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-white-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\tab-white-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\vid-bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\images\youtube.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\js\jquery-1.3.2.min.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\js\jquery.autocomplete.min.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\Thumbs.db (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.www.youtube\skin\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\dynamicelements\vmntoolbar.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\rss\rss.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\search\engines.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\search\search.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\data\weather\icons.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\634017460871087500_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\about.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\babylon_logo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\bing_16x16.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\bing_searchicon_20x22_spaced_hover_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\bing_searchicon_20x22_spaced_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\blank_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\bluelite.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\bluesky.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\btn-search-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\btn-settings-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\btn-settings.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\btn-widgets-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\btn-widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\btn_settings.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\ca.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\checkmytext_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\checkmytext_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dictionary.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dictionary_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dictionary_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\divider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\downloadcom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dtxlogo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\email.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\email_on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\eteacher_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\facebook.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\feed_icon2_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\feed_icon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\france_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\games.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\gamesicon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\games_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred0.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred0_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred1.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred1_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred2.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred2_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred3.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred3_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred4.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred4_5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphred5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\graphredna.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\grey.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\ico-shield.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\images.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\italy_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lichen.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\logo-about.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\logo-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\logo-separator.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\logo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\mail.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\menuseparatorback.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\modify-save.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\modify.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\modifyhot.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\music.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\namespacetoolbar.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\networkicons_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\news.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\orange.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\pixsy.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\protect-id.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\relatedlinks.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-collapse.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-delete.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-expand.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-feed.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-folder-remove.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-folder-rename.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-folder.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-found.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-reload.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss-subscribe.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rssback.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rsstopback.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\rss_feed_icon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\search-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\settings.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\shopping.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\siteinfo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\skin-bluelite.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\skin-bluesky.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\skin-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\skin-lichen.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\skin-orange.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\skin-yellow.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\skin.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\spain_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\technorati.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\toolbarsplitter.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\translate.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\translate_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\translate_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\truste_about.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\tvicons_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\tvicon_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\tv_icon3_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\usa_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\vmn.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\vmn.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\web.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\whtsmke_logo_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\whtsmke_logo_png2_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\whtsmke_logo_png3_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\whtsmke_logo_png4_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\whtsmke_logo_png5_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\whtsmke_logo_png_png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\wikipedia.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\yahoosearch.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\yellow.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\youtube.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\zoom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\dtxwizard\skin\icon_library\Basics\folder.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\add.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\aol.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\arrow-dn.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\arrow-right-disabled.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\arrow-right.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\arrow-up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btn-divider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btn-end.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btn-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btn-mdl_ff.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btn-start.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btnover-divider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btnover-end.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btnover-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btnover-mdl_ff.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\bg-btnover-start.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\blank.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btn-widgets-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btn-widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btnback-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btnback-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btnleft-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btnleft-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btnright-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btnright-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\btn_slider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\button-splitter-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\button-splitter-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\checkmark.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\chevron.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\collapse.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\comcast.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\dtx.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\edit-back-hot.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\edit-back.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\expand.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\found.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\gmail.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\highlight.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\highlight_blue.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\highlight_cyan.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\highlight_lime.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\highlight_magenta.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\highlight_yellow.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\hotmail.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\ico-check.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\imap.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\lastsearch-thumb-back.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\loadingmid.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\lock.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\logo-separator.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\mailcom.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menuitem-splitter.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menuitemback-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menuitemback-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menuitemleft-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menuitemleft-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menuitemright-down-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menuitemright-vista.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menu_bg-basic.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menu_separator_bar.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\menu_separator_white.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\modify.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\move.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\movetarget.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\pop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\reload.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\remove.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\rename.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\resize-box.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\rss.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\rsschannelback.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\RSSLogo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\rsstabdivider.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\scroll-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\scroll-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\search-go.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\text-ellipsis.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\toolbarsplitter.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\transparent_1px.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\yahoo.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\footer.htm (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\gamecategory.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\gameData.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\gameList.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\games.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\gametype.xsl (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\inithtml.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\popupgames.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\popuphtml.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\popuprss.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\popupwidgets.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\scroll.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\css\panels.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\css\popupabout.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\css\popupgames.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\css\popupRSS.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\css\popupwidgets.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\main.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\css\dialog.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\bg.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\btn-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\btn-wide-close-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\btn-wide-close.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\default.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-off-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-off-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-on-l.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\tab-on-r.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\transparent.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\ttlbar-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\ttlbar-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\ttlbar-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-mdl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-right-resize.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-btm-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\images\win-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\scripts\defscript.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-dn.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-sml-drop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-sml.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\arrow-up.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\arrowr-bluew5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\bg-aboutbox.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\bg-btnover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\bg-pnl520x390.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-back.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-drag.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-moredetails.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-next-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-next.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-previous-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-previous.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\bullet-orange.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\gamethumb-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\gamethumb2-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-calendar.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-download.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-joystick24.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-news24.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-play.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\ico-tags.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-Add.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-download.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-info.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-play.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\icon-shop.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\menul-bgon.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\menul-bgover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\panel-botm-noscroll.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scroll-bg-206.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scroll-bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scroll-topwin.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollb.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt-disable.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\scrollt.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\star_x_grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\star_x_orange.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\truste_about.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\view-detailed-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\view-detailed-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\view-thumb-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\view-thumb-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\widgets-square-16px.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\widgets-square-24px.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\images\widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\managerpanel.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\volumeslider.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\css\manager.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\css\slider.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\bg-pnl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\collapsed_button.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\expanded_button.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-playstation-down.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-playstation-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-playstation.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\ico-radio.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\music-note.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-pause-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-pause.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-play-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-btn-play.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-bg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-buffer.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-busy.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-off.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-on.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-eq-warning.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options-design-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options-design.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options-on.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-options.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-0.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-1.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-2.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-3.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\radio-volume-mute.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\scrollbar-handle.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\scrollbar-track.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\slider.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\slideron.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\radio\images\track.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_02.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_03.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_04.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_06.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_07.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_08.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_09.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_10.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_11.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_12.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_13.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_14.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_15.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_16.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_18.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_19.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_20.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\border_21.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\close-hot.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\close-normal.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\loadingmid.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\proxy.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\template.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\template.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\templateff.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\uwa\throbber.gif (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\cond999.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\icons.xml (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\na-s.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\na-t.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\na.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\icons\weather.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\popupweather.css (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\popupweather.html (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\add.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\box-check.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm-over.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\options\options-main.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\options\options-search.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\options\options-weather.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\options\options-widgets.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\searchbar\searchbar-background-left.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\searchbar\searchbar-background-middle.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\chrome\skin\searchbar\searchbar-background-right.png (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\program files (x86)\whitesmoketoolbar\components\windowmediator.js (PUP.WhiteSmoke) -> Quarantined and deleted successfully.
  4. Seems like everything is working normally now, thank you for the help!
  5. 2010/12/03 07:01:12.0722 TDSS rootkit removing tool 2.4.10.1 Dec 2 2010 12:28:01 2010/12/03 07:01:12.0722 ================================================================================ 2010/12/03 07:01:12.0722 SystemInfo: 2010/12/03 07:01:12.0722 2010/12/03 07:01:12.0722 OS Version: 6.1.7600 ServicePack: 0.0 2010/12/03 07:01:12.0722 Product type: Workstation 2010/12/03 07:01:12.0722 ComputerName: ROOK 2010/12/03 07:01:12.0722 UserName: Chris 2010/12/03 07:01:12.0722 Windows directory: C:\Windows 2010/12/03 07:01:12.0722 System windows directory: C:\Windows 2010/12/03 07:01:12.0722 Running under WOW64 2010/12/03 07:01:12.0722 Processor architecture: Intel x64 2010/12/03 07:01:12.0722 Number of processors: 2 2010/12/03 07:01:12.0722 Page size: 0x1000 2010/12/03 07:01:12.0722 Boot type: Normal boot 2010/12/03 07:01:12.0722 ================================================================================ 2010/12/03 07:01:12.0723 Utility is running under WOW64 2010/12/03 07:01:12.0988 Initialize success 2010/12/03 07:01:17.0717 ================================================================================ 2010/12/03 07:01:17.0717 Scan started 2010/12/03 07:01:17.0717 Mode: Manual; 2010/12/03 07:01:17.0717 ================================================================================ 2010/12/03 07:01:19.0611 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 2010/12/03 07:01:19.0630 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 2010/12/03 07:01:19.0651 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 2010/12/03 07:01:19.0698 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 2010/12/03 07:01:19.0722 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 2010/12/03 07:01:19.0748 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 2010/12/03 07:01:19.0776 afcdp (3f5fdc12ffa4794fc3a178a26d48e7cf) C:\Windows\system32\DRIVERS\afcdp.sys 2010/12/03 07:01:19.0806 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys 2010/12/03 07:01:19.0830 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 2010/12/03 07:01:19.0843 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 2010/12/03 07:01:19.0858 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 2010/12/03 07:01:19.0870 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 2010/12/03 07:01:19.0881 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 2010/12/03 07:01:19.0903 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys 2010/12/03 07:01:19.0926 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 2010/12/03 07:01:19.0938 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys 2010/12/03 07:01:19.0977 AnyDVD (454b3cb335089b674917247ca67d5bb0) C:\Windows\system32\Drivers\AnyDVD.sys 2010/12/03 07:01:19.0988 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 2010/12/03 07:01:20.0027 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 2010/12/03 07:01:20.0066 archlp (f97c3aaf0699e0b85df1a02de8aae333) C:\Windows\system32\drivers\archlp.sys 2010/12/03 07:01:20.0082 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 2010/12/03 07:01:20.0126 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/12/03 07:01:20.0137 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 2010/12/03 07:01:20.0167 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 2010/12/03 07:01:20.0202 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 2010/12/03 07:01:20.0225 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 2010/12/03 07:01:20.0258 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 2010/12/03 07:01:20.0273 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys 2010/12/03 07:01:20.0283 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2010/12/03 07:01:20.0295 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2010/12/03 07:01:20.0310 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 2010/12/03 07:01:20.0322 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 2010/12/03 07:01:20.0335 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 2010/12/03 07:01:20.0346 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 2010/12/03 07:01:20.0358 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/12/03 07:01:20.0393 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 2010/12/03 07:01:20.0416 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 2010/12/03 07:01:20.0437 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 2010/12/03 07:01:20.0468 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 2010/12/03 07:01:20.0508 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/12/03 07:01:20.0547 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 2010/12/03 07:01:20.0593 cmuda3 (2835bf2a864cde9184c80cf4e6a485f9) C:\Windows\system32\drivers\cmudax3.sys 2010/12/03 07:01:20.0650 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 2010/12/03 07:01:20.0673 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 2010/12/03 07:01:20.0695 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 2010/12/03 07:01:20.0790 cpuz132 (c9c25778efe890baa4087e32937016a0) C:\Windows\system32\drivers\cpuz132_x64.sys 2010/12/03 07:01:20.0800 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 2010/12/03 07:01:20.0841 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys 2010/12/03 07:01:20.0903 DefragFS (cec7f24e28b40829c0fd2d523e72b5d3) C:\Windows\system32\drivers\DefragFS.sys 2010/12/03 07:01:20.0921 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys 2010/12/03 07:01:20.0957 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 2010/12/03 07:01:20.0970 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 2010/12/03 07:01:21.0011 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 2010/12/03 07:01:21.0041 DXGKrnl (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys 2010/12/03 07:01:21.0090 eamonm (398fdc5694f2ba9e51e321ca40d1706e) C:\Windows\system32\DRIVERS\eamonm.sys 2010/12/03 07:01:21.0156 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 2010/12/03 07:01:21.0228 ehdrv (e99457900012b53b2226f146ecaf9136) C:\Windows\system32\DRIVERS\ehdrv.sys 2010/12/03 07:01:21.0277 ElbyCDIO (a14d6e3ef78f6d6ac42f98d633f2400a) C:\Windows\system32\Drivers\ElbyCDIO.sys 2010/12/03 07:01:21.0300 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 2010/12/03 07:01:21.0346 ENTECH64 (12c061d9f9621be916d58191872ec281) C:\Windows\system32\DRIVERS\ENTECH64.sys 2010/12/03 07:01:21.0368 epfwwfpr (a2af094dcbe8bff7e898d327750506a0) C:\Windows\system32\DRIVERS\epfwwfpr.sys 2010/12/03 07:01:21.0406 epmntdrv (9eafb3b3b60b8ad958985152a9309aca) C:\Windows\system32\epmntdrv.sys 2010/12/03 07:01:21.0426 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 2010/12/03 07:01:21.0456 EuGdiDrv (fb949ed2c93c878a189039f3d7730942) C:\Windows\system32\EuGdiDrv.sys 2010/12/03 07:01:21.0473 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 2010/12/03 07:01:21.0495 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 2010/12/03 07:01:21.0518 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 2010/12/03 07:01:21.0540 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 2010/12/03 07:01:21.0560 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 2010/12/03 07:01:21.0576 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/12/03 07:01:21.0598 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 2010/12/03 07:01:21.0626 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 2010/12/03 07:01:21.0642 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 2010/12/03 07:01:21.0670 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 2010/12/03 07:01:21.0692 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 2010/12/03 07:01:21.0737 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/12/03 07:01:21.0758 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 2010/12/03 07:01:21.0792 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys 2010/12/03 07:01:21.0816 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/12/03 07:01:21.0826 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 2010/12/03 07:01:21.0837 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 2010/12/03 07:01:21.0848 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 2010/12/03 07:01:21.0873 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 2010/12/03 07:01:21.0907 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 2010/12/03 07:01:21.0936 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 2010/12/03 07:01:21.0952 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 2010/12/03 07:01:21.0976 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/12/03 07:01:21.0996 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys 2010/12/03 07:01:22.0022 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 2010/12/03 07:01:22.0045 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 2010/12/03 07:01:22.0058 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 2010/12/03 07:01:22.0077 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/12/03 07:01:22.0091 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2010/12/03 07:01:22.0106 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 2010/12/03 07:01:22.0126 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 2010/12/03 07:01:22.0142 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 2010/12/03 07:01:22.0162 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/12/03 07:01:22.0192 JRAID (3ce8227864a5c4574f5fd99658d69885) C:\Windows\system32\DRIVERS\jraid.sys 2010/12/03 07:01:22.0208 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/12/03 07:01:22.0227 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/12/03 07:01:22.0260 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 2010/12/03 07:01:22.0288 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 2010/12/03 07:01:22.0305 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 2010/12/03 07:01:22.0333 L8042Kbd (f33c5d79d3273530e1892a0922283a7b) C:\Windows\system32\DRIVERS\L8042Kbd.sys 2010/12/03 07:01:22.0385 LHidFilt (0a7d6ed578d85f0c35353424ee3f5245) C:\Windows\system32\DRIVERS\LHidFilt.Sys 2010/12/03 07:01:22.0431 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 2010/12/03 07:01:22.0451 LMouFilt (6542e2e6db58118fbb1b82a68ce3aff9) C:\Windows\system32\DRIVERS\LMouFilt.Sys 2010/12/03 07:01:22.0477 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 2010/12/03 07:01:22.0497 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 2010/12/03 07:01:22.0513 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2010/12/03 07:01:22.0540 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2010/12/03 07:01:22.0557 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 2010/12/03 07:01:22.0662 MagicTune (b3b7c5f26f3f8c7992350b7ede64f5c9) C:\Windows\system32\drivers\MTiCtwl.sys 2010/12/03 07:01:22.0820 MBAMProtector (e330051cce41eb4522e5dcebc15adcea) C:\Windows\system32\drivers\mbam.sys 2010/12/03 07:01:22.0842 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 2010/12/03 07:01:22.0862 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 2010/12/03 07:01:22.0906 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 2010/12/03 07:01:22.0927 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 2010/12/03 07:01:22.0957 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 2010/12/03 07:01:22.0985 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 2010/12/03 07:01:23.0001 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 2010/12/03 07:01:23.0021 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 2010/12/03 07:01:23.0042 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 2010/12/03 07:01:23.0066 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 2010/12/03 07:01:23.0093 mrxsmb (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/12/03 07:01:23.0115 mrxsmb10 (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/12/03 07:01:23.0132 mrxsmb20 (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/12/03 07:01:23.0147 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 2010/12/03 07:01:23.0170 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 2010/12/03 07:01:23.0191 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 2010/12/03 07:01:23.0216 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 2010/12/03 07:01:23.0226 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 2010/12/03 07:01:23.0261 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 2010/12/03 07:01:23.0280 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/12/03 07:01:23.0297 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 2010/12/03 07:01:23.0311 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 2010/12/03 07:01:23.0335 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/12/03 07:01:23.0356 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 2010/12/03 07:01:23.0377 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 2010/12/03 07:01:23.0393 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 2010/12/03 07:01:23.0433 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 2010/12/03 07:01:23.0475 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 2010/12/03 07:01:23.0502 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 2010/12/03 07:01:23.0525 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/12/03 07:01:23.0545 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/12/03 07:01:23.0568 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/12/03 07:01:23.0590 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 2010/12/03 07:01:23.0610 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 2010/12/03 07:01:23.0632 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 2010/12/03 07:01:23.0688 NetworkX (2263727032e9b19231a706046b8c82d3) C:\Windows\system32\ckldrv.sys 2010/12/03 07:01:23.0715 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 2010/12/03 07:01:23.0765 nmwcdcx64 (2c761cc067acf0fb4ea13930b09bfeea) C:\Windows\system32\drivers\ccdcmbox64.sys 2010/12/03 07:01:23.0801 nmwcdnsucx64 (ce90d1dd60db810a45e13fccea47e890) C:\Windows\system32\drivers\nmwcdnsucx64.sys 2010/12/03 07:01:23.0826 nmwcdnsux64 (f5a8219ea8a6b67280308fae169b65c0) C:\Windows\system32\drivers\nmwcdnsux64.sys 2010/12/03 07:01:23.0853 nmwcdx64 (63051819d5cac0fa49c425fc5e1a2b5c) C:\Windows\system32\drivers\ccdcmbx64.sys 2010/12/03 07:01:23.0886 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 2010/12/03 07:01:23.0908 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 2010/12/03 07:01:23.0945 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys 2010/12/03 07:01:23.0967 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 2010/12/03 07:01:24.0013 NVHDA (ed9380f201c8126425c09bed96dbe1e5) C:\Windows\system32\drivers\nvhda64v.sys 2010/12/03 07:01:24.0196 nvlddmkm (f9efa2f16c2e2ce32918957b45037e01) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2010/12/03 07:01:24.0376 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/12/03 07:01:24.0421 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 2010/12/03 07:01:24.0440 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 2010/12/03 07:01:24.0468 pccsmcfd (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys 2010/12/03 07:01:24.0481 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 2010/12/03 07:01:24.0493 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 2010/12/03 07:01:24.0515 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 2010/12/03 07:01:24.0551 pcouffin (af7ce12c4f3dc8cb2b07685c916bbcfe) C:\Windows\system32\Drivers\pcouffin.sys 2010/12/03 07:01:24.0568 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 2010/12/03 07:01:24.0613 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 2010/12/03 07:01:24.0678 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 2010/12/03 07:01:24.0691 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 2010/12/03 07:01:24.0718 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 2010/12/03 07:01:24.0751 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 2010/12/03 07:01:24.0780 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 2010/12/03 07:01:24.0805 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 2010/12/03 07:01:24.0823 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 2010/12/03 07:01:24.0853 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 2010/12/03 07:01:24.0875 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/12/03 07:01:24.0900 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/12/03 07:01:24.0921 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 2010/12/03 07:01:24.0940 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 2010/12/03 07:01:24.0957 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 2010/12/03 07:01:24.0973 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/12/03 07:01:24.0990 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys 2010/12/03 07:01:25.0011 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 2010/12/03 07:01:25.0035 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 2010/12/03 07:01:25.0056 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 2010/12/03 07:01:25.0081 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 2010/12/03 07:01:25.0133 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys 2010/12/03 07:01:25.0173 Revoflt (9c3ac71a9934b884fac567a8807e9c4d) C:\Windows\system32\DRIVERS\revoflt.sys 2010/12/03 07:01:25.0201 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 2010/12/03 07:01:25.0235 RTL8167 (3b01789ee4eaee97f5eb46b711387d5e) C:\Windows\system32\DRIVERS\Rt64win7.sys 2010/12/03 07:01:25.0257 RTL8169 (faeeed5a8949e6ba611a7b738ad28cee) C:\Windows\system32\DRIVERS\Rtlh64.sys 2010/12/03 07:01:25.0273 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys 2010/12/03 07:01:25.0300 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 2010/12/03 07:01:25.0320 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 2010/12/03 07:01:25.0345 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 2010/12/03 07:01:25.0368 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 2010/12/03 07:01:25.0383 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 2010/12/03 07:01:25.0411 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 2010/12/03 07:01:25.0453 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/12/03 07:01:25.0468 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2010/12/03 07:01:25.0483 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/12/03 07:01:25.0495 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 2010/12/03 07:01:25.0543 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2010/12/03 07:01:25.0558 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 2010/12/03 07:01:25.0577 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 2010/12/03 07:01:25.0607 snapman (27ba49f89468fddae6c2b311c53bce3a) C:\Windows\system32\DRIVERS\snapman.sys 2010/12/03 07:01:25.0632 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 2010/12/03 07:01:25.0678 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys 2010/12/03 07:01:25.0678 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb 2010/12/03 07:01:25.0682 sptd - detected Locked file (1) 2010/12/03 07:01:25.0720 srv (de6f5658da951c4bc8e498570b5b0d5f) C:\Windows\system32\DRIVERS\srv.sys 2010/12/03 07:01:25.0746 srv2 (4d33d59c0b930c523d29f9bd40cda9d2) C:\Windows\system32\DRIVERS\srv2.sys 2010/12/03 07:01:25.0772 srvnet (5a663fd67049267bc5c3f3279e631ffb) C:\Windows\system32\DRIVERS\srvnet.sys 2010/12/03 07:01:25.0815 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 2010/12/03 07:01:25.0845 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys 2010/12/03 07:01:25.0867 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys 2010/12/03 07:01:25.0883 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 2010/12/03 07:01:25.0946 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys 2010/12/03 07:01:25.0990 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys 2010/12/03 07:01:26.0017 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 2010/12/03 07:01:26.0035 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 2010/12/03 07:01:26.0073 tdrpman258 (bf7ac81df6fbe09438d9dc7188178ea9) C:\Windows\system32\DRIVERS\tdrpm258.sys 2010/12/03 07:01:26.0095 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 2010/12/03 07:01:26.0113 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 2010/12/03 07:01:26.0142 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 2010/12/03 07:01:26.0181 timounter (2c1caf5563548a15515eab07d2a069c6) C:\Windows\system32\DRIVERS\timntr.sys 2010/12/03 07:01:26.0215 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/12/03 07:01:26.0242 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 2010/12/03 07:01:26.0253 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 2010/12/03 07:01:26.0278 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 2010/12/03 07:01:26.0315 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 2010/12/03 07:01:26.0330 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 2010/12/03 07:01:26.0341 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 2010/12/03 07:01:26.0391 upperdev (bcd611d240604ceee7f90805361fab50) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys 2010/12/03 07:01:26.0412 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys 2010/12/03 07:01:26.0435 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/12/03 07:01:26.0447 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 2010/12/03 07:01:26.0466 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys 2010/12/03 07:01:26.0483 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys 2010/12/03 07:01:26.0502 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys 2010/12/03 07:01:26.0512 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 2010/12/03 07:01:26.0542 usbser (0f0c72a657c622286013788b886968ad) C:\Windows\system32\drivers\usbser.sys 2010/12/03 07:01:26.0566 UsbserFilt (d91be2644b18b4e3c69982fe0e1e97d6) C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys 2010/12/03 07:01:26.0582 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/12/03 07:01:26.0601 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/12/03 07:01:26.0635 VClone (84bb306b7863883018d7f3eb0c453bd5) C:\Windows\system32\DRIVERS\VClone.sys 2010/12/03 07:01:26.0653 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 2010/12/03 07:01:26.0667 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/12/03 07:01:26.0683 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 2010/12/03 07:01:26.0696 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 2010/12/03 07:01:26.0715 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 2010/12/03 07:01:26.0731 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys 2010/12/03 07:01:26.0743 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys 2010/12/03 07:01:26.0756 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 2010/12/03 07:01:26.0781 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 2010/12/03 07:01:26.0806 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 2010/12/03 07:01:26.0836 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys 2010/12/03 07:01:26.0858 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys 2010/12/03 07:01:26.0886 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 2010/12/03 07:01:26.0911 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys 2010/12/03 07:01:26.0926 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 2010/12/03 07:01:26.0947 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/03 07:01:26.0955 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/03 07:01:26.0983 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 2010/12/03 07:01:27.0017 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 2010/12/03 07:01:27.0061 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 2010/12/03 07:01:27.0083 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 2010/12/03 07:01:27.0195 WinRing0_1_2_0 (0c0195c48b6b8582fa6f6373032118da) C:\Users\Chris\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys 2010/12/03 07:01:27.0226 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys 2010/12/03 07:01:27.0242 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/12/03 07:01:27.0270 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 2010/12/03 07:01:27.0318 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 2010/12/03 07:01:27.0346 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/12/03 07:01:27.0391 \HardDisk1 - detected Rootkit.Win32.TDSS.tdl4 (0) 2010/12/03 07:01:27.0402 ================================================================================ 2010/12/03 07:01:27.0402 Scan finished 2010/12/03 07:01:27.0402 ================================================================================ 2010/12/03 07:01:27.0408 Detected object count: 2 2010/12/03 07:01:36.0782 Locked file(sptd) - User select action: Skip 2010/12/03 07:01:36.0814 \HardDisk1 - will be cured after reboot 2010/12/03 07:01:36.0814 Rootkit.Win32.TDSS.tdl4(\HardDisk1) - User select action: Cure 2010/12/03 07:01:42.0455 Deinitialize success
  6. MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows 7 Ultimate Edition Windows Information: (build 7600), 64-bit Base Board Manufacturer: Gigabyte Technology Co., Ltd. BIOS Manufacturer: Award Software International, Inc. System Manufacturer: Gigabyte Technology Co., Ltd. System Product Name: EP45-UD3P Logical Drives Mask: 0x008003fc Kernel Drivers (total 171): 0x02C63000 \SystemRoot\system32\ntoskrnl.exe 0x02C1A000 \SystemRoot\system32\hal.dll 0x00BB2000 \SystemRoot\system32\kdcom.dll 0x00CE8000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x00D2C000 \SystemRoot\system32\PSHED.dll 0x00D40000 \SystemRoot\system32\CLFS.SYS 0x00C00000 \SystemRoot\system32\CI.dll 0x00E66000 \SystemRoot\system32\drivers\Wdf01000.sys 0x00F0A000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x010CD000 \SystemRoot\System32\Drivers\spgu.sys 0x011F3000 \SystemRoot\System32\Drivers\WMILIB.SYS 0x01000000 \SystemRoot\System32\Drivers\SCSIPORT.SYS 0x0102F000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x01086000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x01090000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x00F19000 \SystemRoot\system32\DRIVERS\pci.sys 0x0109D000 \SystemRoot\System32\drivers\partmgr.sys 0x010B2000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x00F4C000 \SystemRoot\System32\drivers\volmgrx.sys 0x00FA8000 \SystemRoot\system32\DRIVERS\pciide.sys 0x00FAF000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x00FBF000 \SystemRoot\System32\drivers\mountmgr.sys 0x00FD9000 \SystemRoot\system32\DRIVERS\atapi.sys 0x00E00000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x00E2A000 \SystemRoot\system32\DRIVERS\msahci.sys 0x00E35000 \SystemRoot\system32\DRIVERS\jraid.sys 0x00E50000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x00D9E000 \SystemRoot\system32\drivers\fltmgr.sys 0x00FE2000 \SystemRoot\system32\drivers\fileinfo.sys 0x0120D000 \SystemRoot\System32\Drivers\Ntfs.sys 0x014ED000 \SystemRoot\System32\Drivers\msrpc.sys 0x0154B000 \SystemRoot\System32\Drivers\ksecdd.sys 0x01565000 \SystemRoot\System32\Drivers\cng.sys 0x015D8000 \SystemRoot\System32\drivers\pcw.sys 0x015E9000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x0162B000 \SystemRoot\system32\drivers\ndis.sys 0x0171D000 \SystemRoot\system32\drivers\NETIO.SYS 0x0177D000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x01802000 \SystemRoot\System32\drivers\tcpip.sys 0x017A8000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x01400000 \SystemRoot\system32\DRIVERS\timntr.sys 0x01600000 \SystemRoot\system32\DRIVERS\vmstorfl.sys 0x013B0000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x01A41000 \SystemRoot\system32\DRIVERS\tdrpm258.sys 0x01BAD000 \SystemRoot\System32\Drivers\spldr.sys 0x01BB5000 \SystemRoot\system32\DRIVERS\snapman.sys 0x01A00000 \SystemRoot\System32\drivers\rdyboost.sys 0x01610000 \SystemRoot\System32\Drivers\mup.sys 0x01BF5000 \SystemRoot\System32\drivers\hwpolicy.sys 0x01CD5000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x01D0F000 \SystemRoot\system32\DRIVERS\disk.sys 0x01D25000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x01D8D000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x01DB7000 \SystemRoot\System32\Drivers\Null.SYS 0x01DC0000 \SystemRoot\System32\Drivers\Beep.SYS 0x01DC7000 \SystemRoot\system32\DRIVERS\ehdrv.sys 0x01DEC000 \SystemRoot\system32\drivers\MTiCtwl.sys 0x01C00000 \SystemRoot\System32\drivers\vga.sys 0x01C0E000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x01C33000 \SystemRoot\System32\drivers\watchdog.sys 0x01C43000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x01C4C000 \SystemRoot\system32\drivers\rdpencdd.sys 0x01C55000 \SystemRoot\system32\drivers\rdprefmp.sys 0x01C5E000 \SystemRoot\System32\Drivers\Msfs.SYS 0x01C69000 \SystemRoot\System32\Drivers\Npfs.SYS 0x01C7A000 \SystemRoot\system32\DRIVERS\tdx.sys 0x01C98000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x03EE9000 \SystemRoot\system32\drivers\afd.sys 0x03F73000 \SystemRoot\System32\DRIVERS\netbt.sys 0x03FB8000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x03FC1000 \SystemRoot\system32\DRIVERS\pacer.sys 0x03FE7000 \SystemRoot\system32\DRIVERS\netbios.sys 0x03E00000 \SystemRoot\system32\DRIVERS\serial.sys 0x03E1D000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x03E38000 \SystemRoot\system32\DRIVERS\termdd.sys 0x03E4C000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x03E9D000 \SystemRoot\system32\drivers\nsiproxy.sys 0x03EA9000 \SystemRoot\system32\ckldrv.sys 0x03EB4000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x03EBF000 \SystemRoot\System32\Drivers\ElbyCDIO.sys 0x03ECA000 \SystemRoot\System32\drivers\discache.sys 0x04030000 \SystemRoot\system32\drivers\csc.sys 0x040B3000 \SystemRoot\System32\Drivers\dfsc.sys 0x040D1000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x040E2000 \SystemRoot\system32\drivers\archlp.sys 0x04109000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x0412F000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x04C25000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys 0x057F7000 \SystemRoot\system32\DRIVERS\nvBridge.kmd 0x042AF000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x043A3000 \SystemRoot\System32\drivers\dxgmms1.sys 0x04200000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x04224000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x04231000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x04287000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x04145000 \SystemRoot\system32\DRIVERS\Rt64win7.sys 0x0440C000 \SystemRoot\system32\drivers\cmudax3.sys 0x04572000 \SystemRoot\system32\drivers\portcls.sys 0x045AF000 \SystemRoot\system32\drivers\drmk.sys 0x04184000 \SystemRoot\system32\drivers\ks.sys 0x045D1000 \SystemRoot\system32\drivers\ksthunk.sys 0x04634000 \SystemRoot\system32\DRIVERS\1394ohci.sys 0x04672000 \SystemRoot\system32\DRIVERS\serenum.sys 0x0467E000 \SystemRoot\system32\DRIVERS\parport.sys 0x0469B000 \SystemRoot\System32\Drivers\AnyDVD.sys 0x046BD000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x046CA000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x046DA000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x046F0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x04714000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x04720000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x0474F000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x0476A000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x0478B000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x047A5000 \SystemRoot\System32\Drivers\pcouffin.sys 0x047BA000 \SystemRoot\system32\DRIVERS\rdpbus.sys 0x047C5000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x047D4000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x047E3000 \SystemRoot\system32\DRIVERS\VClone.sys 0x047F2000 \SystemRoot\system32\DRIVERS\swenum.sys 0x04600000 \SystemRoot\system32\DRIVERS\umbus.sys 0x05C0E000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x05C68000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x05C7D000 \SystemRoot\system32\drivers\nvhda64v.sys 0x05CA6000 \SystemRoot\System32\Drivers\crashdmp.sys 0x05CB4000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x05CC0000 \SystemRoot\System32\Drivers\dump_msahci.sys 0x05CCB000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x05CDE000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x05CFB000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x05CFD000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x05D0B000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x05D24000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x05D2D000 \SystemRoot\system32\DRIVERS\LHidFilt.Sys 0x05D42000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x05D4F000 \SystemRoot\system32\DRIVERS\LMouFilt.Sys 0x05D63000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0x05D7E000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x05D8C000 \SystemRoot\system32\drivers\usbaudio.sys 0x000F0000 \SystemRoot\System32\win32k.sys 0x05DA7000 \SystemRoot\System32\drivers\Dxapi.sys 0x05DB3000 \SystemRoot\system32\DRIVERS\monitor.sys 0x005A0000 \SystemRoot\System32\TSDDD.dll 0x00650000 \SystemRoot\System32\cdd.dll 0x05DC1000 \SystemRoot\system32\drivers\luafv.sys 0x05807000 \SystemRoot\system32\DRIVERS\eamonm.sys 0x058DE000 \SystemRoot\system32\drivers\WudfPf.sys 0x058FF000 \SystemRoot\System32\Drivers\DefragFS.SYS 0x05924000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x05939000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x0766D000 \SystemRoot\system32\drivers\HTTP.sys 0x07735000 \SystemRoot\system32\DRIVERS\bowser.sys 0x07753000 \SystemRoot\System32\drivers\mpsdrv.sys 0x0776B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x07798000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x07600000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x07623000 \??\C:\Windows\system32\drivers\cpuz132_x64.sys 0x0762B000 \SystemRoot\system32\DRIVERS\epfwwfpr.sys 0x05951000 \SystemRoot\system32\drivers\peauth.sys 0x0764C000 \??\C:\Windows\system32\drivers\regi.sys 0x07654000 \SystemRoot\System32\Drivers\secdrv.SYS 0x041C7000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x077E6000 \SystemRoot\System32\drivers\tcpipreg.sys 0x077F8000 \??\C:\Users\Chris\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys 0x07A22000 \SystemRoot\System32\DRIVERS\srv2.sys 0x07A89000 \SystemRoot\System32\DRIVERS\srv.sys 0x07B1F000 \SystemRoot\system32\DRIVERS\WUDFRd.sys 0x07B50000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x76F20000 \Windows\System32\ntdll.dll 0x48510000 \Windows\System32\smss.exe 0xFF240000 \Windows\System32\apisetschema.dll Processes (total 48): 0 System Idle Process 4 System 436 C:\Windows\System32\smss.exe 904 csrss.exe 968 C:\Windows\System32\wininit.exe 976 csrss.exe 108 C:\Windows\System32\services.exe 408 C:\Windows\System32\lsass.exe 548 C:\Windows\System32\lsm.exe 672 C:\Windows\System32\winlogon.exe 892 C:\Windows\System32\svchost.exe 1056 C:\Windows\System32\svchost.exe 1132 C:\Windows\System32\svchost.exe 1208 C:\Windows\System32\svchost.exe 1260 C:\Windows\System32\svchost.exe 1424 C:\Windows\System32\svchost.exe 1628 C:\Windows\System32\svchost.exe 1748 C:\Windows\System32\spoolsv.exe 1820 C:\Windows\System32\svchost.exe 1944 C:\Program Files (x86)\Bonjour\mDNSResponder.exe 2016 C:\Windows\System32\Crypserv.exe 1080 C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe 1568 C:\Windows\System32\svchost.exe 1784 C:\Windows\System32\svchost.exe 2468 WUDFHost.exe 2496 C:\Windows\System32\svchost.exe 2628 C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 3036 C:\Windows\System32\taskhost.exe 620 C:\Windows\System32\dwm.exe 2672 C:\Windows\explorer.exe 2776 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe 232 C:\Windows\SysWOW64\rundll32.exe 1052 C:\Program Files\Logitech\SetPointP\SetPoint.exe 852 C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe 2004 C:\Users\Chris\AppData\Local\Apps\F.lux\flux.exe 2168 C:\Program Files\Windows Sidebar\sidebar.exe 1764 C:\Program Files (x86)\foobar2000\foobar2000.exe 3316 C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe 3328 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 3568 C:\Windows\System32\SearchIndexer.exe 3628 C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe 2508 C:\Windows\System32\svchost.exe 2112 C:\Windows\System32\SearchProtocolHost.exe 4600 C:\Windows\System32\SearchFilterHost.exe 4800 C:\Windows\System32\audiodg.exe 1556 C:\Users\Chris\Desktop\MBRCheck.exe 1532 C:\Windows\System32\conhost.exe 2940 C:\Windows\System32\dllhost.exe \\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS) \\.\X: --> \\.\PhysicalDrive0 at offset 0x00000000`007e0000 (NTFS) PhysicalDrive1 Model Number: WDCWD6401AALS-00L3B2, Rev: 01.03B01 PhysicalDrive0 Model Number: SAMSUNGHD103SJ, Rev: 1AJ10001 Size Device Name MBR Status -------------------------------------------- 596 GB \\.\PhysicalDrive1 MBR Code Faked! SHA1: 1BB72AA843C54C64E74C9F6C9BD22FA2AFA08966 931 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
  7. Extras.txt OTL Extras logfile created on: 11/28/2010 2:17:46 PM - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Chris\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 67.00% Memory free 8.00 Gb Paging File | 7.00 Gb Available in Paging File | 82.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 596.17 Gb Total Space | 518.98 Gb Free Space | 87.05% Space Free | Partition Type: NTFS Drive X: | 931.50 Gb Total Space | 88.30 Gb Free Space | 9.48% Space Free | Partition Type: NTFS Computer Name: ROOK | User Name: Chris | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation) .scr[@ = Icad.load.scr] -- Reg Error: Key error. File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation) .scr [@ = Icad.load.scr] -- Reg Error: Key error. File not found [HKEY_USERS\S-1-5-21-1554432839-2126977190-2861617609-1001\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [ACDSee Photo Manager 12.Manage] -- "C:\Program Files (x86)\ACD Systems\ACDSee\12.0\ACDSeeQV12.exe" "%1" (ACD Systems International Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [takeownership] -- cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDSee Photo Manager 12.Manage] -- "C:\Program Files (x86)\ACD Systems\ACDSee\12.0\ACDSeeQV12.exe" "%1" (ACD Systems International Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [takeownership] -- cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "[iNSTALLDIR]CKOUT.exe" = [iNSTALLDIR]CKOUT.exe:*:Enabled:CKOUT.exe (CadenceLicenseManager) "[iNSTALLDIR]NEOLINLD.exe" = [iNSTALLDIR]NEOLINLD.exe:*:Enabled:NEOLINLD.exe (CadenceLicenseManager) "[iNSTALLDIR]alta.exe" = [iNSTALLDIR]alta.exe:*:Enabled:alta.exe (CadenceLicenseManager) "[iNSTALLDIR]ambitd.exe" = [iNSTALLDIR]ambitd.exe:*:Enabled:ambitd.exe (CadenceLicenseManager) "[iNSTALLDIR]axislmd.exe" = [iNSTALLDIR]axislmd.exe:*:Enabled:axislmd.exe (CadenceLicenseManager) "[iNSTALLDIR]cadmosd.exe" = [iNSTALLDIR]cadmosd.exe:*:Enabled:cadmosd.exe (CadenceLicenseManager) "[iNSTALLDIR]cdslmd.exe" = [iNSTALLDIR]cdslmd.exe:*:Enabled:cdslmd.exe (CadenceLicenseManager) "[iNSTALLDIR]dailmd.exe" = [iNSTALLDIR]dailmd.exe:*:Enabled:dailmd.exe (CadenceLicenseManager) "[iNSTALLDIR]dsmtlmd.exe" = [iNSTALLDIR]dsmtlmd.exe:*:Enabled:dsmtlmd.exe (CadenceLicenseManager) "[iNSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe" = [iNSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe:*:Enabled:CDS_FLEXId_Dongle_Driver_I nstaller.exe (CadenceLicenseManager) "[iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe" = [iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe:*:Enabled:FLEXId_Dongle_Driver_Installer .exe (CadenceLicenseManager) "[iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe" = [iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe:*:Enabled:FLEXId_Dongle_Driver_Instal ler_64.exe (CadenceLicenseManager) "[iNSTALLDIR]g2c_d.exe" = [iNSTALLDIR]g2c_d.exe:*:Enabled:g2c_d.exe (CadenceLicenseManager) "[iNSTALLDIR]hlds.exe" = [iNSTALLDIR]hlds.exe:*:Enabled:hlds.exe (CadenceLicenseManager) "[iNSTALLDIR]installs.exe" = [iNSTALLDIR]installs.exe:*:Enabled:installs.exe (CadenceLicenseManager) "[iNSTALLDIR]k2techld.exe" = [iNSTALLDIR]k2techld.exe:*:Enabled:k2techld.exe (CadenceLicenseManager) "[iNSTALLDIR]lmCheckExpiration.exe" = [iNSTALLDIR]lmCheckExpiration.exe:*:Enabled:lmCheckExpiration.exe (CadenceLicenseManager) "[iNSTALLDIR]lmgrd.exe" = [iNSTALLDIR]lmgrd.exe:*:Enabled:lmgrd.exe (CadenceLicenseManager) "[iNSTALLDIR]lmtools.exe" = [iNSTALLDIR]lmtools.exe:*:Enabled:lmtools.exe (CadenceLicenseManager) "[iNSTALLDIR]lmutil.exe" = [iNSTALLDIR]lmutil.exe:*:Enabled:lmutil.exe (CadenceLicenseManager) "[iNSTALLDIR]perf_test.exe" = [iNSTALLDIR]perf_test.exe:*:Enabled:perf_test.exe (CadenceLicenseManager) "[iNSTALLDIR]platod.exe" = [iNSTALLDIR]platod.exe:*:Enabled:platod.exe (CadenceLicenseManager) "[iNSTALLDIR]qtdaemon.exe" = [iNSTALLDIR]qtdaemon.exe:*:Enabled:qtdaemon.exe (CadenceLicenseManager) "[iNSTALLDIR]qtrekd.exe" = [iNSTALLDIR]qtrekd.exe:*:Enabled:qtrekd.exe (CadenceLicenseManager) "[iNSTALLDIR]simplexlmd.exe" = [iNSTALLDIR]simplexlmd.exe:*:Enabled:simplexlmd.exe (CadenceLicenseManager) "[iNSTALLDIR]spdaemon.exe" = [iNSTALLDIR]spdaemon.exe:*:Enabled:spdaemon.exe (CadenceLicenseManager) "[iNSTALLDIR]speedd.exe" = [iNSTALLDIR]speedd.exe:*:Enabled:speedd.exe (CadenceLicenseManager) "[iNSTALLDIR]verisityd.exe" = [iNSTALLDIR]verisityd.exe:*:Enabled:verisityd.exe (CadenceLicenseManager) "[iNSTALLDIR]verplex.exe" = [iNSTALLDIR]verplex.exe:*:Enabled:verplex.exe (CadenceLicenseManager) "[iNSTALLDIR]LicenseClientConfiguration.exe" = [iNSTALLDIR]LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration. exe (CadenceLicenseManager) "[iNSTALLDIR]LicenseServerConfiguration.exe" = [iNSTALLDIR]LicenseServerConfiguration.exe:*:Enabled:LicenseServerConfiguration. exe (CadenceLicenseManager) "[iNSTALLDIR]Licensing\LicenseClientConfiguration.exe" = [iNSTALLDIR]Licensing\LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration.exe (spb16.3) "[iNSTALLDIR]tools\bin\versionviewer.exe" = [iNSTALLDIR]tools\bin\versionviewer.exe:*:Enabled:versionviewer.exe (spb16.3) "[iNSTALLDIR]tools\bin\switchversion.exe" = [iNSTALLDIR]tools\bin\switchversion.exe:*:Enabled:switchversion.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sys_root.exe" = [iNSTALLDIR]tools\pcb\bin\sys_root.exe:*:Enabled:sys_root.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdnshelp.exe" = [iNSTALLDIR]tools\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe" = [iNSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe:*:Enabled:_cdnshelp.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe" = [iNSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe" = [iNSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe:*:Enabled:cdnshelpindexer.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\indexer.exe" = [iNSTALLDIR]tools\cdnshelp\bin\indexer.exe:*:Enabled:indexer.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\tagtest.exe" = [iNSTALLDIR]tools\cdnshelp\bin\tagtest.exe:*:Enabled:tagtest.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\topicgen.exe" = [iNSTALLDIR]tools\cdnshelp\bin\topicgen.exe:*:Enabled:topicgen.exe (spb16.3) "[iNSTALLDIR]tools\capture\Pcadi.exe" = [iNSTALLDIR]tools\capture\Pcadi.exe:*:Enabled:Pcadi.exe (spb16.3) "[iNSTALLDIR]tools\capture\comp16.exe" = [iNSTALLDIR]tools\capture\comp16.exe:*:Enabled:comp16.exe (spb16.3) "[iNSTALLDIR]tools\capture\Capture.exe" = [iNSTALLDIR]tools\capture\Capture.exe:*:Enabled:Capture.exe (spb16.3) "[iNSTALLDIR]tools\capture\pstswp.exe" = [iNSTALLDIR]tools\capture\pstswp.exe:*:Enabled:pstswp.exe (spb16.3) "[iNSTALLDIR]tools\capture\tutorial\Captutor.exe" = [iNSTALLDIR]tools\capture\tutorial\Captutor.exe:*:Enabled:Captutor.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsOaPathUtil.exe" = [iNSTALLDIR]tools\bin\cdsOaPathUtil.exe:*:Enabled:cdsOaPathUtil.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsUnzip.exe" = [iNSTALLDIR]tools\bin\cdsUnzip.exe:*:Enabled:cdsUnzip.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsZip.exe" = [iNSTALLDIR]tools\bin\cdsZip.exe:*:Enabled:cdsZip.exe (spb16.3) "[iNSTALLDIR]tools\bin\cds_root.exe" = [iNSTALLDIR]tools\bin\cds_root.exe:*:Enabled:cds_root.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsinfo.exe" = [iNSTALLDIR]tools\bin\cdsinfo.exe:*:Enabled:cdsinfo.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdswhich.exe" = [iNSTALLDIR]tools\bin\cdswhich.exe:*:Enabled:cdswhich.exe (spb16.3) "[iNSTALLDIR]tools\bin\clsAdminTool.exe" = [iNSTALLDIR]tools\bin\clsAdminTool.exe:*:Enabled:clsAdminTool.exe (spb16.3) "[iNSTALLDIR]tools\bin\clsbd.exe" = [iNSTALLDIR]tools\bin\clsbd.exe:*:Enabled:clsbd.exe (spb16.3) "[iNSTALLDIR]tools\bin\dregprint.exe" = [iNSTALLDIR]tools\bin\dregprint.exe:*:Enabled:dregprint.exe (spb16.3) "[iNSTALLDIR]tools\bin\nmp.exe" = [iNSTALLDIR]tools\bin\nmp.exe:*:Enabled:nmp.exe (spb16.3) "[iNSTALLDIR]tools\bin\nmppath.exe" = [iNSTALLDIR]tools\bin\nmppath.exe:*:Enabled:nmppath.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\java-rmi.exe" = [iNSTALLDIR]tools\jre\bin\java-rmi.exe:*:Enabled:java-rmi.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\java.exe" = [iNSTALLDIR]tools\jre\bin\java.exe:*:Enabled:java.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\javacpl.exe" = [iNSTALLDIR]tools\jre\bin\javacpl.exe:*:Enabled:javacpl.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\javaw.exe" = [iNSTALLDIR]tools\jre\bin\javaw.exe:*:Enabled:javaw.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\javaws.exe" = [iNSTALLDIR]tools\jre\bin\javaws.exe:*:Enabled:javaws.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\jucheck.exe" = [iNSTALLDIR]tools\jre\bin\jucheck.exe:*:Enabled:jucheck.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\jureg.exe" = [iNSTALLDIR]tools\jre\bin\jureg.exe:*:Enabled:jureg.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\jusched.exe" = [iNSTALLDIR]tools\jre\bin\jusched.exe:*:Enabled:jusched.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\keytool.exe" = [iNSTALLDIR]tools\jre\bin\keytool.exe:*:Enabled:keytool.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\kinit.exe" = [iNSTALLDIR]tools\jre\bin\kinit.exe:*:Enabled:kinit.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\klist.exe" = [iNSTALLDIR]tools\jre\bin\klist.exe:*:Enabled:klist.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\ktab.exe" = [iNSTALLDIR]tools\jre\bin\ktab.exe:*:Enabled:ktab.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\orbd.exe" = [iNSTALLDIR]tools\jre\bin\orbd.exe:*:Enabled:orbd.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\pack200.exe" = [iNSTALLDIR]tools\jre\bin\pack200.exe:*:Enabled:pack200.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\policytool.exe" = [iNSTALLDIR]tools\jre\bin\policytool.exe:*:Enabled:policytool.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\rmid.exe" = [iNSTALLDIR]tools\jre\bin\rmid.exe:*:Enabled:rmid.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\rmiregistry.exe" = [iNSTALLDIR]tools\jre\bin\rmiregistry.exe:*:Enabled:rmiregistry.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\servertool.exe" = [iNSTALLDIR]tools\jre\bin\servertool.exe:*:Enabled:servertool.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\ssvagent.exe" = [iNSTALLDIR]tools\jre\bin\ssvagent.exe:*:Enabled:ssvagent.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\tnameserv.exe" = [iNSTALLDIR]tools\jre\bin\tnameserv.exe:*:Enabled:tnameserv.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\unpack200.exe" = [iNSTALLDIR]tools\jre\bin\unpack200.exe:*:Enabled:unpack200.exe (spb16.3) "[iNSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe" = [iNSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe:*:Enabled:tclsh80.exe (spb16.3) "[iNSTALLDIR]tools\tcltk\tcl\bin\wish80.exe" = [iNSTALLDIR]tools\tcltk\tcl\bin\wish80.exe:*:Enabled:wish80.exe (spb16.3) "[iNSTALLDIR]tools\bin\clu.exe" = [iNSTALLDIR]tools\bin\clu.exe:*:Enabled:clu.exe (spb16.3) "[iNSTALLDIR]tools\bin\van.exe" = [iNSTALLDIR]tools\bin\van.exe:*:Enabled:van.exe (spb16.3) "[iNSTALLDIR]tools\bin\cmfeedback.exe" = [iNSTALLDIR]tools\bin\cmfeedback.exe:*:Enabled:cmfeedback.exe (spb16.3) "[iNSTALLDIR]tools\bin\consmgr.exe" = [iNSTALLDIR]tools\bin\consmgr.exe:*:Enabled:consmgr.exe (spb16.3) "[iNSTALLDIR]tools\bin\emsChecker.exe" = [iNSTALLDIR]tools\bin\emsChecker.exe:*:Enabled:emsChecker.exe (spb16.3) "[iNSTALLDIR]tools\bin\emsMkError.exe" = [iNSTALLDIR]tools\bin\emsMkError.exe:*:Enabled:emsMkError.exe (spb16.3) "[iNSTALLDIR]tools\bin\msgHelp.exe" = [iNSTALLDIR]tools\bin\msgHelp.exe:*:Enabled:msgHelp.exe (spb16.3) "[iNSTALLDIR]tools\bin\eoa.exe" = [iNSTALLDIR]tools\bin\eoa.exe:*:Enabled:eoa.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsMsgServer.exe" = [iNSTALLDIR]tools\bin\cdsMsgServer.exe:*:Enabled:cdsMsgServer.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsNameServer.exe" = [iNSTALLDIR]tools\bin\cdsNameServer.exe:*:Enabled:cdsNameServer.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsRemote.exe" = [iNSTALLDIR]tools\bin\cdsRemote.exe:*:Enabled:cdsRemote.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsRemshClient.exe" = [iNSTALLDIR]tools\bin\cdsRemshClient.exe:*:Enabled:cdsRemshClient.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsRunHidden.exe" = [iNSTALLDIR]tools\bin\cdsRunHidden.exe:*:Enabled:cdsRunHidden.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsServIpc.exe" = [iNSTALLDIR]tools\bin\cdsServIpc.exe:*:Enabled:cdsServIpc.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsmps.exe" = [iNSTALLDIR]tools\bin\cdsmps.exe:*:Enabled:cdsmps.exe (spb16.3) "[iNSTALLDIR]tools\bin\mpsinfo.exe" = [iNSTALLDIR]tools\bin\mpsinfo.exe:*:Enabled:mpsinfo.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe:*:Enabled:def2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe:*:Enabled:lef2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe:*:Enabled:oa2def.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2lef.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2lef.exe:*:Enabled:oa2lef.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2spef.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2spef.exe:*:Enabled:oa2spef.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2strm.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2strm.exe:*:Enabled:oa2strm.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2verilog.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2verilog.exe:*:Enabled:oa2verilog.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oaDMTurboServer.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oaDMTurboServer.exe:*:Enabled:oaDMTurboServer.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oaFSLockD.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oaFSLockD.exe:*:Enabled:oaFSLockD.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oaGetVersion.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oaGetVersion.exe:*:Enabled:oaGetVersion.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\spef2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\spef2oa.exe:*:Enabled:spef2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\strm2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\strm2oa.exe:*:Enabled:strm2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\verilog2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\verilog2oa.exe:*:Enabled:verilog2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\verilogAnnotate.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\verilogAnnotate.exe:*:Enabled:verilogAnnotate.exe (spb16.3) "[iNSTALLDIR]tools\bin\PSpiceExplorerSrvr.exe" = [iNSTALLDIR]tools\bin\PSpiceExplorerSrvr.exe:*:Enabled:PSpiceExplorerSrvr.exe (spb16.3) "[iNSTALLDIR]tools\bin\regsvr32.exe" = [iNSTALLDIR]tools\bin\regsvr32.exe:*:Enabled:regsvr32.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\mkdefcfg.exe" = [iNSTALLDIR]tools\fet\bin\mkdefcfg.exe:*:Enabled:mkdefcfg.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\versiontool.exe" = [iNSTALLDIR]tools\fet\bin\versiontool.exe:*:Enabled:versiontool.exe (spb16.3) "[iNSTALLDIR]tools\capture\sch2cap.exe" = [iNSTALLDIR]tools\capture\sch2cap.exe:*:Enabled:sch2cap.exe (spb16.3) "[iNSTALLDIR]tools\dfII\bin\skill.exe" = [iNSTALLDIR]tools\dfII\bin\skill.exe:*:Enabled:skill.exe (spb16.3) "[iNSTALLDIR]tools\dfII\bin\skill_g.exe" = [iNSTALLDIR]tools\dfII\bin\skill_g.exe:*:Enabled:skill_g.exe (spb16.3) "[iNSTALLDIR]tools\pspice\pspiceaa.exe" = [iNSTALLDIR]tools\pspice\pspiceaa.exe:*:Enabled:pspiceaa.exe (spb16.3) "[iNSTALLDIR]tools\pspice\Magneticdesigner.exe" = [iNSTALLDIR]tools\pspice\Magneticdesigner.exe:*:Enabled:Magneticdesigner.exe (spb16.3) "[iNSTALLDIR]tools\pspice\ModelEd.exe" = [iNSTALLDIR]tools\pspice\ModelEd.exe:*:Enabled:ModelEd.exe (spb16.3) "[iNSTALLDIR]tools\pspice\IndiceFileGeneration.exe" = [iNSTALLDIR]tools\pspice\IndiceFileGeneration.exe:*:Enabled:IndiceFileGeneration.exe (spb16.3) "[iNSTALLDIR]tools\pspice\MrkSrvr.exe" = [iNSTALLDIR]tools\pspice\MrkSrvr.exe:*:Enabled:MrkSrvr.exe (spb16.3) "[iNSTALLDIR]tools\pspice\PSpiceEnc.exe" = [iNSTALLDIR]tools\pspice\PSpiceEnc.exe:*:Enabled:PSpiceEnc.exe (spb16.3) "[iNSTALLDIR]tools\pspice\SimSrvr.exe" = [iNSTALLDIR]tools\pspice\SimSrvr.exe:*:Enabled:SimSrvr.exe (spb16.3) "[iNSTALLDIR]tools\pspice\psp_cmd.exe" = [iNSTALLDIR]tools\pspice\psp_cmd.exe:*:Enabled:psp_cmd.exe (spb16.3) "[iNSTALLDIR]tools\pspice\pspice.exe" = [iNSTALLDIR]tools\pspice\pspice.exe:*:Enabled:pspice.exe (spb16.3) "[iNSTALLDIR]tools\pspice\simmgr.exe" = [iNSTALLDIR]tools\pspice\simmgr.exe:*:Enabled:simmgr.exe (spb16.3) "[iNSTALLDIR]tools\pspice\stmed.exe" = [iNSTALLDIR]tools\pspice\stmed.exe:*:Enabled:stmed.exe (spb16.3) "[iNSTALLDIR]tools\fsp\bin\fsp.exe" = [iNSTALLDIR]tools\fsp\bin\fsp.exe:*:Enabled:fsp.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\QPSetEditor.exe" = [iNSTALLDIR]tools\fet\bin\QPSetEditor.exe:*:Enabled:QPSetEditor.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\UniversalBrowser.exe" = [iNSTALLDIR]tools\fet\bin\UniversalBrowser.exe:*:Enabled:UniversalBrowser.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\pcbCache.exe" = [iNSTALLDIR]tools\fet\bin\pcbCache.exe:*:Enabled:pcbCache.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\lrm.exe" = [iNSTALLDIR]tools\fet\bin\lrm.exe:*:Enabled:lrm.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\purge.exe" = [iNSTALLDIR]tools\fet\bin\purge.exe:*:Enabled:purge.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\rollback.exe" = [iNSTALLDIR]tools\fet\bin\rollback.exe:*:Enabled:rollback.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\a2dxf.exe" = [iNSTALLDIR]tools\pcb\bin\a2dxf.exe:*:Enabled:a2dxf.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dxf2a.exe" = [iNSTALLDIR]tools\pcb\bin\dxf2a.exe:*:Enabled:dxf2a.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\artwork.exe" = [iNSTALLDIR]tools\pcb\bin\artwork.exe:*:Enabled:artwork.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\allegro.exe" = [iNSTALLDIR]tools\pcb\bin\allegro.exe:*:Enabled:allegro.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\allegro_batch.exe" = [iNSTALLDIR]tools\pcb\bin\allegro_batch.exe:*:Enabled:allegro_batch.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\allegro_free_viewer.exe" = [iNSTALLDIR]tools\pcb\bin\allegro_free_viewer.exe:*:Enabled:allegro_free_viewer.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\db_change_type.exe" = [iNSTALLDIR]tools\pcb\bin\db_change_type.exe:*:Enabled:db_change_type.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dbdoctor.exe" = [iNSTALLDIR]tools\pcb\bin\dbdoctor.exe:*:Enabled:dbdoctor.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dbdoctor_ui.exe" = [iNSTALLDIR]tools\pcb\bin\dbdoctor_ui.exe:*:Enabled:dbdoctor_ui.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dbstat.exe" = [iNSTALLDIR]tools\pcb\bin\dbstat.exe:*:Enabled:dbstat.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dfa_dlg.exe" = [iNSTALLDIR]tools\pcb\bin\dfa_dlg.exe:*:Enabled:dfa_dlg.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dfa_update.exe" = [iNSTALLDIR]tools\pcb\bin\dfa_update.exe:*:Enabled:dfa_update.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\downrev_library.exe" = [iNSTALLDIR]tools\pcb\bin\downrev_library.exe:*:Enabled:downrev_library.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\enved.exe" = [iNSTALLDIR]tools\pcb\bin\enved.exe:*:Enabled:enved.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\flash_convert.exe" = [iNSTALLDIR]tools\pcb\bin\flash_convert.exe:*:Enabled:flash_convert.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\fpbrowse.exe" = [iNSTALLDIR]tools\pcb\bin\fpbrowse.exe:*:Enabled:fpbrowse.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\layer_compare.exe" = [iNSTALLDIR]tools\pcb\bin\layer_compare.exe:*:Enabled:layer_compare.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\qvupdate.exe" = [iNSTALLDIR]tools\pcb\bin\qvupdate.exe:*:Enabled:qvupdate.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sip_free_viewer.exe" = [iNSTALLDIR]tools\pcb\bin\sip_free_viewer.exe:*:Enabled:sip_free_viewer.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\systemdump.exe" = [iNSTALLDIR]tools\pcb\bin\systemdump.exe:*:Enabled:systemdump.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\uprev.exe" = [iNSTALLDIR]tools\pcb\bin\uprev.exe:*:Enabled:uprev.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\batch_drc.exe" = [iNSTALLDIR]tools\pcb\bin\batch_drc.exe:*:Enabled:batch_drc.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\bbvia.exe" = [iNSTALLDIR]tools\pcb\bin\bbvia.exe:*:Enabled:bbvia.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\convert_gerber.exe" = [iNSTALLDIR]tools\pcb\bin\convert_gerber.exe:*:Enabled:convert_gerber.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\create_devices.exe" = [iNSTALLDIR]tools\pcb\bin\create_devices.exe:*:Enabled:create_devices.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\create_sym.exe" = [iNSTALLDIR]tools\pcb\bin\create_sym.exe:*:Enabled:create_sym.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\draw_check.exe" = [iNSTALLDIR]tools\pcb\bin\draw_check.exe:*:Enabled:draw_check.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dump_libraries.exe" = [iNSTALLDIR]tools\pcb\bin\dump_libraries.exe:*:Enabled:dump_libraries.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\plctxt.exe" = [iNSTALLDIR]tools\pcb\bin\plctxt.exe:*:Enabled:plctxt.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\genfeedformat.exe" = [iNSTALLDIR]tools\pcb\bin\genfeedformat.exe:*:Enabled:genfeedformat.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\netrev.exe" = [iNSTALLDIR]tools\pcb\bin\netrev.exe:*:Enabled:netrev.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\idf_in.exe" = [iNSTALLDIR]tools\pcb\bin\idf_in.exe:*:Enabled:idf_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\idf_out.exe" = [iNSTALLDIR]tools\pcb\bin\idf_out.exe:*:Enabled:idf_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\idx_out.exe" = [iNSTALLDIR]tools\pcb\bin\idx_out.exe:*:Enabled:idx_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\iges_in.exe" = [iNSTALLDIR]tools\pcb\bin\iges_in.exe:*:Enabled:iges_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\iges_out.exe" = [iNSTALLDIR]tools\pcb\bin\iges_out.exe:*:Enabled:iges_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ipc356_out.exe" = [iNSTALLDIR]tools\pcb\bin\ipc356_out.exe:*:Enabled:ipc356_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\explot.exe" = [iNSTALLDIR]tools\pcb\bin\explot.exe:*:Enabled:explot.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\gbplot.exe" = [iNSTALLDIR]tools\pcb\bin\gbplot.exe:*:Enabled:gbplot.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\genrad.exe" = [iNSTALLDIR]tools\pcb\bin\genrad.exe:*:Enabled:genrad.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\gloss.exe" = [iNSTALLDIR]tools\pcb\bin\gloss.exe:*:Enabled:gloss.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ncroute.exe" = [iNSTALLDIR]tools\pcb\bin\ncroute.exe:*:Enabled:ncroute.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\nctape.exe" = [iNSTALLDIR]tools\pcb\bin\nctape.exe:*:Enabled:nctape.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\netin.exe" = [iNSTALLDIR]tools\pcb\bin\netin.exe:*:Enabled:netin.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pad_designer.exe" = [iNSTALLDIR]tools\pcb\bin\pad_designer.exe:*:Enabled:pad_designer.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\l2a.exe" = [iNSTALLDIR]tools\pcb\bin\l2a.exe:*:Enabled:l2a.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pads_in.exe" = [iNSTALLDIR]tools\pcb\bin\pads_in.exe:*:Enabled:pads_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pcad_in.exe" = [iNSTALLDIR]tools\pcb\bin\pcad_in.exe:*:Enabled:pcad_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\placement.exe" = [iNSTALLDIR]tools\pcb\bin\placement.exe:*:Enabled:placement.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\swap.exe" = [iNSTALLDIR]tools\pcb\bin\swap.exe:*:Enabled:swap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\downrev14.exe" = [iNSTALLDIR]tools\pcb\bin\downrev14.exe:*:Enabled:downrev14.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile13.exe" = [iNSTALLDIR]tools\pcb\bin\techfile13.exe:*:Enabled:techfile13.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile14.exe" = [iNSTALLDIR]tools\pcb\bin\techfile14.exe:*:Enabled:techfile14.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile15.exe" = [iNSTALLDIR]tools\pcb\bin\techfile15.exe:*:Enabled:techfile15.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor14.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor14.exe:*:Enabled:dbdoctor14.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor15.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor15.exe:*:Enabled:dbdoctor15.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbfix11.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbfix11.exe:*:Enabled:dbfix11.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbfix12.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbfix12.exe:*:Enabled:dbfix12.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbfix13.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbfix13.exe:*:Enabled:dbfix13.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\downrev15.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\downrev15.exe:*:Enabled:downrev15.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spif.exe" = [iNSTALLDIR]tools\pcb\bin\spif.exe:*:Enabled:spif.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spif_batch.exe" = [iNSTALLDIR]tools\pcb\bin\spif_batch.exe:*:Enabled:spif_batch.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mbs2lib.exe" = [iNSTALLDIR]tools\pcb\bin\mbs2lib.exe:*:Enabled:mbs2lib.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\FSvia.exe" = [iNSTALLDIR]tools\pcb\bin\FSvia.exe:*:Enabled:FSvia.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\FSviaSolver.exe" = [iNSTALLDIR]tools\pcb\bin\FSviaSolver.exe:*:Enabled:FSviaSolver.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\bem2d.exe" = [iNSTALLDIR]tools\pcb\bin\bem2d.exe:*:Enabled:bem2d.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ems2d.exe" = [iNSTALLDIR]tools\pcb\bin\ems2d.exe:*:Enabled:ems2d.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\extracta.exe" = [iNSTALLDIR]tools\pcb\bin\extracta.exe:*:Enabled:extracta.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\fatten.exe" = [iNSTALLDIR]tools\pcb\bin\fatten.exe:*:Enabled:fatten.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\gate_assign.exe" = [iNSTALLDIR]tools\pcb\bin\gate_assign.exe:*:Enabled:gate_assign.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\il_allegro.exe" = [iNSTALLDIR]tools\pcb\bin\il_allegro.exe:*:Enabled:il_allegro.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\j2script.exe" = [iNSTALLDIR]tools\pcb\bin\j2script.exe:*:Enabled:j2script.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mcm_escapes.exe" = [iNSTALLDIR]tools\pcb\bin\mcm_escapes.exe:*:Enabled:mcm_escapes.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mpiexec.exe" = [iNSTALLDIR]tools\pcb\bin\mpiexec.exe:*:Enabled:mpiexec.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\parallel.exe" = [iNSTALLDIR]tools\pcb\bin\parallel.exe:*:Enabled:parallel.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pe_wordpad.exe" = [iNSTALLDIR]tools\pcb\bin\pe_wordpad.exe:*:Enabled:pe_wordpad.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pre_check.exe" = [iNSTALLDIR]tools\pcb\bin\pre_check.exe:*:Enabled:pre_check.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\refresh_padstack.exe" = [iNSTALLDIR]tools\pcb\bin\refresh_padstack.exe:*:Enabled:refresh_padstack.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\refresh_symbol.exe" = [iNSTALLDIR]tools\pcb\bin\refresh_symbol.exe:*:Enabled:refresh_symbol.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\refresh_vs.exe" = [iNSTALLDIR]tools\pcb\bin\refresh_vs.exe:*:Enabled:refresh_vs.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\reftxt.exe" = [iNSTALLDIR]tools\pcb\bin\reftxt.exe:*:Enabled:reftxt.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\report.exe" = [iNSTALLDIR]tools\pcb\bin\report.exe:*:Enabled:report.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\smpd.exe" = [iNSTALLDIR]tools\pcb\bin\smpd.exe:*:Enabled:smpd.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile.exe" = [iNSTALLDIR]tools\pcb\bin\techfile.exe:*:Enabled:techfile.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\wmpiconfig.exe" = [iNSTALLDIR]tools\pcb\bin\wmpiconfig.exe:*:Enabled:wmpiconfig.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\wmpiexec.exe" = [iNSTALLDIR]tools\pcb\bin\wmpiexec.exe:*:Enabled:wmpiexec.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\wmpiregister.exe" = [iNSTALLDIR]tools\pcb\bin\wmpiregister.exe:*:Enabled:wmpiregister.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\zrouter.exe" = [iNSTALLDIR]tools\pcb\bin\zrouter.exe:*:Enabled:zrouter.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\bodygen.exe" = [iNSTALLDIR]tools\fet\bin\bodygen.exe:*:Enabled:bodygen.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\newgenasym.exe" = [iNSTALLDIR]tools\fet\bin\newgenasym.exe:*:Enabled:newgenasym.exe (spb16.3) "[iNSTALLDIR]tools\msbase\vcredist_x86.exe" = [iNSTALLDIR]tools\msbase\vcredist_x86.exe:*:Enabled:vcredist_x86.exe (spb16.3) "[iNSTALLDIR]tools\perl5\bin\perl.exe" = [iNSTALLDIR]tools\perl5\bin\perl.exe:*:Enabled:perl.exe (spb16.3) "[iNSTALLDIR]tools\perl5\bin\perlglob.exe" = [iNSTALLDIR]tools\perl5\bin\perlglob.exe:*:Enabled:perlglob.exe (spb16.3) "[iNSTALLDIR]tools\perl5\ntt\cmd32.exe" = [iNSTALLDIR]tools\perl5\ntt\cmd32.exe:*:Enabled:cmd32.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\productServer.exe" = [iNSTALLDIR]tools\pcb\bin\productServer.exe:*:Enabled:productServer.exe (spb16.3) "[iNSTALLDIR]tools\bin\conceptNmpListCheck.exe" = [iNSTALLDIR]tools\bin\conceptNmpListCheck.exe:*:Enabled:conceptNmpListCheck.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\cpmaccess.exe" = [iNSTALLDIR]tools\fet\bin\cpmaccess.exe:*:Enabled:cpmaccess.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\libaccess.exe" = [iNSTALLDIR]tools\fet\bin\libaccess.exe:*:Enabled:libaccess.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\projmgr.exe" = [iNSTALLDIR]tools\fet\bin\projmgr.exe:*:Enabled:projmgr.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\pseteditor.exe" = [iNSTALLDIR]tools\fet\bin\pseteditor.exe:*:Enabled:pseteditor.exe (spb16.3) "[iNSTALLDIR]tools\specctra\bin\mbs2sp.exe" = [iNSTALLDIR]tools\specctra\bin\mbs2sp.exe:*:Enabled:mbs2sp.exe (spb16.3) "[iNSTALLDIR]tools\specctra\bin\sp2mbs.exe" = [iNSTALLDIR]tools\specctra\bin\sp2mbs.exe:*:Enabled:sp2mbs.exe (spb16.3) "[iNSTALLDIR]tools\specctra\bin\specctra.exe" = [iNSTALLDIR]tools\specctra\bin\specctra.exe:*:Enabled:specctra.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\signoise.exe" = [iNSTALLDIR]tools\pcb\bin\signoise.exe:*:Enabled:signoise.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\lis2buf.exe" = [iNSTALLDIR]tools\pcb\bin\lis2buf.exe:*:Enabled:lis2buf.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\modeleditor.exe" = [iNSTALLDIR]tools\pcb\bin\modeleditor.exe:*:Enabled:modeleditor.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\modelintegrity.exe" = [iNSTALLDIR]tools\pcb\bin\modelintegrity.exe:*:Enabled:modelintegrity.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\modelsim.exe" = [iNSTALLDIR]tools\pcb\bin\modelsim.exe:*:Enabled:modelsim.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spc2dml.exe" = [iNSTALLDIR]tools\pcb\bin\spc2dml.exe:*:Enabled:spc2dml.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sigxp.exe" = [iNSTALLDIR]tools\pcb\bin\sigxp.exe:*:Enabled:sigxp.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\aprepmap.exe" = [iNSTALLDIR]tools\pcb\bin\aprepmap.exe:*:Enabled:aprepmap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ashowmap.exe" = [iNSTALLDIR]tools\pcb\bin\ashowmap.exe:*:Enabled:ashowmap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\aconvmap.exe" = [iNSTALLDIR]tools\pcb\bin\aconvmap.exe:*:Enabled:aconvmap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\brd2dml.exe" = [iNSTALLDIR]tools\pcb\bin\brd2dml.exe:*:Enabled:brd2dml.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dml2brd.exe" = [iNSTALLDIR]tools\pcb\bin\dml2brd.exe:*:Enabled:dml2brd.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dmlcheck.exe" = [iNSTALLDIR]tools\pcb\bin\dmlcheck.exe:*:Enabled:dmlcheck.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dmlcrypt.exe" = [iNSTALLDIR]tools\pcb\bin\dmlcrypt.exe:*:Enabled:dmlcrypt.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ftsmerge.exe" = [iNSTALLDIR]tools\pcb\bin\ftsmerge.exe:*:Enabled:ftsmerge.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ibis2signoise.exe" = [iNSTALLDIR]tools\pcb\bin\ibis2signoise.exe:*:Enabled:ibis2signoise.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ibischk3.exe" = [iNSTALLDIR]tools\pcb\bin\ibischk3.exe:*:Enabled:ibischk3.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ibischk4.exe" = [iNSTALLDIR]tools\pcb\bin\ibischk4.exe:*:Enabled:ibischk4.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\icmchk.exe" = [iNSTALLDIR]tools\pcb\bin\icmchk.exe:*:Enabled:icmchk.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mergedml.exe" = [iNSTALLDIR]tools\pcb\bin\mergedml.exe:*:Enabled:mergedml.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mkdeviceindex.exe" = [iNSTALLDIR]tools\pcb\bin\mkdeviceindex.exe:*:Enabled:mkdeviceindex.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\quad2signoise.exe" = [iNSTALLDIR]tools\pcb\bin\quad2signoise.exe:*:Enabled:quad2signoise.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sigwave.exe" = [iNSTALLDIR]tools\pcb\bin\sigwave.exe:*:Enabled:sigwave.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sigxsect.exe" = [iNSTALLDIR]tools\pcb\bin\sigxsect.exe:*:Enabled:sigxsect.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spc2spc.exe" = [iNSTALLDIR]tools\pcb\bin\spc2spc.exe:*:Enabled:spc2spc.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\tlsim.exe" = [iNSTALLDIR]tools\pcb\bin\tlsim.exe:*:Enabled:tlsim.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ts2dml.exe" = [iNSTALLDIR]tools\pcb\bin\ts2dml.exe:*:Enabled:ts2dml.exe (spb16.3) "C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe" = C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (OpenSight Software, LLC) "[iNSTALLDIR]CKOUT.exe" = [iNSTALLDIR]CKOUT.exe:*:Enabled:CKOUT.exe (CadenceLicenseManager) "[iNSTALLDIR]NEOLINLD.exe" = [iNSTALLDIR]NEOLINLD.exe:*:Enabled:NEOLINLD.exe (CadenceLicenseManager) "[iNSTALLDIR]alta.exe" = [iNSTALLDIR]alta.exe:*:Enabled:alta.exe (CadenceLicenseManager) "[iNSTALLDIR]ambitd.exe" = [iNSTALLDIR]ambitd.exe:*:Enabled:ambitd.exe (CadenceLicenseManager) "[iNSTALLDIR]axislmd.exe" = [iNSTALLDIR]axislmd.exe:*:Enabled:axislmd.exe (CadenceLicenseManager) "[iNSTALLDIR]cadmosd.exe" = [iNSTALLDIR]cadmosd.exe:*:Enabled:cadmosd.exe (CadenceLicenseManager) "[iNSTALLDIR]cdslmd.exe" = [iNSTALLDIR]cdslmd.exe:*:Enabled:cdslmd.exe (CadenceLicenseManager) "[iNSTALLDIR]dailmd.exe" = [iNSTALLDIR]dailmd.exe:*:Enabled:dailmd.exe (CadenceLicenseManager) "[iNSTALLDIR]dsmtlmd.exe" = [iNSTALLDIR]dsmtlmd.exe:*:Enabled:dsmtlmd.exe (CadenceLicenseManager) "[iNSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe" = [iNSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe:*:Enabled:CDS_FLEXId_Dongle_Driver_I nstaller.exe (CadenceLicenseManager) "[iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe" = [iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe:*:Enabled:FLEXId_Dongle_Driver_Installer .exe (CadenceLicenseManager) "[iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe" = [iNSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe:*:Enabled:FLEXId_Dongle_Driver_Instal ler_64.exe (CadenceLicenseManager) "[iNSTALLDIR]g2c_d.exe" = [iNSTALLDIR]g2c_d.exe:*:Enabled:g2c_d.exe (CadenceLicenseManager) "[iNSTALLDIR]hlds.exe" = [iNSTALLDIR]hlds.exe:*:Enabled:hlds.exe (CadenceLicenseManager) "[iNSTALLDIR]installs.exe" = [iNSTALLDIR]installs.exe:*:Enabled:installs.exe (CadenceLicenseManager) "[iNSTALLDIR]k2techld.exe" = [iNSTALLDIR]k2techld.exe:*:Enabled:k2techld.exe (CadenceLicenseManager) "[iNSTALLDIR]lmCheckExpiration.exe" = [iNSTALLDIR]lmCheckExpiration.exe:*:Enabled:lmCheckExpiration.exe (CadenceLicenseManager) "[iNSTALLDIR]lmgrd.exe" = [iNSTALLDIR]lmgrd.exe:*:Enabled:lmgrd.exe (CadenceLicenseManager) "[iNSTALLDIR]lmtools.exe" = [iNSTALLDIR]lmtools.exe:*:Enabled:lmtools.exe (CadenceLicenseManager) "[iNSTALLDIR]lmutil.exe" = [iNSTALLDIR]lmutil.exe:*:Enabled:lmutil.exe (CadenceLicenseManager) "[iNSTALLDIR]perf_test.exe" = [iNSTALLDIR]perf_test.exe:*:Enabled:perf_test.exe (CadenceLicenseManager) "[iNSTALLDIR]platod.exe" = [iNSTALLDIR]platod.exe:*:Enabled:platod.exe (CadenceLicenseManager) "[iNSTALLDIR]qtdaemon.exe" = [iNSTALLDIR]qtdaemon.exe:*:Enabled:qtdaemon.exe (CadenceLicenseManager) "[iNSTALLDIR]qtrekd.exe" = [iNSTALLDIR]qtrekd.exe:*:Enabled:qtrekd.exe (CadenceLicenseManager) "[iNSTALLDIR]simplexlmd.exe" = [iNSTALLDIR]simplexlmd.exe:*:Enabled:simplexlmd.exe (CadenceLicenseManager) "[iNSTALLDIR]spdaemon.exe" = [iNSTALLDIR]spdaemon.exe:*:Enabled:spdaemon.exe (CadenceLicenseManager) "[iNSTALLDIR]speedd.exe" = [iNSTALLDIR]speedd.exe:*:Enabled:speedd.exe (CadenceLicenseManager) "[iNSTALLDIR]verisityd.exe" = [iNSTALLDIR]verisityd.exe:*:Enabled:verisityd.exe (CadenceLicenseManager) "[iNSTALLDIR]verplex.exe" = [iNSTALLDIR]verplex.exe:*:Enabled:verplex.exe (CadenceLicenseManager) "[iNSTALLDIR]LicenseClientConfiguration.exe" = [iNSTALLDIR]LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration. exe (CadenceLicenseManager) "[iNSTALLDIR]LicenseServerConfiguration.exe" = [iNSTALLDIR]LicenseServerConfiguration.exe:*:Enabled:LicenseServerConfiguration. exe (CadenceLicenseManager) "[iNSTALLDIR]Licensing\LicenseClientConfiguration.exe" = [iNSTALLDIR]Licensing\LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration.exe (spb16.3) "[iNSTALLDIR]tools\bin\versionviewer.exe" = [iNSTALLDIR]tools\bin\versionviewer.exe:*:Enabled:versionviewer.exe (spb16.3) "[iNSTALLDIR]tools\bin\switchversion.exe" = [iNSTALLDIR]tools\bin\switchversion.exe:*:Enabled:switchversion.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sys_root.exe" = [iNSTALLDIR]tools\pcb\bin\sys_root.exe:*:Enabled:sys_root.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdnshelp.exe" = [iNSTALLDIR]tools\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe" = [iNSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe:*:Enabled:_cdnshelp.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe" = [iNSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe" = [iNSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe:*:Enabled:cdnshelpindexer.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\indexer.exe" = [iNSTALLDIR]tools\cdnshelp\bin\indexer.exe:*:Enabled:indexer.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\tagtest.exe" = [iNSTALLDIR]tools\cdnshelp\bin\tagtest.exe:*:Enabled:tagtest.exe (spb16.3) "[iNSTALLDIR]tools\cdnshelp\bin\topicgen.exe" = [iNSTALLDIR]tools\cdnshelp\bin\topicgen.exe:*:Enabled:topicgen.exe (spb16.3) "[iNSTALLDIR]tools\capture\Pcadi.exe" = [iNSTALLDIR]tools\capture\Pcadi.exe:*:Enabled:Pcadi.exe (spb16.3) "[iNSTALLDIR]tools\capture\comp16.exe" = [iNSTALLDIR]tools\capture\comp16.exe:*:Enabled:comp16.exe (spb16.3) "[iNSTALLDIR]tools\capture\Capture.exe" = [iNSTALLDIR]tools\capture\Capture.exe:*:Enabled:Capture.exe (spb16.3) "[iNSTALLDIR]tools\capture\pstswp.exe" = [iNSTALLDIR]tools\capture\pstswp.exe:*:Enabled:pstswp.exe (spb16.3) "[iNSTALLDIR]tools\capture\tutorial\Captutor.exe" = [iNSTALLDIR]tools\capture\tutorial\Captutor.exe:*:Enabled:Captutor.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsOaPathUtil.exe" = [iNSTALLDIR]tools\bin\cdsOaPathUtil.exe:*:Enabled:cdsOaPathUtil.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsUnzip.exe" = [iNSTALLDIR]tools\bin\cdsUnzip.exe:*:Enabled:cdsUnzip.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsZip.exe" = [iNSTALLDIR]tools\bin\cdsZip.exe:*:Enabled:cdsZip.exe (spb16.3) "[iNSTALLDIR]tools\bin\cds_root.exe" = [iNSTALLDIR]tools\bin\cds_root.exe:*:Enabled:cds_root.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsinfo.exe" = [iNSTALLDIR]tools\bin\cdsinfo.exe:*:Enabled:cdsinfo.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdswhich.exe" = [iNSTALLDIR]tools\bin\cdswhich.exe:*:Enabled:cdswhich.exe (spb16.3) "[iNSTALLDIR]tools\bin\clsAdminTool.exe" = [iNSTALLDIR]tools\bin\clsAdminTool.exe:*:Enabled:clsAdminTool.exe (spb16.3) "[iNSTALLDIR]tools\bin\clsbd.exe" = [iNSTALLDIR]tools\bin\clsbd.exe:*:Enabled:clsbd.exe (spb16.3) "[iNSTALLDIR]tools\bin\dregprint.exe" = [iNSTALLDIR]tools\bin\dregprint.exe:*:Enabled:dregprint.exe (spb16.3) "[iNSTALLDIR]tools\bin\nmp.exe" = [iNSTALLDIR]tools\bin\nmp.exe:*:Enabled:nmp.exe (spb16.3) "[iNSTALLDIR]tools\bin\nmppath.exe" = [iNSTALLDIR]tools\bin\nmppath.exe:*:Enabled:nmppath.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\java-rmi.exe" = [iNSTALLDIR]tools\jre\bin\java-rmi.exe:*:Enabled:java-rmi.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\java.exe" = [iNSTALLDIR]tools\jre\bin\java.exe:*:Enabled:java.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\javacpl.exe" = [iNSTALLDIR]tools\jre\bin\javacpl.exe:*:Enabled:javacpl.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\javaw.exe" = [iNSTALLDIR]tools\jre\bin\javaw.exe:*:Enabled:javaw.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\javaws.exe" = [iNSTALLDIR]tools\jre\bin\javaws.exe:*:Enabled:javaws.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\jucheck.exe" = [iNSTALLDIR]tools\jre\bin\jucheck.exe:*:Enabled:jucheck.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\jureg.exe" = [iNSTALLDIR]tools\jre\bin\jureg.exe:*:Enabled:jureg.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\jusched.exe" = [iNSTALLDIR]tools\jre\bin\jusched.exe:*:Enabled:jusched.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\keytool.exe" = [iNSTALLDIR]tools\jre\bin\keytool.exe:*:Enabled:keytool.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\kinit.exe" = [iNSTALLDIR]tools\jre\bin\kinit.exe:*:Enabled:kinit.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\klist.exe" = [iNSTALLDIR]tools\jre\bin\klist.exe:*:Enabled:klist.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\ktab.exe" = [iNSTALLDIR]tools\jre\bin\ktab.exe:*:Enabled:ktab.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\orbd.exe" = [iNSTALLDIR]tools\jre\bin\orbd.exe:*:Enabled:orbd.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\pack200.exe" = [iNSTALLDIR]tools\jre\bin\pack200.exe:*:Enabled:pack200.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\policytool.exe" = [iNSTALLDIR]tools\jre\bin\policytool.exe:*:Enabled:policytool.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\rmid.exe" = [iNSTALLDIR]tools\jre\bin\rmid.exe:*:Enabled:rmid.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\rmiregistry.exe" = [iNSTALLDIR]tools\jre\bin\rmiregistry.exe:*:Enabled:rmiregistry.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\servertool.exe" = [iNSTALLDIR]tools\jre\bin\servertool.exe:*:Enabled:servertool.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\ssvagent.exe" = [iNSTALLDIR]tools\jre\bin\ssvagent.exe:*:Enabled:ssvagent.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\tnameserv.exe" = [iNSTALLDIR]tools\jre\bin\tnameserv.exe:*:Enabled:tnameserv.exe (spb16.3) "[iNSTALLDIR]tools\jre\bin\unpack200.exe" = [iNSTALLDIR]tools\jre\bin\unpack200.exe:*:Enabled:unpack200.exe (spb16.3) "[iNSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe" = [iNSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe:*:Enabled:tclsh80.exe (spb16.3) "[iNSTALLDIR]tools\tcltk\tcl\bin\wish80.exe" = [iNSTALLDIR]tools\tcltk\tcl\bin\wish80.exe:*:Enabled:wish80.exe (spb16.3) "[iNSTALLDIR]tools\bin\clu.exe" = [iNSTALLDIR]tools\bin\clu.exe:*:Enabled:clu.exe (spb16.3) "[iNSTALLDIR]tools\bin\van.exe" = [iNSTALLDIR]tools\bin\van.exe:*:Enabled:van.exe (spb16.3) "[iNSTALLDIR]tools\bin\cmfeedback.exe" = [iNSTALLDIR]tools\bin\cmfeedback.exe:*:Enabled:cmfeedback.exe (spb16.3) "[iNSTALLDIR]tools\bin\consmgr.exe" = [iNSTALLDIR]tools\bin\consmgr.exe:*:Enabled:consmgr.exe (spb16.3) "[iNSTALLDIR]tools\bin\emsChecker.exe" = [iNSTALLDIR]tools\bin\emsChecker.exe:*:Enabled:emsChecker.exe (spb16.3) "[iNSTALLDIR]tools\bin\emsMkError.exe" = [iNSTALLDIR]tools\bin\emsMkError.exe:*:Enabled:emsMkError.exe (spb16.3) "[iNSTALLDIR]tools\bin\msgHelp.exe" = [iNSTALLDIR]tools\bin\msgHelp.exe:*:Enabled:msgHelp.exe (spb16.3) "[iNSTALLDIR]tools\bin\eoa.exe" = [iNSTALLDIR]tools\bin\eoa.exe:*:Enabled:eoa.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsMsgServer.exe" = [iNSTALLDIR]tools\bin\cdsMsgServer.exe:*:Enabled:cdsMsgServer.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsNameServer.exe" = [iNSTALLDIR]tools\bin\cdsNameServer.exe:*:Enabled:cdsNameServer.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsRemote.exe" = [iNSTALLDIR]tools\bin\cdsRemote.exe:*:Enabled:cdsRemote.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsRemshClient.exe" = [iNSTALLDIR]tools\bin\cdsRemshClient.exe:*:Enabled:cdsRemshClient.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsRunHidden.exe" = [iNSTALLDIR]tools\bin\cdsRunHidden.exe:*:Enabled:cdsRunHidden.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsServIpc.exe" = [iNSTALLDIR]tools\bin\cdsServIpc.exe:*:Enabled:cdsServIpc.exe (spb16.3) "[iNSTALLDIR]tools\bin\cdsmps.exe" = [iNSTALLDIR]tools\bin\cdsmps.exe:*:Enabled:cdsmps.exe (spb16.3) "[iNSTALLDIR]tools\bin\mpsinfo.exe" = [iNSTALLDIR]tools\bin\mpsinfo.exe:*:Enabled:mpsinfo.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe:*:Enabled:def2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe:*:Enabled:lef2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe:*:Enabled:oa2def.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2lef.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2lef.exe:*:Enabled:oa2lef.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2spef.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2spef.exe:*:Enabled:oa2spef.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2strm.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2strm.exe:*:Enabled:oa2strm.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oa2verilog.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oa2verilog.exe:*:Enabled:oa2verilog.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oaDMTurboServer.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oaDMTurboServer.exe:*:Enabled:oaDMTurboServer.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oaFSLockD.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oaFSLockD.exe:*:Enabled:oaFSLockD.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\oaGetVersion.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\oaGetVersion.exe:*:Enabled:oaGetVersion.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\spef2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\spef2oa.exe:*:Enabled:spef2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\strm2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\strm2oa.exe:*:Enabled:strm2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\verilog2oa.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\verilog2oa.exe:*:Enabled:verilog2oa.exe (spb16.3) "[iNSTALLDIR]OpenAccess\bin\win32\opt\verilogAnnotate.exe" = [iNSTALLDIR]OpenAccess\bin\win32\opt\verilogAnnotate.exe:*:Enabled:verilogAnnotate.exe (spb16.3) "[iNSTALLDIR]tools\bin\PSpiceExplorerSrvr.exe" = [iNSTALLDIR]tools\bin\PSpiceExplorerSrvr.exe:*:Enabled:PSpiceExplorerSrvr.exe (spb16.3) "[iNSTALLDIR]tools\bin\regsvr32.exe" = [iNSTALLDIR]tools\bin\regsvr32.exe:*:Enabled:regsvr32.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\mkdefcfg.exe" = [iNSTALLDIR]tools\fet\bin\mkdefcfg.exe:*:Enabled:mkdefcfg.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\versiontool.exe" = [iNSTALLDIR]tools\fet\bin\versiontool.exe:*:Enabled:versiontool.exe (spb16.3) "[iNSTALLDIR]tools\capture\sch2cap.exe" = [iNSTALLDIR]tools\capture\sch2cap.exe:*:Enabled:sch2cap.exe (spb16.3) "[iNSTALLDIR]tools\dfII\bin\skill.exe" = [iNSTALLDIR]tools\dfII\bin\skill.exe:*:Enabled:skill.exe (spb16.3) "[iNSTALLDIR]tools\dfII\bin\skill_g.exe" = [iNSTALLDIR]tools\dfII\bin\skill_g.exe:*:Enabled:skill_g.exe (spb16.3) "[iNSTALLDIR]tools\pspice\pspiceaa.exe" = [iNSTALLDIR]tools\pspice\pspiceaa.exe:*:Enabled:pspiceaa.exe (spb16.3) "[iNSTALLDIR]tools\pspice\Magneticdesigner.exe" = [iNSTALLDIR]tools\pspice\Magneticdesigner.exe:*:Enabled:Magneticdesigner.exe (spb16.3) "[iNSTALLDIR]tools\pspice\ModelEd.exe" = [iNSTALLDIR]tools\pspice\ModelEd.exe:*:Enabled:ModelEd.exe (spb16.3) "[iNSTALLDIR]tools\pspice\IndiceFileGeneration.exe" = [iNSTALLDIR]tools\pspice\IndiceFileGeneration.exe:*:Enabled:IndiceFileGeneration.exe (spb16.3) "[iNSTALLDIR]tools\pspice\MrkSrvr.exe" = [iNSTALLDIR]tools\pspice\MrkSrvr.exe:*:Enabled:MrkSrvr.exe (spb16.3) "[iNSTALLDIR]tools\pspice\PSpiceEnc.exe" = [iNSTALLDIR]tools\pspice\PSpiceEnc.exe:*:Enabled:PSpiceEnc.exe (spb16.3) "[iNSTALLDIR]tools\pspice\SimSrvr.exe" = [iNSTALLDIR]tools\pspice\SimSrvr.exe:*:Enabled:SimSrvr.exe (spb16.3) "[iNSTALLDIR]tools\pspice\psp_cmd.exe" = [iNSTALLDIR]tools\pspice\psp_cmd.exe:*:Enabled:psp_cmd.exe (spb16.3) "[iNSTALLDIR]tools\pspice\pspice.exe" = [iNSTALLDIR]tools\pspice\pspice.exe:*:Enabled:pspice.exe (spb16.3) "[iNSTALLDIR]tools\pspice\simmgr.exe" = [iNSTALLDIR]tools\pspice\simmgr.exe:*:Enabled:simmgr.exe (spb16.3) "[iNSTALLDIR]tools\pspice\stmed.exe" = [iNSTALLDIR]tools\pspice\stmed.exe:*:Enabled:stmed.exe (spb16.3) "[iNSTALLDIR]tools\fsp\bin\fsp.exe" = [iNSTALLDIR]tools\fsp\bin\fsp.exe:*:Enabled:fsp.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\QPSetEditor.exe" = [iNSTALLDIR]tools\fet\bin\QPSetEditor.exe:*:Enabled:QPSetEditor.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\UniversalBrowser.exe" = [iNSTALLDIR]tools\fet\bin\UniversalBrowser.exe:*:Enabled:UniversalBrowser.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\pcbCache.exe" = [iNSTALLDIR]tools\fet\bin\pcbCache.exe:*:Enabled:pcbCache.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\lrm.exe" = [iNSTALLDIR]tools\fet\bin\lrm.exe:*:Enabled:lrm.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\purge.exe" = [iNSTALLDIR]tools\fet\bin\purge.exe:*:Enabled:purge.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\rollback.exe" = [iNSTALLDIR]tools\fet\bin\rollback.exe:*:Enabled:rollback.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\a2dxf.exe" = [iNSTALLDIR]tools\pcb\bin\a2dxf.exe:*:Enabled:a2dxf.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dxf2a.exe" = [iNSTALLDIR]tools\pcb\bin\dxf2a.exe:*:Enabled:dxf2a.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\artwork.exe" = [iNSTALLDIR]tools\pcb\bin\artwork.exe:*:Enabled:artwork.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\allegro.exe" = [iNSTALLDIR]tools\pcb\bin\allegro.exe:*:Enabled:allegro.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\allegro_batch.exe" = [iNSTALLDIR]tools\pcb\bin\allegro_batch.exe:*:Enabled:allegro_batch.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\allegro_free_viewer.exe" = [iNSTALLDIR]tools\pcb\bin\allegro_free_viewer.exe:*:Enabled:allegro_free_viewer.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\db_change_type.exe" = [iNSTALLDIR]tools\pcb\bin\db_change_type.exe:*:Enabled:db_change_type.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dbdoctor.exe" = [iNSTALLDIR]tools\pcb\bin\dbdoctor.exe:*:Enabled:dbdoctor.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dbdoctor_ui.exe" = [iNSTALLDIR]tools\pcb\bin\dbdoctor_ui.exe:*:Enabled:dbdoctor_ui.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dbstat.exe" = [iNSTALLDIR]tools\pcb\bin\dbstat.exe:*:Enabled:dbstat.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dfa_dlg.exe" = [iNSTALLDIR]tools\pcb\bin\dfa_dlg.exe:*:Enabled:dfa_dlg.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dfa_update.exe" = [iNSTALLDIR]tools\pcb\bin\dfa_update.exe:*:Enabled:dfa_update.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\downrev_library.exe" = [iNSTALLDIR]tools\pcb\bin\downrev_library.exe:*:Enabled:downrev_library.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\enved.exe" = [iNSTALLDIR]tools\pcb\bin\enved.exe:*:Enabled:enved.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\flash_convert.exe" = [iNSTALLDIR]tools\pcb\bin\flash_convert.exe:*:Enabled:flash_convert.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\fpbrowse.exe" = [iNSTALLDIR]tools\pcb\bin\fpbrowse.exe:*:Enabled:fpbrowse.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\layer_compare.exe" = [iNSTALLDIR]tools\pcb\bin\layer_compare.exe:*:Enabled:layer_compare.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\qvupdate.exe" = [iNSTALLDIR]tools\pcb\bin\qvupdate.exe:*:Enabled:qvupdate.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sip_free_viewer.exe" = [iNSTALLDIR]tools\pcb\bin\sip_free_viewer.exe:*:Enabled:sip_free_viewer.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\systemdump.exe" = [iNSTALLDIR]tools\pcb\bin\systemdump.exe:*:Enabled:systemdump.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\uprev.exe" = [iNSTALLDIR]tools\pcb\bin\uprev.exe:*:Enabled:uprev.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\batch_drc.exe" = [iNSTALLDIR]tools\pcb\bin\batch_drc.exe:*:Enabled:batch_drc.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\bbvia.exe" = [iNSTALLDIR]tools\pcb\bin\bbvia.exe:*:Enabled:bbvia.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\convert_gerber.exe" = [iNSTALLDIR]tools\pcb\bin\convert_gerber.exe:*:Enabled:convert_gerber.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\create_devices.exe" = [iNSTALLDIR]tools\pcb\bin\create_devices.exe:*:Enabled:create_devices.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\create_sym.exe" = [iNSTALLDIR]tools\pcb\bin\create_sym.exe:*:Enabled:create_sym.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\draw_check.exe" = [iNSTALLDIR]tools\pcb\bin\draw_check.exe:*:Enabled:draw_check.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dump_libraries.exe" = [iNSTALLDIR]tools\pcb\bin\dump_libraries.exe:*:Enabled:dump_libraries.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\plctxt.exe" = [iNSTALLDIR]tools\pcb\bin\plctxt.exe:*:Enabled:plctxt.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\genfeedformat.exe" = [iNSTALLDIR]tools\pcb\bin\genfeedformat.exe:*:Enabled:genfeedformat.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\netrev.exe" = [iNSTALLDIR]tools\pcb\bin\netrev.exe:*:Enabled:netrev.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\idf_in.exe" = [iNSTALLDIR]tools\pcb\bin\idf_in.exe:*:Enabled:idf_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\idf_out.exe" = [iNSTALLDIR]tools\pcb\bin\idf_out.exe:*:Enabled:idf_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\idx_out.exe" = [iNSTALLDIR]tools\pcb\bin\idx_out.exe:*:Enabled:idx_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\iges_in.exe" = [iNSTALLDIR]tools\pcb\bin\iges_in.exe:*:Enabled:iges_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\iges_out.exe" = [iNSTALLDIR]tools\pcb\bin\iges_out.exe:*:Enabled:iges_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ipc356_out.exe" = [iNSTALLDIR]tools\pcb\bin\ipc356_out.exe:*:Enabled:ipc356_out.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\explot.exe" = [iNSTALLDIR]tools\pcb\bin\explot.exe:*:Enabled:explot.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\gbplot.exe" = [iNSTALLDIR]tools\pcb\bin\gbplot.exe:*:Enabled:gbplot.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\genrad.exe" = [iNSTALLDIR]tools\pcb\bin\genrad.exe:*:Enabled:genrad.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\gloss.exe" = [iNSTALLDIR]tools\pcb\bin\gloss.exe:*:Enabled:gloss.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ncroute.exe" = [iNSTALLDIR]tools\pcb\bin\ncroute.exe:*:Enabled:ncroute.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\nctape.exe" = [iNSTALLDIR]tools\pcb\bin\nctape.exe:*:Enabled:nctape.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\netin.exe" = [iNSTALLDIR]tools\pcb\bin\netin.exe:*:Enabled:netin.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pad_designer.exe" = [iNSTALLDIR]tools\pcb\bin\pad_designer.exe:*:Enabled:pad_designer.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\l2a.exe" = [iNSTALLDIR]tools\pcb\bin\l2a.exe:*:Enabled:l2a.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pads_in.exe" = [iNSTALLDIR]tools\pcb\bin\pads_in.exe:*:Enabled:pads_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pcad_in.exe" = [iNSTALLDIR]tools\pcb\bin\pcad_in.exe:*:Enabled:pcad_in.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\placement.exe" = [iNSTALLDIR]tools\pcb\bin\placement.exe:*:Enabled:placement.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\swap.exe" = [iNSTALLDIR]tools\pcb\bin\swap.exe:*:Enabled:swap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\downrev14.exe" = [iNSTALLDIR]tools\pcb\bin\downrev14.exe:*:Enabled:downrev14.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile13.exe" = [iNSTALLDIR]tools\pcb\bin\techfile13.exe:*:Enabled:techfile13.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile14.exe" = [iNSTALLDIR]tools\pcb\bin\techfile14.exe:*:Enabled:techfile14.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile15.exe" = [iNSTALLDIR]tools\pcb\bin\techfile15.exe:*:Enabled:techfile15.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor14.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor14.exe:*:Enabled:dbdoctor14.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor15.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbdoctor15.exe:*:Enabled:dbdoctor15.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbfix11.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbfix11.exe:*:Enabled:dbfix11.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbfix12.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbfix12.exe:*:Enabled:dbfix12.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\dbfix13.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\dbfix13.exe:*:Enabled:dbfix13.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\vc5\downrev15.exe" = [iNSTALLDIR]tools\pcb\bin\vc5\downrev15.exe:*:Enabled:downrev15.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spif.exe" = [iNSTALLDIR]tools\pcb\bin\spif.exe:*:Enabled:spif.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spif_batch.exe" = [iNSTALLDIR]tools\pcb\bin\spif_batch.exe:*:Enabled:spif_batch.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mbs2lib.exe" = [iNSTALLDIR]tools\pcb\bin\mbs2lib.exe:*:Enabled:mbs2lib.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\FSvia.exe" = [iNSTALLDIR]tools\pcb\bin\FSvia.exe:*:Enabled:FSvia.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\FSviaSolver.exe" = [iNSTALLDIR]tools\pcb\bin\FSviaSolver.exe:*:Enabled:FSviaSolver.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\bem2d.exe" = [iNSTALLDIR]tools\pcb\bin\bem2d.exe:*:Enabled:bem2d.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ems2d.exe" = [iNSTALLDIR]tools\pcb\bin\ems2d.exe:*:Enabled:ems2d.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\extracta.exe" = [iNSTALLDIR]tools\pcb\bin\extracta.exe:*:Enabled:extracta.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\fatten.exe" = [iNSTALLDIR]tools\pcb\bin\fatten.exe:*:Enabled:fatten.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\gate_assign.exe" = [iNSTALLDIR]tools\pcb\bin\gate_assign.exe:*:Enabled:gate_assign.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\il_allegro.exe" = [iNSTALLDIR]tools\pcb\bin\il_allegro.exe:*:Enabled:il_allegro.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\j2script.exe" = [iNSTALLDIR]tools\pcb\bin\j2script.exe:*:Enabled:j2script.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mcm_escapes.exe" = [iNSTALLDIR]tools\pcb\bin\mcm_escapes.exe:*:Enabled:mcm_escapes.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mpiexec.exe" = [iNSTALLDIR]tools\pcb\bin\mpiexec.exe:*:Enabled:mpiexec.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\parallel.exe" = [iNSTALLDIR]tools\pcb\bin\parallel.exe:*:Enabled:parallel.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pe_wordpad.exe" = [iNSTALLDIR]tools\pcb\bin\pe_wordpad.exe:*:Enabled:pe_wordpad.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\pre_check.exe" = [iNSTALLDIR]tools\pcb\bin\pre_check.exe:*:Enabled:pre_check.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\refresh_padstack.exe" = [iNSTALLDIR]tools\pcb\bin\refresh_padstack.exe:*:Enabled:refresh_padstack.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\refresh_symbol.exe" = [iNSTALLDIR]tools\pcb\bin\refresh_symbol.exe:*:Enabled:refresh_symbol.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\refresh_vs.exe" = [iNSTALLDIR]tools\pcb\bin\refresh_vs.exe:*:Enabled:refresh_vs.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\reftxt.exe" = [iNSTALLDIR]tools\pcb\bin\reftxt.exe:*:Enabled:reftxt.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\report.exe" = [iNSTALLDIR]tools\pcb\bin\report.exe:*:Enabled:report.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\smpd.exe" = [iNSTALLDIR]tools\pcb\bin\smpd.exe:*:Enabled:smpd.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\techfile.exe" = [iNSTALLDIR]tools\pcb\bin\techfile.exe:*:Enabled:techfile.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\wmpiconfig.exe" = [iNSTALLDIR]tools\pcb\bin\wmpiconfig.exe:*:Enabled:wmpiconfig.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\wmpiexec.exe" = [iNSTALLDIR]tools\pcb\bin\wmpiexec.exe:*:Enabled:wmpiexec.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\wmpiregister.exe" = [iNSTALLDIR]tools\pcb\bin\wmpiregister.exe:*:Enabled:wmpiregister.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\zrouter.exe" = [iNSTALLDIR]tools\pcb\bin\zrouter.exe:*:Enabled:zrouter.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\bodygen.exe" = [iNSTALLDIR]tools\fet\bin\bodygen.exe:*:Enabled:bodygen.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\newgenasym.exe" = [iNSTALLDIR]tools\fet\bin\newgenasym.exe:*:Enabled:newgenasym.exe (spb16.3) "[iNSTALLDIR]tools\msbase\vcredist_x86.exe" = [iNSTALLDIR]tools\msbase\vcredist_x86.exe:*:Enabled:vcredist_x86.exe (spb16.3) "[iNSTALLDIR]tools\perl5\bin\perl.exe" = [iNSTALLDIR]tools\perl5\bin\perl.exe:*:Enabled:perl.exe (spb16.3) "[iNSTALLDIR]tools\perl5\bin\perlglob.exe" = [iNSTALLDIR]tools\perl5\bin\perlglob.exe:*:Enabled:perlglob.exe (spb16.3) "[iNSTALLDIR]tools\perl5\ntt\cmd32.exe" = [iNSTALLDIR]tools\perl5\ntt\cmd32.exe:*:Enabled:cmd32.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\productServer.exe" = [iNSTALLDIR]tools\pcb\bin\productServer.exe:*:Enabled:productServer.exe (spb16.3) "[iNSTALLDIR]tools\bin\conceptNmpListCheck.exe" = [iNSTALLDIR]tools\bin\conceptNmpListCheck.exe:*:Enabled:conceptNmpListCheck.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\cpmaccess.exe" = [iNSTALLDIR]tools\fet\bin\cpmaccess.exe:*:Enabled:cpmaccess.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\libaccess.exe" = [iNSTALLDIR]tools\fet\bin\libaccess.exe:*:Enabled:libaccess.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\projmgr.exe" = [iNSTALLDIR]tools\fet\bin\projmgr.exe:*:Enabled:projmgr.exe (spb16.3) "[iNSTALLDIR]tools\fet\bin\pseteditor.exe" = [iNSTALLDIR]tools\fet\bin\pseteditor.exe:*:Enabled:pseteditor.exe (spb16.3) "[iNSTALLDIR]tools\specctra\bin\mbs2sp.exe" = [iNSTALLDIR]tools\specctra\bin\mbs2sp.exe:*:Enabled:mbs2sp.exe (spb16.3) "[iNSTALLDIR]tools\specctra\bin\sp2mbs.exe" = [iNSTALLDIR]tools\specctra\bin\sp2mbs.exe:*:Enabled:sp2mbs.exe (spb16.3) "[iNSTALLDIR]tools\specctra\bin\specctra.exe" = [iNSTALLDIR]tools\specctra\bin\specctra.exe:*:Enabled:specctra.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\signoise.exe" = [iNSTALLDIR]tools\pcb\bin\signoise.exe:*:Enabled:signoise.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\lis2buf.exe" = [iNSTALLDIR]tools\pcb\bin\lis2buf.exe:*:Enabled:lis2buf.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\modeleditor.exe" = [iNSTALLDIR]tools\pcb\bin\modeleditor.exe:*:Enabled:modeleditor.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\modelintegrity.exe" = [iNSTALLDIR]tools\pcb\bin\modelintegrity.exe:*:Enabled:modelintegrity.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\modelsim.exe" = [iNSTALLDIR]tools\pcb\bin\modelsim.exe:*:Enabled:modelsim.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spc2dml.exe" = [iNSTALLDIR]tools\pcb\bin\spc2dml.exe:*:Enabled:spc2dml.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sigxp.exe" = [iNSTALLDIR]tools\pcb\bin\sigxp.exe:*:Enabled:sigxp.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\aprepmap.exe" = [iNSTALLDIR]tools\pcb\bin\aprepmap.exe:*:Enabled:aprepmap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ashowmap.exe" = [iNSTALLDIR]tools\pcb\bin\ashowmap.exe:*:Enabled:ashowmap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\aconvmap.exe" = [iNSTALLDIR]tools\pcb\bin\aconvmap.exe:*:Enabled:aconvmap.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\brd2dml.exe" = [iNSTALLDIR]tools\pcb\bin\brd2dml.exe:*:Enabled:brd2dml.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dml2brd.exe" = [iNSTALLDIR]tools\pcb\bin\dml2brd.exe:*:Enabled:dml2brd.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dmlcheck.exe" = [iNSTALLDIR]tools\pcb\bin\dmlcheck.exe:*:Enabled:dmlcheck.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\dmlcrypt.exe" = [iNSTALLDIR]tools\pcb\bin\dmlcrypt.exe:*:Enabled:dmlcrypt.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ftsmerge.exe" = [iNSTALLDIR]tools\pcb\bin\ftsmerge.exe:*:Enabled:ftsmerge.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ibis2signoise.exe" = [iNSTALLDIR]tools\pcb\bin\ibis2signoise.exe:*:Enabled:ibis2signoise.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ibischk3.exe" = [iNSTALLDIR]tools\pcb\bin\ibischk3.exe:*:Enabled:ibischk3.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ibischk4.exe" = [iNSTALLDIR]tools\pcb\bin\ibischk4.exe:*:Enabled:ibischk4.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\icmchk.exe" = [iNSTALLDIR]tools\pcb\bin\icmchk.exe:*:Enabled:icmchk.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mergedml.exe" = [iNSTALLDIR]tools\pcb\bin\mergedml.exe:*:Enabled:mergedml.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\mkdeviceindex.exe" = [iNSTALLDIR]tools\pcb\bin\mkdeviceindex.exe:*:Enabled:mkdeviceindex.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\quad2signoise.exe" = [iNSTALLDIR]tools\pcb\bin\quad2signoise.exe:*:Enabled:quad2signoise.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sigwave.exe" = [iNSTALLDIR]tools\pcb\bin\sigwave.exe:*:Enabled:sigwave.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\sigxsect.exe" = [iNSTALLDIR]tools\pcb\bin\sigxsect.exe:*:Enabled:sigxsect.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\spc2spc.exe" = [iNSTALLDIR]tools\pcb\bin\spc2spc.exe:*:Enabled:spc2spc.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\tlsim.exe" = [iNSTALLDIR]tools\pcb\bin\tlsim.exe:*:Enabled:tlsim.exe (spb16.3) "[iNSTALLDIR]tools\pcb\bin\ts2dml.exe" = [iNSTALLDIR]tools\pcb\bin\ts2dml.exe:*:Enabled:ts2dml.exe (spb16.3) "C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe" = C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (OpenSight Software, LLC) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe" = C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (OpenSight Software, LLC) "C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe" = C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (OpenSight Software, LLC) ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.0+ (r404) "{067A32A4-7E21-4BAA-95ED-9665BCE035F5}" = NI-RPC 4.1.1f0 for 64 Bit Windows "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0B7AFE8D-1265-4025-AD23-3624CEAD4F3C}" = NI Xalan Delay Load 1.10.1 64-bit "{0CADBEE0-59CA-4382-9A67-BA5CB07B6EFC}" = NI Xerces Delay Load 2.7.1 64-bit "{104FB32A-7CE3-4C4B-B2AA-70C613FF9DFA}" = iTunes "{153DC15F-C59E-4603-BF81-00CEA1116DCA}" = NI LabVIEW Broker (64 bit) "{16EC1499-8B35-431A-B55D-3EE4558C1385}" = O&O UnErase "{174443DD-EF03-41F8-A66D-987EBBBC1517}" = NI System State Publisher (64-bit) "{21903252-3854-48D6-8F0C-F648CFA818C9}" = NI Help Assistant (64bit) "{33EB1061-ABF1-4470-A540-32E97A610536}" = Apple Mobile Device Support "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour "{4EBBC187-6988-4B10-A846-E1DBD2AD2B8D}" = NI Math Kernel Libraries (64-bit) "{62208237-D078-4D28-84FA-D1812FF6C940}" = NI Assistant Framework 64-bit "{639673E9-D53F-44F4-A046-485C8A6ADA16}" = Paint.NET v3.5.6 "{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.4.3 "{79E44BF5-C355-4A5D-8F9F-25F53ACF794E}" = NI VC2008MSMs x64 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 "{9328624D-0388-4F5B-98AB-9FBC5559F8E9}" = NI TDMS (64-bit) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{999A9B8E-4E5C-4DF0-9E9C-FEC1E12190B4}" = NI MAX Support for 64 Bit Windows "{99FA9ED4-21E6-47E0-B986-F8D0998E453A}" = NI System API Windows 64-bit "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 260.89 "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 260.89 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 260.89 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.9.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{B7607FC8-72AD-486D-B6B7-A402D5876309}" = PerfectDisk 11 Professional "{B860298B-CE03-4DE2-B92E-422F2C20A2D8}_is1" = PDF-XChange Lite 4 "{C5F268F1-0856-43E2-B6F1-2470EEE48D2A}" = ESET NOD32 Antivirus "{CA7DAF6F-D5F4-46FD-A824-7E0B472C3211}" = NI USI 1.7.0 64-Bit "{CCC79B52-19CF-4A50-BE60-AEE3DE96B3EA}" = NI Web Pipeline 2.0.1 64-bit support "{D0F9AD6F-2C2A-44A8-8961-F21B5356E050}" = NI Logos64 XT Support "{D4F0D273-9967-4BD8-B85F-FA03C2504475}" = NI DataSocket 4.7.0 (64-bit) "{D8C0E5E1-3B66-465D-8F9B-F591F5CDA726}" = NI Trace Engine (64-bit) "{DA7916C4-07D8-45D3-9EE7-BE24811554EB}" = NI-DAQmx - LabVIEW shared documentation for 64 Bit Windows 1.5.0 "{E68686D1-A5BB-467A-8DE7-A01166722607}" = NI VC2005MSMs x64 "{EC90795D-968C-4BCA-B958-27B111F3B3F6}" = NI Logos64 5.1 "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FB96D69B-1731-4312-8D92-5768478A0539}" = NI SSL Support (64-bit) "{FE096FC3-47A3-4555-AF67-1B49BF9DE0B3}" = NI Portable Configuration Help for 64 Bit Windows 4.6.0 "{FF4E0155-F956-4895-9D0A-C3754456C1BE}" = NI MXS 4.6.0 for 64 Bit Windows "{FFFA9DD7-58D7-464B-BD5B-7224BFC4B039}" = NI Variable Engine (64-bit) "45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0) "CCleaner" = CCleaner "C-Media PCI Audio Driver" = HT OMEGA STRIKER7.1 "CPUID CPU-Z_is1" = CPUID CPU-Z 1.53 "FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "NewsBin5" = NewsBin Pro "SP6" = Logitech SetPoint 6.15 "WinRAR archiver" = WinRAR archiver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{04B552B1-4EC5-4F1B-9F02-FD3DF5A71184}" = NI Assistant Framework "{04D66B46-4349-407C-9297-9B43648E4C84}" = NI LabVIEW Run-Time Engine Interop 2009 "{05046BCC-5E64-4A85-8615-D84DE4C1D865}" = NI VC2005MSMs x86 "{07A8ED9E-B98E-437F-B750-241B412BE924}" = Garmin USB Drivers "{07A99739-82EE-4537-AF2E-1607015D9992}" = NI Service Locator "{08133ED0-B6EB-49CD-B0EF-60502E41D15E}" = NI Xerces Delay Load 2.7.1 "{094621AC-72E7-4167-8A06-CCDDBEBC233F}" = NI LabVIEW 2009 Help File "{0FB31DF8-38DF-4C9D-B313-AFAFC3FBA02B}" = NI LVBrokerAux 8.2.1 "{0FD812C9-3BBE-4CC5-A43C-B7304E3EC581}" = NI Web Pipeline 2.0.1 "{148E08FF-D7C4-46ED-8D4D-601C67FE0AFD}" = Rosetta Stone Version 3 "{19C120B7-F7A6-4105-9D62-1F6305B2E2CF}" = NI DataSocket 4.7.0 "{1B06E3AF-1CE2-4085-AE4E-DFEC369E86D3}" = NI Logos XT Support "{1D6F0B9D-F19E-43AB-9D8E-2E3653212C72}" = NI LabVIEW 2009 MeasAppChm File "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F85CAAA-B786-4E5B-AADD-638856992EF3}" = Opera 10.53 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{2108E50D-978D-4D62-A837-4F12A61ADF15}" = NI LabVIEW 2009 License "{229A26F7-81A9-4A17-9D00-6CF4D08CEA44}" = NI LabVIEW 2009 WWW "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{23940B09-32B3-4C36-88A9-E787862E2AE9}" = NI Variable Engine LabVIEW 2009 Support "{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v1.4.2499.0 "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java 6 Update 22 "{278AF4F9-DC1C-49DC-B871-C0BAEBD4F458}" = NI License Manager "{297FA251-FF30-4F16-978C-4A65EA804EFF}" = NI LabVIEW Real-Time Error Dialog "{2A98DB42-3743-4022-ADFA-42AE811484AE}" = NI EULA Depot "{2AD5E818-E2EE-4BBF-A2BF-29022C6FC236}" = NI Assistant Framework LabVIEW 2009 Support "{2BEB102E-F9CD-4881-984B-E288F66FD394}" = Quake Live Mozilla Plugin "{2D72E0EC-D695-4BFB-A246-F07BAAA91AA1}" = NI Remote Provider for MAX 4.6.0 "{307300E8-6D0E-48AD-AC4B-D41A9549DEEB}" = NI LabVIEW 2009 Examples "{34EE2F0F-D6EA-4C36-8315-41107048D48D}" = NI-DAQmx - LabVIEW shared documentation "{35872655-EA55-4A90-8DAA-AD2B777B8CAC}" = NI LabVIEW 2009 Applibs "{383AD0A2-FD79-4CF0-B823-C695E32BD08D}" = NI LabVIEW Run-Time Engine Web Services "{38A0E959-7FC3-4583-8B2F-03A3E7A4A026}" = The iPod Application Installer II "{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg "{3F188640-B4F5-44D5-BBF3-DAB70CF5629B}" = NI LabVIEW Compare Utility 9.0.0 "{40D9D764-7FD7-4036-B565-6D94DEEBD4A5}" = NI LabVIEW Merge Utility 9.0.0 "{4159DD60-49C1-4323-A1A5-FB060CBA35C5}" = NI Measurement Studio Recipe Processor "{416B50BB-64CE-46C5-81A6-7F842CC35CDC}" = NI LabVIEW MAX XML "{4186FEBC-F0CC-4185-A406-24292BC9877A}" = Nokia Software Updater "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant "{45A5461A-7D1D-4A91-B033-0B85E7AB25C2}" = NI MXS 4.6.0f0 for LabVIEW Real-Time "{45FA54F6-8574-49D2-9E2D-0BDDE6237822}" = NI LabVIEW Run-Time Engine 8.2.1 "{47A0A80F-8DC0-43EB-B9B4-36FD86979DF7}" = Nokia Connectivity Cable Driver "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D581C40-11D0-476B-A943-76506924B722}" = NI Distributed System Manager 2009 "{4E049CBB-01EE-4859-B4C8-26E42263CEE4}" = NI LabVIEW Run-Time Engine 2009 "{50F9A1FC-39D8-46E8-8234-1A1A68A4033E}" = NI Variable Engine 2.3.0 "{51E23D68-FE69-4728-A8EE-F12856B046C7}" = NI LabVIEW 2009 User.lib "{52C3DD72-17E5-4E0D-83A8-FB42FCE3A8EF}" = NI-RPC 4.1.1f0 for Phar Lap ETS "{57B77060-04B4-468E-89A9-F68EEE466F57}" = NI USI 1.7.0 "{57F37CA1-6FA3-46D2-8F01-AD3A26FA4E9B}" = NI Assistant Framework LabVIEW Code Generator 2009 "{596C11D1-2285-4057-99F6-735B50EB87E1}" = NI System API RT "{5A70FCD2-C019-4723-868F-07CD6C7755FF}" = NI Logos 5.1 "{5E2E0DF8-75EC-47E2-9583-3229A4CF5C95}" = NI LabVIEW 2009 Project "{6447FE3A-8B2C-41DB-9791-322B8445B3E9}" = NI LabVIEW Deployable License 2009 "{64D24684-9E7E-4876-B5E5-1E134996988D}" = Cadence SPB/OrCAD 16.3 "{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6F7D11DC-DE87-45C8-A37E-A35B724FC771}" = NI Help Assistant "{71929EC1-FDB2-4A67-AAAD-936E4539FA84}_is1" = Driver Sweeper 2.1.0 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74F5CBE0-D208-46E5-8593-C07D3FDF8454}" = NI LabVIEW 2009 CINtools "{7559B6F5-180B-479A-A8CD-2175EFBC61F8}" = NI LabVIEW 2009 Deployment Framework "{77B1B7C6-4C2F-4D0C-A807-F1A2910B7AC4}" = NI LabVIEW 2009 Resource "{79E9C7C5-4FCC-4DFF-B79E-17319E9522F3}" = MagicTunePremium "{7ACFB216-29F7-4331-A5ED-2563AEB51F21}" = NI Trace Engine "{7C62B54A-E524-4F3D-83E7-0F2ABAFC978A}" = NI Xalan Delay Load 1.10.1 "{7E3668CB-1228-416E-B721-C2FA3247B985}" = NI LabVIEW Real-Time FIFO for Runtime "{7E7A035C-9DC5-40B0-B873-002B14CCE3B8}" = NI-RPC 4.1.1f0 "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials "{81B2907E-0F93-4217-8840-A217EF59A244}" = PC Connectivity Solution "{82B8F87D-C75E-4270-B030-49ECDAFF1B53}" = NI MAX Remote Configuration Installer 4.6 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{88D1DA3C-09FA-4CA7-BB6B-2CEACCFA95D5}" = NI System State Publisher "{89A7BD8C-0FC3-49EF-9072-5C8371C0A4D6}" = NI LabVIEW Web Services Runtime "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A5D448D-FBA1-40B6-9131-03659BC83319}" = NI LabVIEW 2009 Menus "{8AF869D1-F416-4855-8177-EB75D73CC992}" = NI LabVIEW 2009 Web Server "{8F54D841-4334-49BC-AAB0-6DC4586CE812}" = Passware Kit Forensic 10.1 "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010 "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{9033A0BF-9B8A-4C27-812B-40BA10855E2D}" = NI LabVIEW 2009 Simulation "{91FD3E1D-FE00-4ECB-8379-204704812A9D}" = Crystal10 "{92769F9C-453B-40C9-B129-6E8E52586C8E}" = NI LabVIEW Broker "{927C1DDA-61DC-4B95-A138-8A1377E33A9A}" = NI Portable Configuration 4.6.0 "{93B8921B-2AC6-4A58-A87C-19B633DB6860}" = NI Software Provider for MAX 4.6.0 "{96094CE5-7920-47FD-8A02-68A7B5B1785F}" = NI System API Windows 32-bit "{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v4.0 "{9862682B-2CDB-4D67-9D8B-EC3CDA85F1CB}" = NI LabVIEW 2009 VI.lib "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B79CE5E-ECAA-4D23-9924-0BF5A3F440F0}" = NI LabVIEW 2009 gMath "{9F7DBC83-611C-4407-8817-8FD63E149288}" = NI SSL LabVIEW 2009 Support "{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A4E71872-9E83-483C-8AE0-184B943C7EE5}" = Brother HL-2170W "{A5CBD7C5-CF16-443F-A4F2-3503C9DE311B}" = ACDSee Photo Manager 12 "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger "{A96395DA-AFC5-459E-A374-CE10E84FEEB2}" = NI TDM Excel Add-In 2.1 "{ABD79E99-F9E3-413B-8D18-11070754355F}" = NI Math Kernel Libraries "{AE9AA575-DE74-4711-B3B3-2977D76CC1BB}" = NI TDMS "{AF32BE73-E284-444E-B310-7EE80192949B}" = NI LabWindows/CVI DLL Builder for LabVIEW "{AFEDF70D-8DC3-40CB-93A0-F276E64BDF9C}" = NI VC2008MSMs x86 "{B3C9A441-C34D-40F3-9D3B-00EDDDAC74F1}" = Garmin Communicator Plugin "{B4B6D62D-9BDF-48A6-AE95-E4F730369D26}" = NI Logos LabVIEW 2009 Support "{B5BD3DA8-1A63-4042-90FA-B26C361382C9}" = NI Remote PXI Provider for MAX 4.6.0 "{B5F47039-9B19-4AC3-9A4A-E1CA3068E59F}" = ArcSoft TotalMedia Theatre 3 "{B8E65E0D-30D8-49BD-B92C-0E77A09545D6}" = NI MAX LabVIEW Support 4.6.0 "{B963C648-249B-4145-BC14-56488262E9A9}" = NI MDF Support "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX "{BA0C85C1-E5CC-4F58-84FB-8DA29F3412F0}" = NI Uninstaller "{BB4B8FCF-44B4-4957-B92F-5F5A631AF629}" = CADopia IntelliCAD 4 "{BC724C7B-48C3-46B8-B6A2-F4296953B3FD}" = Cadence License Manager 10.80 "{C25215FC-5900-48B0-B93C-8D3379027312}" = PASW Statistics 18 "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{C484CC8D-03CF-4022-89C4-DB4F02E8A15B}" = Crystal Reports 2008 Runtime "{C57A08DC-0D4B-41E1-82A3-6290292E5B87}" = NI LabVIEW 2009 Instr.lib "{C6BF965C-5A8C-498E-A6AD-B594D583F7B3}" = NI LabVIEW 2009 "{CEDA69AF-DD7A-42A8-B6D3-65BA0592D34E}" = NI Instrument IO Assistant for LabVIEW 9.0 32 "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype
  8. Thanks for the reply. OTL.txt OTL logfile created on: 11/28/2010 2:17:46 PM - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Chris\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 67.00% Memory free 8.00 Gb Paging File | 7.00 Gb Available in Paging File | 82.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 596.17 Gb Total Space | 518.98 Gb Free Space | 87.05% Space Free | Partition Type: NTFS Drive X: | 931.50 Gb Total Space | 88.30 Gb Free Space | 9.48% Space Free | Partition Type: NTFS Computer Name: ROOK | User Name: Chris | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - File not found -- C:\Windows\SysWow64\crypserv.exe PRC - [2010/11/28 14:16:04 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Chris\Desktop\OTL.exe PRC - [2010/11/05 02:46:52 | 001,974,272 | ---- | M] () -- C:\Program Files (x86)\foobar2000\foobar2000.exe PRC - [2010/08/12 14:16:26 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe PRC - [2009/08/28 22:00:12 | 000,966,656 | ---- | M] () -- C:\Users\Chris\Local Settings\Apps\F.lux\flux.exe PRC - [2009/06/17 03:44:11 | 000,085,160 | ---- | M] (Elaborate Bytes AG) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe ========== Modules (SafeList) ========== MOD - [2010/11/28 14:16:04 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Chris\Desktop\OTL.exe MOD - [2010/08/20 21:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll MOD - [2009/07/13 17:15:31 | 000,154,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll MOD - [2009/07/13 17:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - File not found [On_Demand | Stopped] -- C:\Windows\SysNative\PnkBstrA.exe -- (PnkBstrA) SRV:64bit: - File not found [On_Demand | Stopped] -- C:\Windows\SysNative\srvany.exe -- (KMService) SRV:64bit: - [2010/08/12 14:18:40 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV:64bit: - [2010/08/12 14:16:26 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn) SRV:64bit: - [2010/08/10 11:27:22 | 002,610,952 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe -- (PDAgent) SRV:64bit: - [2010/08/10 11:27:04 | 002,266,376 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe -- (PDEngine) SRV:64bit: - [2010/05/06 01:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV:64bit: - [2010/02/23 11:51:20 | 001,030,600 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2009/07/13 17:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:64bit: - [2008/05/07 15:29:38 | 000,122,880 | ---- | M] (CrypKey (Canada) Ltd.) [Auto | Running] -- C:\Windows\SysNative\Crypserv.exe -- (Crypkey License) SRV - [2010/10/08 00:03:46 | 000,369,256 | ---- | M] (NVIDIA Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2010/09/30 00:10:08 | 000,075,064 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2010/05/11 18:54:00 | 002,480,048 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv) SRV - [2010/04/29 14:39:34 | 000,304,464 | ---- | M] (Malwarebytes Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/26 14:14:04 | 000,652,800 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2009/11/12 02:50:24 | 000,894,136 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) SRV - [2009/10/20 11:41:48 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2009/07/16 16:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2009/06/23 12:29:48 | 000,740,968 | ---- | M] (National Instruments Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService) SRV - [2009/06/23 10:23:14 | 001,007,616 | ---- | M] (Macrovision Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager) SRV - [2009/06/18 06:01:50 | 000,356,912 | ---- | M] (National Instruments Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService) SRV - [2009/06/18 05:57:28 | 000,042,544 | ---- | M] (National Instruments Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\lkads.exe -- (lkClassAds) SRV - [2009/06/18 05:56:32 | 000,053,296 | ---- | M] (National Instruments Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\lktsrv.exe -- (lkTimeSync) SRV - [2009/06/15 19:44:40 | 000,012,696 | ---- | M] (National Instruments Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\National Instruments\MAX\nimxs.exe -- (mxssvr) SRV - [2009/06/10 13:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009/06/04 03:14:28 | 000,013,896 | ---- | M] (National Instruments Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\nisvcloc.exe -- (niSvcLoc) SRV - [2009/06/03 09:26:34 | 000,098,304 | ---- | M] (OPC Foundation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Opcenum.exe -- (OpcEnum) SRV - [2008/10/31 13:52:54 | 000,695,136 | ---- | M] (National Instruments, Inc.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\lkcitdl.exe -- (LkCitadelServer) SRV - [2007/10/12 08:48:58 | 001,370,752 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Cadence\LicenseManager\lmgrd.exe -- (Cadence License Manager) SRV - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService) ========== Driver Services (SafeList) ========== DRV:64bit: - File not found [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dhahelper.sys -- (DhaHelper) DRV:64bit: - [2010/09/07 12:08:55 | 000,155,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2010/07/29 13:31:26 | 000,168,544 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm) DRV:64bit: - [2010/07/29 13:31:26 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv) DRV:64bit: - [2010/07/29 13:31:26 | 000,126,320 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr) DRV:64bit: - [2010/07/15 07:44:20 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv) DRV:64bit: - [2010/07/15 07:44:20 | 000,009,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv) DRV:64bit: - [2010/05/11 18:54:00 | 000,251,488 | ---- | M] (Acronis) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp) DRV:64bit: - [2010/05/11 18:53:58 | 001,477,728 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm258.sys -- (tdrpman258) Acronis Try&Decide and Restore Points filter (build 258) DRV:64bit: - [2010/05/11 18:53:57 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter) DRV:64bit: - [2010/05/11 18:53:53 | 000,257,120 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman) DRV:64bit: - [2010/04/29 14:39:28 | 000,024,664 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2010/04/07 06:28:22 | 000,121,280 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD) DRV:64bit: - [2010/03/18 01:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt) DRV:64bit: - [2010/03/18 01:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt) DRV:64bit: - [2010/02/26 12:33:40 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys -- (UsbserFilt) DRV:64bit: - [2010/02/26 12:33:24 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev) DRV:64bit: - [2010/02/26 12:33:22 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdcx64) DRV:64bit: - [2010/02/26 12:33:22 | 000,019,456 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcdx64) DRV:64bit: - [2010/02/26 12:21:22 | 000,173,056 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys -- (nmwcdnsux64) DRV:64bit: - [2010/02/26 12:21:20 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys -- (nmwcdnsucx64) DRV:64bit: - [2010/01/13 07:19:10 | 000,142,848 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ArcHlp.sys -- (archlp) DRV:64bit: - [2010/01/01 09:20:28 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO) DRV:64bit: - [2009/12/30 11:21:24 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt) DRV:64bit: - [2009/12/01 11:31:10 | 001,155,072 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cmudax3.sys -- (cmuda3) DRV:64bit: - [2009/11/28 01:36:30 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:64bit: - [2009/09/22 17:32:39 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb) DRV:64bit: - [2009/09/22 17:32:33 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus) DRV:64bit: - [2009/09/20 13:41:07 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin) DRV:64bit: - [2009/08/20 23:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/08/09 13:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone) DRV:64bit: - [2009/07/13 17:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009/07/13 17:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/13 17:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/07/13 16:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser) DRV:64bit: - [2009/06/17 08:53:34 | 000,030,736 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L8042Kbd.sys -- (L8042Kbd) DRV:64bit: - [2009/06/10 12:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2009/03/27 00:23:54 | 000,019,432 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz132_x64.sys -- (cpuz132) DRV:64bit: - [2008/11/04 12:12:08 | 000,023,096 | ---- | M] (Samsung Electronics, Inc. ) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\MTiCtwl.sys -- (MagicTune) DRV:64bit: - [2008/09/17 14:14:00 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64) DRV:64bit: - [2008/08/28 10:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd) DRV:64bit: - [2008/07/30 18:21:48 | 000,093,784 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID) DRV:64bit: - [2008/03/17 09:12:26 | 000,028,664 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\Ckldrv.sys -- (NetworkX) DRV:64bit: - [2007/06/25 04:37:14 | 000,108,032 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rtlh64.sys -- (RTL8169) DRV:64bit: - [2007/04/17 11:51:50 | 000,014,112 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi) DRV - [2010/11/27 05:34:04 | 000,014,544 | ---- | M] (OpenLibSys.org) [Kernel | Auto | Running] -- C:\Users\Chris\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys -- (WinRing0_1_2_0) DRV - [2010/07/15 07:44:20 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv) DRV - [2010/07/15 07:44:20 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv) DRV - [2010/04/08 19:46:06 | 000,007,168 | ---- | M] (MPlayer <http://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) [Kernel | System | Stopped] -- C:\Windows\SysWOW64\drivers\dhahelper.sys -- (DhaHelper) DRV - [2010/04/07 06:28:22 | 000,121,280 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD) DRV - [2005/06/10 09:01:00 | 000,007,140 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysWow64\drivers\cvintdrv.sys -- (cvintdrv) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form=ZGAPHP IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.bing.com/?pc=Z007&form=ZGAPHP IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form=ZGAPHP IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.bing.com/?pc=Z007&form=ZGAPHP IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form=ZGAPHP IE - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ IE - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us IE - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 48 8D E3 54 B5 89 CB 01 [binary data] IE - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.openintab: true FF - prefs.js..browser.startup.homepage: "http://www.bing.com/?pc=Z007&form=ZGAPHP" FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2 FF - prefs.js..extensions.enabledItems: {5F590AA2-1221-4113-A6F4-A4BB62414FAC}:0.45.6.20100202.1 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1 FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {EE9EE85E-CA01-4107-909A-CB6E8AC31B6A}:1.9.1 FF - prefs.js..extensions.enabledItems: rein@notiz.jp:3.6.1 FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z007&form=ZGAADF&q=" FF - user.js..browser.search.openintab: true FF - HKLM\software\mozilla\Firefox\Extensions\\{EE9EE85E-CA01-4107-909A-CB6E8AC31B6A}: C:\Users\Chris\AppData\Local\{EE9EE85E-CA01-4107-909A-CB6E8AC31B6A} [2010/11/27 02:55:57 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/10/27 18:38:07 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/10/27 18:38:07 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/11/27 07:05:55 | 000,000,000 | ---D | M] [2010/07/28 13:24:58 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Mozilla\Extensions [2010/07/28 13:24:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010/11/28 14:13:12 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\extensions [2010/08/26 13:22:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2010/06/21 20:46:44 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC} [2010/11/03 06:00:44 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010/10/08 09:30:55 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} [2010/01/22 09:03:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\extensions\{d650973c-0444-4ac7-9d00-19e3613c83b9} [2010/01/22 09:02:21 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\extensions\rein@notiz.jp [2010/11/27 02:51:42 | 000,001,919 | ---- | M] () -- C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\zt2hw3p2.default\searchplugins\bing-zugo.xml [2010/11/28 14:13:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions [2010/10/21 05:32:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010/09/15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll [2007/02/08 09:48:16 | 000,028,448 | ---- | M] (National Instruments) -- C:\Program Files (x86)\Mozilla Firefox\plugins\NPLV82Win32.dll [2009/06/23 18:40:40 | 000,025,088 | ---- | M] (National Instruments) -- C:\Program Files (x86)\Mozilla Firefox\plugins\nplv90win32.dll [1999/12/31 16:00:00 | 000,166,680 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll [2010/11/27 05:28:17 | 000,001,919 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing-zugo.xml O1 HOSTS File: ([2010/06/21 11:58:20 | 000,001,156 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 iw2.slysoft.com O1 - Hosts: 127.0.0.1 sb2.slysoft.com O1 - Hosts: 127.0.0.1 ev1.slysoft.com O1 - Hosts: 127.0.0.1 h3.slysoft.com O1 - Hosts: 127.0.0.1 ovh1.slysoft.com O1 - Hosts: 127.0.0.1 iw1.slysoft.com O1 - Hosts: 127.0.0.1 sb.slysoft.com O1 - Hosts: 127.0.0.1 iw5h.slysoft.com O1 - Hosts: 127.0.0.1 iw4.slysoft.com O1 - Hosts: 127.0.0.1 reverse.privatedns.com O1 - Hosts: 127.0.0.1 update.slysoft.com O1 - Hosts: 127.0.0.1 ns6.gandi.net O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O3 - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4:64bit: - HKLM..\Run: [CmPCIaudio] C:\Windows\Syswow64\CMICNFG3.DLL (C-Media Corporation) O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG) O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001..\Run: [F.lux] C:\Users\Chris\Local Settings\Apps\F.lux\flux.exe () O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found O4 - Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\foobar2000.exe - Shortcut.lnk = C:\Program Files (x86)\foobar2000\foobar2000.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data] O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data] O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1554432839-2126977190-2861617609-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings...vzTCPConfig.CAB (Reg Error: Key error.) O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (PDBoot.exe) - File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010/11/28 14:15:59 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Chris\Desktop\OTL.exe [2010/11/27 12:02:11 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW [2010/11/27 11:59:38 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Chris\Desktop\HijackThis.exe [2010/11/27 09:43:46 | 000,000,000 | ---D | C] -- C:\NewsBin [2010/11/27 07:33:03 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\ESET [2010/11/27 07:05:55 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET [2010/11/27 07:05:55 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2010/11/27 05:28:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\whitesmoketoolbar [2010/11/27 05:22:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileASSASSIN [2010/11/27 04:22:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER [2010/11/27 04:21:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services [2010/11/27 04:21:33 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2010/11/27 04:21:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework [2010/11/27 04:21:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition [2010/11/27 04:20:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8 [2010/11/27 04:19:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office [2010/11/27 04:19:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services [2010/11/27 04:18:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office [2010/11/27 04:17:58 | 000,000,000 | RH-D | C] -- C:\MSOCache [2010/11/27 02:55:57 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\{EE9EE85E-CA01-4107-909A-CB6E8AC31B6A} [2010/11/27 02:51:21 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\VS Revo Group [2010/11/27 02:51:18 | 000,031,800 | ---- | C] (VS Revo Group) -- C:\Windows\SysNative\drivers\revoflt.sys [2010/11/27 02:51:17 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group [2010/11/26 13:36:59 | 000,000,000 | ---D | C] -- C:\Program Files\NewsBin [2010/11/26 13:20:47 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\Gravity [2010/11/26 13:12:00 | 000,000,000 | ---D | C] -- X:\My Documents\downloads [2010/11/26 13:09:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SABnzbd [2010/11/26 13:09:12 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\Passware [2010/11/26 13:07:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Passware [2010/11/26 11:54:26 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\NewsBin [2010/11/25 02:43:46 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\GRETECH [2010/11/25 02:43:46 | 000,000,000 | ---D | C] -- X:\My Documents\GomPlayer [2010/11/25 02:43:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GRETECH [2010/11/21 11:57:36 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\HD Tune Pro [2010/11/21 11:56:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HD Tune Pro [2010/11/07 06:35:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5 [2010/11/07 06:34:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MeGUI [2010/11/03 06:47:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AOR [2010/11/03 06:17:56 | 000,000,000 | ---D | C] -- C:\ProgramData\CrypKey [2010/11/03 06:17:44 | 000,165,888 | ---- | C] (Kenonic Controls) -- C:\Windows\Ckconfig.exe [2010/11/03 06:17:44 | 000,122,880 | ---- | C] (CrypKey (Canada) Ltd.) -- C:\Windows\SysNative\Crypserv.exe [2010/11/03 06:17:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Stellar Phoenix Outlook PST Repair [2009/09/20 13:41:07 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Chris\AppData\Roaming\pcouffin.sys [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010/11/28 14:16:58 | 000,629,057 | ---- | M] () -- C:\Users\Chris\Desktop\RkU3.8.388.590.rar [2010/11/28 14:16:04 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Chris\Desktop\OTL.exe [2010/11/28 14:07:32 | 000,017,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010/11/28 14:07:32 | 000,017,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010/11/28 14:04:40 | 000,887,684 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010/11/28 14:04:40 | 000,742,236 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010/11/28 14:04:40 | 000,145,624 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010/11/28 14:00:47 | 000,000,200 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job [2010/11/28 14:00:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010/11/28 14:00:11 | 3219,886,080 | -HS- | M] () -- C:\hiberfil.sys [2010/11/27 11:59:41 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Chris\Desktop\HijackThis.exe [2010/11/27 05:28:13 | 000,001,112 | ---- | M] () -- C:\Windows\SysWow64\Improve Your PC.lnk [2010/11/27 05:13:56 | 000,435,744 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010/11/27 04:34:24 | 000,001,139 | ---- | M] () -- C:\Users\Chris\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk [2010/11/27 04:32:48 | 000,614,400 | ---- | M] () -- C:\Windows\AutoKMS.exe [2010/11/27 04:32:48 | 000,000,135 | ---- | M] () -- C:\Windows\AutoKMS.ini [2010/11/27 02:55:59 | 000,000,120 | ---- | M] () -- C:\Users\Chris\AppData\Local\Jlofex.dat [2010/11/27 02:55:59 | 000,000,000 | ---- | M] () -- C:\Users\Chris\AppData\Local\Vpoceq.bin [2010/11/26 13:05:10 | 000,000,703 | ---- | M] () -- C:\Windows\NewsRover.INI [2010/11/25 04:28:45 | 000,001,189 | ---- | M] () -- C:\Users\Chris\AppData\Roaming\vso_ts_preview.xml [2010/11/25 00:27:09 | 016,298,936 | ---- | M] () -- C:\Users\Chris\Desktop\fbanext-ps3-r364.rar [2010/11/06 18:26:57 | 000,049,664 | ---- | M] () -- X:\My Documents\Gas_Load_Data.xls [2010/11/05 09:21:49 | 000,000,280 | ---- | M] () -- C:\Windows\SysNative\PDBootState [2010/11/03 06:46:45 | 000,000,139 | ---- | M] () -- C:\Windows\Crypkey.ini [2010/11/03 06:18:16 | 000,001,680 | ---- | M] () -- C:\Windows\SysNative\esnecil.ind [2010/11/03 06:18:16 | 000,000,004 | ---- | M] () -- C:\Windows\vx86036.dat [2010/11/01 13:06:10 | 000,046,592 | ---- | M] () -- X:\My Documents\High Vac Pump Down Data 2010.xls [2010/10/30 23:32:52 | 000,083,968 | ---- | M] () -- X:\My Documents\Hi Vac Pump Down Report.doc [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/11/28 14:16:56 | 000,629,057 | ---- | C] () -- C:\Users\Chris\Desktop\RkU3.8.388.590.rar [2010/11/27 05:28:13 | 000,001,112 | ---- | C] () -- C:\Windows\SysWow64\Improve Your PC.lnk [2010/11/27 04:34:24 | 000,001,139 | ---- | C] () -- C:\Users\Chris\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk [2010/11/27 04:32:48 | 000,614,400 | ---- | C] () -- C:\Windows\AutoKMS.exe [2010/11/27 04:32:48 | 000,000,200 | ---- | C] () -- C:\Windows\tasks\AutoKMS.job [2010/11/27 04:30:20 | 000,000,135 | ---- | C] () -- C:\Windows\AutoKMS.ini [2010/11/27 02:55:59 | 000,000,120 | ---- | C] () -- C:\Users\Chris\AppData\Local\Jlofex.dat [2010/11/27 02:55:59 | 000,000,000 | ---- | C] () -- C:\Users\Chris\AppData\Local\Vpoceq.bin [2010/11/26 12:56:06 | 000,000,703 | ---- | C] () -- C:\Windows\NewsRover.INI [2010/11/25 00:26:05 | 016,298,936 | ---- | C] () -- C:\Users\Chris\Desktop\fbanext-ps3-r364.rar [2010/11/06 18:58:05 | 000,049,664 | ---- | C] () -- X:\My Documents\Gas_Load_Data.xls [2010/11/03 06:18:16 | 000,000,004 | ---- | C] () -- C:\Windows\vx86036.dat [2010/11/03 06:17:56 | 000,001,680 | ---- | C] () -- C:\Windows\SysNative\esnecil.ind [2010/11/03 06:17:47 | 000,000,139 | ---- | C] () -- C:\Windows\Crypkey.ini [2010/11/03 06:17:44 | 000,028,664 | ---- | C] () -- C:\Windows\SysNative\Ckldrv.sys [2010/11/03 06:17:44 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe [2010/11/03 06:17:44 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll [2010/11/03 06:17:44 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe [2010/10/30 23:45:35 | 000,046,592 | ---- | C] () -- X:\My Documents\High Vac Pump Down Data 2010.xls [2010/10/30 23:32:52 | 000,083,968 | ---- | C] () -- X:\My Documents\Hi Vac Pump Down Report.doc [2010/10/08 18:42:55 | 000,000,258 | ---- | C] () -- C:\Windows\ODBC.INI [2010/08/10 10:37:43 | 000,014,848 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll [2010/08/10 10:37:43 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys [2010/08/10 10:37:43 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys [2010/07/01 16:20:48 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll [2010/07/01 16:20:48 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll [2010/02/13 12:47:09 | 000,013,474 | ---- | C] () -- C:\Windows\PSPICEEV.INI [2010/02/13 12:47:07 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\lffax60n.dll [2010/02/13 12:47:07 | 000,141,824 | ---- | C] () -- C:\Windows\SysWow64\lfcmp60n.dll [2010/02/13 12:47:07 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\lfpng60n.dll [2010/02/13 12:47:07 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\lftif60n.dll [2010/02/13 12:47:07 | 000,043,008 | ---- | C] () -- C:\Windows\SysWow64\ltfil60n.dll [2010/02/13 12:47:07 | 000,023,552 | ---- | C] () -- C:\Windows\SysWow64\lfpcx60n.dll [2010/02/13 12:47:07 | 000,022,528 | ---- | C] () -- C:\Windows\SysWow64\lfpct60n.dll [2010/02/13 12:47:07 | 000,022,528 | ---- | C] () -- C:\Windows\SysWow64\lfeps60n.dll [2010/02/13 12:47:07 | 000,022,016 | ---- | C] () -- C:\Windows\SysWow64\lfbmp60n.dll [2010/02/13 12:47:07 | 000,020,480 | ---- | C] () -- C:\Windows\SysWow64\lfpsd60n.dll [2010/02/13 12:47:07 | 000,019,968 | ---- | C] () -- C:\Windows\SysWow64\lftga60n.dll [2010/02/13 12:47:07 | 000,019,456 | ---- | C] () -- C:\Windows\SysWow64\lfwpg60n.dll [2010/02/13 12:47:07 | 000,019,456 | ---- | C] () -- C:\Windows\SysWow64\lfwmf60n.dll [2010/02/13 12:47:07 | 000,018,432 | ---- | C] () -- C:\Windows\SysWow64\lfmsp60n.dll [2010/02/13 12:47:07 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\lfmac60n.dll [2010/02/13 12:47:07 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\implode.dll [2010/01/27 10:35:05 | 000,001,821 | ---- | C] () -- C:\ProgramData\GeorgeYohngVST.ini [2010/01/26 21:46:22 | 000,000,050 | ---- | C] () -- C:\Windows\MegaManager.INI [2010/01/15 18:23:49 | 000,003,518 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfg [2010/01/15 18:23:49 | 000,001,512 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.imi [2010/01/14 16:19:03 | 000,000,152 | ---- | C] () -- C:\Windows\BRVIDEO.INI [2010/01/14 16:19:03 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini [2010/01/14 16:18:54 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\brlmw03a.ini [2010/01/14 16:18:53 | 000,009,868 | ---- | C] () -- C:\Windows\HL-2170W.INI [2010/01/14 16:18:47 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI [2010/01/14 16:17:43 | 000,000,247 | ---- | C] () -- C:\Windows\Brownie.ini [2010/01/12 12:26:02 | 000,002,516 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys [2010/01/12 12:26:02 | 000,000,088 | RHS- | C] () -- C:\ProgramData\52D2B25CEF.sys [2009/10/16 19:51:43 | 000,001,872 | ---- | C] () -- C:\Windows\Cmicnfg3.ini.cfl [2009/10/16 19:51:23 | 000,002,857 | ---- | C] () -- C:\Windows\cmudax3.ini [2009/10/13 10:19:44 | 000,000,540 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\AutoGK.ini [2009/09/25 09:48:39 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2009/09/23 12:02:49 | 000,000,396 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2009/09/20 13:42:29 | 000,001,189 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\vso_ts_preview.xml [2009/09/20 13:41:26 | 000,000,034 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\pcouffin.log [2009/09/20 13:41:07 | 000,099,384 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\inst.exe [2009/09/20 13:41:07 | 000,007,859 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\pcouffin.cat [2009/09/20 13:41:07 | 000,001,167 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\pcouffin.inf [2009/09/20 13:35:53 | 000,798,932 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2009/09/20 11:09:45 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP6.dll [2009/09/20 11:07:54 | 000,007,602 | ---- | C] () -- C:\Users\Chris\AppData\Local\Resmon.ResmonCfg [2009/07/13 15:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 13:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009/06/14 13:15:52 | 000,000,244 | ---- | C] () -- C:\Windows\SysWow64\nirpc.ini [2005/06/10 09:00:00 | 000,007,140 | ---- | C] () -- C:\Windows\SysWow64\drivers\cvintdrv.sys < End of report >
  9. I get random site redirects to ads when clicking on links using the current Firefox with adblock plus. I have the latest version of NOD32 installed as my anti-vrius.. I have run Malwarebyte's Anti-Malware as well as an online virus scan and the problem continues. Here's my HiJackThis log, any help would be greatly appreciated. I get random site redirects to ads when clicking on google links using the current Firefox with adblock plus. This just started happening today and some new icons appeared on my desktop while I was browsing a website. The new icons were shortcuts to "White Smoke Translator". I have the latest version of NOD32 installed as my anti-virus.. I have run Malwarebyte's Anti-Malware as well as an online virus scan and the problem continues even after finding 15+ infected items. I have attached my current HiJackThis log Win7 x64 fully updated ESET NOD32 4.2.64.12 fully updated Mozilla Firefox 3.6.12 /w AdBlock Plus MBAM 1.46 fully updated I just ran MBAM again, but still having the redirects. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5199 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 11/27/2010 1:34:26 PM mbam-log-2010-11-27 (13-34-26).txt Scan type: Quick scan Objects scanned: 159601 Time elapsed: 2 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:WindowsTemptovb.tmpsetup.exe (Trojan.Dropper) -> No action taken. Obviously I had it delete the file and I rebooted. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:03:37 PM, on 11/27/2010 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16671) Boot mode: Normal Running processes: C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Users\Chris\Local Settings\Apps\F.lux\flux.exe C:\Program Files (x86)\foobar2000\foobar2000.exe C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Users\Chris\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form=ZGAPHP R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKCU\..\Run: [F.lux] "C:\Users\Chris\Local Settings\Apps\F.lux\flux.exe" /noshow O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: foobar2000.exe - Shortcut.lnk = C:\Program Files (x86)\foobar2000\foobar2000.exe O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings...vzTCPConfig.CAB O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2F3E28F2-35A9-4237-8534-BD4ABF32655C}: NameServer = 68.238.128.12,68.238.64.12 O17 - HKLM\System\CS1\Services\Tcpip\..\{2F3E28F2-35A9-4237-8534-BD4ABF32655C}: NameServer = 68.238.128.12,68.238.64.12 O17 - HKLM\System\CS2\Services\Tcpip\..\{2F3E28F2-35A9-4237-8534-BD4ABF32655C}: NameServer = 68.238.128.12,68.238.64.12 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe O23 - Service: Cadence License Manager - Macrovision Corporation - C:\Cadence\LicenseManager\lmgrd.exe O23 - Service: Crypkey License - Unknown owner - crypserv.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\Windows\SysWOW64\lkcitdl.exe O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\Windows\SysWOW64\lkads.exe O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\Windows\SysWOW64\lktsrv.exe O23 - Service: Flexlm (lmgrd) - Unknown owner - C:\OrCAD\OrCAD_10.5\IntelliCAD 4\LicenseManager\lmgrd.exe (file missing) O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files (x86)\National Instruments\MAX\nimxs.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\Windows\SysWOW64\nisvcloc.exe O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: OpcEnum - OPC Foundation - C:\Windows\SysWOW64\OpcEnum.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) -- End of file - 11067 bytes hijackthis.log hijackthis.log
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.