Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HijackThisLog for Malware Infection- Help please


  • This topic is locked This topic is locked
10 replies to this topic

#1 rojam

rojam

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:48 AM

Posted 18 February 2010 - 12:56 PM

Hello, basically my computer has become infected with Malware: I've installed Hijackthis and procexp to help myself out but my computer problems still persist so I need some expert help. My computer is sometimes very slow or unresponsive: this is due to svchost.exe occasionally running processes that take up nearly all of my CPU's resources. The malware has disabled my regedit and task manager functions, as well as disabled my active desktop. It also pops up seemingly random sites at random times when I use Firefox, and am occasionally unable to search google.com and browse from there because I'll click on a site and then the malware takes me to some random new one. Sometimes choosing the cached version on google helps, other times it does not. Here is my Hijackthislog: if there's any further information I can provide to help you help me, please let me know. And thanks for sharing your knowledge.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:43:39 AM, on 2/18/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\mIRC\mirc.exe
C:\Documents and Settings\Major Castleberry\Desktop\procexp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=Userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-2025429265-1004336348-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O15 - Trusted Zone: http://*.buy-internet-security10.com
O15 - Trusted Zone: http://*.is-soft-download.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.buy-internet-security10.com (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: STOPzilla Service (szserver) - Unknown owner - (no file)

--
End of file - 5848 bytes


BC AdBot (Login to Remove)

 


#2 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:08:48 AM

Posted 18 February 2010 - 06:39 PM

Good evening. smile.gif

Take a trip to this webpage for download links and instructions for running Combofix by sUBs.*
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console so, should you choose not to allow the installation, you may not get the results you hoped for.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for either.

So long, and thanks for all the fish.

 

 


#3 rojam

rojam
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:48 AM

Posted 21 February 2010 - 12:48 AM

Sorry for the late response: I've been quite busy and not at home much. Combofix seems to have done an exemplary job of eliminating all the bad filepaths, rootkits and malware bullsnot. Active desktop is back, computer appears to be operating normally, as before the infection. Only strange thing is on my desktop instead of call the icons appearing, well, regular, they all have this powder-blue bordering: I'm not sure what that is but as for everything else: primo. Thanks so much for the help, and this is the Combofix log as requested.

ComboFix 10-02-18.09 - Major Castleberry 02/19/2010 12:09:42.1.2 - x86
Running from: c:\documents and settings\Major Castleberry\My Documents\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\confin.sys
c:\documents and settings\Major Castleberry\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Major Castleberry\Application Data\SystemProc
c:\documents and settings\Major Castleberry\Application Data\SystemProc\lsass.exe
c:\documents and settings\Major Castleberry\Application Data\wiaservg.log
c:\documents and settings\Major Castleberry\Desktop\Internet Security 2010.lnk
c:\documents and settings\Major Castleberry\Local Settings\Application Data\{7B60D158-32A0-4F6A-8478-E3B91E387C0F}
c:\documents and settings\Major Castleberry\Local Settings\Application Data\{7B60D158-32A0-4F6A-8478-E3B91E387C0F}\chrome.manifest
c:\documents and settings\Major Castleberry\Local Settings\Application Data\{7B60D158-32A0-4F6A-8478-E3B91E387C0F}\chrome\content\_cfg.js
c:\documents and settings\Major Castleberry\Local Settings\Application Data\{7B60D158-32A0-4F6A-8478-E3B91E387C0F}\chrome\content\overlay.xul
c:\documents and settings\Major Castleberry\Local Settings\Application Data\{7B60D158-32A0-4F6A-8478-E3B91E387C0F}\install.rdf
c:\documents and settings\Major Castleberry\Start Menu\Internet Security 2010.lnk
c:\program files\CyberDefender
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\DelayLoad.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\Explorer Bars.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\Explorer Plugins.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\Hosts.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\IE Extensions.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\IE Main.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\IE Menubar.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\IE Searchbar.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\Run.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\Service.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\URLSearchHooks.dat
c:\program files\CyberDefender\AntiSpyware\{F2F16AEC-74E4-41E4-BE9E-6FE0A195CE94}\Shield\WinLogon.dat
c:\program files\CyberDefender\AntiSpyware\3D.tmp
c:\program files\CyberDefender\AntiSpyware\cdaspat.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat1.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat11.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat12.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat13.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat14.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat2.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat3.dat.03
c:\program files\CyberDefender\AntiSpyware\cdaspat4.dat.03
c:\program files\CyberDefender\AntiSpyware\Includes\Alert.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Adware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Alert Internet Explorer.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Alert Startup Program.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Browser Changer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Browser Plugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\BrowserChanger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\BrowserPlugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Bundler.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\categories.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Commercial Key Logger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\CommercialKeyLogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Cookie.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Data Miner.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\DataMiner.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Key Logger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\KeyLogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Low Risk Adware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\LowRiskAdware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Malware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\P2P.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\RAT.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Report Tracking Cookie.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Restore tracking cookie.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Search Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\SearchHijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Spyware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Stealth.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Trojan Downloader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Category\TrojanDownloader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\007 Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\007 Spy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\123mania.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\180ad Solution.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\180search Assistant.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\180SearchAssistant.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\180Solutions.com SurfAssistant.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\2020Search.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\2020Search.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\2nd-thought.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\2nd thought.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\404search.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\7AdPower.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\7FaSSt.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\7search-BrowserAccelerator.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\911-search.info.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ABC Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ABetterInternet.Aurora.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ABetterInternet.Ceres.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ABetterInternet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\About Blank.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Abox.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Absolute Key Logger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\abxtoolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Ace Club Casino.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AceNotes Free.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Aconti-Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Aconti.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ActiveSearch (411 Ferret).txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ActiveSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ActMon Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Acx Install.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Ad-Flow.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Ad-Popper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdBars.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdBreak.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdBureau.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdDestroyer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adintelligence.AproposToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adlogix Browser Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adlogix.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Admanager Controller.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Admess.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Admilli Service.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdPlus-SurferBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdRoar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adrotator.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdShooter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adtomi.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adultlinks Quickbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adultlinks.Quickbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adultlinks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Advanced Searchbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Advertbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Advertising.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adviva.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AdvSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Advware.BetterInternet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ADWARE.BINET.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adware.FOne.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Adware.HotSearchBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AFA Internet Enhancement.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Ahead Nero Burning Rom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Alexa Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Alexa.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\All-In-One Telcom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AllCyberSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Altnet Software.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Altnet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AltnetBDE.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AlwaysUpdatedNews.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Alyon.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Andlotsmore.com dialler.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AntiLamer Light.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AntivirusGold.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Aornum.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Apropos.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Ares.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AsianRaw Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Atwola Cookie.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Aureate-Radiate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Aureate Group Mail.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Aureate or Radiate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Aureate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AutoSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\AutoUpdate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Avenue Media.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Azesearch Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BackDoor-BDI.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.Agent.EN.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.Delf.is.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.Hackdoor.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.Jeem.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.Prorat.16.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.Rbot.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.Thunk.E.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Backdoor.win32.bifrose.d.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BackWeb Lite.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BackWeb.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BargainBuddy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BDE Projector.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BDHelper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BDPlugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BDSearch Plugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BearShare.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Begin2search.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Belcaro GoldenRetriever.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Berbew Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BFast.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BHO_DealHelper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bho_SEP.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bho_SideFind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BigTrafficNetwork.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bikinidesk.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BingoFun Games.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BlazeFind.Bridge.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BlazeFind.Browserhelper2.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BlazeFind.SearchEnhancer.ISTbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BlazeFind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BlazingTools Perfect Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Blondes.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bluemountain.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bokja NetInfo.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BonziBuddy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BookedSpace.Remanent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BookedSpace.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BPS Spyware Remover.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bridge.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Brilliant Digital.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BroadCastPC.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserAid.Featured-Results.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserAid.INetP.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserAid.RunDLL16.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserAid.SearchandClick.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserAid.Startium.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserAid.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserPal.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BrowserToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BuddyLinks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BuddyMediaBHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bulla.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Bullguard Popup Ad.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BullsEye Network.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BullsEye.CashBack.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BullsEye.eXact Advertising.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BullsEye.eXact.ISEXEng.Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\BullsEye.NaviSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\C-Dilla.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\C2.lop.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CallingHome.biz.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Carpe Diem.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Carpediem.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CAS.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Cashback.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CasinoClient.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CasinoOnNet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CasinoPalazzo.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Central-24 Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CES webmail.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Claria.Dashbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Claria.Precision Time.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Claria.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Claria.Weatherscope.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClearSearch.Net.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CleverIEHooker.Jeired.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClickAgents.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClickAlchemy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClickSpring.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClickSpring_MediaTickets.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClickSpring_PurityScan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Clickyes2enter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClimaxBucks.InternetOptimizer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ClipGenie.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Clkoptimizer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Clocksync.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Comedy-Planet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Comet Cursor.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Comet Systems.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Comload.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Commander Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components for About Blank.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components for BC Computing spy software.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components for IGetNet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components for Keyloggers.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components for MBP dialers.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components for SBSoft.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components For Spectorsoft.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Common Components for Transponders.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CommonName.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Comsoft.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Conducent FlexPak.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Conducent TimeSink.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ConfuSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Connector Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CoolSavings.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CoolWebSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CoreMetrics.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Coulomb Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Coulomb Ltd.Content Access Plugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CouponAge.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CouponsAndOffers.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CrackSpider.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CrazyWinnings.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Crush.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\CustomToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Cydoor.TOPicks.a.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Cydoor.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Daily Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DailyWinner.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DailyWinnerBHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Daosearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DAP.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dapsol Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dapsol.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DashBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Date Regon.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DateMaker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DCON.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DealHelper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DelfinProject.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Derbiz.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Desktop Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dialer.Axload.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dialer.IEDisco.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dialer.Scom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dialer.UDconnect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dialer2004.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DialerData Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DialerMaker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DialerOffline.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dialerplatform.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DialXS.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Diamond Deal Casino.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Divago.Surfairy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DivX Pro 5.1.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Dluca-M.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Domain Sponsor Cookie.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DoubleClick.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Download Accelerator Plus ads.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Download Accelerator.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Downloader.Lunii.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DownloadPlus.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DownloadReceiver.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DownloadWare.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DSO Exploit.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DSSAgent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DyFuCA.InternetOptimizer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\DyFuCA.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\E2G.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\E2Give.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EasyBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EasySearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EasyWebSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eBates MoneyMaker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eBates.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eBayToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eBlaster.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eGroup.InstantAccess.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eGroupDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Elite toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EliteBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Elitum.EliteBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Emesx.dll.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\emusic.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EnConfidence.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ePlugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ErrorGuard.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ESP Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eSyndicate BHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eUniverse.IncrediFind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eUniverse.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eUniverse.UpdMgr.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EverAd.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eXact Advertising.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eXact ISEXEng.Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ExactSearchBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Excite.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ExDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ezCyberSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EzSearchbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\eZula HotText.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\EzuLa.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\F__kSite.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FactoryNetwork Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Fairtale Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Farmmext.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Farsighter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Fast Video Player Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FastClick.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Fastfind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FastSeeker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Fastvideoplayer dialler.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FastVideoPlayer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FavoriteMan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FCI.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FileFreedom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FindSpy.A.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FindWhateverNow.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FizzleWizzle Search Bar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FlashEnhancer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FlashenhancerBHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FlashGet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FlashTrack.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Flingstone Infamous Downloader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Flyswat.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Forbes.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Free Scratch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FreeConnectLtd.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FreeScratchAndWin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FreeScratchCards.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Fresh Bar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Funny Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FunWeb.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\FunWebProducts.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN-eWallet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN-Supported Software.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN.DashBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN.Date Manager.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN.Precision Time.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN.Screen Scenes.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GAIN.Weatherscope.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GameSpy Arcade.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Gator.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GetMirar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GigaTech SuperBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GigexAgent-SpeedDelivery.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Global Netcom Inc.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GlobalCS Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GlobalDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GloboSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Gloggle.Shing.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Gloogle Downloader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GMSoft Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GogoTools.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GoHip.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GoIndirect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Golden Eye.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Golden Palace Casino.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GoZilla.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Grip Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Grokster.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\GSIM.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\H@tKeysH@@k.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hacker.ag.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Haczyk.Ulubione.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HalfLemon.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HangUpTeam.TechnicRat.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Haxdoor-H.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hellz Little Spy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hi-Wire.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hijacker.IEHost.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HitBox.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HitHopper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HitsLink.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Holystic-Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Holystic.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HomepageProtector.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hot_Pleasure.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hotsearchbar Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HotSearchBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hungry Hands porn hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HungryHands BHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HuntBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\HuntToolBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Huysuzseks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Hyperlinker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Ibero Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IberoDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IBIS Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\icannnews.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ICOO Loader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IE Access.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IE Driver.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IE Plugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ie2bar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEAccess.IEDial.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEFeats.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEHijacker.Find4u.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEHijacker.HereToFind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEHijacker.Hotoffers.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEHijacker.richfind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEHIjacker.SearchExe.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEHijacker.ZestyFind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IELoader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEMenuExtension Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEPageHelper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IEPlugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IESearchToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\iGetNet.Natural Language Navigation.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IGetNet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ILookup.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ILookup.Vroomsearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ImIServer IEPlugin.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IncrediFindBHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\InetSpeak.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Instafinder.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Instant Access.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IntermixMedia.KeenValue.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Internet Washer Pro.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\InternetDelivery.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\InternetOptimizer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\InternetWasher.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IntexusDial.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IPinsight.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\iSearch desktop search.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\iSearch Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\iSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.ISTactiveX.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.ISTbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.ISTsvc.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.ISTsvc_Updater.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.PowerScan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.SideFind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.Slotch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISearchTech.YSB.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\istbar.dotcomToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISTbar.Slotch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\istbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ISTbar.XXXToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\IwantSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\iWon.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Jeem.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Jeired.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Jraun.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\KazaaLite.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Kazoom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\KeenValue PerfectNav.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\KeenValue.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\KEXplorer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\KeyCaptor.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Keyhost Hijacker - JRaun.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Klez.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\LimeShop.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Limewire.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\LinkGrabber 99.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\LinkMaker Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\LinkMaker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\LinkSynergy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Locators.com Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Look2Me.Topconverting.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Look2Me.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Lop.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Lop.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\LoudMarketing.WinFavorites.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Lovefreegames Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Lycos Sidesearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Lycos.SideSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\LZIO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MagicControl.Agent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MagicControl.Av.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MagicControl.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MagicControl.WinMgts.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MainPean Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Mainpean Stardialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MainPean.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MakeThemCry.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Malware.Psguard.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Malware.TopAntiSpyware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MarketDart.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Marketscore Internet Accelerator.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Marketscore Netsetter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Marketscore(Netsetter).txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Masta Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Mastacash.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MatrixDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Maxifiles.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Media Pass.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Media Tickets.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaBuddy (FileFreedom).txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaCharger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaGateway.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaLoads Enhanced.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaMotor.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaPass.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaPlex.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaTicket.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaTickets.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MediaUpdate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MegaSearch Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Megasearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Memory Watcher.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MemoryMeter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MemoryWatcher.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Metadirect hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Metadirect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\metareward.com Cookie.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MicroGaming.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\midADdle.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Mindset Interactive - Favoriteman.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MiniBug.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Mirar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MoeMoney.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MOM.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MoneyTree.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Morpheus.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MPGCom Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MSConnect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MSView.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MX-Targeting.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\My Daily Horoscope.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\My Search.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\My Way.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\myDoom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MyNetProtector.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MyPointsPointAlert.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\MySearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\n-CASE.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NaughtyPops.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NavExcel.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NavHelper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NaviSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Navpmc.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\nCASE.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NeededWare.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Neo Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Netpal.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NetRatings Premeter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NetRatings.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Netservices BV.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Netsonic.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Netster Searchbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Netvenda.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Netvision Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Netword Agent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Network Essentials.Hopper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Network Essentials.ScBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Network Essentials.Search-Exe.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Network Essentials.SmartpopOops.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Network Essentials.SmartPops.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Network Essentials.WindowEnhancer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Network1.Popups.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NetworkEssentials.SCBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NetworkEssentials.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\New.net.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NewDotNet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NewsUpdate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NJStar Asian Explorer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NN_Bar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NoCreditCard Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NowBox.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NV-Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\NVDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Oemji Bar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Oemji Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OfferAgent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OffshoreClicks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\One2one Viewer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OnFlow.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OnlDial.MaConnect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OnlDial.Ole.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OnWebMedia.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Oodlz.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OpenSite.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OpinionBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OrbitExplorer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OutLaster.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Overpro.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\OverPro.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\P2P Networking.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ParisVoyeur Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PeopleOnPage.Apropos.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PeopleOnPage.AproposMedia.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PeopleOnPage.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PeoplePC Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Peper Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Peper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Perfect Keylogger Lite.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Perfect Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Phony search redirector.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Piratos.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PKings-IEHelper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Pops-Stop.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Pops Stop.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PopUpDefence.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Popuper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Popuppers Advertising.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Porn Dialer 5-2-46-112.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Porn Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\pornbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PowerReg Scheduler.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PowerSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Powerstrip.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PrecisionPop.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PrecisionTime.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Preview AdService.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ProDyne Webinstall.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PromulGate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Prutect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PSGuard Desktop Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PSGuard.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Puper.UpdateSearches.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\PurityScan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\QaBar-Adult Links Toolband.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\QaBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Qcbar.AdultLinks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\QHosts.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Qidion Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Quicknavigate Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\QuickPage.SwitchDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\QuickSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Radlight 3 PRO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Radlight Divx Player.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RadLight Media Player.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Radlight.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RapidBlaster.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RasDial.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RCPrograms.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Redhotnetworks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RedV.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Regsync.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RelatedLinks BHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RelatedLinks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Remote Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ReplaceSearch.BHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Rex Services.Adtrojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RichFind.Q.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RightFinder.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RiverSoftware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Roings.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Rsync.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Ruboskizo.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RVP.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\RXToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Rydial.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Safecast.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Safeguard Protect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SafeSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SafeSurfing.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SahAgent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SandBoxer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SaveNow - WhenUSave.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SaveNow.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Scam.Trackzapper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SCBAR.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SDBot.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Search-Pounder.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Search Assistant.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Search Miracle.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Search Relevancy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Search Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Searchalot.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchAndClick.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchbarCash.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchCentrix.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchEnhancement hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchEnhancement.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchExe.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchFast.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchForIt Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Searchforit.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchForIt.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Searchit.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchMaid.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchMiracle.EliteBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Searchmiracle.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchPounders Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchRelevancy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchSquire.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchV.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\searchwww.hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SearchWWW.IEToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SecondThought.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Secret-Crush.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SecretCrush.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Security iGuard.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\seekseek hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Seeq Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Sesso.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SexCounter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Sexfiles Dialers.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SexFiles.nu.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SexList.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SexTracker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShareDocs.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShopAtHome.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShopAtHomeSelect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShopForGood.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShopNav Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShopNav.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShopNavSearch.Srng.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ShowBehind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\sICRO Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SideFind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SideSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SinSource.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Slagent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SlimFTP.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SlotchBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SmartBrowser.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SmartPops - Network Essentials.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SmitFraud.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Softomate Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Specific911 Hijack.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Spector Pro Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpediaBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Speedblaster.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpeedDelivery.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Spy Recon Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpyArsenal HomeKeylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpyBlast.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpyBuddy Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpyDeleter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpyKeylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpyKiller 2005.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpyPC Keylogger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpySheriff.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Spyware.Perezzz.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpywareNo.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SpywareNuker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SquireSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Srng.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\StarInstall(MainPean).txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Startnow.Hyperbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Startpage.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Starware Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Starware.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Statblaster.MemoryWatcher.b.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Statblaster.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\StoolBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\StopPop.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Strip Player.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SubSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SunInfoConnect.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SupaSeek.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Super-gals.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Super-spider Hijacker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SuperBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Superlogy.com.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Supersmileys.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SupremeSpy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SureBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Surf Accuracy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Surfairy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SurfAssistant.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Surfbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SurfSideKick.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SwimSuitNetwork.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SwitchDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SyncroAd.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SySsfitb.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\System Soap Pro.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\System Soap.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\System Spy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\System1060.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SysWeb-Telecom Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SysWebTelecom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\SyvumClickTM.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TafBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Target Saver.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TargetNet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Targetsaver.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Targetsoft.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TeenXXX (TinyBar).txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Teknum Updater.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TestTimer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TheSearchMall.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TIB Browser.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TIBS Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TIBS dialers.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TIBS Premium Rate Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TIBS Premium Rate Dialler.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TightVNC.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Timbuktu Pro.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Timesink.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TinTel dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TinTel.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TinyBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Tinyo.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ToolbarCC.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TopConverting Crazywinnings.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TopConverting Downloader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Topconverting.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TOPicks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TopMoxie.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TopPicks.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TopRebates.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TopSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TrafficHog.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Ahexe.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Alchemy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.BI.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Bolger.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Ceres.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.LocalNRD.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Multimpp.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.MXTarget.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Pynix.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Speer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.Twain-tech.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Transponder.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Troj.Dloader.FQ.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan-Downloader-Hidden.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan-Downloader-Stubby.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan-Fake Warning.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan Common Components.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan Downloader Apher.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan drsnsrch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Banker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.CallingHome.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Delf.IT.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Dialer.FU.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.DNS Changer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Downloader.BHOmod.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Downloader.CT.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Downloader.Domcom.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Downloader.FH.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Downloader.FQ.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Downloader.Pacimedia.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Downloader.Small.BDZ.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Dropper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Drsnsrch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Dumaru.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.FakeAlert.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.FakeSpy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.FavAdd.ae.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Favadd.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Hacktool.Rootkit.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Pakes.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Popuper.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Proxy.BK.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Proxy.Webber.O.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Sheldor.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Spywad.A.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.StartPage.BN.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.startpage.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Stubby.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Win32.Revop.c.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Win32.Sdbot-QG.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Trojan.Wuviewer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TSCash.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Tubby Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TubbyBHO.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TurboDownload.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TV Media Display.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TvMedia.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Twain-tech.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TwainTech.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Twister.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\TX4.BrowserAd.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\UCmore.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\UKVideo2 Dialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Unknown Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ValueAd.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VBouncer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Virtual Bouncer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VirtualBouncer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Virtumonde.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VLoading.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\vx2 (Transponder).txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VX2 Transponder variant.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VX2.aBetterInternet.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VX2.BTGrab.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VX2.DealsOnline.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VX2.Host.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VX2.LocalNRD.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\VX2.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\W32.Bagle.I.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\W32.HLLW.Xolox.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WareOut.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Web3000.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebDialer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebHancer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebInstall.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebRebates.TopRebates.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebRebates.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebSearch Toolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WebTrends live.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenU.ClockSync.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenU.Control.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenU.DesktopToolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenU.SaveNow.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenU.Search.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenU.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenU.WeatherCast.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenUSave.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WhenUSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WildMedia.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WildTangent.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win-Spy.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win32.Backdoor.Jeem.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\win32.blaster.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win32.Downloader.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win32.LolaWeb.Trojan.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\win32.mydoom.p@mm.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win32.Perfiler.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win32.Sasser.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win32.Welchia.B.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Win32.winshow.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WinAD.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WindowEnhancer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Windows AdControl.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WindUpdate.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WindUpdates.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WinFavorites.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Wink.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Winpage Blocker.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Winpup.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Winpup32.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WinTools.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Wishbone.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Wowvirgins.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\WurldMedia.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Xrenoder.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Xupiter.OrbitExplorer.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Xupiter.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\XXXDIAL.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\XXXtoolbar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\YourSiteBar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ZANGO Search Assistant.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Zango.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Zestyfind.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ZipClix.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\Zoombar.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Description\ZSearch.txt
c:\program files\CyberDefender\AntiSpyware\Includes\Loading Index.htm
c:\program files\CyberDefender\AntiSpyware\Includes\NoItems Index.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Notify.wav
c:\program files\CyberDefender\AntiSpyware\Includes\Report Spyware.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Report.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Restore Spyware.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Restore.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Settings Browser Helper Objects.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Settings Internet Explorer.htm
c:\program files\CyberDefender\AntiSpyware\Includes\Settings Startup Program.htm
c:\program files\CyberDefender\AntiSpyware\sum.htm
c:\program files\CyberDefender\AntiSpyware\UserGuide\cybdefantispy.set
c:\program files\CyberDefender\AntiVirus\3F.tmp
c:\program files\CyberDefender\AntiVirus\cdavpat.dat.03
c:\program files\CyberDefender\AntiVirus\cdavpat.dat.04
c:\program files\CyberDefender\AntiVirus\cdavpat.dat.05
c:\program files\CyberDefender\AntiVirus\cdavpat.dat.06
c:\program files\CyberDefender\AntiVirus\Html\History eMail.htm
c:\program files\CyberDefender\AntiVirus\Html\History File.htm
c:\program files\CyberDefender\AntiVirus\Html\Loading Index.htm
c:\program files\CyberDefender\AntiVirus\Html\NoItems Index.htm
c:\program files\CyberDefender\AntiVirus\Html\Notify.wav
c:\program files\CyberDefender\AntiVirus\UserGuide\CybDefAV.set
c:\program files\CyberDefender\AntiVirus\uwcdsoe.dl_
c:\program files\CyberDefender\AntiVirus\uwcdsolk.dl_
c:\program files\CyberDefender\AntiVirus\uwhook32.dl_
c:\program files\CyberDefender\cdinstx.log
c:\program files\CyberDefender\earlySpam\cdinstx.log
c:\program files\CyberDefender\earlySpam\images\block_normal.bmp
c:\program files\CyberDefender\earlySpam\images\block_over.bmp
c:\program files\CyberDefender\earlySpam\images\earlySPAMBtn.bmp
c:\program files\CyberDefender\earlySpam\images\grant_normal.bmp
c:\program files\CyberDefender\earlySpam\images\grant_over.bmp
c:\program files\CyberDefender\earlySpam\images\options_normal.bmp
c:\program files\CyberDefender\earlySpam\images\options_over.bmp
c:\program files\CyberDefender\earlySpam\images\spy_normal.bmp
c:\program files\CyberDefender\earlySpam\images\spy_over.bmp
c:\program files\CyberDefender\eula.rtf
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\block_normal.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\block_over.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\earlySPAMBtn.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\grant_normal.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\grant_over.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\options_normal.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\options_over.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\spy_normal.bmp
c:\program files\CyberDefender\InstallModule\AntiSpam\CSIDL_PROGRAM_FILES\earlySpam\images\spy_over.bmp
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\database.db
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Includes\Loading.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Includes\NoItems Index.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Includes\Password Cookie.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Includes\Passwords Index.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Includes\Privacy Index.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\charset.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\cookie.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\defaultCharset.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\form.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\frame.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\gray.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\green.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\host.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bg.jpg
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bg_button.jpg
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bg_top.jpg
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_go.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_go_down.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_go_over.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_grey.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_red - Copy.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_red.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_red_down.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\bt_red_over.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\caution.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\frame.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\logo.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\logo.jpg
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\logo_orange.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\topbar.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\topbar_orange.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\images\warning.gif
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\popup.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\port.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\protocol.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\red.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\referrer.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\scamalert.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\scamalert.htm1
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\script.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\security.html
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\style.css
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\Scam Alert\yellow.htm
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\stbarpat.dat.03
c:\program files\CyberDefender\InstallModule\SecurityToolbar\CSIDL_LOCAL_APPDATA\CyberDefender\UserGuide\cybdefstbar.set
c:\program files\CyberDefender\UserGuide\CybDefISS.set
c:\program files\Internet Explorer\js.mui
c:\program files\InternetSecurity2010
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\windows\system32\18467.exe
c:\windows\system32\41.exe
c:\windows\system32\certstore.dat
c:\windows\system32\ctfmon .exe
c:\windows\system32\driVERs\bichze.sys
c:\windows\system32\flags.ini
c:\windows\system32\info.tmp
c:\windows\system32\narenodo.dll
c:\windows\system32\ndisdrv.sys
c:\windows\system32\ndismgr.sys
c:\windows\system32\rimuwuka.exe
c:\windows\system32\rundll32 .exe
c:\windows\system32\spool\prtprocs\w32x86\00005999.tmp
c:\windows\system32\uses32.dat
c:\windows\system32\warning.html
c:\windows\Tasks\psoxhcpp.job

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it tongue.gif
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_6TO4
-------\Legacy_IAS
-------\Legacy_IPRIP
-------\Legacy_WINSTS
-------\Service_6to4
-------\Service_Iprip
-------\Legacy_bichze
-------\Legacy_ndisdrv
-------\Legacy_ndismgr
-------\Service_bichze
-------\Service_ndisdrv
-------\Service_ndismgr


((((((((((((((((((((((((( Files Created from 2010-01-19 to 2010-02-19 )))))))))))))))))))))))))))))))
.

2010-02-17 12:26 . 2010-02-17 12:26 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2010-02-16 07:11 . 2010-02-16 07:11 -------- d-----w- c:\windows\Watson
2010-02-16 07:11 . 2010-02-16 07:11 -------- d-----w- c:\program files\Microsoft Games
2010-02-15 18:33 . 2010-02-15 18:33 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities
2010-02-11 17:44 . 2010-02-11 17:44 3072 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{F29428D8-9231-7C54-3968-F48077C10C20}-kbdsock.dll
2010-02-11 17:43 . 2010-02-11 17:43 3072 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{0D546011-7C27-A608-A92A-717C88C0516F}-kbdsock.dll
2010-02-09 08:31 . 2010-02-09 08:31 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{6F64241A-3F5B-A94F-0F59-61359C02481E}-irmonex.dll
2010-02-09 08:26 . 2010-02-09 08:26 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FFD4A6C2-3629-8359-F7D9-B46F10CA7BCA}-irmonex.dll
2010-02-09 08:21 . 2010-02-09 08:21 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FA9B47FE-4366-3E78-2861-D38F0D1F246D}-irmonex.dll
2010-02-09 08:16 . 2010-02-09 08:16 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{5FE7EA86-A70C-1103-6589-15CCCB8434AF}-irmonex.dll
2010-02-09 08:10 . 2010-02-09 08:10 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{343C9F2D-A858-3338-D6FB-C3FE446194A5}-irmonex.dll
2010-02-09 08:05 . 2010-02-09 08:05 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{1AFF6994-EC7B-8524-A93A-77A938214A94}-irmonex.dll
2010-02-09 08:00 . 2010-02-09 08:00 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4DFD7425-A1F0-7072-4F55-1DFC9A9FBB72}-irmonex.dll
2010-02-09 07:55 . 2010-02-09 07:55 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{8EFC9CE7-259A-F4F4-9530-4E6428CF6997}-irmonex.dll
2010-02-09 07:49 . 2010-02-09 07:49 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{0DB9D86C-3ACA-7CD3-1DA9-79E2775D58B7}-irmonex.dll
2010-02-09 07:44 . 2010-02-09 07:44 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{EAD8566F-E092-C5CC-62CD-F7D390B127D1}-irmonex.dll
2010-02-09 07:39 . 2010-02-09 07:39 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{DF9C4A77-CBA6-98B6-164F-7A6CB562F189}-irmonex.dll
2010-02-09 07:34 . 2010-02-09 07:34 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{36B70773-93FE-F3A6-D6BE-E80DFCA0A17E}-irmonex.dll
2010-02-09 07:28 . 2010-02-09 07:28 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{3523A7EE-613F-C4E0-2867-4BE6D6BD37FF}-irmonex.dll
2010-02-09 07:23 . 2010-02-09 07:23 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{BDCB74FD-D1B2-DC6C-E818-9EF006F03F92}-irmonex.dll
2010-02-09 07:18 . 2010-02-09 07:18 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B4EDFEDC-D804-A783-FDF7-64BA9E12F49C}-irmonex.dll
2010-02-09 07:13 . 2010-02-09 07:13 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{0356CD3C-C8D2-67F6-5DBC-F02512879CA3}-irmonex.dll
2010-02-09 07:07 . 2010-02-09 07:07 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{9A95A403-5CF2-535A-8251-3A888246102B}-irmonex.dll
2010-02-09 07:02 . 2010-02-09 07:02 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{26F1F89F-0F26-2A0C-E492-C449FDBB2C2C}-irmonex.dll
2010-02-09 06:57 . 2010-02-09 06:57 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{038268C9-F054-592B-5DCB-E805F52EE8C7}-irmonex.dll
2010-02-09 06:52 . 2010-02-09 06:52 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{59EF96DD-52DA-F523-EC6C-7103F9408FDF}-irmonex.dll
2010-02-09 06:47 . 2010-02-09 06:47 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4F3A223E-C241-F1AD-7858-4C8AF7707D08}-irmonex.dll
2010-02-09 06:41 . 2010-02-09 06:41 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A25B3494-4505-6173-1A5C-7D74DE04F03C}-irmonex.dll
2010-02-09 06:36 . 2010-02-09 06:36 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{8AECEC17-38FB-A7BF-1EBE-2001DEC9F9B8}-irmonex.dll
2010-02-09 06:31 . 2010-02-09 06:31 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{033D0E92-955F-AF7B-93ED-5CBB2ABDB411}-irmonex.dll
2010-02-09 06:25 . 2010-02-09 06:25 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{9CE11BC4-D093-7FA6-B529-58B1B9E7CAFA}-irmonex.dll
2010-02-09 06:20 . 2010-02-09 06:20 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{1C773811-F66D-DC0B-78DA-4C0D7DB56117}-irmonex.dll
2010-02-09 06:15 . 2010-02-09 06:15 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{D5EEFB17-D47B-11C3-8AD4-0A6AD5A3CD6E}-irmonex.dll
2010-02-09 06:10 . 2010-02-09 06:10 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{BAAEA17A-6B2E-8BE2-677A-C80A46E9EEA5}-irmonex.dll
2010-02-09 06:05 . 2010-02-09 06:05 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B2323590-91FE-A6B3-B37D-8E83B8786EF8}-irmonex.dll
2010-02-09 05:59 . 2010-02-09 05:59 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{7A7C03A8-A387-F04A-D383-E44002EA5BED}-irmonex.dll
2010-02-09 05:54 . 2010-02-09 05:54 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A7957C59-9A66-8854-D0C3-89CC6744E61E}-irmonex.dll
2010-02-09 05:49 . 2010-02-09 05:49 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{10A4A97E-95EA-E7CD-B9BD-C00D947FA8BB}-irmonex.dll
2010-02-09 05:44 . 2010-02-09 05:44 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{EA8F88CD-45E7-0D96-6C8C-CE9626D0A5F2}-irmonex.dll
2010-02-09 05:38 . 2010-02-09 05:38 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{7F22E10E-25DD-BC3F-1081-7A0D53BB8100}-irmonex.dll
2010-02-09 05:33 . 2010-02-09 05:33 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A807D79B-BE01-941A-4447-BD1ECD8447A9}-irmonex.dll
2010-02-09 05:28 . 2010-02-09 05:28 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{D78137B6-05FA-9F64-4956-5EAFEA648AFF}-irmonex.dll
2010-02-09 05:23 . 2010-02-09 05:23 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{CCB9DE1C-87FE-6FE7-E728-C6E4A8E57AC7}-irmonex.dll
2010-02-09 05:17 . 2010-02-09 05:17 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{7702287B-C026-CEFE-5E7F-6B40A860569F}-irmonex.dll
2010-02-09 05:12 . 2010-02-09 05:12 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{3555AB4B-6D27-DB42-AEDF-41026B088AEE}-irmonex.dll
2010-02-09 05:07 . 2010-02-09 05:07 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A35A93D3-BD8C-485F-9D68-266D217A8816}-irmonex.dll
2010-02-09 05:02 . 2010-02-09 05:02 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FD24B54F-747D-3FF9-8BCA-B950734190FB}-irmonex.dll
2010-02-09 04:56 . 2010-02-09 04:56 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{F082D0A8-F738-BA4B-4661-A679D18F1FD8}-irmonex.dll
2010-02-09 04:51 . 2010-02-09 04:51 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{CA9E5143-C7B5-5F57-B98B-5271DEBE26C7}-irmonex.dll
2010-02-09 04:46 . 2010-02-09 04:46 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{44C98F2C-F6A7-F77C-A77F-774159D7FC05}-irmonex.dll
2010-02-09 04:40 . 2010-02-09 04:40 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{3E8CD10C-2D1A-7503-714B-DDCEE5EAAA80}-irmonex.dll
2010-02-09 04:39 . 2010-02-09 04:39 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4ED02ADD-48FA-EBA1-15AA-D22CF0837DCD}-irmonex.dll
2010-02-09 04:35 . 2010-02-09 04:35 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{20939EDD-C260-93B2-1786-D3BB61ED3C60}-irmonex.dll
2010-02-09 04:30 . 2010-02-09 04:30 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{0BF94F3C-1F27-ABDC-028A-A05A0DFF5D62}-irmonex.dll
2010-02-09 04:25 . 2010-02-09 04:25 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4051EE3B-F8FB-56F1-A797-4D20FEA15190}-irmonex.dll
2010-02-09 04:20 . 2010-02-09 04:20 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4A04F557-19C1-A221-AA31-3351C6064181}-irmonex.dll
2010-02-09 04:14 . 2010-02-09 04:14 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{BC1DB3EE-8059-5B86-A855-24C62FEDF0C2}-irmonex.dll
2010-02-09 04:09 . 2010-02-09 04:09 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{E495CBCF-B548-B874-09DD-C0B9DC66452A}-irmonex.dll
2010-02-09 04:04 . 2010-02-09 04:04 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{7D9FF01D-9E14-9E52-B408-AD6D46FFB957}-irmonex.dll
2010-02-09 03:59 . 2010-02-09 03:59 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{C4C397A6-A56E-894F-FA71-567AE0789E4F}-irmonex.dll
2010-02-09 03:53 . 2010-02-09 03:53 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{613906CE-5AA1-61E8-B78E-49D92A9A3662}-irmonex.dll
2010-02-09 03:48 . 2010-02-09 03:48 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A2F756A8-6B70-8E45-8BB9-508D46D600DC}-irmonex.dll
2010-02-09 03:43 . 2010-02-09 03:43 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{3BB5C154-3195-8C47-6B59-505D43F97B80}-irmonex.dll
2010-02-09 03:38 . 2010-02-09 03:38 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B94260CA-0578-142A-2DFB-97CB65CAAE8D}-irmonex.dll
2010-02-09 03:32 . 2010-02-09 03:32 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{85BCB755-B337-6192-3CA6-6DDA634D2AA3}-irmonex.dll
2010-02-09 03:27 . 2010-02-09 03:27 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{8C9CEE37-7F36-78CF-7BBC-1C043E9FA136}-irmonex.dll
2010-02-09 03:22 . 2010-02-09 03:22 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{EFD6B08D-7E89-9DEE-EAE6-EE926125505E}-irmonex.dll
2010-02-09 03:17 . 2010-02-09 03:17 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{46428878-A5D0-6D1C-44C2-9D6A5E171E47}-irmonex.dll
2010-02-09 03:11 . 2010-02-09 03:11 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A0B610C3-390D-2147-10D1-CF9BD758DC5E}-irmonex.dll
2010-02-09 03:06 . 2010-02-09 03:06 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B6605D5C-AE7D-3DBB-36AA-36C0051726F3}-irmonex.dll
2010-02-09 03:01 . 2010-02-09 03:01 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{C76EDA27-9855-F0F4-5D5A-47E0527070FC}-irmonex.dll
2010-02-09 02:56 . 2010-02-09 02:56 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{23CE34D7-E6F7-C2DE-9232-F7CAB96D5E96}-irmonex.dll
2010-02-09 02:51 . 2010-02-09 02:51 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B458C67B-5174-51FD-AEAD-D7B0168D5967}-irmonex.dll
2010-02-09 02:45 . 2010-02-09 02:45 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{3762E462-2B47-4B54-B4F9-AC029A4A4DF0}-irmonex.dll
2010-02-09 02:40 . 2010-02-09 02:40 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{725F1C38-9B94-0A8F-0C18-15D1CDAAEC57}-irmonex.dll
2010-02-09 02:36 . 2010-02-09 02:36 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{83F52DE8-8AD4-549C-C205-8B1660736BF7}-irmonex.dll
2010-02-09 02:35 . 2010-02-09 02:35 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{E02BBBF0-79E3-E4DA-2D5F-EBA071AD5094}-irmonex.dll
2010-02-09 02:29 . 2010-02-09 02:29 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B06DA0E8-B895-22ED-2058-CCA9F326076C}-irmonex.dll
2010-02-09 02:24 . 2010-02-09 02:24 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{74C412DD-30F6-DE1A-E08D-78FE612AF94F}-irmonex.dll
2010-02-09 02:19 . 2010-02-09 02:19 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{6365FBA8-E709-933F-3941-8C822A9556B8}-irmonex.dll
2010-02-09 02:14 . 2010-02-09 02:14 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{1C854018-A604-A923-4847-2BC0AAF048D7}-irmonex.dll
2010-02-09 02:08 . 2010-02-09 02:08 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{48089540-E2F0-29AB-FAB0-E07034180213}-irmonex.dll
2010-02-09 02:03 . 2010-02-09 02:03 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B15880AE-39D4-3C9B-2C8F-C5C697238EE1}-irmonex.dll
2010-02-09 01:58 . 2010-02-09 01:58 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{C330C50E-968F-2C7E-3B68-56C630A342AC}-irmonex.dll
2010-02-09 01:53 . 2010-02-09 01:53 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{F1922E5B-A73E-C95B-9263-F284F3E79E05}-irmonex.dll
2010-02-09 01:47 . 2010-02-09 01:47 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{6A78ECCA-69EE-F799-91C1-1E16CCB84190}-irmonex.dll
2010-02-09 01:42 . 2010-02-09 01:42 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A6A52805-1981-30BC-F6F2-70A114B41186}-irmonex.dll
2010-02-09 01:37 . 2010-02-09 01:37 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{ABA761F0-0B27-DBA1-8601-30019AB8BFFC}-irmonex.dll
2010-02-09 01:32 . 2010-02-09 01:32 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{89B4BBDE-313D-727B-EC0E-12178665C689}-irmonex.dll
2010-02-09 01:26 . 2010-02-09 01:26 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{1165563F-3B43-4644-1D34-AFA02706FB39}-irmonex.dll
2010-02-09 01:21 . 2010-02-09 01:21 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{EA4BDD69-22A4-2970-37D2-5AFB4E2F083F}-irmonex.dll
2010-02-09 01:16 . 2010-02-09 01:16 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{E4065B6F-9051-3E3F-9138-43CD21E9467D}-irmonex.dll
2010-02-09 01:11 . 2010-02-09 01:11 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{0A21337C-C9F9-EF7E-4490-A19AAF8A34BC}-irmonex.dll
2010-02-09 01:05 . 2010-02-09 01:05 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{8182649A-01C8-4280-DB56-7715214BC22B}-irmonex.dll
2010-02-09 01:00 . 2010-02-09 01:00 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{8A003AF0-8E71-C3A1-846E-2D51E26EB1DD}-irmonex.dll
2010-02-09 00:55 . 2010-02-09 00:55 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{5B256237-F208-2C80-535C-69C44031C1B1}-irmonex.dll
2010-02-09 00:50 . 2010-02-09 00:50 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{660AC3C4-3C37-DDC0-12E0-A4E391FF9AFE}-irmonex.dll
2010-02-09 00:44 . 2010-02-09 00:44 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{21C111C0-34A8-DCF8-AECE-C26970379A7A}-irmonex.dll
2010-02-09 00:39 . 2010-02-09 00:39 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{3CA8944D-74DC-071C-1969-B41A7C8B35EA}-irmonex.dll
2010-02-09 00:34 . 2010-02-09 00:34 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{9BA5DCA7-B014-BC00-86E4-C4D660B22779}-irmonex.dll
2010-02-09 00:29 . 2010-02-09 00:29 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{64C3499B-971D-AF3D-F333-BCA07B8E8087}-irmonex.dll
2010-02-09 00:23 . 2010-02-09 00:23 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{CB179A1D-4DEC-7A39-DAB3-4B28C35FA504}-irmonex.dll
2010-02-09 00:18 . 2010-02-09 00:18 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{1407C464-B99B-A873-0BE1-7B2867835F84}-irmonex.dll
2010-02-09 00:13 . 2010-02-09 00:13 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{AEE3EE28-5875-553F-6279-B65CEE054FC5}-irmonex.dll
2010-02-09 00:08 . 2010-02-09 00:08 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{ED259864-4F23-22F5-A86E-058D3B4AEC17}-irmonex.dll
2010-02-09 00:02 . 2010-02-09 00:02 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{222ACADF-DA44-AA3E-0B1E-3E716DF1DFBF}-irmonex.dll
2010-02-08 23:57 . 2010-02-08 23:57 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{DF817FEF-43CE-A221-4541-36F2812062D0}-irmonex.dll
2010-02-08 23:52 . 2010-02-08 23:52 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{E363F53A-1E7A-F93F-B0EB-89FCBF925E0C}-irmonex.dll
2010-02-08 23:47 . 2010-02-08 23:47 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{2E434686-F12D-2436-D2E8-D128C67465F1}-irmonex.dll
2010-02-08 23:41 . 2010-02-08 23:41 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{CEFD750E-E5D9-D17B-E776-ECB335A5332D}-irmonex.dll
2010-02-08 23:36 . 2010-02-08 23:36 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{41884D3E-A1AD-5E1B-AB6E-7859927178AB}-irmonex.dll
2010-02-08 23:31 . 2010-02-08 23:31 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{42BCD81F-3C3E-2BB1-6B86-B16A30DBFE7C}-irmonex.dll
2010-02-08 23:20 . 2010-02-08 23:20 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{50CFFC71-AE30-2A43-1F67-D95F06EFD20A}-irmonex.dll
2010-02-08 23:15 . 2010-02-08 23:15 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{991C30EF-8641-E58D-7AB3-E6D8F78DBE74}-irmonex.dll
2010-02-08 23:10 . 2010-02-08 23:10 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{3D8615A7-DABC-ECF2-EFAF-9ED68D4B8303}-irmonex.dll
2010-02-08 23:05 . 2010-02-08 23:05 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{DB9D93B0-3446-12A7-3F5F-76BBFC038C76}-irmonex.dll
2010-02-08 22:57 . 2010-02-08 22:57 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FE6C29E8-FCB1-B357-FF8E-54EA65E86E2B}-irmonex.dll
2010-02-08 22:54 . 2010-02-08 22:54 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B77C98CC-D256-C9D2-BC63-04D4A53F2758}-irmonex.dll
2010-02-08 22:49 . 2010-02-08 22:49 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{DB8F01D6-5521-08CB-E9C8-3B62C29C4369}-irmonex.dll
2010-02-08 22:44 . 2010-02-08 22:44 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{F6BAD537-55F6-1FA8-5723-CEAC18664FE5}-irmonex.dll
2010-02-08 22:38 . 2010-02-08 22:38 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{2FC6217F-386F-DFC5-4D7F-8FC40102B83A}-irmonex.dll
2010-02-08 22:33 . 2010-02-08 22:33 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B8CAD3D5-3611-161C-8E91-0F6EEAE6DF7B}-irmonex.dll
2010-02-08 22:28 . 2010-02-08 22:28 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{294959FA-B745-FFFC-57C4-3CF06788C726}-irmonex.dll
2010-02-08 22:23 . 2010-02-08 22:23 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{20EDE63F-EEEC-4584-E2D3-D83CEE27C446}-irmonex.dll
2010-02-08 22:17 . 2010-02-08 22:17 73728 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{D9F2C21E-7350-0FF1-F41B-B55C3E2EDBB9}-irmonex.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 20:08 . 2009-12-31 01:26 -------- d-----w- c:\program files\Common Files\PC Tools
2010-02-19 20:07 . 2009-07-14 12:32 -------- d-----w- c:\documents and settings\Major Castleberry\Application Data\mIRC
2010-02-19 20:01 . 2009-03-04 08:30 43720 -c--a-w- c:\documents and settings\Major Castleberry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-19 19:48 . 2009-12-31 01:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-19 19:48 . 2009-12-31 01:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-19 19:48 . 2009-11-07 00:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-19 11:34 . 2009-12-31 01:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-18 06:29 . 2009-07-14 12:32 -------- d-----w- c:\program files\mIRC
2010-02-18 04:35 . 2010-01-06 06:12 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-14 05:31 . 2009-03-04 10:36 -------- d-----w- c:\program files\World of Warcraft
2010-02-07 19:29 . 2009-03-08 02:05 -------- d-----w- c:\program files\QuickTime
2010-02-06 09:14 . 2009-12-29 19:34 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-04 08:38 . 2009-03-08 02:06 -------- d-----w- c:\program files\iTunes
2010-02-02 09:02 . 2009-11-26 09:53 79488 ----a-w- c:\documents and settings\Major Castleberry\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-02 08:57 . 2009-12-30 18:37 -------- d-----w- c:\program files\Unlocker
2010-02-02 08:56 . 2009-03-05 01:01 -------- d-----w- c:\program files\Curse
2010-02-02 01:40 . 2010-02-02 01:40 39424 ----a-w- c:\windows\pchealth\helpctr\binaries\OLD260.tmp
2010-02-02 01:40 . 2010-02-02 01:40 39424 ----a-w- c:\windows\system32\OLD25D.tmp
2010-01-25 19:24 . 2009-12-29 20:08 120 ----a-w- c:\windows\Nligo.dat
2010-01-25 17:23 . 2009-12-29 20:08 0 ----a-w- c:\windows\Ldicabuleze.bin
2010-01-14 19:12 . 2009-12-29 18:38 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 18:28 . 2010-01-10 16:48 27911 ----a-w- c:\windows\system32\IJ3O9R00KU.dat
2010-01-13 18:28 . 2010-01-10 16:48 1860 ----a-w- c:\windows\system32\0SX0TUVES.dat
2009-12-31 02:18 . 2009-12-31 02:18 33558 ----a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\Firefox_Toolbar_Uninstaller.exe
2009-12-31 01:26 . 2009-12-31 01:16 89734640 ----a-w- c:\documents and settings\All Users\Application Data\Google Updater\cache\packdata_ci_sd_7.0.0.514_en_setup.exe
2009-12-31 01:15 . 2009-12-31 01:15 -------- d-----w- c:\program files\Google
2009-12-31 00:50 . 2009-12-29 20:36 -------- d-----w- c:\documents and settings\Major Castleberry\Application Data\SUPERAntiSpyware.com
2009-12-31 00:50 . 2009-03-27 01:22 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-31 00:49 . 2009-11-07 00:01 -------- d-----w- c:\program files\PC Cleaner
2009-12-31 00:48 . 2009-12-29 19:22 -------- d-----w- c:\program files\STOPzilla!
2009-12-31 00:48 . 2009-11-06 22:41 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2009-12-30 01:14 . 2009-12-30 01:14 -------- d-----w- c:\documents and settings\Major Castleberry\Application Data\Malwarebytes
2009-12-30 01:13 . 2009-12-30 01:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-30 00:52 . 2009-12-30 00:52 -------- d-----w- c:\program files\Trend Micro
2009-12-29 21:46 . 2009-12-29 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-12-29 20:41 . 2009-12-29 19:22 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-12-29 20:37 . 2009-12-29 20:37 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-29 20:36 . 2009-12-29 20:36 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-29 20:24 . 2009-12-29 20:03 1072 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-12-29 20:06 . 2009-12-29 19:23 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-12-29 19:22 . 2009-12-29 19:22 -------- d-----w- c:\program files\Common Files\iS3
2009-12-29 05:28 . 2009-12-29 05:28 -------- d-----w- c:\program files\Alwil Software
2009-12-28 04:27 . 2009-11-02 04:49 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-12-27 08:27 . 2009-04-05 05:38 -------- d-----w- c:\program files\DivX
2009-12-27 08:26 . 2009-12-27 08:26 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-12-22 04:58 . 2009-12-21 03:25 -------- d-----w- c:\program files\7-Zip
2009-12-21 19:14 . 2004-08-04 07:56 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-16 22:42 . 2009-12-31 02:40 872960 ----a-w- c:\documents and settings\Major Castleberry\Application Data\Mozilla\Firefox\Profiles\xans4jht.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 22:42 . 2009-12-31 02:40 43008 ----a-w- c:\documents and settings\Major Castleberry\Application Data\Mozilla\Firefox\Profiles\xans4jht.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 22:42 . 2009-12-31 02:40 340480 ----a-w- c:\documents and settings\Major Castleberry\Application Data\Mozilla\Firefox\Profiles\xans4jht.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 22:41 . 2009-12-31 02:40 346624 ----a-w- c:\documents and settings\Major Castleberry\Application Data\Mozilla\Firefox\Profiles\xans4jht.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-07 18:04 . 2009-12-07 18:04 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
.
CODE
<pre>
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Adobe\Updater6\adobe_updater .exe
c:\program files\Common Files\Microsoft Shared\DW\dwtrig20 .exe
c:\program files\Common Files\Nero\Lib\nerocheck .exe
c:\program files\Curse\curseclient .exe
c:\program files\Google\Google Updater\googleupdater .exe
c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Microsoft Security Essentials\msseces .exe
c:\program files\Nero\Nero8\Nero BackItUp\nbkeyscan .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Spybot - Search & Destroy\teatimer .exe
c:\program files\Unlocker\unlockerassistant .exe
c:\windows\pchealth\helpctr\binaries\msconfig .exe
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 10:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AntiVirus Plus.lnk]
backup=c:\windows\pss\AntiVirus Plus.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Major Castleberry^Start Menu^Programs^Startup^AntiVirus Plus.lnk]
backup=c:\windows\pss\AntiVirus Plus.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Curse\\curseclient .exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Battle.net

R0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [x]
R0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys [x]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys [x]
R4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [2009-06-26 85504]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-12-17 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-12-17 74480]
S3 Envy24HFS;ICE Envy24 Family Audio Controller WDM;c:\windows\system32\drivers\Envy24HF.sys [2004-11-26 577664]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2007-12-26 272128]

.
Contents of the 'Scheduled Tasks' folder

2010-02-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-31 01:15]

2010-02-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-03 01:36]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: buy-internet-security10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Major Castleberry\Application Data\Mozilla\Firefox\Profiles\xans4jht.default\
FF - component: c:\documents and settings\Major Castleberry\Application Data\Mozilla\Firefox\Profiles\xans4jht.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

Toolbar-SITEguard - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-19 12:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2196)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-19 12:28:18 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-19 20:28

Pre-Run: 977,936,384 bytes free
Post-Run: 5,418,663,936 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 7CB7A75450EBE4671D9B73D415F83A09


#4 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:08:48 AM

Posted 21 February 2010 - 02:40 PM

Good evening. smile.gif

We'll start with the icon issue:

Right click the Desktop and select Properties.
Select the Desktop Tab.
Click the Customise Desktop... button.
Select the Web Tab.
Make sure that Lock desktop items is unchecked, unchecking it if necessary, and OK your way out of both windows.

Right click the desktop and select Arrange icons by and ensure that Lock Web Items on Desktop is unchecked, unchecking it if necessary.

Let me know if this corrects the problem.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download a copy of DDS by sUBs from one of the following locations: Link1; Link2; Link3
  • Double click the tool to run it.
  • You can read the screen that appears, or not - the tool runs anyway.
  • When the tool has finished, two Notepad windows will appear.
  • You need to save both as they will disappear when closed.
  • File > Save As... from the Toolbar will allow you to do this.
  • Copy and Paste both logs into your next reply.
  • Please check after posting that both logs are complete.

Edited by Noviciate, 21 February 2010 - 02:49 PM.

So long, and thanks for all the fish.

 

 


#5 rojam

rojam
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:48 AM

Posted 22 February 2010 - 02:36 AM

Thanks once again: 100% on point. No more strange bordering: computer appears to be completely functional. Here are the DDS and Attach Logs as requested (Attach log is attached per the instructions after the DDS tool was finished).


DDS (Ver_09-12-01.01) - NTFSx86
Run by Major Castleberry at 23:28:57.25 on Sun 02/21/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============


============== Pseudo HJT Report ===============

uLocal Page = \blank.htm
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
{d3f669eb-57ce-4f45-8fbd-e245cbb46366}
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\majorc~1\applic~1\mozilla\firefox\profiles\xans4jht.default\
FF - component: c:\documents and settings\major castleberry\application data\mozilla\firefox\profiles\xans4jht.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2010-02-19 20:05:45 0 d-sha-r- C:\cmdcons
2010-02-19 20:04:21 98816 ----a-w- c:\windows\sed.exe
2010-02-19 20:04:21 77312 ----a-w- c:\windows\MBR.exe
2010-02-19 20:04:21 261632 ----a-w- c:\windows\PEV.exe
2010-02-19 20:04:21 161792 ----a-w- c:\windows\SWREG.exe
2010-02-16 07:11:25 0 d-----w- c:\windows\Watson
2010-02-16 07:11:25 0 d-----w- c:\program files\Microsoft Games
2010-02-06 10:13:53 30784 ----a-w- c:\windows\system32\drivers\jtrdlhcp.sys
2010-02-06 09:45:50 30784 ----a-w- c:\windows\system32\drivers\czyiyrvy.sys
2010-02-06 09:30:21 30784 ----a-w- c:\windows\system32\drivers\unmyizpl.sys
2010-02-06 09:14:52 30784 ----a-w- c:\windows\system32\drivers\esvmdptu.sys
2010-02-06 09:06:16 30784 ----a-w- c:\windows\system32\drivers\bsxgulhg.sys
2010-02-02 08:34:51 0 d-----w- c:\windows\XSxS
2010-02-02 08:34:51 0 d-----w- c:\program files\Xenocode
2010-02-02 07:43:33 3153920 ----a-w- c:\documents and settings\major castleberry\secsetup.sdb
2010-02-02 02:35:19 7302 ----a-w- c:\windows\system32\rrt_vf.wav
2010-02-02 02:35:19 7148 ----a-w- c:\windows\system32\rrt_tv.wav
2010-02-02 02:35:19 6282 ----a-w- c:\windows\system32\rrt_tn.wav
2010-02-02 02:35:19 16244 ----a-w- c:\windows\system32\rrt_is.wav
2010-02-02 01:40:08 39424 ----a-w- c:\windows\system32\OLD25D.tmp
2010-01-26 05:44:14 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-26 03:54:44 1052 --sha-r- c:\documents and settings\major castleberry\ntuser.pol

==================== Find3M ====================

2010-01-14 19:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 18:28:51 27911 ----a-w- c:\windows\system32\IJ3O9R00KU.dat
2010-01-13 18:28:51 1860 ----a-w- c:\windows\system32\0SX0TUVES.dat
2009-12-29 20:24:32 1072 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-12-21 19:14:05 916480 ------w- c:\windows\system32\wininet.dll

============= FINISH: 23:29:15.93 ===============


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)


==== Disk Partitions =========================


==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

AAC Decoder
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
Age of Mythology Gold
AMD Processor Driver
ASUSUpdate
ATI - Software Uninstall Utility
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
ATI Parental Control & Encoder
AutoUpdate
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CDDRV_Installer
Curse Client
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Plus Web Player
DivX Version Checker
DriverAgent by eSupport.com
erLT
Google Toolbar for Firefox
H.264 Decoder
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
iTunes
Java™ 6 Update 11
KhalInstallWrapper
Logitech Desktop Messenger
Logitech SetPoint
Marvell Miniport Driver
McAfee Security Scan
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Office Professional Edition 2003
Microsoft Security Essentials
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
mIRC
Miro
MKV Splitter
Mozilla Firefox (3.5.8)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB954459)
Nero 8 Essentials
neroxml
NETGEAR WG111v2 wireless USB 2.0 adapter
PC Pitstop Driver Alert2 2.0.0.0
QuickTime
Realtek High Definition Audio Driver
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows XP (KB972270)
TBS WMP Plug-in
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
VC80CRTRedist - 8.0.50727.4053
Ventrilo Client
WebFldrs XP
WGT624 Configuration Wizard
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
WinRAR archiver
World of Warcraft

==== End Of File ===========================


Edited to add contents of attachment to make it easier to review - Nov.

Attached Files


Edited by Noviciate, 22 February 2010 - 03:47 PM.


#6 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:08:48 AM

Posted 22 February 2010 - 04:18 PM

Good evening. smile.gif

While Attach.txt is added as an attachment as standard, I prefer to see it on screen rather than have to download it each time if I want to review it, so I edited your previous post - it just makes it easier for me.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The main concern I have now is with some damage that has been done by an infection that CF has highlighted:

c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Adobe\Updater6\adobe_updater .exe
c:\program files\Common Files\Microsoft Shared\DW\dwtrig20 .exe
c:\program files\Common Files\Nero\Lib\nerocheck .exe
c:\program files\Curse\curseclient .exe
c:\program files\Google\Google Updater\googleupdater .exe
c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Microsoft Security Essentials\msseces .exe
c:\program files\Nero\Nero8\Nero BackItUp\nbkeyscan .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Spybot - Search & Destroy\teatimer .exe
c:\program files\Unlocker\unlockerassistant .exe
c:\windows\pchealth\helpctr\binaries\msconfig .exe


These are legitimate files that have been renamed with an extra space before the ".exe" and would have then been replaced by malicious versions. While there is no sign of the malicious files which is good, there should be legitimate registry entries that are associated with the legitimate files which aren't present and this poses a problem.

The following software has had some functionality removed because of this:

Java
Adobe Reader speed launch
QuickTime
ATI's CATALYST™ Control Center
Watson Subscriber for SENS Network Notifications from Microsoft Corporation
Nero CD writing software
Curse client
Google Updater
Google Toolbar
iTunes
Spybot - Search & Destroy
Unlocker

Microsoft Security Essentials


Your version of Java is out of date and will be updated shortly, so we can forget that one, but the rest may have reduced functionality, so you will need to reinstall any of these programs that are still present and aren't working properly.

The main worry for me is your anti-virus program, Microsoft Security Essentials, as it must be in fully working order in order to adequately protect your system. I'm not familiar with it, so i'll have to leave it to you to check that all is well, but I would be tempted to download the installation file and uninstall/reinstall it if you have any doubts, just to be on the safe side.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

One other thing that needs doing is to rename one of the files in this list as it is a system file and you may have need of it in future:

c:\windows\pchealth\helpctr\binaries\msconfig .exe

You need to right click it, select Rename and remove the space between msconfig and .exe. Please be careful to do nothing else to it as if it isn't named correctly, your system won't have access to it.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Let me know if you have any questions about any of the above before we tidy things up and you go on your way.

So long, and thanks for all the fish.

 

 


#7 rojam

rojam
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:48 AM

Posted 23 February 2010 - 03:21 PM

I went ahead down the line and renamed each of the individual .exe files: I report nothing out of the ordinary. Once again, thank you for your assistance.

#8 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:08:48 AM

Posted 24 February 2010 - 03:22 PM

Good evening. smile.gif

It isn't sufficient to simply rename the files as there should also be associated registry entries that activate the files at start-up. The one file that I listed to be renamed is a system file and should recreate the registry entry should you use msconfig, the rest are simply "dead" files without registry entries.

Apart from Java, which you can fix by updating as below, you will need to review the rest of the programs in the list in my previous post, those that you still have obviously, and see if they are still functioning correctly. Some programs have files that run on start-up to give added functionality to a program, but these aren't necessarily required and so you may not notice any difference with these options disabled.

If each of the programs works OK, then we can assume that whatever "loss" they have suffered through these files being disabled isn't an issue and there isn't any need to worry about them.

I stress that the one program that is of real concern to me is your anti-virus program as I don't know exactly what functionality it is now missing and unless it works 100%, it isn't doing the job that it was coded for.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

To update Sun Java:
  • Go here and click on the Windows XP/Vista/2000/2003 Offline link in the Windows section near the top.
  • Save the file somewhere handy and then just double click it to update your system.

Let me know how you get on.

So long, and thanks for all the fish.

 

 


#9 rojam

rojam
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:12:48 AM

Posted 26 February 2010 - 05:30 PM

Well, two concerns. One, Windows Installer will not intialize...fail. =( Also when I use facebook.com the chat feature is somewhat laggy at times and i guess its because my Java isnt updated or whatnot: it isn't a major issue but its soooooo annoying.


#10 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:08:48 AM

Posted 27 February 2010 - 06:24 PM

Good evening. smile.gif

QUOTE
One, Windows Installer will not intialize...fail. =(

Is this while attempting to update Java or another application?

So long, and thanks for all the fish.

 

 


#11 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:08:48 AM

Posted 04 March 2010 - 05:04 PM

As there has been no reply for the last five days, this thread has been locked.

So long, and thanks for all the fish.

 

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users