Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

All anti-virus software crashing


  • This topic is locked This topic is locked
66 replies to this topic

#1 Shawnito

Shawnito

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 14 February 2011 - 01:03 PM

I've had a lot of problems with malware and other things recently. The first infection was ThinkPoint and since then I haven't been able to run any security software including MBAM, SUPER anti-spyware, Avast, or even download patches from Windows. I also get a lot of google redirects. I'm running Windows Vista. Thanks so much! Here is the DDS log:

DDS (Ver_10-12-12.02) - NTFSx86
Run by Shawn Lynch at 12:03:49.21 on Mon 02/14/2011
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2045.944 [GMT -5:00]

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\rundll32.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\system32\STacSV.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\I8kfanGUI\I8kfanGUI.exe
C:\Program Files\Ares\Ares.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\Explorer.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Shawn Lynch\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5071006
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5071006
mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5071006
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:18810
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Ask and Record Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: Ask and Record Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [Aim6]
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [i8kfangui] c:\program files\i8kfangui\I8kfanGUI.exe /startup
uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
uRun: [ares] "c:\program files\ares\Ares.exe" -h
uRun: [Ikonecaba] rundll32.exe "c:\windows\system32\config\systemprofile\appdata\local\orveHE.dll",Startup
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [umcfsefs] c:\users\shawnl~1\appdata\local\temp\shibmurkd\hralakusika.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [Broadcom Wireless Manager UI] "c:\windows\system32\WLTRAY.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [<NO NAME>]
mRun: [dscactivate] "c:\dell\dsca.exe" 3
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] "rundll32.exe" c:\windows\system32\nvHotkey.dll,Start
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SigmatelSysTrayApp] "c:\program files\sigmatel\c-major audio\wdm\sttray.exe"
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [PhysXCoreB3GPULibrary28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingPhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [AboutBonjour] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [PhysXCookingB3GPUPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [BonjourAbout] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [PhysXCoreB3GPUDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCorePhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPUPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCorePhysXCoreB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [DynamicPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [BonjourAbout24399] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [DynamicPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [BonjourAbout17103] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour25598] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour4715] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout2554] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout8472] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour6738] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour21100] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour28498] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour5230] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour20830] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout15567] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout32557] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour2927] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour31000] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout19050] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout7603] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout21006] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour17241] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout12503] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout26584] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour11836] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour9793] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout10506] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout29832] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout16339] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout10382] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour18222] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour7666] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour15145] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout2264] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour17207] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour28130] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour3205] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout25790] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout30883] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout22869] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout24120] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour28099] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour7809] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout11026] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour9388] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour20747] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout19463] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour29743] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour24287] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour22133] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout20641] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour22233] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout17945] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout5105] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout3161] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour23201] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour22604] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout30954] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour15941] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout24729] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour14063] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout20093] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour20526] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour24696] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour2497] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour18275] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout18442] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout10630] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour6586] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout850] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout32252] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour22316] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout9133] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout1849] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour20838] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout3845] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour7030] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout24956] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout29666] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour29397] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour17245] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour12344] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout5423] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout26830] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout20050] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour11471] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour24597] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout30472] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour19149] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout26866] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout6204] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout19141] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour21735] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour30825] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour26020] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout31736] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour21894] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour28230] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout31623] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout19647] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout21738] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour9963] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout12808] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour8827] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour22675] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout19606] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout22760] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour25496] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour2305] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout31127] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout6440] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour25544] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour29598] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout18809] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour30323] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout26226] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour26124] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour15467] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout10876] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour7184] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout27959] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour27931] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout11231] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout9772] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout27883] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout20359] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour16778] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour15707] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour14712] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout21426] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout25502] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour14779] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour32306] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour6164] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour18043] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout3903] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout5475] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout23714] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout27940] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour27491] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour15017] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour1882] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout17059] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout19387] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour25441] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout18460] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout5354] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour25390] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour28316] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout2118] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour31643] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout7639] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout30533] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour4282] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout22033] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout7026] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout21089] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour25198] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout17621] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout22050] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout1842] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout11506] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout7810] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour26837] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout15804] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout20282] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [BonjourAbout32232] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [AboutBonjour12382] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [PhysXCoreB3GPUPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [AboutBonjour3430] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRun: [LinkPhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LinkPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreLibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LinkDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPUPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [DynamicPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [DynamicLibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCorePhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [NxCookingPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [NxCookingPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPULibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LinkLibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPUNxCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPUPhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LinkNxCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LibraryLink] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCorePhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPUDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LibraryPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPULink28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCorePhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreNxCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LinkPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCorePhysXCookingB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPULink] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPULibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LibraryDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreLibrary28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [NxCookingLibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LinkPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPUPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreLink] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LibraryPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [NxCookingPhysXCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [DynamicPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPUPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPUPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPUPhysXCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [LibraryPhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPULink28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCoreB3GPUPhysXCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPUNxCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [PhysXCookingB3GPUPhysXCoreB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRun: [CardBusiness292] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRun: [CardBusiness6422] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRun: [BusinessCard] c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe
mRun: [CardBusiness] c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe
mRun: [QuickTimeQuickTimeResources] c:\program files\quicktime\qtsystem\quicktimempeg4.resources\nb.lproj\quicktimequicktimeresources.exe
mRun: [SVGRSRCAdobe] c:\program files\adobe\reader 8.0\reader\plug_ins\imageviewer\en_us\viewersvgrsrc.exe
mRun: [QuickTimeResourcesQuickTime7.6.6] c:\program files\quicktime\qtsystem\quicktimempeg4.resources\nb.lproj\quicktimequicktimeresources.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Ejupayi] rundll32.exe "c:\users\shawn lynch\appdata\local\ozimejes.dll",Startup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunServices: [setup] c:\windows\temp\skaq.tmp\setup.exe
mRunServices: [BonjourAbout] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [PhysXCoreDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [ContentDATsae0965a7157cd26962] "c:\windows\temp\0.6315935161332374.exe"
mRunServices: [ContentCLTzan1.0.107] "c:\windows\temp\0.6315935161332374.exe"
mRunServices: [AboutBonjour] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [ScannerCLTzan] c:\windows\temp\0.6315935161332374.exe
mRunServices: [PhysXCookingB3GPUPhysXCookingB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPULibrary28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPUPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreLibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCorePhysXCookingB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LibraryPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [DynamicNxCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LinkPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [AboutBonjour21138] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour19539] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour9834] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour14984] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout16321] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout18038] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout20415] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour17584] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout1334] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout26611] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout13377] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout21693] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout21768] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout10635] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour8627] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout31547] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout31920] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout32125] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour11698] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour16769] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30397] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour28049] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour4047] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour11684] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour22197] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout18175] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour29465] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout26727] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour3426] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour11504] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout1707] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour5513] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22974] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour5137] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout28082] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout14907] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout29182] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour24696] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour7688] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22015] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout11080] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour8421] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout23572] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour10313] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout11026] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour9388] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour29935] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout19109] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour27376] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout8644] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour1052] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout5842] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour5881] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout20170] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout10688] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22599] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout13361] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22642] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout5472] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout25342] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour22490] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout6430] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour14458] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout5433] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout7727] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour28798] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour10489] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour13613] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour11011] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout7629] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout15199] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout8764] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30837] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout12082] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour20939] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30080] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour27116] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout12809] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout21823] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout1701] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour32297] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour5778] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour7178] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout13362] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30713] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout17148] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout32661] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour21119] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout3477] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour7205] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour1627] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour4958] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour4030] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour26913] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout32749] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout3561] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout1993] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22501] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour57] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout25188] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour19602] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour20401] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour2463] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout21948] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour2541] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour18600] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour6968] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout20802] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout20631] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout30876] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22372] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour19647] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour12413] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout4413] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30628] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout3749] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout24621] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour5340] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour21379] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout29578] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout25684] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout31094] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour4221] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22092] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout26324] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour4986] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout45] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour6094] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour20978] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout15918] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout8091] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour13506] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30261] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour24828] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour23] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour14749] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour29662] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour6257] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout30880] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout9067] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout28192] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout13188] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour31600] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout18390] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour610] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour7298] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30588] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour567] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour4772] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour6762] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout22712] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout31295] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour9563] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour30090] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout26058] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour9487] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour3959] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout12032] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour15925] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout1951] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [BonjourAbout12059] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour22090] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour26671] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour9929] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour13589] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour28198] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [AboutBonjour11942] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [PhysXCoreB3GPUPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [AboutBonjour4664] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [NxCookingPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [DynamicPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPUDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [BonjourAbout27350] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [PhysXCorePhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [AboutBonjour6483] "c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe"
mRunServices: [PhysXCookingB3GPULink] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPUPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUPhysXCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LibraryPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCorePhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LibraryPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUPhysXCore] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [DynamicPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPUNxCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingLibrary28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LibraryDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreLink] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [DynamicPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [DynamicLibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LibraryPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPULibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LinkDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [DynamicLibrary28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreNxCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCorePhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingDynamic28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingPhysXCoreB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LinkPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPUPhysXCoreB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUNxCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LibraryNxCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPUPhysXCookingB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [NxCookingPhysXCookingB3GPU] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LinkPhysXCookingB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCorePhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LibraryPhysXCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LinkPhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUPhysXCoreB3GPU28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUDynamic] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingLibrary] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCookingB3GPUPhysXCore28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [LinkPhysXCooking] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [PhysXCoreB3GPUNxCooking28111] "c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe"
mRunServices: [CardBusiness4827] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRunServices: [CardBusiness19264] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRunServices: [BusinessCard16944] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRunServices: [CardBusiness18756] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRunServices: [CardBusiness19668] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRunServices: [CardBusiness9374] "c:\program files\adobe\adobe illustrator cs3\cool extras\templates\inspiration\spa\businesscard5432.exe"
mRunServices: [ViewerAdobe] c:\program files\adobe\reader 8.0\reader\plug_ins\imageviewer\en_us\viewersvgrsrc.exe
mRunServices: [UpdatetSoftware] c:\program files\apple software update\softwareupdate.resources\updatetsoftware.exe
mRunServices: [SoftwareUpdatet] c:\program files\apple software update\softwareupdate.resources\updatetsoftware.exe
mRunServices: [SplitterSplitter] c:\program files\altomp3 gold\filters\mpadecfiltersplitter1002.exe
mRunServices: [QuickTimeQuickTimeResources] c:\program files\quicktime\qtsystem\quicktime3gpp.resources\fr.lproj\quicktimeresourcesquicktimeresources.exe
mRunServices: [QuickTimeResourcesQuickTimeResources] c:\program files\quicktime\qtsystem\quicktimestreamingextras.resources\pt_pt.lproj\quicktimequicktimeresources7.6.6.exe
mRunServices: [MSVCP71Studio7.10.3052.4] c:\program files\common files\roxio shared\9.0\roxio central33\engine\visualvisual7.10.3077.0.exe
mRunServices: [StudioMFC90U] c:\program files\hp\digital imaging\{9fef1a18-8f26-4f49-a5a4-956c12210624}\setup\networkx86\mfc90visual.exe
mRunServices: [ANPAColor] c:\program files\common files\adobe\adobe asset services cs3\presets\color books\ColorANPA.exe
dRun: [Ikonecaba] rundll32.exe "c:\windows\system32\config\systemprofile\appdata\local\orveHE.dll",Startup
StartupFolder: c:\users\shawnl~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\websho~1.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\users\shawnl~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Webshots Photo Search - c:\program files\webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
LSP: mswsock.dll
DPF: {00000161-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/C/A/7/CA7D2024-EA89-4F15-908C-DA65C1666614/msaud.CAB
DPF: {00000162-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/B/B/0BB06A5C-8611-4840-86B3-54DDDD0344B9/wma9dmo.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\shawnl~1\appdata\roaming\mozilla\firefox\profiles\qhub9v8c.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

============= SERVICES / DRIVERS ===============

R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [2009-10-22 14464]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-10-21 21504]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2007-10-23 104000]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-10-25 24652]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2009-10-21 16896]
RUnknown aswFsBlk;aswFsBlk; [x]
RUnknown aswMonFlt;aswMonFlt; [x]
RUnknown aswSP;aswSP; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-28 136176]
S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\drivers\WSDScan.sys [2009-10-21 19968]

=============== Created Last 30 ================

2011-02-14 15:16:50 3061 ----a-w- c:\users\shawnl~1\appdata\local\irapiyij.dll
2011-02-14 14:27:02 -------- d-----w- c:\program files\Avira
2011-02-14 14:00:39 -------- d-----w- c:\progra~2\Alwil Software
2011-02-14 13:41:44 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-14 13:41:40 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-14 02:56:09 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2011-02-14 02:51:46 -------- d-----w- c:\program files\Panda Security
2011-02-14 02:48:48 -------- d-----w- c:\program files\ESET
2011-02-14 02:42:46 3061 ----a-w- c:\users\shawnl~1\appdata\local\asacofirujiqigis.dll
2011-02-14 02:27:11 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-02-13 23:49:41 1865 ----a-w- c:\users\shawnl~1\appdata\local\acocadisayiko.dll
2011-02-13 23:25:14 1865 ----a-w- c:\users\shawnl~1\appdata\local\ewikijad.dll
2011-02-13 21:23:14 1865 ----a-w- c:\users\shawnl~1\appdata\local\abiribec.dll
2011-02-13 19:21:14 1865 ----a-w- c:\users\shawnl~1\appdata\local\abifohahuroz.dll
2011-02-13 17:19:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\ucezazohecewewec.dll
2011-02-13 15:17:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\owasabejuko.dll
2011-02-13 13:15:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\idebuvogepuwido.dll
2011-02-13 11:13:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\agemolim.dll
2011-02-13 09:12:17 1955 ----a-w- c:\users\shawnl~1\appdata\local\uhagonaman.dll
2011-02-13 07:09:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\ejupadew.dll
2011-02-13 05:07:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\oducosuw.dll
2011-02-13 03:05:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\eqaqaxuwi.dll
2011-02-13 01:03:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\aruvoxad.dll
2011-02-12 23:01:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\opukehadehipenox.dll
2011-02-12 20:59:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\ajoxirakipe.dll
2011-02-12 18:57:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\adepober.dll
2011-02-12 16:55:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\oxowoqanedevac.dll
2011-02-12 14:54:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\ocolulineteriw.dll
2011-02-12 12:51:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\inivemit.dll
2011-02-12 10:49:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\uwemodetakobi.dll
2011-02-12 08:47:21 1865 ----a-w- c:\users\shawnl~1\appdata\local\ecabozey.dll
2011-02-12 06:47:24 1955 ----a-w- c:\users\shawnl~1\appdata\local\oyiseciy.dll
2011-02-12 04:43:21 1865 ----a-w- c:\users\shawnl~1\appdata\local\atofujufuxuzedes.dll
2011-02-12 02:41:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\eqizetifigoreyes.dll
2011-02-12 00:39:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\otewovox.dll
2011-02-11 22:37:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\ugutezivanomozo.dll
2011-02-11 20:35:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\ahenocopolo.dll
2011-02-11 18:33:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\inesedox.dll
2011-02-11 16:31:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\ubutesuxidigib.dll
2011-02-11 16:20:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\utufeboco.dll
2011-02-11 14:18:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\oraquwej.dll
2011-02-11 12:16:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\azoqopac.dll
2011-02-11 10:14:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\uqorukem.dll
2011-02-11 08:12:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\ineyesubaseb.dll
2011-02-11 06:10:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\iyaleqayisa.dll
2011-02-11 04:08:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\unejiqigisohunir.dll
2011-02-11 02:06:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\obofinosobuz.dll
2011-02-11 00:04:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\utefazemi.dll
2011-02-10 22:02:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\uzulefariza.dll
2011-02-10 20:00:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\esoyevevamiwokoj.dll
2011-02-10 17:58:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\ojanisix.dll
2011-02-10 15:56:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\ituhujoj.dll
2011-02-10 13:54:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\oxacadicuvuhox.dll
2011-02-10 11:52:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\oliquyicub.dll
2011-02-10 09:50:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\abenejecux.dll
2011-02-10 07:48:21 1865 ----a-w- c:\users\shawnl~1\appdata\local\uwogolog.dll
2011-02-10 05:46:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\osowonezon.dll
2011-02-10 03:44:21 1865 ----a-w- c:\users\shawnl~1\appdata\local\obutivumejabi.dll
2011-02-10 01:42:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\akubosuy.dll
2011-02-09 23:40:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\ifehuyuruwok.dll
2011-02-09 21:38:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\umeceweweciq.dll
2011-02-09 19:36:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\ibijesaz.dll
2011-02-09 17:34:24 1865 ----a-w- c:\users\shawnl~1\appdata\local\obepokid.dll
2011-02-09 16:09:54 1955 ----a-w- c:\users\shawnl~1\appdata\local\ojajaxesa.dll
2011-02-09 14:06:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\uhejanoxoz.dll
2011-02-09 12:04:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\aqucavalegacu.dll
2011-02-09 10:02:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\adotogolo.dll
2011-02-09 08:00:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\ofakobiloba.dll
2011-02-09 05:58:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\unakoroxaziv.dll
2011-02-09 03:57:32 1865 ----a-w- c:\users\shawnl~1\appdata\local\ahixiyalogujage.dll
2011-02-09 01:54:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\owoxekocubu.dll
2011-02-08 23:53:57 1955 ----a-w- c:\users\shawnl~1\appdata\local\erosovun.dll
2011-02-08 21:50:56 1907 ----a-w- c:\users\shawnl~1\appdata\local\ubusohahoz.dll
2011-02-08 19:48:56 1907 ----a-w- c:\users\shawnl~1\appdata\local\ewiwoluwar.dll
2011-02-08 17:46:56 1907 ----a-w- c:\users\shawnl~1\appdata\local\esetamagabobi.dll
2011-02-08 15:44:57 1907 ----a-w- c:\users\shawnl~1\appdata\local\ugahaqitejigucin.dll
2011-02-08 13:42:57 1907 ----a-w- c:\users\shawnl~1\appdata\local\oriyosamavabowin.dll
2011-02-08 05:28:59 1907 ----a-w- c:\users\shawnl~1\appdata\local\ulowupomukimu.dll
2011-02-08 03:26:59 1907 ----a-w- c:\users\shawnl~1\appdata\local\eviyozewahatewis.dll
2011-02-08 01:24:59 1907 ----a-w- c:\users\shawnl~1\appdata\local\anezinufewor.dll
2011-02-07 23:22:31 1907 ----a-w- c:\users\shawnl~1\appdata\local\oyijiwawanub.dll
2011-02-07 21:20:31 1907 ----a-w- c:\users\shawnl~1\appdata\local\aleciyozoxujesa.dll
2011-02-07 19:18:34 1907 ----a-w- c:\users\shawnl~1\appdata\local\ijidukeq.dll
2011-02-07 17:18:35 1955 ----a-w- c:\users\shawnl~1\appdata\local\iqubisovuniwula.dll
2011-02-07 15:14:32 1907 ----a-w- c:\users\shawnl~1\appdata\local\oxeyujupili.dll
2011-02-07 13:12:33 1907 ----a-w- c:\users\shawnl~1\appdata\local\okatadoqev.dll
2011-02-07 11:10:33 1907 ----a-w- c:\users\shawnl~1\appdata\local\iwajasuq.dll
2011-02-07 09:08:33 1907 ----a-w- c:\users\shawnl~1\appdata\local\upehaxiq.dll
2011-02-07 07:06:33 1907 ----a-w- c:\users\shawnl~1\appdata\local\agepofuy.dll
2011-02-07 05:04:34 1907 ----a-w- c:\users\shawnl~1\appdata\local\efikohiyi.dll
2011-02-07 03:02:34 1907 ----a-w- c:\users\shawnl~1\appdata\local\esoferabatid.dll
2011-02-07 01:00:35 1907 ----a-w- c:\users\shawnl~1\appdata\local\ibovawub.dll
2011-02-06 22:58:35 1907 ----a-w- c:\users\shawnl~1\appdata\local\osuwidumuhi.dll
2011-02-06 20:56:35 1907 ----a-w- c:\users\shawnl~1\appdata\local\eveleluf.dll
2011-02-06 18:54:36 1907 ----a-w- c:\users\shawnl~1\appdata\local\opewowowo.dll
2011-02-06 16:52:36 1907 ----a-w- c:\users\shawnl~1\appdata\local\ujobidov.dll
2011-02-06 14:50:37 1907 ----a-w- c:\users\shawnl~1\appdata\local\ebesiyov.dll
2011-02-06 12:48:37 1907 ----a-w- c:\users\shawnl~1\appdata\local\avugeyajo.dll
2011-02-06 10:46:37 1907 ----a-w- c:\users\shawnl~1\appdata\local\ugubupic.dll
2011-02-06 08:44:38 1907 ----a-w- c:\users\shawnl~1\appdata\local\enicagayusaq.dll
2011-02-06 06:42:38 1907 ----a-w- c:\users\shawnl~1\appdata\local\ikuqirac.dll
2011-02-06 04:42:43 1895 ----a-w- c:\users\shawnl~1\appdata\local\ozedowubucu.dll
2011-02-06 02:38:39 1907 ----a-w- c:\users\shawnl~1\appdata\local\oyixaqab.dll
2011-02-06 00:36:39 1907 ----a-w- c:\users\shawnl~1\appdata\local\igikojeg.dll
2011-02-05 22:34:40 1907 ----a-w- c:\users\shawnl~1\appdata\local\ujodomig.dll
2011-02-05 20:32:40 1907 ----a-w- c:\users\shawnl~1\appdata\local\olinaner.dll
2011-02-05 18:30:40 1907 ----a-w- c:\users\shawnl~1\appdata\local\otazuzes.dll
2011-02-05 16:28:41 1907 ----a-w- c:\users\shawnl~1\appdata\local\okoqenez.dll
2011-02-05 14:26:41 1907 ----a-w- c:\users\shawnl~1\appdata\local\inexaxed.dll
2011-02-05 12:24:41 1907 ----a-w- c:\users\shawnl~1\appdata\local\ewivomad.dll
2011-02-05 10:22:42 1907 ----a-w- c:\users\shawnl~1\appdata\local\ojoduqiruhakucad.dll
2011-02-05 08:20:42 1907 ----a-w- c:\users\shawnl~1\appdata\local\iyisuzupijaf.dll
2011-02-05 06:18:45 1907 ----a-w- c:\users\shawnl~1\appdata\local\utazubij.dll
2011-02-05 04:16:43 1907 ----a-w- c:\users\shawnl~1\appdata\local\ozerudan.dll
2011-02-05 02:14:43 1907 ----a-w- c:\users\shawnl~1\appdata\local\otolasejadazayu.dll
2011-02-05 00:12:44 1907 ----a-w- c:\users\shawnl~1\appdata\local\oyayejamiyumih.dll
2011-02-04 22:11:45 1955 ----a-w- c:\users\shawnl~1\appdata\local\ecomifetelaguz.dll
2011-02-04 20:08:44 1865 ----a-w- c:\users\shawnl~1\appdata\local\irabogiseyite.dll
2011-02-04 18:06:45 1865 ----a-w- c:\users\shawnl~1\appdata\local\ekohuxewo.dll
2011-02-04 16:04:45 1865 ----a-w- c:\users\shawnl~1\appdata\local\usaquwezanon.dll
2011-02-04 14:02:45 1865 ----a-w- c:\users\shawnl~1\appdata\local\ugihasafoxoqoya.dll
2011-02-04 12:00:46 1865 ----a-w- c:\users\shawnl~1\appdata\local\icapizulufuj.dll
2011-02-04 09:58:46 1865 ----a-w- c:\users\shawnl~1\appdata\local\oxekucadicuv.dll
2011-02-04 07:56:46 1865 ----a-w- c:\users\shawnl~1\appdata\local\afadewilulok.dll
2011-02-04 05:54:47 1865 ----a-w- c:\users\shawnl~1\appdata\local\iwofugahopi.dll
2011-02-04 03:52:47 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovuzukohomaloka.dll
2011-02-04 01:50:48 1865 ----a-w- c:\users\shawnl~1\appdata\local\exalofej.dll
2011-02-03 23:48:48 1865 ----a-w- c:\users\shawnl~1\appdata\local\uhiwisucejal.dll
2011-02-03 21:46:48 1865 ----a-w- c:\users\shawnl~1\appdata\local\etatexete.dll
2011-02-03 19:44:48 1865 ----a-w- c:\users\shawnl~1\appdata\local\ejugumam.dll
2011-02-03 17:42:49 1865 ----a-w- c:\users\shawnl~1\appdata\local\ejuyuqiyukeb.dll
2011-02-03 15:40:50 1865 ----a-w- c:\users\shawnl~1\appdata\local\urohohewazucocal.dll
2011-02-03 13:39:14 1865 ----a-w- c:\users\shawnl~1\appdata\local\uwoqikuw.dll
2011-02-03 02:23:38 1865 ----a-w- c:\users\shawnl~1\appdata\local\imekujik.dll
2011-02-03 00:21:39 1865 ----a-w- c:\users\shawnl~1\appdata\local\otaxiwuv.dll
2011-02-02 22:19:39 1865 ----a-w- c:\users\shawnl~1\appdata\local\egaruyaxubexu.dll
2011-02-02 20:17:40 1865 ----a-w- c:\users\shawnl~1\appdata\local\ibosonoc.dll
2011-02-02 18:15:40 1865 ----a-w- c:\users\shawnl~1\appdata\local\ogusiboqu.dll
2011-02-02 16:13:40 1865 ----a-w- c:\users\shawnl~1\appdata\local\oguzoheceweweciq.dll
2011-02-02 14:11:41 1865 ----a-w- c:\users\shawnl~1\appdata\local\unuyanami.dll
2011-02-02 12:09:40 1865 ----a-w- c:\users\shawnl~1\appdata\local\ivabufisawanulam.dll
2011-02-02 10:07:40 1865 ----a-w- c:\users\shawnl~1\appdata\local\evuseyitegigu.dll
2011-02-02 08:07:42 1955 ----a-w- c:\users\shawnl~1\appdata\local\uzalusefubemobel.dll
2011-02-02 06:03:38 1865 ----a-w- c:\users\shawnl~1\appdata\local\uvasokar.dll
2011-02-02 04:01:38 1865 ----a-w- c:\users\shawnl~1\appdata\local\ikifowasila.dll
2011-02-02 01:59:37 1865 ----a-w- c:\users\shawnl~1\appdata\local\usunawoz.dll
2011-02-01 23:57:36 1865 ----a-w- c:\users\shawnl~1\appdata\local\olaxuxuvijuki.dll
2011-02-01 21:55:37 1865 ----a-w- c:\users\shawnl~1\appdata\local\usivimup.dll
2011-02-01 17:49:37 1865 ----a-w- c:\users\shawnl~1\appdata\local\azahowilojihu.dll
2011-02-01 15:48:38 1955 ----a-w- c:\users\shawnl~1\appdata\local\azucujoful.dll
2011-02-01 13:45:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\icoquxuzayahejo.dll
2011-02-01 13:42:07 77912 ----a-w- c:\windows\system32\drivers\klmdb.sys
2011-02-01 03:52:50 1865 ----a-w- c:\users\shawnl~1\appdata\local\eqiharuc.dll
2011-02-01 01:50:50 1865 ----a-w- c:\users\shawnl~1\appdata\local\uminifijore.dll
2011-01-31 23:48:50 1865 ----a-w- c:\users\shawnl~1\appdata\local\obucegaq.dll
2011-01-31 21:46:05 1865 ----a-w- c:\users\shawnl~1\appdata\local\eparigapuqazef.dll
2011-01-31 19:44:05 1865 ----a-w- c:\users\shawnl~1\appdata\local\asuseveg.dll
2011-01-31 17:42:04 1865 ----a-w- c:\users\shawnl~1\appdata\local\olukomemap.dll
2011-01-31 15:40:03 1865 ----a-w- c:\users\shawnl~1\appdata\local\axedahigusu.dll
2011-01-31 13:38:03 1865 ----a-w- c:\users\shawnl~1\appdata\local\ozinonulurupohof.dll
2011-01-31 11:36:03 1865 ----a-w- c:\users\shawnl~1\appdata\local\uxececisuwaq.dll
2011-01-31 09:35:05 1865 ----a-w- c:\users\shawnl~1\appdata\local\ideqivuxe.dll
2011-01-31 07:32:01 1865 ----a-w- c:\users\shawnl~1\appdata\local\amemafuxu.dll
2011-01-31 05:30:01 1865 ----a-w- c:\users\shawnl~1\appdata\local\ejigesavad.dll
2011-01-31 03:28:01 1865 ----a-w- c:\users\shawnl~1\appdata\local\ipixowalif.dll
2011-01-31 01:26:00 1865 ----a-w- c:\users\shawnl~1\appdata\local\ezedoxira.dll
2011-01-30 23:24:00 1865 ----a-w- c:\users\shawnl~1\appdata\local\owacelot.dll
2011-01-30 21:21:59 1865 ----a-w- c:\users\shawnl~1\appdata\local\uqifiboq.dll
2011-01-30 19:19:58 1865 ----a-w- c:\users\shawnl~1\appdata\local\ulejunehohiceki.dll
2011-01-30 17:17:58 1865 ----a-w- c:\users\shawnl~1\appdata\local\unikafomo.dll
2011-01-30 15:15:57 1865 ----a-w- c:\users\shawnl~1\appdata\local\uyiqiyonoxuxab.dll
2011-01-30 13:13:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\aqesodamape.dll
2011-01-30 11:11:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\ucomuligizoyowoh.dll
2011-01-30 09:09:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\ufalogiwabafitiz.dll
2011-01-30 07:07:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\exoweyifeg.dll
2011-01-30 05:05:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\asofacosa.dll
2011-01-30 03:03:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\elegifopaniya.dll
2011-01-30 01:01:57 1865 ----a-w- c:\users\shawnl~1\appdata\local\oyeyonox.dll
2011-01-29 22:59:57 1865 ----a-w- c:\users\shawnl~1\appdata\local\evopeter.dll
2011-01-29 20:57:57 1865 ----a-w- c:\users\shawnl~1\appdata\local\aqonerokowucafo.dll
2011-01-29 18:55:57 1865 ----a-w- c:\users\shawnl~1\appdata\local\oxihucucaqiqeje.dll
2011-01-29 16:53:57 1865 ----a-w- c:\users\shawnl~1\appdata\local\ediyepeteroq.dll
2011-01-29 14:51:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\inamuwes.dll
2011-01-29 12:49:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\uwalozugecava.dll
2011-01-29 10:47:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\atamogoyi.dll
2011-01-29 08:45:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\icomijigoki.dll
2011-01-29 06:43:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\uhahohil.dll
2011-01-29 04:42:55 1955 ----a-w- c:\users\shawnl~1\appdata\local\edeqeqalux.dll
2011-01-29 02:39:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\udezodulipor.dll
2011-01-29 00:37:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\umubazukohoma.dll
2011-01-28 22:35:52 1865 ----a-w- c:\users\shawnl~1\appdata\local\iwusitadux.dll
2011-01-28 20:33:52 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovuyovupomub.dll
2011-01-28 18:31:51 1865 ----a-w- c:\users\shawnl~1\appdata\local\evatuzar.dll
2011-01-28 16:29:51 1865 ----a-w- c:\users\shawnl~1\appdata\local\oxoqiyuk.dll
2011-01-28 14:28:49 1865 ----a-w- c:\users\shawnl~1\appdata\local\alonoxok.dll
2011-01-28 10:21:51 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovobehavaqegayux.dll
2011-01-28 08:19:52 1865 ----a-w- c:\users\shawnl~1\appdata\local\amehavaqegayux.dll
2011-01-28 06:17:50 1865 ----a-w- c:\users\shawnl~1\appdata\local\erotekudat.dll
2011-01-28 04:15:50 1865 ----a-w- c:\users\shawnl~1\appdata\local\ihorayap.dll
2011-01-28 02:13:49 1865 ----a-w- c:\users\shawnl~1\appdata\local\agisaxupeto.dll
2011-01-28 00:11:49 1865 ----a-w- c:\users\shawnl~1\appdata\local\onufatahixoweto.dll
2011-01-27 22:10:51 1955 ----a-w- c:\users\shawnl~1\appdata\local\omemohagiqinic.dll
2011-01-27 20:07:50 1907 ----a-w- c:\users\shawnl~1\appdata\local\eqegovag.dll
2011-01-27 18:05:50 1907 ----a-w- c:\users\shawnl~1\appdata\local\ilisabamo.dll
2011-01-27 16:04:56 1955 ----a-w- c:\users\shawnl~1\appdata\local\aqowufilelufiwu.dll
2011-01-27 03:09:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\oroyoqanejob.dll
2011-01-27 01:07:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\owitelag.dll
2011-01-26 23:05:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\ilinubesida.dll
2011-01-26 21:03:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\exihudusibo.dll
2011-01-26 19:01:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\unonikaz.dll
2011-01-26 16:59:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\enixojuxap.dll
2011-01-26 14:57:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\aqapufaxawiroz.dll
2011-01-26 06:44:58 1955 ----a-w- c:\users\shawnl~1\appdata\local\eduvanoqiqurih.dll
2011-01-26 04:41:58 1865 ----a-w- c:\users\shawnl~1\appdata\local\alokaxodemadav.dll
2011-01-26 02:39:58 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovojigokimaki.dll
2011-01-26 00:37:59 1865 ----a-w- c:\users\shawnl~1\appdata\local\ojefixipu.dll
2011-01-25 22:35:59 1865 ----a-w- c:\users\shawnl~1\appdata\local\oqorowij.dll
2011-01-25 20:35:00 1955 ----a-w- c:\users\shawnl~1\appdata\local\etiletunuxafujah.dll
2011-01-25 18:32:00 1865 ----a-w- c:\users\shawnl~1\appdata\local\enobizag.dll
2011-01-25 16:32:03 1955 ----a-w- c:\users\shawnl~1\appdata\local\iyamiwumezimimi.dll
2011-01-25 14:29:02 1955 ----a-w- c:\users\shawnl~1\appdata\local\ajagidimeqaguvi.dll
2011-01-25 12:27:03 1955 ----a-w- c:\users\shawnl~1\appdata\local\owesazuyufomor.dll
2011-01-25 10:24:01 1865 ----a-w- c:\users\shawnl~1\appdata\local\uyekijirazohit.dll
2011-01-25 08:22:01 1865 ----a-w- c:\users\shawnl~1\appdata\local\uhojopev.dll
2011-01-25 06:21:03 1955 ----a-w- c:\users\shawnl~1\appdata\local\ejohegoz.dll
2011-01-25 04:18:02 1865 ----a-w- c:\users\shawnl~1\appdata\local\obeyudikugomuk.dll
2011-01-25 02:16:04 1865 ----a-w- c:\users\shawnl~1\appdata\local\aliwokoj.dll
2011-01-25 00:14:06 1865 ----a-w- c:\users\shawnl~1\appdata\local\ujeyuhaxovab.dll
2011-01-24 22:11:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\anuyepeteroqaxac.dll
2011-01-24 20:09:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\ivonilecola.dll
2011-01-24 18:07:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\imuhunic.dll
2011-01-24 16:07:22 1955 ----a-w- c:\users\shawnl~1\appdata\local\usavadebiberer.dll
2011-01-24 14:03:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\enepiwam.dll
2011-01-24 12:01:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovakutegefixi.dll
2011-01-24 10:00:21 1955 ----a-w- c:\users\shawnl~1\appdata\local\ibisadiy.dll
2011-01-24 07:57:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\ezehasafoxoqoya.dll
2011-01-24 05:55:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\ikutamux.dll
2011-01-24 03:53:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\agacolal.dll
2011-01-24 01:52:15 1955 ----a-w- c:\users\shawnl~1\appdata\local\ocixebuxe.dll
2011-01-23 23:49:14 1865 ----a-w- c:\users\shawnl~1\appdata\local\uxupadaxu.dll
2011-01-23 21:47:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\ufokisoxebuxe.dll
2011-01-23 19:45:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\ocesaneyulexaheq.dll
2011-01-23 17:43:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\akafofoc.dll
2011-01-23 15:41:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\axorogeh.dll
2011-01-23 13:39:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\orilokahubo.dll
2011-01-23 11:37:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\udesawanulamol.dll
2011-01-23 09:35:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\aqutaqunuhogaj.dll
2011-01-23 07:33:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\okizelagarobif.dll
2011-01-23 05:32:19 1955 ----a-w- c:\users\shawnl~1\appdata\local\uxupabus.dll
2011-01-23 03:29:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\onilidarexowex.dll
2011-01-23 01:27:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovunuveruqapiwes.dll
2011-01-22 23:25:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\uvikamodetakobi.dll
2011-01-22 21:23:19 1865 ----a-w- c:\users\shawnl~1\appdata\local\ijodapeqikodado.dll
2011-01-22 19:21:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovajagedeyo.dll
2011-01-22 17:19:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\uyoseqov.dll
2011-01-22 15:17:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\ujupuficuzuhi.dll
2011-01-21 18:39:09 1865 ----a-w- c:\users\shawnl~1\appdata\local\ahuvalegacude.dll
2011-01-21 16:37:09 1865 ----a-w- c:\users\shawnl~1\appdata\local\oqokanug.dll
2011-01-21 14:35:09 1865 ----a-w- c:\users\shawnl~1\appdata\local\apulodas.dll
2011-01-21 06:21:11 1865 ----a-w- c:\users\shawnl~1\appdata\local\igodejemilape.dll
2011-01-21 04:19:11 1865 ----a-w- c:\users\shawnl~1\appdata\local\uwasurasewisu.dll
2011-01-21 02:17:12 1865 ----a-w- c:\users\shawnl~1\appdata\local\acazeyaw.dll
2011-01-21 00:15:12 1865 ----a-w- c:\users\shawnl~1\appdata\local\ediwoxewofeseduz.dll
2011-01-20 22:13:13 1865 ----a-w- c:\users\shawnl~1\appdata\local\itogepukog.dll
2011-01-20 20:11:13 1865 ----a-w- c:\users\shawnl~1\appdata\local\orunohidimenipa.dll
2011-01-20 18:09:13 1865 ----a-w- c:\users\shawnl~1\appdata\local\osobezudana.dll
2011-01-20 16:07:14 1865 ----a-w- c:\users\shawnl~1\appdata\local\ifoyumihoyopog.dll
2011-01-20 14:05:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\oduqovab.dll
2011-01-20 12:03:14 1865 ----a-w- c:\users\shawnl~1\appdata\local\udohilon.dll
2011-01-20 10:01:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\ofocijeno.dll
2011-01-20 07:59:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\efekedom.dll
2011-01-20 05:57:15 1865 ----a-w- c:\users\shawnl~1\appdata\local\ukidoyatupekamos.dll
2011-01-20 03:57:19 1955 ----a-w- c:\users\shawnl~1\appdata\local\idevucuy.dll
2011-01-20 01:53:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\onizufer.dll
2011-01-19 23:51:16 1865 ----a-w- c:\users\shawnl~1\appdata\local\ukowepew.dll
2011-01-19 21:49:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\avihoqusiwojiy.dll
2011-01-19 19:47:17 1865 ----a-w- c:\users\shawnl~1\appdata\local\avipiseriyovuzi.dll
2011-01-19 17:45:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\irolucip.dll
2011-01-19 15:43:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\oqakohodopuvonej.dll
2011-01-19 13:41:18 1865 ----a-w- c:\users\shawnl~1\appdata\local\okofipujil.dll
2011-01-19 03:23:20 1865 ----a-w- c:\users\shawnl~1\appdata\local\ezomeposucefu.dll
2011-01-19 01:21:21 1865 ----a-w- c:\users\shawnl~1\appdata\local\anirereweril.dll
2011-01-18 23:20:22 1955 ----a-w- c:\users\shawnl~1\appdata\local\ejaluwaruyum.dll
2011-01-18 21:17:21 1865 ----a-w- c:\users\shawnl~1\appdata\local\equgeqel.dll
2011-01-18 19:15:26 1865 ----a-w- c:\users\shawnl~1\appdata\local\opiciferabatid.dll
2011-01-18 17:13:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovamumokek.dll
2011-01-18 15:11:22 1865 ----a-w- c:\users\shawnl~1\appdata\local\ekonabon.dll
2011-01-18 13:09:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\oqihavonaxehi.dll
2011-01-18 11:07:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\ipicucen.dll
2011-01-18 09:05:23 1865 ----a-w- c:\users\shawnl~1\appdata\local\uzoquwej.dll
2011-01-18 07:05:27 1955 ----a-w- c:\users\shawnl~1\appdata\local\ifudegemidaribiy.dll
2011-01-18 05:01:24 1865 ----a-w- c:\users\shawnl~1\appdata\local\ovixoret.dll
2011-01-18 02:59:25 1865 ----a-w- c:\users\shawnl~1\appdata\local\odakafiyacikofe.dll
2011-01-18 00:57:25 1865 ----a-w- c:\users\shawnl~1\appdata\local\oqiwuqewidumuhi.dll
2011-01-17 22:54:57 1865 ----a-w- c:\users\shawnl~1\appdata\local\akesilarefozuzi.dll
2011-01-17 20:53:59 1955 ----a-w- c:\users\shawnl~1\appdata\local\umasivolupufaxaw.dll
2011-01-17 18:51:58 1955 ----a-w- c:\users\shawnl~1\appdata\local\ilodemadavakulej.dll
2011-01-17 16:48:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\agelaquv.dll
2011-01-17 14:47:56 1955 ----a-w- c:\users\shawnl~1\appdata\local\axanidopumamajux.dll
2011-01-17 12:44:55 1865 ----a-w- c:\users\shawnl~1\appdata\local\odotecuxisetaco.dll
2011-01-17 10:42:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\iyiwisucejalafoq.dll
2011-01-17 08:40:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\abilawetidalu.dll
2011-01-17 06:39:54 1955 ----a-w- c:\users\shawnl~1\appdata\local\emofiqejivuluy.dll
2011-01-17 04:36:52 1865 ----a-w- c:\users\shawnl~1\appdata\local\uvovofamana.dll
2011-01-17 02:36:59 1955 ----a-w- c:\users\shawnl~1\appdata\local\ovodumos.dll
2011-01-17 00:32:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\ohixovesebevax.dll
2011-01-16 22:30:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\ijazaziz.dll
2011-01-16 20:28:53 1865 ----a-w- c:\users\shawnl~1\appdata\local\akuwukaza.dll
2011-01-16 18:26:54 1865 ----a-w- c:\users\shawnl~1\appdata\local\axifaduf.dll
2011-01-16 16:25:55 1955 ----a-w- c:\users\shawnl~1\appdata\local\ifaziyemamer.dll
2011-01-16 14:22:56 1865 ----a-w- c:\users\shawnl~1\appdata\local\anuyujupiliyojo.dll
2011-01-16 13:09:06 1865 ----a-w- c:\users\shawnl~1\appdata\local\efiviqoh.dll
2011-01-16 11:07:05 1865 ----a-w- c:\users\shawnl~1\appdata\local\ohobodam.dll
2011-01-16 09:05:05 1865 ----a-w- c:\users\shawnl~1\appdata\local\ilehivafecujof.dll
2011-01-16 07:03:07 1865 ----a-w- c:\users\shawnl~1\appdata\local\urocotezivanomo.dll
2011-01-16 05:01:03 1865 ----a-w- c:\users\shawnl~1\appdata\local\equrifum.dll
2011-01-16 02:59:03 1865 ----a-w- c:\users\shawnl~1\appdata\local\agaxexiv.dll
2011-01-15 22:53:04 1865 ----a-w- c:\users\shawnl~1\appdata\local\atubaxiti.dll
2011-01-15 20:51:04 1865 ----a-w- c:\users\shawnl~1\appdata\local\upicofir.dll
2011-01-15 18:49:05 1865 ----a-w- c:\users\shawnl~1\appdata\local\inuqapiw.dll

==================== Find3M ====================

2010-12-02 03:35:18 4280320 ----a-w- c:\windows\system32\GPhotos.scr
2010-11-28 11:59:27 639488 ----a-w- c:\users\shawnl~1\appdata\roaming\hotfix.exe
2010-11-28 11:59:27 190 ----a-w- c:\users\shawnl~1\appdata\roaming\sdhkryu.bat
2006-05-03 10:06:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 11:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 13:30:52 216064 --sh--r- c:\windows\system32\nbDX.dll

============= FINISH: 12:04:30.08 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:42 AM

Posted 19 February 2011 - 11:30 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process. Please also continue to work with me until I give you the all clear. Even if your computer appears to act better, you may still be infected.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.

Once we start working together, please reply back within 3 days or this thread may be closed so we can help others who are waiting.

We need to create an OTL report,
  • Please download OTL from this link.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Under the Custom Scan box paste this in:

    netsvcs
    msconfig
    drivers32 /all
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\*.sys /90
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    CREATERESTOREPOINT

  • Click the Quick Scan button.
  • The scan should take a few minutes.
  • Please copy and paste both logs in your reply.

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice

Then create another GMER log and post it as an attachment to the reply where you post your new OTL log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


In your reply, please post both OTL logs and the GMER log.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#3 Shawnito

Shawnito
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 19 February 2011 - 10:17 PM

Unfortunately, when I download OTL, the software installs and runs correctly. But during the scan, the program crashes with no warning error. After the crash, I cannot open OTL and an error message appears stating "windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access them." This is the same problem I have with all anti-virus and anti-malware programs including MBAM, SUPER, and Avast. Thanks.

#4 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:42 AM

Posted 20 February 2011 - 11:18 AM

Hello, Shawnito.


Next, please download ComboFix from one of these locations:
* IMPORTANT !!! Save ComboFix.exe to your Desktop as etavaresCF.exe
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on etavaresCF.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply, along with any symptoms that are present after it runs.

Note: After running Combofix, you may receive an error about "illegal operation on a registry key that has been marked for deletion." If you receive this error, please reboot and it should disappear.

etavares


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#5 Shawnito

Shawnito
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 20 February 2011 - 12:39 PM

I downloaded ComboFix as etavaresCF.exe and when I run it, a small loading bar appears that says "Combofix" and when it finishes loading the program simply stops running with no error message. Subsequent attempts to run the program result in the same thing. Also, in the meantime, Apple's iTunes mobile device support has stopped working. Thanks!

#6 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:42 AM

Posted 20 February 2011 - 05:59 PM

OK, something is interfering. We'll try this two ways. First, please ensure you have disabled all your antivirus and antispyware programs. Ensure they aren't temporarily disabled, but that they will stay disabled on a reboot if CF needs to reboot and continue running (pretty typical).

Then, see this page for links and instructions to download RKill. Use the first link in the list to try rkill.com. Save it to your desktop. Double-click it to run it. If the rkill window pops up and goes away, it didn't 'stick'. Try it again. and again, and again in rapid succession. If you get an antivirus warning (even a fake one), read the instructions in the thread. If you try it about 20 times in a row, stop, delete it, and proceed down the list (rkill.exe, rkill.scr, eXplorer.exe, etc.) You'll know it will stick as you'll see the window stay open and a log file will pop up. Once it 'sticks' and completes running, immediately download and save combofix again. Save it as shawnito.exe this time instead of etavaresCF.exe and run it as before. Don't reboot or waste any time as things will reload if you reboot.

Did that work? If not, we have other options.

Edited by etavares, 20 February 2011 - 06:00 PM.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#7 Shawnito

Shawnito
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 20 February 2011 - 06:20 PM

Thanks for the reply.

RKill ran successfully but ComboFix repeated the load then crash, despite renaming the file.

#8 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:42 AM

Posted 21 February 2011 - 09:40 AM

Hello, Shawnito.
OK, one more try with Combofix, but different from before. By crash, I'm assuming it just stops and there's no error message? If this doesn't work, we'll do another approach.

First, run Rkill as before.



Please print these instructions first!

If you have downloaded Combofix, please delete it and download again from one of these links and save to your desktop.
IMPORTANT: When prompted to save the file from the link, please save it as CFix.exe


Now please run ComboFix using these instructions:

  • Close all applications and windows (including this one) so that you have nothing open and are at your Desktop.
  • Go to Start -> Run...
  • Open notepad and copy/paste the text in the quotebox below into it:

    KillAll::

  • Save this as CFScript.txt, in the same location as CFix.exe
    Posted Image
  • Refering to the picture above, drag CFScript into CFix.exe
  • If it prompts you do download and install the Microsoft Windows Recovery Console please WAIT and do NOT click ok yet , first:
    • Go to Start -> Control Panel -> Network and Internet Connections -> Network Connections
    • Right-click your default connection, usually Local Area Connection or Dial-up Connection (if you are using dial-up), and left-click Repair
    • Once done, click Close and exit the Network Connections window.
    • Now click OK in order to let ComboFix download the Recovery Console.
    • When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • When the RC is successfully installed, click Yes to continue scanning for malware.
  • When finished, ComboFix shall produce a log for you (located at C:\ComboFix.txt). Post the entire contents of that report in your next reply for further review, and so we may continue cleansing the system.

Note: After running Combofix, you may receive an error about "illegal operation on a registry key that has been marked for deletion." If you receive this error, please reboot and it should disappear.

etavares


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#9 Shawnito

Shawnito
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 21 February 2011 - 06:28 PM

etavares,

your description of the ComboFix crash is correct. The program simply stops running with no message of any kind. The second approach at running ComboFix also led to an identical crash. Thanks!

Shawn

#10 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:42 AM

Posted 22 February 2011 - 06:22 PM

Hello, Shawnito.

OK, let's look at one file, delete another manually and see if that helps.

if it doesn't...do you have access to a clean computer and a flash drive? We can create a bootable USB to allow us to run our tools and clean up.

Also, if you have a clean computer, do you have access to a CD burner? We can create a bootable antivirus CD as well.





Step 1

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please click this link-->Jotti

When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.

c:\program files\bonjour\bonjour.resources\en_gb.lproj\bonjourabout27991.exe
c:\program files\ageia technologies\v2.8.1\libraryphysxcore.exe


Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/



Step 2

Use Windows Explorer to find and delete these item(s) if they are still present.

Files:
c:\users\shawn lynch\appdata\local\ozimejes.dll
c:\windows\temp\skaq.tmp\setup.exe
c:\windows\temp\0.6315935161332374.exe
c:\users\shawnl~1\appdata\local\temp\shibmurkd\hralakusika.exe



As an example:
To delete C:\WINDOWS\badfile.dll
Double click the My Computer icon on your Desktop. Or click on the Windows KEY + E.
Double click on Local Disc (C:\)
Double click on the Windows folder,
Right click on badfile.dll and then from the menu that appears, click on Delete




Step 3


Let's try an online scan. I'm thinking it won't work, but it's worth a shot.

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image

etavares


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#11 Shawnito

Shawnito
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 22 February 2011 - 08:13 PM

etavares,

the two files you asked me to scan were not in the file locations you stated so I wasn't able to find them and scan them. As for the files to delete, two weren't there, I deleted the last one, and the first file (c:\users\shawn lynch\appdata\local\ozimejes.dll) claimed I didn't have permission to alter it. Just for fun, I analyzed that file with Jotti and it found a bunch of malware/viruses. The Jotti log for that file is below. Finally, I do have access to a clean computer with a CD burner so I can do that no problem.

[ArcaVir]
2011-02-22 Found nothing
[G DATA]
2011-02-23 Gen:Variant.Kazy.3281
[Avast! antivirus]
2011-02-22 Win32:MalOb-DT
[Ikarus]
2011-02-22 Trojan-Spy.Win32.Zbot
[Grisoft AVG Anti-Virus]
2011-02-22 Hiloti.CA
[Kaspersky Anti-Virus]
2011-02-22 Trojan-Downloader.Win32.Mufanom.aqda
[Avira AntiVir]
2011-02-22 TR/Crypt.XPACK.Gen
[ESET NOD32]
2011-02-22 Found nothing
[Softwin BitDefender]
2011-02-22 Gen:Variant.Kazy.3281
[Panda Antivirus]
2011-02-22 Found nothing
[ClamAV]
2011-02-23 Found nothing
[Quick Heal]
2011-02-22 Found nothing
[CPsecure]
2011-02-22 Found nothing
[Sophos]
2011-02-23 Mal/Hiloti-D
[Dr.Web]
2011-02-23 Trojan.Hiloti.2
[VirusBlokAda VBA32]
2011-02-22 Found nothing
[Frisk F-Prot Antivirus]
2011-02-22 Found nothing
[VirusBuster]
2011-02-22 Trojan.Hiloti.Gen!Pac.2
[F-Secure Anti-Virus]
2011-02-22 Gen:Variant.Kazy.3281

#12 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:42 AM

Posted 23 February 2011 - 06:30 PM

OK, let's use the AntiVir Rescue CD. Follow the instructions in that thread to make the CD on your clean computer, then boot the infected computer from it. Save the log after scanning and post it here. (You'll need to reboot normally at that point). We'll remove the files it quarantined after that.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#13 Shawnito

Shawnito
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 24 February 2011 - 04:09 PM

etavares,

I successfully ran the diagnostic from the CD-ROM. I actually ran it twice because the CD transposed the names of my disk drives (i.e. the C: was labeled D: and vice versa) and I couldn't find the log file the first time because I was looking in the wrong drive folders. I attached both logs below though the second one is many of the same files only renamed by the program. My computer has, however, developed a major problem. I am using a Dell Inspiron 1520 and the keyboard is entirely non-functioning in windows. I ran the boot diagnostics and the keyboard passed all tests. The keyboard also works in diagnostic modes. I an use the on-screen keyboard. I don't know what to do about that.


Avira / Linux Version 1.9.152.0
Copyright (c) 2010 by Avira GmbH
All rights reserved.
engine set:         8.2.4.170
VDF Version:        7.11.3.205
Scan start time: Thu Feb 24 01:27:31 2011
configuration file: /etc/avira/scancl.conf

ALERT: [TR/Diple.ua] /media/Devices/sda3/$Recycle.Bin/S-1-5-21-1249859320-1213524460-3051424315-1000/$RLJYN02.exe <<< Is the Trojan horse TR/Diple.ua [renamed]
ALERT: [TR/Dldr.WMA.Wimad.X] /media/Devices/sda3/$Recycle.Bin/S-1-5-21-1249859320-1213524460-3051424315-1000/$R964ITD.wma <<< Is the Trojan horse TR/Dldr.WMA.Wimad.X [renamed]
ALERT: [TR/Crypt.ZPACK.Gen] /media/Devices/sda3/Program Files/Adobe/Adobe Illustrator CS3/Cool Extras/Templates/Inspiration/Spa/BusinessCard5432.exe <<< Is the Trojan horse TR/Crypt.ZPACK.Gen [renamed]
ALERT: [TR/Crypt.ZPACK.Gen] /media/Devices/sda3/Program Files/Adobe/Reader 8.0/Reader/plug_ins/ImageViewer/en_US/ViewerSVGRSRC.exe <<< Is the Trojan horse TR/Crypt.ZPACK.Gen [renamed]
WARNING: [Unexpected end of file] /media/Devices/sda3/Program Files/AltoMP3 Gold/uninst.exe
ALERT: [TR/Crypt.ZPACK.Gen] /media/Devices/sda3/Program Files/Apple Software Update/SoftwareUpdate.Resources/UpdatetSoftware.exe <<< Is the Trojan horse TR/Crypt.ZPACK.Gen [renamed]
WARNING: [Archive is invalid or corrupt] /media/Devices/sda3/Program Files/WinRAR/rarnew.dat
ALERT: [TR/Crypt.ZPACK.Gen] /media/Devices/sda3/Program Files/QuickTime/QTSystem/QuickTimeMPEG4.Resources/nb.lproj/QuickTimeQuickTimeResources.exe <<< Is the Trojan horse TR/Crypt.ZPACK.Gen [renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/230647.exe <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Code.taf.6] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/230648.exe <<< Is the Trojan horse TR/Code.taf.6 [archive scan abort][renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/233861.exe <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Code.taf.6] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/233862.exe <<< Is the Trojan horse TR/Code.taf.6 [archive scan abort][renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/Temp/0.36896830821808846.exe <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Diple.ua] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/Temp/8.500762024358503E8.exe <<< Is the Trojan horse TR/Diple.ua [renamed]
ALERT: [EXP/Pidief.Cru.2] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/Temp/plugtmp-8/plugin-fnbmjrhukuhwf.pdf <<< Contains signature of the exploits EXP/Pidief.Cru.2 [archive scan abort][renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda3/Users/Shawn Lynch/AppData/Local/ozimejes.dll <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [Java/Dldr.Agen.AG.2] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/14/731a3a4e-48febc4d --> AppletX.class <<< Contains signature of the Java virus JAVA/Dldr.Agen.AG.2 [archive scan abort]
ALERT: [TR/Horse.TJH] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/19/1cb06393-3690fc75 --> sunny/Changes.class <<< Is the Trojan horse TR/Horse.TJH [archive scan abort]
ALERT: [Java/Agent.HN] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/20/5bcb2454-70736371 --> bpac/a.class <<< Contains signature of the Java virus JAVA/Agent.HN [archive scan abort]
ALERT: [Java/Agent.DS] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/26/3036fb1a-385e870f --> dev/s/AdgredY.class <<< Contains signature of the Java virus JAVA/Agent.DS [archive scan abort]
ALERT: [JAVA/OpenStrem.BN.2] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/36/535872a4-10d85dad --> myf/y/AppletX.class <<< Contains signature of the Java virus JAVA/OpenStrem.BN.2 [archive scan abort]
ALERT: [EXP/CVE-2010-0842.A] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/41/1763d7e9-2d4c5a29 --> vmain.class <<< Contains signature of the exploits EXP/CVE-2010-0842.A [archive scan abort]
ALERT: [EXP/CVE-2009-3869.A] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/45/64d634ad-70ac366f --> vmain.class <<< Contains signature of the exploits EXP/CVE-2009-3869.A [archive scan abort]
ALERT: [Java/Agent.G] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/45/667bb02d-5a8918dd --> myf/y/AppletX.class <<< Contains signature of the Java virus JAVA/Agent.G [archive scan abort]
ALERT: [EXP/CVE-2009-3867.GM] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/56/412339b8-361a4cda --> vmain.class <<< Contains signature of the exploits EXP/CVE-2009-3867.GM [archive scan abort]
ALERT: [EXP/CVE-2008-5353.RC] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/63/4052083f-26eadddb --> vload.class <<< Contains signature of the exploits EXP/CVE-2008-5353.RC [archive scan abort]
ALERT: [Java/Agent.O.2] /media/Devices/sda3/Users/Shawn Lynch/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/7/650a1207-7bd014b8 --> C.class <<< Contains signature of the Java virus JAVA/Agent.O.2 [archive scan abort]
ALERT: [TR/Code.taf.6] /media/Devices/sda3/Users/Shawn Lynch/AppData/Roaming/hotfix.exe <<< Is the Trojan horse TR/Code.taf.6 [archive scan abort][renamed]
WARNING: [Archive is invalid or corrupt] /media/Devices/sda3/Users/Shawn Lynch/Desktop/New WinRAR archive.rar
WARNING: [Unsupported archive version] /media/Devices/sda3/Users/Shawn Lynch/OOo_2.3.0_Win32Intel_install_wJRE_en-US.exe
ALERT: [TR/Dldr.WMA.Wimad.X] /media/Devices/sda3/Users/Shawn Lynch/Music/Arcade Fire - Neighborhoods.wma <<< Is the Trojan horse TR/Dldr.WMA.Wimad.X [renamed]
ALERT: [TR/Spy.Agent.blbk.1] /media/Devices/sda3/Windows/assembly/GAC_MSIL/Desktop.ini <<< Is the Trojan horse TR/Spy.Agent.blbk.1 [renamed]
WARNING: [Unexpected end of file] /media/Devices/sda3/Windows/Downloaded Program Files/unagiuninst.exe
ALERT: [HTML/Fraud.DI] /media/Devices/sda3/Windows/System32/config/systemprofile/AppData/Local/Bcuwedi.dat <<< Contains signature of the HTML script virus HTML/Fraud.DI [renamed]
ALERT: [JS/Agent.psa.20] /media/Devices/sda3/Windows/System32/config/systemprofile/AppData/Local/Microsoft/Windows/Temporary Internet Files/Content.IE5/CPSUOV64/index[1].htm <<< Contains signature of the Java script virus JS/Agent.psa.20 [renamed]
ALERT: [HTML/FakeAlert.lok] /media/Devices/sda3/Windows/System32/config/systemprofile/AppData/Local/Microsoft/Windows/Temporary Internet Files/Content.IE5/CPSUOV64/yh[1].htm <<< Contains signature of the HTML script virus HTML/FakeAlert.lok [renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda3/Windows/System32/config/systemprofile/AppData/Local/orveHE.dll <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [Java/Agent.DS.1] /media/Devices/sda3/Windows/System32/config/systemprofile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/43/261030ab-4742509b --> dev/s/AdgredY.class <<< Contains signature of the Java virus JAVA/Agent.DS.1 [archive scan abort]
ALERT: [TR/FraudPack.bepr] /media/Devices/sda3/Windows/System32/config/systemprofile/AppData/Roaming/alggui.exe <<< Is the Trojan horse TR/FraudPack.bepr [renamed]
ALERT: [TR/Rootkit.Gen] /media/Devices/sda3/Windows/System32/drivers/kbdclass.sys <<< Is the Trojan horse TR/Rootkit.Gen [renamed]
ALERT: [TR/Spy.53248.458] /media/Devices/sda3/Windows/System32/FastUv32.dll <<< Is the Trojan horse TR/Spy.53248.458 [renamed]
ALERT: [TR/Scar.bxjl.1] /media/Devices/sda3/Windows/System32/sysservice1.exe <<< Is the Trojan horse TR/Scar.bxjl.1 [renamed]
ALERT: [RKIT/Sirefef.D.4] /media/Devices/sda3/Windows/winsxs/x86_Microsoft.Windows.Shell.HWEventDetector_6595b64144ccf1df_5.2.2.3_x-ww_5390e909/shsvcs.dll <<< Contains signature of Rootkits RKIT/Sirefef.D.4 [renamed]

Attached Files


Edited by etavares, 24 February 2011 - 06:40 PM.
paste results of scan


#14 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:42 AM

Posted 24 February 2011 - 06:45 PM

Hello, Shawnito.

The keyboard driver was patched by a virus and removed by AntiVir. Let's look for a clean copy and see if we can replace it. We may need to do this outside of Windows, but let's try here first. I also need to warn you about Rootkits.

Backdoor Warning
One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you do decide to proceed, please continue with the fix below.



Step 1

Download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

If you have a 64-bit system, please download the 64 bit version from here:
SystemLook (64-bit)

  • Double-click SystemLook.exe to run it.
  • A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff".
  • Copy and Paste the content of the following codebox into the main textfield under "File":
    :filefind
    kbdclass.*
    
  • Please Confirm everything is copied and Pasted as I have provided above
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan.
  • Please post this log in your next reply.


Note: The log can also be found on your Desktop entitled SystemLook.txt
2nd Note: The scan may take a while from several seconds to a minute or more depending on the number of files you have and how fast your computer can perform the task


etavares


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#15 Shawnito

Shawnito
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:42 AM

Posted 24 February 2011 - 10:44 PM

etavares,

for now, lets continue with the fix. I will make sure to alert our banks to the danger. Here is the Systemlook log. Is there any way to get the keyboard driver in the meantime?

SystemLook 04.09.10 by jpshortstuff
Log created at 19:10 on 24/02/2011 by Shawn Lynch
Administrator - Elevation successful

========== filefind ==========

Searching for "kbdclass.*"
C:\Windows\SoftwareDistribution\Download\df81987ce1972154ab659b2f560f1610\x86_keyboard.inf_31bf3856ad364e35_6.0.6001.18000_none_974e6dd8d8f8ec7e\kbdclass.sys --a---- 35384 bytes [21:36 23/09/2008] [07:41 19/01/2008] 37605E0A8CF00CBBA538E753E4344C6E
C:\Windows\System32\drivers\kbdclass.sys.vir --a---- 35384 bytes [18:11 21/10/2009] [03:41 19/01/2008] 390D6489CF16D5386B6C84284E1C6DFB
C:\Windows\System32\drivers\en-US\kbdclass.sys.mui --a---- 4608 bytes [12:38 02/11/2006] [12:38 02/11/2006] 69A5D812DA82E2236BF5A00E977E3E5C
C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_93b1c41f\kbdclass.sys --a---- 32872 bytes [10:25 02/11/2006] [09:49 02/11/2006] 1A48765F92BA1A88445FC25C9C9D94FC
C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_a81145df\kbdclass.sys --a---- 35384 bytes [08:14 14/02/2008] [08:14 14/02/2008] B076B2AB806B3F696DAB21375389101C
C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_da7e599e\kbdclass.sys --a---- 35384 bytes [18:11 21/10/2009] [03:41 19/01/2008] 37605E0A8CF00CBBA538E753E4344C6E
C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_f55d5e51\kbdclass.sys --a---- 35384 bytes [18:11 21/10/2009] [03:41 19/01/2008] 37605E0A8CF00CBBA538E753E4344C6E
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_2c720f8d6f7323d4\kbdclass.sys.mui --a---- 4608 bytes [12:38 02/11/2006] [12:38 02/11/2006] 69A5D812DA82E2236BF5A00E977E3E5C
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_ar-sa_982bf1fdaa2cfde6\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] 45190983C75D892CCDD4834F09DCEE14
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_cs-cz_e9754a2188352b68\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] 5C66636BBC99C406E8DB2EBE3C250E24
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_da-dk_86af2a487e7b2767\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] 64850C48023D1F36671216088F1577B2
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_de-de_83dabf8480517c01\kbdclass.sys.mui --a---- 5632 bytes [08:14 14/02/2008] [08:14 14/02/2008] D60B9C38273A97F14431679C63507184
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_el-gr_2c70ed176f66e48f\kbdclass.sys.mui --a---- 6144 bytes [08:14 14/02/2008] [08:14 14/02/2008] 63F99369155876F698B251989F86205E
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_en-us_2ccb957d6f2f87c6\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] BEE6D87D0AAC1C0E639DD4BE4CB05024
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_es-es_2c96f2616f56796b\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] A899EC8ECAB2A5F1B4240901772FDA34
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_fi-fi_cbb1f70e64706b95\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] 9C63C3593304E5C3D5003CF5C974B6C1
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_fr-fr_cf4e686062288fcd\kbdclass.sys.mui --a---- 5632 bytes [08:14 14/02/2008] [08:14 14/02/2008] 404544824FCEF54AE17F2739A07FCE83
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_he-il_136e1002489790bb\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] 5823AACA41FFD613A9D83A1A460BF5FB
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_hu-hu_16bee8a846885ee9\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] 67D97A8C3497AA1B9A16BB4D864802BC
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_it-it_b9765ea7395a754b\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] 21D1A0DF1117B20CA4D876959B1FE3E3
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_ja-jp_5b9bddb42c758726\kbdclass.sys.mui --a---- 4096 bytes [08:14 14/02/2008] [08:14 14/02/2008] 151CEAD6D2DE0109150A2C6BDA20E354
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_ko-kr_ff05ba691ee64e3c\kbdclass.sys.mui --a---- 4096 bytes [08:14 14/02/2008] [08:14 14/02/2008] 9E5CE928E2FCAA35FDE877CF3D8E73B7
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_nb-no_e7983b9df70b79f8\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:15 14/02/2008] 8475390D112F5377E6131A0009C1FF8B
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_nl-nl_e5d786dbf83783cd\kbdclass.sys.mui --a---- 5632 bytes [08:15 14/02/2008] [08:15 14/02/2008] 517497F7C4AC3219882454600AC8F92B
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_pl-pl_2c13e15ddd59f181\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] 4C52C6741A6199D756C463966DA1DD08
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_pt-br_2e67cc01dbe38565\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] 0E3CF2840FFCF864A1C1FD55D63B3838
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_pt-pt_2f499b6ddb52f541\kbdclass.sys.mui --a---- 5632 bytes [08:15 14/02/2008] [08:15 14/02/2008] 3B2B979CACA04268C75B4B8235961511
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_ru-ru_75ecad31c034836d\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] 764092540B76BE70D2E2B680878282E9
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_sv-se_11e797a6b75d8dc8\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] 54A8D4D73A290DA5DDEF551FA850A5DD
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_tr-tr_baf4e1eda6198fb9\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] 7FEC310A14B9145206919EA7E5B3ED7A
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_zh-cn_8c51ffeb565161d8\kbdclass.sys.mui --a---- 3584 bytes [08:15 14/02/2008] [08:15 14/02/2008] E1FB9F5510379F8B1B22B2F677242F35
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.16609_zh-tw_904e3d4153c23e48\kbdclass.sys.mui --a---- 3584 bytes [08:15 14/02/2008] [08:15 14/02/2008] 853CDA44EFFB5A19464388823ADE8F14
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_ar-sa_98901d92c36772d0\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] FA5E8B274DB99B89392B98CFADCDEE04
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_cs-cz_e9d975b6a16fa052\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] 1B6B540117C1AFDB9C51D230DD81CFBD
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_da-dk_871355dd97b59c51\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] 0E52245E966112DB881DF64C14EF5AD4
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_de-de_843eeb19998bf0eb\kbdclass.sys.mui --a---- 5632 bytes [08:14 14/02/2008] [08:14 14/02/2008] E336FA755BFBAB1D5C239A1A02063279
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_el-gr_2cd518ac88a15979\kbdclass.sys.mui --a---- 6144 bytes [08:14 14/02/2008] [08:14 14/02/2008] 476B0FE6DE853EA26E3E37780135CAEA
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_en-us_2d2fc1128869fcb0\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] A33543C00396091B942D560374CD3E04
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_es-es_2cfb1df68890ee55\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] 9BC15C6F6ED8C0362C38D1C46DFFF679
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_fi-fi_cc1622a37daae07f\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] 6914A8E6184C41E22EFC67211202053D
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_fr-fr_cfb293f57b6304b7\kbdclass.sys.mui --a---- 5632 bytes [08:14 14/02/2008] [08:14 14/02/2008] 28B18A8A56E231831E6B5BB56AFB9ECA
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_he-il_13d23b9761d205a5\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] 767CFBFED83226E1531FAEAE1002398D
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_hu-hu_1723143d5fc2d3d3\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] 2A52F4886DF1046FFD049ADDF509A882
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_it-it_b9da8a3c5294ea35\kbdclass.sys.mui --a---- 5120 bytes [08:14 14/02/2008] [08:14 14/02/2008] 2F4643E92F10B8D0CFD336B90F9F9014
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_ja-jp_5c00094945affc10\kbdclass.sys.mui --a---- 4096 bytes [08:14 14/02/2008] [08:14 14/02/2008] E85D18767FAD4548DCC1A482CC566287
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_ko-kr_ff69e5fe3820c326\kbdclass.sys.mui --a---- 4096 bytes [08:14 14/02/2008] [08:14 14/02/2008] 46C6F5BE892EE3A613E615752D77EE10
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_nb-no_e7fc67331045eee2\kbdclass.sys.mui --a---- 4608 bytes [08:14 14/02/2008] [08:14 14/02/2008] F82D25634F9C4B8F0F040B9B8893761A
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_nl-nl_e63bb2711171f8b7\kbdclass.sys.mui --a---- 5632 bytes [08:15 14/02/2008] [08:15 14/02/2008] E859900D8D8861DE0532127915D47A4E
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_pl-pl_2c780cf2f694666b\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] C8C961C007C69E7DBCAD6F0E248DABC5
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_pt-br_2ecbf796f51dfa4f\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] 9D6C395DC3518532D6F54B125DA98E91
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_pt-pt_2fadc702f48d6a2b\kbdclass.sys.mui --a---- 5632 bytes [08:15 14/02/2008] [08:15 14/02/2008] C2E0AE807934438618F5DBE1EFFEDC55
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_ru-ru_7650d8c6d96ef857\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] A3FAA588EAC25B685E46F8F070A7A842
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_sv-se_124bc33bd09802b2\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] F8ED42E9F0D10A6FCE79E7F4DF1C197D
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_tr-tr_bb590d82bf5404a3\kbdclass.sys.mui --a---- 5120 bytes [08:15 14/02/2008] [08:15 14/02/2008] 3D370EDB5A572709DAACD77DBD1639A7
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_zh-cn_8cb62b806f8bd6c2\kbdclass.sys.mui --a---- 3584 bytes [08:15 14/02/2008] [08:15 14/02/2008] 534972FFE765037DA235253B80F32EC7
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6000.20734_zh-tw_90b268d66cfcb332\kbdclass.sys.mui --a---- 3584 bytes [08:15 14/02/2008] [08:15 14/02/2008] 617521218377A7B6384F299A82366872
C:\Windows\winsxs\x86_keyboard.inf.resources_31bf3856ad364e35_6.0.6001.18000_en-us_2ea8d1896c5e34a8\kbdclass.sys.mui --a---- 4608 bytes [12:38 02/11/2006] [12:38 02/11/2006] 69A5D812DA82E2236BF5A00E977E3E5C
C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.0.6000.16609_none_957131ccdbca3f9c\kbdclass.sys --a---- 35384 bytes [08:14 14/02/2008] [08:14 14/02/2008] B076B2AB806B3F696DAB21375389101C
C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.0.6000.20734_none_95d55d61f504b486\kbdclass.sys --a---- 35384 bytes [08:14 14/02/2008] [08:14 14/02/2008] C9B0CF786D5F151A43C7BE8E243F2819
C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.0.6001.18000_none_974e6dd8d8f8ec7e\kbdclass.sys --a---- 35384 bytes [18:11 21/10/2009] [03:41 19/01/2008] 37605E0A8CF00CBBA538E753E4344C6E
C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.0.6002.18005_none_9939e6e4d61ab7ca\kbdclass.sys --a---- 35384 bytes [18:11 21/10/2009] [03:41 19/01/2008] 37605E0A8CF00CBBA538E753E4344C6E

-= EOF =-




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users